Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

GDPR and Email Extraction: What You Need to Know

On this page

Why GDPR Matters for Extracted Email Addresses

The General Data Protection Regulation (GDPR) governs how personal data of individuals in the European Economic Area (EEA) and the UK is collected, stored and used. An email address is personal data under GDPR, regardless of how it was obtained.

Extracting email addresses from files, documents or web pages does not automatically violate GDPR. Collecting and extracting personal data is itself processing. Establish a lawful basis and purpose before extraction, and assess your later use separately.

Email Extractor is a client-side tool that processes files in your browser. The extraction itself is a local operation. GDPR obligations arise when you store, organise or act on the extracted addresses.

Lawful Bases for Processing

GDPR requires a lawful basis before you process personal data. For extracted email addresses, three bases are most commonly relevant:

Consent. The data subject has given clear, affirmative consent for a specific purpose. This is the strongest basis for marketing emails. Consent must be freely given, specific, informed and unambiguous. Pre-ticked boxes and implied consent do not qualify.

Legitimate interest. You have a genuine business reason to contact someone, and this interest is not overridden by the individual's rights. B2B outreach to a company's publicly listed contact address may fall under legitimate interest, but you must conduct a Legitimate Interest Assessment (LIA) and document your reasoning.

Contract performance. Processing is necessary to fulfil a contract with the data subject, or to take steps at their request before entering a contract. This applies when someone has already engaged with your business and you need their email to deliver what was agreed.

Note that extracting an address from a public source does not create consent. A company publishing its team's email addresses on a contact page does not mean those individuals consented to receive marketing from third parties.

What GDPR Requires in Practice

Documentation

Keep a record of where each email address came from and what lawful basis you are relying on. When you download results from Email Extractor as CSV with sources, the source column shows which file each address was extracted from. Save this alongside your processing records.

Purpose limitation

Use extracted addresses only for the purpose you documented. If you extracted addresses from conference attendee lists to follow up on a specific event, do not add those addresses to a general marketing newsletter without separate justification.

Data minimisation

Extract and retain only the addresses you actually need. If you are looking for procurement contacts at a company, do not store every address from their entire website.

Storage limitation

Do not keep extracted addresses indefinitely. Set a review period and delete addresses you no longer need. If someone never responds to your outreach, continuing to store their address requires ongoing justification.

Right to be informed

When you contact someone whose address you extracted, tell them where you got their address and why you are contacting them. This is required under Articles 13 and 14 of GDPR. For data not obtained directly from the data subject, you must provide this information within a reasonable period and no later than one month.

Right to object and erasure

Anyone can ask you to stop processing their data or to delete it. You must have a process for handling these requests and must respond within one month.

B2B vs B2C Considerations

GDPR applies to natural persons (individuals), not to companies. However, most B2B email addresses identify an individual (priya@example.com is personal data; info@example.com is less clear but may still be treated as personal data depending on context).

In the UK, assess PECR separately from your UK GDPR lawful basis. Corporate subscribers and individual subscribers have different rules; sole traders and some partnerships count as individual subscribers. Legitimate interests cannot replace consent where PECR requires consent. See the ICO business-to-business marketing guidance. Rules elsewhere depend on the relevant national law.

Check the specific rules for the country where the recipient is based, not where your business is located.

Practical Steps

  1. Before extracting: Decide your purpose and lawful basis. If you are extracting addresses for marketing, determine whether you have consent or a documented legitimate interest.

  2. During extraction: Use Email Extractor to process your files. Download results as CSV with sources to maintain provenance records.

  3. After extraction: Review the list. Remove addresses that do not match your stated purpose. Remove personal addresses when you only need business contacts, and vice versa.

  4. Before sending: Include your identity, the source of their address, and an unsubscribe mechanism in every message. If you are relying on legitimate interest for B2B outreach, state this clearly.

  5. Ongoing: Honour opt-out requests promptly. Delete addresses you no longer need. Keep your processing records up to date.

What Email Extractor Does Not Do

Email Extractor extracts addresses from text and files. It does not verify whether an address is valid, check consent status, send messages, or manage opt-outs. These steps require separate tools and processes.

For information on verifying extracted addresses, see What Is Email Validation. For writing compliant outreach, see How to Write a Clear Outreach Email After Extraction.

Further Reading

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)