GDPR and Email Marketing: What EU Businesses Need to Know
The General Data Protection Regulation has been in force since May 2018, but misunderstandings about what it requires for email marketing persist. Some businesses overcomplicate their compliance posture; others underestimate what's required and expose themselves to regulatory risk.
This article covers what GDPR actually says about email marketing, what a compliant workflow looks like, and how email verification fits into it.
What GDPR requires for email marketing
GDPR doesn't prohibit email marketing. It regulates the basis on which you can send it. For direct marketing to individuals, the relevant legal bases are:
Consent (Article 6(1)(a))
The most commonly cited basis for email marketing. Under GDPR, valid consent must be:
- Freely given — the person had a genuine choice and was not coerced or required to consent as a condition of service
- Specific — consent to receive marketing emails is separate from consent to terms of service, privacy policy, or other purposes
- Informed — the person understood what they were consenting to, from whom, and for what purpose
- Unambiguous — given by a clear affirmative action (e.g. ticking a box), not by a pre-ticked box or silence
Crucially, consent must be as easy to withdraw as it was to give. An unsubscribe link in every email is not optional — it's legally required for consent-based sends.
Legitimate interests (Article 6(1)(f))
Legitimate interests is a flexible basis that may apply to B2B marketing in some circumstances. The logic: a business may have a legitimate interest in contacting other businesses about relevant products or services, provided that interest is balanced against the recipient's rights and interests.
Legitimate interests does not work well for consumer marketing. It works better for B2B communications where there is a plausible commercial relationship or genuine relevance to the recipient's role.
Using legitimate interests requires a documented Legitimate Interests Assessment (LIA) — you must be able to show you've considered whether the processing is necessary, proportionate, and not overridden by the recipient's interests.
The ePrivacy Directive (also relevant)
Alongside GDPR, the ePrivacy Directive (sometimes called the "Cookie Law," though it covers more than cookies) specifically addresses unsolicited electronic communications. In most EU member states, this directive requires prior consent for direct marketing emails to individuals.
The interaction between GDPR and ePrivacy is sometimes confusing. The practical summary: for marketing emails to individual consumers in the EU, consent under GDPR is necessary but may not be sufficient — ePrivacy rules in the specific member state may impose additional requirements.
What GDPR requires you to record
It's not enough to obtain consent — you must be able to prove it. Required records for consent-based email marketing include:
- When the person consented
- What they consented to (the exact wording they saw)
- How they consented (the mechanism used)
- Which version of your privacy notice was in place at the time
This is why pre-checked boxes, verbal consent, and informal "sign here" approaches don't work under GDPR — they don't produce a verifiable record.
If you can't prove someone consented, you can't rely on consent as your legal basis. If a supervisory authority (like the Dutch Autoriteit Persoonsgegevens or the UK ICO) asks for evidence of consent, you need to be able to provide it for any address on your list.
How long you can keep email addresses
GDPR doesn't specify a maximum retention period, but it requires that personal data isn't kept "longer than is necessary for the purpose for which it was collected."
For email marketing, this means:
- If someone unsubscribes, their address should be removed from your marketing list — but you may retain it on a suppression list to ensure you don't accidentally re-add them
- If you haven't mailed someone in a long time (typically 12–24 months, depending on your stated purpose) and they haven't engaged, it becomes harder to justify continuing to hold and use their address for marketing
- Old lists acquired from third parties where consent records don't exist cannot be used for marketing in the EU
Practical rule: If you can't demonstrate recent engagement or recent consent, the address should be removed from your active marketing database or re-confirmed before use.
Subject access requests and the right to erasure
Under GDPR, individuals have the right to:
- Request access to the personal data you hold about them (a Subject Access Request, or SAR)
- Request that their data be erased (the "right to be forgotten")
- Request correction of inaccurate data
For email marketing, the most common request is erasure. When you receive a deletion request:
- Remove the email address from all marketing lists
- Delete associated profile data unless there's another legal basis to retain it (e.g. transaction records for tax purposes)
- Retain the email address on a suppression list (without other personal data) to prevent re-adding them if you receive the contact again
The suppression list retention is specifically allowed by GDPR's legitimate interests basis — it's necessary to comply with the person's original opt-out request.
Data processing agreements for email service providers
When you use an email service provider (ESP) like Mailchimp, Klaviyo, or Sendgrid, your subscribers' data is processed by a third party. Under GDPR, this requires a Data Processing Agreement (DPA).
Most reputable ESPs offer DPAs as a standard part of their terms of service for EU customers, or on request. If yours doesn't offer one, that's a red flag. Sending subscriber data to an ESP without a DPA in place is a GDPR compliance gap.
Check that your ESP:
- Signs a DPA with you (or publishes a standard DPA you accept)
- Is transparent about where subscriber data is stored (EU-hosted or covered by SCCs for US-hosted services)
- Maintains appropriate security certifications
Email verification and GDPR
Email verification is a processing activity under GDPR — you're sending personal data (email addresses) to a third-party service to be checked against mail servers.
What this means in practice:
Use an EU-hosted verification service — if your subscribers are EU residents, their email addresses are personal data. Using a verification service that processes data outside the EU requires that service to have adequate data protection measures in place (SCCs, Binding Corporate Rules, or adequacy decision).
Include verification in your privacy notice — your privacy policy should describe what you do with subscriber data, including that addresses may be verified for accuracy. This is straightforward to add and most subscribers would expect it.
Don't store verification results as permanent profiles — verification tells you whether an address is deliverable. It shouldn't be used to build a richer profile of the individual.
StopBouncing processes email addresses solely for deliverability checking and does not use them for any other purpose. The service is designed to be used in a GDPR-compliant workflow.
Common GDPR mistakes in email marketing
Re-using old lists without re-confirmation — lists collected before GDPR (or where consent records are unclear) cannot simply be carried over. Old lists need to be re-confirmed or deleted.
Using pre-ticked boxes — still seen frequently. Pre-ticked consent boxes do not constitute valid consent under GDPR.
Bundled consent — asking someone to consent to marketing at the same time as accepting terms and conditions, with no separate opt-in. Each purpose needs its own consent mechanism.
No suppression list — removing unsubscribed addresses from a list without maintaining a suppression record means they can be re-added in the future (through a new sign-up, a CRM import, etc.), violating their original opt-out.
Ignoring SARs — Subject Access Requests must be responded to within one month. Ignoring them is a regulatory compliance failure.
Using third-party data without adequate DPAs — purchasing a B2B contact list and mailing it without verifying the DPA chain (how the data was collected, what consent exists) is high-risk.
What a GDPR-compliant email marketing workflow looks like
- Collect consent with a clear, specific opt-in — explicit checkbox, no pre-ticking, clearly labelled purpose
- Record consent — timestamp, consent text version, IP address
- Send a confirmation email (double opt-in) — confirms the address is real and the person intentionally signed up
- Process email data under a DPA — signed agreement with your ESP and any verification services
- Verify addresses before sending — catches invalid addresses and protects deliverability
- Include an unsubscribe link in every marketing email — legally required
- Process opt-outs immediately — add to suppression list, remove from active marketing list
- Respond to SARs within one month — provide or delete data as requested
- Review and purge old data — remove addresses you can no longer justify retaining
Summary
GDPR requires consent for consumer email marketing — specific, informed, freely given, and documented. It doesn't prohibit email marketing, and it doesn't make it impossible. It makes it harder to cut corners.
The businesses that find GDPR difficult are usually the ones that relied on practices that were already questionable before the regulation: buying lists, adding people without consent, re-using old data without re-confirmation. For businesses that built their lists properly, compliance is largely a matter of documentation and process.
Email verification fits naturally into a GDPR-compliant workflow — it processes addresses briefly for a legitimate purpose (ensuring messages are deliverable) and doesn't create any additional compliance risk when done with a service that operates appropriate data protection standards.
Ready to clean your email list?
Verify thousands of addresses in minutes. No subscription — pay only for what you use.