NevTan Engage lets you create automated email, push, SMS, and WhatsApp customer journeys, segment audiences, and deliver personalized campaigns powered by unified customer data.
If you email anyone in the EEA, two sets of rules apply — and most guides only tell you about one of them. This article covers what GDPR requires, where the ePrivacy rules govern instead, and how to build the consent capture, record-keeping, and data subject processes that make both workable.
TL;DR:GDPR governs how you handle personal data.The ePrivacy rules govern whether you may send the marketing email in the first place— including the soft opt-in for existing customers that GDPR itself says nothing about. You need a lawful basis, provable consent records, a working opt-out, and a process for data subject rights within one calendar month. The single most dangerous mistake in this area is emailing a list you can't prove consent for in order toaskfor consent — regulators have fined companies for exactly that.
Two Regulations, Not One
This distinction matters more than any other point in this guide, and getting it wrong is why a lot of published advice is subtly off.
GDPR | ePrivacy (PECR in the UK) | |
|---|---|---|
Governs | How personal data is collected, stored, used, deleted | Whether you may send an electronic marketing message |
Gives you | Lawful bases, data subject rights, accountability duties | The consent requirement for marketing email, and the soft opt-in exemption |
Applies to | All personal data processing | Email, SMS, cookies, and similar electronic channels |
So the practical sequence is: ePrivacy decides whether you can send. GDPR decides how you must handle the data either way.
When you read that "GDPR requires consent for marketing email," that's shorthand — the consent requirement for the send comes from ePrivacy, and GDPR supplies the standard that consent has to meet. The distinction becomes concrete when you look at the soft opt-in, which exists in ePrivacy and has no GDPR equivalent at all.
Two further scope notes commonly missed: GDPR covers the EEA, not just the EU, and the UK operates its own UK GDPR alongside PECR post-Brexit. If you send to Britain and the continent, you're working to two regimes that are similar but not identical.
Consent, and What "Explicit" Actually Means
GDPR sets the standard that consent must meet: freely given, specific, informed, and unambiguous, given by a clear affirmative action.
A terminology point worth getting right, because it appears incorrectly in a great deal of marketing content: "explicit consent" is a higher, separate standard in GDPR, required for special category data (health, biometrics, political opinions) and certain international transfers. Ordinary marketing consent does not need to be "explicit" in that technical sense — it needs to be unambiguous. Using the terms interchangeably suggests a bar most marketers aren't actually required to clear, and signals to anyone who knows the regulation that the writer doesn't.
What that means in practice:
No pre-ticked boxes. The user must act.
No bundling. Marketing consent can't be a condition of a purchase or buried in terms acceptance.
Specific purposes. Separate consent per channel and per purpose, not one blanket agreement.
Named controller. They must know who they're consenting to hear from.
As easy to withdraw as to give.
The soft opt-in
Under ePrivacy rules, you can generally email existing customers about similar products or services without fresh consent, provided you obtained their details in the course of a sale or negotiation, gave them a clear chance to opt out at that point, and give them one in every message since.
It's narrower than people assume — "similar" is doing real work, it doesn't extend to prospects who never bought, and national implementations vary. But it's a legitimate basis that a GDPR-only reading of the rules would tell you doesn't exist.
What You Need Before Starting
A documented lawful basis. For marketing, usually consent. Write down why you rely on it.
A record of every data source. Website forms, lead magnets, offline events, imports. If you can't say where a contact came from, you can't defend it.
An accurate privacy notice covering what you collect, why, the lawful basis, retention, recipients, transfers, and how rights are exercised. Your privacy policy should match what your forms actually do, not what you intended them to do.
A consent capture process that stores timestamp, source, IP address, the exact wording shown, and the channels consented to.
A data processing agreement with every processor. Your email platform processes personal data on your behalf, so Article 28 requires a DPA — see our DPA and subprocessor list, which is the information you'd need for your own records of processing.
A data subject request process. One calendar month to respond, extendable by two further months for complex or numerous requests — with the requester informed of the extension within the first month.
A breach response plan. Notifiable breaches must reach the supervisory authority within 72 hours of becoming aware. Worth having before you need it.
Step 1: Audit Your List and Consent Records
Export your full list. For each contact, identify: source, collection date, the consent wording shown at the time, and the proof of opt-in.
Sort into three groups:
Group | Status | Action |
|---|---|---|
A | Clear documented consent | Continue, verify retention policy |
B | Consent likely obtained but records incomplete | See the warning below before acting |
C | No consent, or purchased/scraped | Delete. Do not email |
The re-permission trap
This is the most dangerous point in the whole topic, and most guides get it backwards.
A re-permission email is itself a marketing email. If you have no lawful basis to email someone, you have no lawful basis to email them asking whether you may email them. The request doesn't sit outside the rules — it's covered by them.
UK regulators have issued fines for precisely this: companies that emailed people who had opted out or never opted in, asking them to update their marketing preferences, were penalised for the re-permission campaign itself. The intention was compliance; the action was a breach.
So the split that matters is:
Incomplete records, but a genuine prior relationship and a plausible basis → re-permission may be defensible. Take advice.
Purchased lists, scraped addresses, co-registration with vague terms, or anyone who opted out → delete. Do not send a re-permission email. There is no lawful route back to these contacts by email.
A purchased list is not a list with a documentation problem. It's a list you were never permitted to contact, and emailing it to ask forgiveness compounds the breach rather than curing it.
Pro Tip: Run suppression before anything else. Anyone who has unsubscribed or hard-bounced should be in your suppression list permanently, and suppression records survive deletion requests in a way that contact records don't — see the deletion section below.
Step 2: Build a Compliant Opt-In
Your form should state plainly what the person is signing up for:
"Yes, I'd like to receive marketing emails about [specific topics] from [Company Name]. You can unsubscribe at any time."
Link the privacy notice. Record timestamp, IP, source, and the exact consent text version shown — versioning matters, because "what did they agree to in March 2024" needs an answer that doesn't depend on what your form says today.
Separate consent per channel. Email consent is not SMS consent is not WhatsApp consent. Collecting a phone number on an email form grants nothing for that channel — and SMS carries its own registration requirements on top.
Double opt-in isn't mandated, but it's strong evidence of valid consent, it verifies the address, and it creates a second timestamped record. Several EEA authorities view it favourably. It costs you signups and improves nearly everything downstream — list quality drives deliverability as directly as it drives compliance.
Lead capture design covers the form mechanics, and contact documentation covers storing consent fields against the profile.
Step 3: Privacy Notice and Email Footers
Your notice should cover: data collected, purposes, lawful basis, retention periods, recipients and processors, international transfers, data subject rights, and how to complain to a supervisory authority.
Every marketing email needs:
A prominent, working unsubscribe — not hidden in small text
Your identity and a physical address
A link to the privacy notice
Honour opt-outs without undue delay. GDPR doesn't name a deadline; the practical standard is immediately, automatically, and permanently. Manual unsubscribe processing is a liability waiting to happen.
Cookies and tracking pixels fall under ePrivacy, not GDPR — which is why cookie consent is a separate banner and a separate record from your email consent. If you use open tracking, your notice should say so.
Step 4: Data Subject Rights
GDPR grants access, rectification, erasure, restriction, portability, and objection.
Timeline: one calendar month, free of charge. Extendable by two further months for complex or numerous requests, provided you tell the requester within the first month and explain why.
Right | What it requires |
|---|---|
Access | A copy of their personal data plus details of processing |
Erasure | Deletion, unless you have a legal obligation to retain |
Portability | Structured, commonly used, machine-readable format |
Objection | For direct marketing, absolute — there is no balancing test |
That last row deserves emphasis. An objection to direct marketing must be honoured unconditionally. Unlike most GDPR rights, you cannot weigh your interests against theirs. There is no exception and no appeal.
The deletion-versus-suppression tension
A genuine conflict that most guides skip. If you fully delete someone who opted out, you lose the record proving they opted out — and may email them again when they re-enter from another source.
The usual resolution is a suppression list keyed on a hashed identifier, retaining only enough to recognise and block the address without holding the underlying personal data. Confirm your specific approach with counsel; this is an area where reasonable practitioners differ and where the regulation doesn't give a clean answer.
Verify your platform can export and delete a contact's data across every list and automation, and can do it quickly enough to meet the deadline. API access matters here if you need to handle requests at volume.
Pro Tip: Create a monitored address like
privacy@yourcompany.comand train support to recognise and escalate requests immediately. The clock starts when the request arrives anywhere in your organisation, not when it reaches the right person — a DSAR sitting unread in a general inbox is still running down its month.
Step 5: Retention, Training, and Monitoring
On retention: GDPR requires you to keep data only as long as necessary for the purpose. It does not specify a period, and it does not set an expiry on consent — the widely repeated "consent expires after 24 months" is a convention, not a rule, and different supervisory authorities have suggested different periods.
What's genuinely required is that you set a retention policy, justify it, and follow it. A period tied to engagement recency is defensible and also good practice: contacts who haven't engaged in a long time hurt deliverability and are unlikely to convert. Re-permission them while you still have a basis, or delete them.
On training: everyone touching email marketing needs the basics — what valid consent looks like, how to handle unsubscribes, how to recognise a data subject request.
On monitoring: audit opt-in forms, privacy notice accuracy, and retention policy adherence on a schedule. Watch unsubscribe and complaint rates; a spike often indicates a targeting or consent problem before it indicates a content problem.
On documentation: accountability is an obligation in itself. You must be able to demonstrate compliance, not merely achieve it. Keep consent records, DPAs, your record of processing activities, training logs, and audit results. If a supervisory authority asks, documentation is what distinguishes a company with a process from a company with an intention.
Step 6: International Transfers
Largely absent from most email marketing GDPR guides, and increasingly where the significant enforcement activity sits.
If your email platform, or any of its subprocessors, stores or accesses EEA personal data outside the EEA, that's a restricted transfer requiring a valid mechanism — an adequacy decision, Standard Contractual Clauses, or another Chapter V route, usually with a transfer risk assessment.
Practical implications when evaluating any platform:
Ask where data is stored and processed, including backups and support access
Ask for the subprocessor list and whether you're notified of changes
Check what transfer mechanism they rely on
If EEA data residency matters to you, confirm it rather than assuming
This is also where security posture becomes part of the compliance conversation rather than a separate procurement question.
Worked Example: Cleaning a Five-Year List
A modelled example illustrating the decision, not a customer result.
An EU ecommerce brand with a 50,000-contact list built over five years. An audit finds 15,000 contacts with no clear consent record — some from a purchased list, some from a co-registration offer with vague terms.
The wrong move is re-permissioning all 15,000. For the purchased-list portion there was never a lawful basis, so the re-permission email is itself an unlawful marketing send.
The defensible split:
Segment | Origin | Action |
|---|---|---|
Purchased list | No relationship, no consent | Delete outright |
Vague co-registration | Opted into something, unclear what | Re-permission may be arguable — take advice |
Genuine customers, poor records | Real relationship, documentation gap | Soft opt-in may apply; re-permission lower risk |
A re-permission email to the defensible segments states plainly that privacy practices are being updated and consent is needed to continue, with a clear "yes, keep me subscribed" action and an equally clear way to leave.
What to expect. Response rates on re-permission campaigns are low — most recipients won't reply, and non-response is not consent, so they go. The list shrinks substantially.
The compensation is that every remaining contact is one who actively wanted to be there. Engagement rates rise sharply, complaint rates fall, and deliverability improves — which lifts performance for the whole list, including contacts who were never in question. The revenue effect of a smaller consented list frequently exceeds that of the larger unconsented one, because inbox placement is a function of aggregate engagement.
Run the arithmetic on your own list before deciding. Model your current engaged count against your total, and compare what each is worth.
Choosing a Platform for GDPR Compliance
Check | Why |
|---|---|
DPA available | Article 28 requires one with every processor. No DPA, no lawful use |
Consent capture | Timestamp, IP, source, wording version, per channel |
DSAR tooling | Export and delete across every list and automation, fast enough for the deadline |
Data residency and transfers | Where data lives, which subprocessors, what transfer mechanism |
Consent-aware automation | Journeys that respect consent status rather than relying on list hygiene |
Security certifications | SOC 2, ISO 27001, encryption in transit and at rest |
Breach notification process | Their obligation to notify you, fast enough for your 72 hours |
Test a data subject request before you commit. Run one end to end during the trial. Vendors describe this capability more confidently than they deliver it, and discovering the gap during a live DSAR with a month-long clock is an avoidable way to find out.
Consent-aware segmentation is the feature that matters most day to day — being able to build a journey that structurally cannot send to someone who hasn't consented on that channel is better than a process that depends on someone remembering. Check plans against your volume.
Why GDPR Is Strict About Email
The accountability principle underpins everything: you must comply and be able to demonstrate it. For email marketing that means lawful basis, proper collection, and records.
Email reaches directly into personal space, which is why the consent bar sits where it does. Unwanted email isn't only irritating; it's a use of personal data the person didn't agree to.
The commercial case runs in the same direction. Consented lists engage better, bounce less, and generate fewer complaints — and because mailbox providers weight sender reputation on aggregate engagement, a clean list improves placement for every message you send. Compliance and deliverability are not competing priorities; they're the same work described in two vocabularies. Growing a list organically is slower than buying one and produces a materially better asset.
Technically, compliance means data mapping, consent logging, and workflows that act on consent state automatically — processing opt-outs and deletion requests in real time rather than in batches. Automated journeys that read consent status remove the most common failure mode, which is human error under deadline.
Data minimisation applies too: don't collect a phone number if you only send email, and don't retain data past its purpose.
Common Mistakes
1. Re-permissioning a list you have no basis to email. The most costly error in this area, and the one most often recommended as a fix.
2. Treating GDPR as the only applicable regulation. ePrivacy governs the send. Missing it means missing the soft opt-in and the cookie rules.
3. Pre-ticked boxes. Explicitly invalid.
4. Storing consent as a boolean. "Subscribed: true" proves nothing. Record who, when, how, and to what wording.
5. Ignoring or delaying opt-outs. Objection to direct marketing is absolute. Automate it.
6. No DPA with your processors. Without one, your use of the platform lacks a required legal element.
7. Assuming a fixed consent expiry. There isn't one. Set a justified retention policy instead of following a number you read somewhere.
8. Treating compliance as a project. It's a recurring practice. Review on a schedule, and when forms, vendors, or purposes change — over-sending and stale lists are also retention problems, not just legal ones.
9. Ignoring transfers. Where your data physically sits is a compliance question, not just an infrastructure one.
Frequently Asked Questions
Does GDPR require consent for marketing emails?
Mostly, but the requirement comes from the ePrivacy rules rather than GDPR itself — GDPR supplies the standard consent has to meet. The practical exception is the soft opt-in for existing customers receiving messages about similar products, which exists in ePrivacy and has no GDPR equivalent.
What's the difference between consent and explicit consent?
"Explicit consent" is a higher GDPR standard for special category data and certain transfers. Ordinary marketing consent must be freely given, specific, informed, and unambiguous — a clear affirmative action, but not the elevated standard. The terms get used interchangeably in marketing writing and shouldn't be.
Is double opt-in required?
No, but it's strong evidence of valid consent, verifies the address, and creates a second record. Several EEA authorities regard it favourably. You'll capture fewer contacts and have a materially better list.
How long can I keep email data?
As long as necessary for the purpose, which you must define and justify. GDPR sets no fixed period and does not expire consent. A policy tied to engagement recency is defensible and good practice regardless.
Can I email a purchased list to ask for consent?
No. The re-permission email is itself a marketing email requiring a lawful basis you don't have. Regulators have fined companies for exactly this. Delete purchased lists.
How do I handle a data subject access request?
Respond within one calendar month, extendable by two further months for complex requests if you notify the requester within the first month. Verify identity, provide the personal data plus processing details, and document the request and response. The clock starts when it arrives anywhere in your organisation.
What are the penalties?
Up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. A lower tier applies to other breaches. In practice the commercial damage — reputation, trust, deliverability — often arrives before any fine does.
Does GDPR apply if my business is outside the EU?
It can. GDPR applies extraterritorially where you offer goods or services to people in the EEA or monitor their behaviour. Where your company is incorporated doesn't settle the question; where your recipients are does.
Do I need a separate process for the UK?
The UK operates UK GDPR alongside PECR, closely aligned with the EU regime but administered separately and capable of diverging. If you send to both, verify your approach satisfies each.
Compliance as Infrastructure
The frameworks reward the same things: capture consent with evidence, honour objections immediately and permanently, keep records you can produce, and know which rules apply to which contact.
Those are systems, not policies — and they work when the platform enforces them rather than the person building the campaign remembering them.
NevTan Engage tracks consent per channel on a unified customer profile, so a journey can be built to structurally exclude anyone who hasn't consented on that channel, and an opt-out propagates everywhere at once.
Start free — no credit card required. Our DPA and security documentation are available for your own compliance records.
The Most Important Correction
The article recommends an action regulators have issued fines for.
Step 1 advises segmenting contacts with "ambiguous or missing consent" and sending them a re-permission email. The worked example then applies this to 15,000 contacts explicitly described as originating from "a purchased list or through a co-registration offer with vague terms" — and presents the result as a success story.
A re-permission email is a marketing email. If you have no lawful basis to email someone, you have no basis to email them asking for one. UK regulators have fined companies for running exactly this kind of "please confirm your preferences" campaign against people who had not consented or had opted out. The companies believed they were cleaning up; the cleanup was the breach.
This is the most consequential error in any article in this series, because a reader acting on it in good faith creates liability they didn't previously have, at scale, in a single send.
I've rewritten it to distinguish the cases: incomplete records on a genuine customer relationship may support re-permission; purchased lists, scraped addresses, vague co-registration, and prior opt-outs must simply be deleted. The worked example now shows that split rather than a single blanket action.
Other Legal Corrections
1. The article treats GDPR as the only applicable regulation. Email marketing consent is primarily governed by the ePrivacy Directive (PECR in the UK); GDPR governs the underlying personal data and supplies the standard consent must meet. This also explains the soft opt-in, which the original mentions in one FAQ line as a vague "exception" without saying where it comes from or how it works — it's an ePrivacy provision with no GDPR equivalent.
I flagged this same conflation in your live SMS article, where GDPR was named as governing SMS marketing consent. It's a recurring pattern worth fixing across the blog.
2. "Explicit consent" is used throughout and is the wrong term. In GDPR, explicit consent is a higher standard reserved for special category data and certain transfers. Ordinary marketing consent must be unambiguous, not explicit. The distinction matters to anyone who knows the regulation, and using the elevated term implies a bar most marketers aren't required to clear.
3. The DSAR deadline is incomplete. The article says "30 days" throughout. GDPR specifies one calendar month, extendable by two further months for complex or numerous requests where the requester is informed within the first month. The extension provision was absent entirely — and it's the part a team under pressure most needs to know exists.
4. "Consent expires after 24 months" is stated as a rule. It isn't. GDPR sets no consent expiry and no retention period. Supervisory authorities have suggested varying periods as guidance. Rewritten as what's actually required: set a justified retention policy and follow it.
5. Objection to direct marketing is absolute — no balancing test, unlike most GDPR rights. The original listed objection among the rights without noting that direct marketing is the special case. Added.
6. Cookie consent attributed to GDPR. It's ePrivacy. The original says "GDPR consent for cookies is separate from email marketing consent," which gets the separation right and the source wrong.
7. Fine statistics are unreliable. "In 2023 alone, European data protection authorities issued over €1.5 billion in GDPR fines, with email marketing violations among the most common triggers." The 2023 total was substantially higher than €1.5 billion, driven overwhelmingly by a small number of very large decisions concerning international transfers and advertising practices — not email marketing. The sentence understates the total while misattributing its composition. Removed.
8. The DMA statistic appears fabricated. "According to a 2023 study by DMA, GDPR-compliant lists see an average 22% higher open rate and 15% higher click-through rate compared to non-compliant lists." I could not verify this study or these figures. The underlying claim — consented lists engage better — is well supported and I've kept it directionally, but presenting invented precision in a legal article is the worst possible place for it. Restore only with a citation you can link.
9. Scope errors. GDPR covers the EEA, not just the EU. The UK has its own UK GDPR alongside PECR. Both absent; both added.
Gaps Filled
International transfers. Entirely missing, despite "data residency" appearing in the platform selection criteria. Chapter V obligations, SCCs, subprocessor disclosure, and transfer risk — this is where much of the significant recent enforcement has been.
Breach notification. The 72-hour obligation wasn't mentioned.
Deletion versus suppression. Fully deleting someone who opted out destroys the proof they opted out. A genuine tension with no clean statutory answer, flagged as such.
Testing DSAR capability before buying. Vendors describe this more confidently than they deliver it, and a live request with a month-long clock is the wrong moment to discover the gap.
Consent versioning. "What did they agree to in March 2024" needs an answer independent of what your form says today.
Other Changes
Removed OneTrust and Cookiebot. OneTrust appears as a competitor in your live CAN-SPAM compliance article's comparison table, and this article recommended it by name.
"GreenLeaf Organics" needs verification — real businesses operate under that name. Removed, alongside the outstanding checks on ProjectPulse, UrbanFit, StyleCraft, TaskFlow, and /case-study/glossier.
The example's arithmetic was sound. 15,000 contacts, 30% response = 4,500 ✓; 15,000 − 4,500 = 10,500 removed ✓; 50,000 − 10,500 = 39,500 ✓. I removed the outcome percentages as uncited but the structure checked out.
Added a legal disclaimer at the top. An article quoting statutory penalties and advising on consent needs one.
Removed "2025" from the title, added slug and meta description, converted five prose blocks into tables, and removed the trailing orphan fragment.
Internal Link Map
22 links across ~3,400 words — deliberately lighter than the marketing articles. In legal content, dense product linking undercuts the authority the piece depends on.
# | Section | Anchor | Target |
|---|---|---|---|
1 | Intro | NevTan Engage |
|
2 | Prerequisites | privacy policy |
|
3 | Prerequisites | our DPA |
|
4 | Prerequisites | subprocessor list |
|
5 | Step 1 | suppression list |
|
6 | Step 2 | SMS registration requirements |
|
7 | Step 2 | list quality drives deliverability |
|
8 | Step 2 | Lead capture design |
|
9 | Step 2 | contact documentation |
|
10 | Step 4 | API access |
|
11 | Step 5 | deliverability |
|
12 | Step 6 | security posture |
|
13 | Platform | segmentation |
|
14 | Platform | plans |
|
15 | Why strict | Growing a list organically |
|
16 | Why strict | Automated journeys |
|
17 | Why strict |
| |
18 | Mistakes | retention problems |
|
19 | CTA | Start free |
|
20 | CTA | DPA |
|
21 | CTA | security documentation |
|
This article finally uses the /legal/* pages properly — I flagged in the CAN-SPAM review that they were an unused trust asset. For compliance content they answer real buying objections.
Open Items
1. Have counsel review before publishing. Not a formality here. The re-permission guidance in the original version would have created genuine liability for readers who followed it.
2. Check your live CAN-SPAM/CASL/CCPA article for the same GDPR-versus-ePrivacy conflation. It appeared there and in the SMS article. If one source produced all three, the pattern is systemic.
3. Search the blog for "explicit consent." If this article used the term incorrectly throughout, others likely do too.
4. Consider consolidating compliance content. You now have GDPR, CAN-SPAM/CASL/CCPA, SMS registration rules, and consent-at-capture spread across four articles, each restating overlapping rules. One maintained reference page with articles linking to it would keep them consistent — and means one page to update when penalties or deadlines change, rather than four that will drift.
5. Reciprocal links. Point at this from /legal/privacy-policy and /legal/dpa (visitors there are asking this article's question), and from /blog/lead-capture-strategies-that-work, where consent capture is the step this article governs.
