GDPR Email Marketing Checklist: 15 Requirements You Cannot Ignore
On this page
Who GDPR Applies To
The General Data Protection Regulation applies if you process personal data of people in the European Economic Area (EEA), regardless of where your business is located. An email address is personal data under GDPR.
If you send emails to anyone in the EU, EEA or UK (which has its own equivalent, UK GDPR), these requirements apply to you.
The Checklist
1. Establish a lawful basis for processing
GDPR requires a legal basis for processing personal data. For email marketing, two bases are commonly used:
Consent: The person explicitly agreed to receive your emails. This is the safest basis for marketing to individuals.
Legitimate interest: You have a genuine business reason for contacting the person, and their rights do not override your interest. This can apply to B2B marketing in some EU member states, but you must conduct a legitimate interest assessment (LIA) and document it.
Do not assume legitimate interest covers everything. When in doubt, get consent.
2. Make consent specific and informed
Consent must be:
- Freely given: No pre-ticked boxes. No bundling consent with terms of service.
- Specific: Consent to receive marketing emails is separate from consent to process data for other purposes.
- Informed: The person must know who is collecting their data, why, and how it will be used.
- Unambiguous: A clear affirmative action (checking a box, clicking a button, typing their email into a specifically labelled field).
A vague "by using this site you agree to our communications" is not valid consent.
3. Record and store consent evidence
You must be able to demonstrate that consent was given. Record:
- When consent was given (timestamp).
- How consent was given (which form, which page, which checkbox text).
- What the person consented to (exact wording they agreed to).
- Who gave consent (email address and any other identifying information).
Keep these records for as long as you process the person's data.
4. Separate opt-ins for different purposes
Consent for a newsletter is not consent for product announcements. Consent for marketing emails is not consent for partner offers.
If you send different types of email, offer separate opt-in choices for each. Do not bundle them into a single checkbox.
5. Never use pre-ticked boxes
Under GDPR, silence and inactivity do not constitute consent. A pre-ticked checkbox on a form does not count as opt-in. The person must actively check the box themselves.
6. Allow easy withdrawal of consent
People can withdraw consent at any time. You must make it as easy to withdraw as it was to give. In practice:
- Include an unsubscribe link in every marketing email.
- The unsubscribe process should be one or two clicks, not a multi-step process requiring login.
- Process unsubscribes promptly (within a few days at most).
7. Honour data subject rights
Under GDPR, individuals have specific rights regarding their data. You must be prepared to handle:
Right of access: The person can request a copy of all data you hold about them, including their email address, consent records, email interaction history and any other personal data.
Right to rectification: The person can ask you to correct inaccurate data.
Right to erasure ("right to be forgotten"): The person can ask you to delete all their personal data. When you receive such a request, remove them from all lists and delete their data from all systems within 30 days.
Right to restrict processing: The person can ask you to stop processing their data while a complaint or correction is being handled.
Right to data portability: The person can request their data in a machine-readable format.
8. Maintain a processing activities record
Article 30 of GDPR requires maintaining records of your data processing activities. For email marketing, document:
- What personal data you collect (email address, name, etc.).
- Why you collect it (marketing communications).
- Your lawful basis (consent or legitimate interest).
- Who has access to the data (your team, your email marketing platform, any third-party processors).
- How long you retain it.
- What security measures protect it.
9. Use a data processing agreement with vendors
Your email marketing platform, CRM and any other tool that processes your subscribers' data is a "data processor" under GDPR. You need a Data Processing Agreement (DPA) with each one.
Most major platforms (Mailchimp, HubSpot, ActiveCampaign, Brevo, etc.) offer a standard DPA. Sign it. If a vendor does not offer one, that is a red flag.
10. Implement data minimisation
Collect only the data you need for the stated purpose. If you need an email address to send a newsletter, do not also require a phone number, home address and date of birth on the signup form.
Every additional field you collect increases your compliance burden and your risk in the event of a data breach.
11. Set retention limits
Do not keep personal data indefinitely. Define how long you retain email addresses and associated data, and delete it when the retention period ends.
Practical approach:
- Active subscribers: retain as long as they remain subscribed.
- Unsubscribed contacts: retain for suppression purposes (to prevent re-subscribing them accidentally), but remove all other data.
- Bounced addresses: retain on your suppression list, remove other data.
- Inactive subscribers (no engagement in 12+ months): consider deletion or re-consent.
12. Secure the data
GDPR requires appropriate technical and organisational measures to protect personal data.
For email lists, this means:
- Access controls (not everyone in your company needs access to the full email list).
- Encryption of stored data.
- Secure transfer protocols (HTTPS, encrypted email).
- Regular security reviews of your email marketing platform and other tools.
- Staff training on data protection.
13. Report data breaches
If your email list is compromised (hacked, accidentally published, accessed by unauthorised parties), you must:
- Notify your supervisory authority within 72 hours if the breach poses a risk to individuals.
- Notify affected individuals without undue delay if the breach poses a high risk to their rights and freedoms.
Have a breach response plan ready before it happens.
14. Handle cross-border transfers
If you transfer personal data outside the EEA (for example, by using a US-based email marketing platform), you need a legal mechanism for the transfer.
Common mechanisms:
- Standard Contractual Clauses (SCCs): Contract terms approved by the European Commission.
- Adequacy decisions: Some countries are deemed to provide adequate protection (check the current list, as it changes).
- The EU-US Data Privacy Framework (for certified US companies).
Most major email platforms have updated their terms to include SCCs.
15. Appoint a representative (if outside the EU)
If your business is outside the EU/EEA but processes data of EU residents, you may need to appoint an EU representative under Article 27. This is someone in the EU who serves as a point of contact for data protection authorities.
The representative requirement does not apply if your processing is occasional, small-scale and unlikely to result in risk to individuals. Regular email marketing to EU residents is likely to trigger this requirement.
How This Applies to Email Extraction
When you use Email Extractor to extract email addresses from files, the tool processes data client-side in your browser (for file-based extraction). No data is uploaded to a server. This has privacy advantages, but GDPR obligations still apply to how you use the extracted addresses.
Key considerations:
- Extraction does not create consent. Having someone's email address is not the same as having permission to email them.
- If you extracted addresses from sources where the person did not consent to receive marketing from you, you need a lawful basis before sending.
- Verify and clean extracted lists before use. See Best Email Verification Services.
- If your source files contain EU personal data, handle them according to your processing records and retention policies.
Enforcement Reality
GDPR is enforced by national data protection authorities (DPAs). Fines can reach up to 4% of annual global turnover or 20 million euros, whichever is higher.
In practice, enforcement actions for email marketing violations have resulted in fines ranging from thousands to millions of euros. The most common violations:
- Sending marketing emails without valid consent.
- Not honouring unsubscribe requests.
- Not responding to data subject access requests.
- Insufficient consent records.
The risk is not just financial. A GDPR complaint can trigger an investigation that consumes significant time and resources, even if no fine results.