GDPR and Email Extraction: What You Need to Know
On this page
Why GDPR Matters for Extracted Email Addresses
The General Data Protection Regulation (GDPR) governs how personal data of individuals in the European Economic Area (EEA) and the UK is collected, stored and used. An email address is personal data under GDPR, regardless of how it was obtained.
Extracting email addresses from files, documents or web pages does not automatically violate GDPR. Collecting and extracting personal data is itself processing. Establish a lawful basis and purpose before extraction, and assess your later use separately.
Email Extractor is a client-side tool that processes files in your browser. The extraction itself is a local operation. GDPR obligations arise when you store, organise or act on the extracted addresses.
Lawful Bases for Processing
GDPR requires a lawful basis before you process personal data. For extracted email addresses, three bases are most commonly relevant:
Consent. The data subject has given clear, affirmative consent for a specific purpose. This is the strongest basis for marketing emails. Consent must be freely given, specific, informed and unambiguous. Pre-ticked boxes and implied consent do not qualify.
Legitimate interest. You have a genuine business reason to contact someone, and this interest is not overridden by the individual's rights. B2B outreach to a company's publicly listed contact address may fall under legitimate interest, but you must conduct a Legitimate Interest Assessment (LIA) and document your reasoning.
Contract performance. Processing is necessary to fulfil a contract with the data subject, or to take steps at their request before entering a contract. This applies when someone has already engaged with your business and you need their email to deliver what was agreed.
Note that extracting an address from a public source does not create consent. A company publishing its team's email addresses on a contact page does not mean those individuals consented to receive marketing from third parties.
What GDPR Requires in Practice
Documentation
Keep a record of where each email address came from and what lawful basis you are relying on. When you download results from Email Extractor as CSV with sources, the source column shows which file each address was extracted from. Save this alongside your processing records.
Purpose limitation
Use extracted addresses only for the purpose you documented. If you extracted addresses from conference attendee lists to follow up on a specific event, do not add those addresses to a general marketing newsletter without separate justification.
Data minimisation
Extract and retain only the addresses you actually need. If you are looking for procurement contacts at a company, do not store every address from their entire website.
Storage limitation
Do not keep extracted addresses indefinitely. Set a review period and delete addresses you no longer need. If someone never responds to your outreach, continuing to store their address requires ongoing justification.
Right to be informed
When you contact someone whose address you extracted, tell them where you got their address and why you are contacting them. This is required under Articles 13 and 14 of GDPR. For data not obtained directly from the data subject, you must provide this information within a reasonable period and no later than one month.
Right to object and erasure
Anyone can ask you to stop processing their data or to delete it. You must have a process for handling these requests and must respond within one month.
B2B vs B2C Considerations
GDPR applies to natural persons (individuals), not to companies. However, most B2B email addresses identify an individual (priya@example.com is personal data; info@example.com is less clear but may still be treated as personal data depending on context).
In the UK, assess PECR separately from your UK GDPR lawful basis. Corporate subscribers and individual subscribers have different rules; sole traders and some partnerships count as individual subscribers. Legitimate interests cannot replace consent where PECR requires consent. See the ICO business-to-business marketing guidance. Rules elsewhere depend on the relevant national law.
Check the specific rules for the country where the recipient is based, not where your business is located.
Practical Steps
Before extracting: Decide your purpose and lawful basis. If you are extracting addresses for marketing, determine whether you have consent or a documented legitimate interest.
During extraction: Use Email Extractor to process your files. Download results as CSV with sources to maintain provenance records.
After extraction: Review the list. Remove addresses that do not match your stated purpose. Remove personal addresses when you only need business contacts, and vice versa.
Before sending: Include your identity, the source of their address, and an unsubscribe mechanism in every message. If you are relying on legitimate interest for B2B outreach, state this clearly.
Ongoing: Honour opt-out requests promptly. Delete addresses you no longer need. Keep your processing records up to date.
What Email Extractor Does Not Do
Email Extractor extracts addresses from text and files. It does not verify whether an address is valid, check consent status, send messages, or manage opt-outs. These steps require separate tools and processes.
For information on verifying extracted addresses, see What Is Email Validation. For writing compliant outreach, see How to Write a Clear Outreach Email After Extraction.
Further Reading
- Official GDPR text
- ICO guide to lawful basis (UK Information Commissioner's Office)
- Email Extraction and Privacy: What You Should Know
- Client-Side vs Server-Side Email Extraction