Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

GDPR Email Marketing Checklist: 15 Requirements You Cannot Ignore

On this page

Who GDPR Applies To

The General Data Protection Regulation applies if you process personal data of people in the European Economic Area (EEA), regardless of where your business is located. An email address is personal data under GDPR.

If you send emails to anyone in the EU, EEA or UK (which has its own equivalent, UK GDPR), these requirements apply to you.

The Checklist

1. Establish a lawful basis for processing

GDPR requires a legal basis for processing personal data. For email marketing, two bases are commonly used:

Consent: The person explicitly agreed to receive your emails. This is the safest basis for marketing to individuals.

Legitimate interest: You have a genuine business reason for contacting the person, and their rights do not override your interest. This can apply to B2B marketing in some EU member states, but you must conduct a legitimate interest assessment (LIA) and document it.

Do not assume legitimate interest covers everything. When in doubt, get consent.

2. Make consent specific and informed

Consent must be:

  • Freely given: No pre-ticked boxes. No bundling consent with terms of service.
  • Specific: Consent to receive marketing emails is separate from consent to process data for other purposes.
  • Informed: The person must know who is collecting their data, why, and how it will be used.
  • Unambiguous: A clear affirmative action (checking a box, clicking a button, typing their email into a specifically labelled field).

A vague "by using this site you agree to our communications" is not valid consent.

3. Record and store consent evidence

You must be able to demonstrate that consent was given. Record:

  • When consent was given (timestamp).
  • How consent was given (which form, which page, which checkbox text).
  • What the person consented to (exact wording they agreed to).
  • Who gave consent (email address and any other identifying information).

Keep these records for as long as you process the person's data.

4. Separate opt-ins for different purposes

Consent for a newsletter is not consent for product announcements. Consent for marketing emails is not consent for partner offers.

If you send different types of email, offer separate opt-in choices for each. Do not bundle them into a single checkbox.

5. Never use pre-ticked boxes

Under GDPR, silence and inactivity do not constitute consent. A pre-ticked checkbox on a form does not count as opt-in. The person must actively check the box themselves.

6. Allow easy withdrawal of consent

People can withdraw consent at any time. You must make it as easy to withdraw as it was to give. In practice:

  • Include an unsubscribe link in every marketing email.
  • The unsubscribe process should be one or two clicks, not a multi-step process requiring login.
  • Process unsubscribes promptly (within a few days at most).

7. Honour data subject rights

Under GDPR, individuals have specific rights regarding their data. You must be prepared to handle:

Right of access: The person can request a copy of all data you hold about them, including their email address, consent records, email interaction history and any other personal data.

Right to rectification: The person can ask you to correct inaccurate data.

Right to erasure ("right to be forgotten"): The person can ask you to delete all their personal data. When you receive such a request, remove them from all lists and delete their data from all systems within 30 days.

Right to restrict processing: The person can ask you to stop processing their data while a complaint or correction is being handled.

Right to data portability: The person can request their data in a machine-readable format.

8. Maintain a processing activities record

Article 30 of GDPR requires maintaining records of your data processing activities. For email marketing, document:

  • What personal data you collect (email address, name, etc.).
  • Why you collect it (marketing communications).
  • Your lawful basis (consent or legitimate interest).
  • Who has access to the data (your team, your email marketing platform, any third-party processors).
  • How long you retain it.
  • What security measures protect it.

9. Use a data processing agreement with vendors

Your email marketing platform, CRM and any other tool that processes your subscribers' data is a "data processor" under GDPR. You need a Data Processing Agreement (DPA) with each one.

Most major platforms (Mailchimp, HubSpot, ActiveCampaign, Brevo, etc.) offer a standard DPA. Sign it. If a vendor does not offer one, that is a red flag.

10. Implement data minimisation

Collect only the data you need for the stated purpose. If you need an email address to send a newsletter, do not also require a phone number, home address and date of birth on the signup form.

Every additional field you collect increases your compliance burden and your risk in the event of a data breach.

11. Set retention limits

Do not keep personal data indefinitely. Define how long you retain email addresses and associated data, and delete it when the retention period ends.

Practical approach:

  • Active subscribers: retain as long as they remain subscribed.
  • Unsubscribed contacts: retain for suppression purposes (to prevent re-subscribing them accidentally), but remove all other data.
  • Bounced addresses: retain on your suppression list, remove other data.
  • Inactive subscribers (no engagement in 12+ months): consider deletion or re-consent.

12. Secure the data

GDPR requires appropriate technical and organisational measures to protect personal data.

For email lists, this means:

  • Access controls (not everyone in your company needs access to the full email list).
  • Encryption of stored data.
  • Secure transfer protocols (HTTPS, encrypted email).
  • Regular security reviews of your email marketing platform and other tools.
  • Staff training on data protection.

13. Report data breaches

If your email list is compromised (hacked, accidentally published, accessed by unauthorised parties), you must:

  • Notify your supervisory authority within 72 hours if the breach poses a risk to individuals.
  • Notify affected individuals without undue delay if the breach poses a high risk to their rights and freedoms.

Have a breach response plan ready before it happens.

14. Handle cross-border transfers

If you transfer personal data outside the EEA (for example, by using a US-based email marketing platform), you need a legal mechanism for the transfer.

Common mechanisms:

  • Standard Contractual Clauses (SCCs): Contract terms approved by the European Commission.
  • Adequacy decisions: Some countries are deemed to provide adequate protection (check the current list, as it changes).
  • The EU-US Data Privacy Framework (for certified US companies).

Most major email platforms have updated their terms to include SCCs.

15. Appoint a representative (if outside the EU)

If your business is outside the EU/EEA but processes data of EU residents, you may need to appoint an EU representative under Article 27. This is someone in the EU who serves as a point of contact for data protection authorities.

The representative requirement does not apply if your processing is occasional, small-scale and unlikely to result in risk to individuals. Regular email marketing to EU residents is likely to trigger this requirement.

How This Applies to Email Extraction

When you use Email Extractor to extract email addresses from files, the tool processes data client-side in your browser (for file-based extraction). No data is uploaded to a server. This has privacy advantages, but GDPR obligations still apply to how you use the extracted addresses.

Key considerations:

  • Extraction does not create consent. Having someone's email address is not the same as having permission to email them.
  • If you extracted addresses from sources where the person did not consent to receive marketing from you, you need a lawful basis before sending.
  • Verify and clean extracted lists before use. See Best Email Verification Services.
  • If your source files contain EU personal data, handle them according to your processing records and retention policies.

Enforcement Reality

GDPR is enforced by national data protection authorities (DPAs). Fines can reach up to 4% of annual global turnover or 20 million euros, whichever is higher.

In practice, enforcement actions for email marketing violations have resulted in fines ranging from thousands to millions of euros. The most common violations:

  • Sending marketing emails without valid consent.
  • Not honouring unsubscribe requests.
  • Not responding to data subject access requests.
  • Insufficient consent records.

The risk is not just financial. A GDPR complaint can trigger an investigation that consumes significant time and resources, even if no fine results.

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)