GDPR for email marketing: a practical guide

If you email anyone in the EU or UK, the GDPR applies to you - wherever your brand is based. Here is what consent, lawful basis and data rights actually mean for an email program, in plain terms.

Updated June 2026/8 min read

This guide is a practical overview, not legal advice. For anything specific to your business, talk to a qualified data-protection professional.

When the GDPR applies to you

The GDPR follows the person, not the company. If you send marketing email to people in the EU or the UK, you fall under it - even if your brand sits in New York or Sydney. Treating it as a baseline, rather than a region-specific add-on, is the simplest way to stay safe.

Consent, the right way

For marketing email, consent must be freely given, specific, informed and unambiguous. In practice that means:

  • No pre-ticked boxes - the subscriber actively opts in.
  • Consent to marketing is separate from agreeing to your terms.
  • You tell people what they are signing up for, in clear language.
  • Buying or scraping lists is never a lawful basis for marketing.

Double opt-in and why it helps

Double opt-in - where a subscriber confirms via a follow-up email - is not strictly required everywhere, but it is good practice. It proves consent, keeps your list clean of typos and bots, and tends to improve deliverability because the people on your list genuinely want to be there.

Keep records

If a regulator asks, you should be able to show how and when each person opted in. Capture the timestamp, the source and what they agreed to. Most email platforms can store this if you set them up to.

Make leaving easy

Every marketing email needs a clear, working unsubscribe link, and the request should take effect quickly. A preference centre - where people choose what they hear about rather than leaving entirely - keeps more subscribers while still respecting their choice.

Honour data rights

People can ask to access, correct, delete or port their data, or object to your using it. Have a simple, repeatable way to handle these requests within the time the GDPR allows, and a single inbox where they land.

Mind data transfers

Your email and analytics tools may store data outside the EU. Check that each provider relies on an adequacy decision or the EU Standard Contractual Clauses, so data keeps an equivalent level of protection when it travels.

Compliance and good email go together

None of this is at odds with growth. A list built on genuine consent, kept clean, and easy to leave is exactly the list that lands in the inbox and converts. Done well, GDPR pushes you toward the habits that make email work.

Want a program that is compliant by default?

As an Amsterdam studio, GDPR is built into how we work. We will review your consent, list and flows and show you what to tighten - free.