GDPR-compliant email marketing: a practical checklist
GDPR turned eight this year, and email marketers still get it wrong in the same handful of places. That's partly because most GDPR content is written by lawyers for lawyers.
Here's the marketer's version: what the regulation actually asks of your email program, as a checklist. (Usual caveat — this is practical guidance, not legal advice.)
1. Have a lawful basis for every address
You can't email someone just because you have their address. For marketing email, your basis is almost always one of two:
Consent — they actively agreed to receive marketing from you. Active means active: no pre-ticked boxes, no consent buried in your terms, no "by downloading this PDF you agree to our newsletter." A separate, unticked checkbox is the standard.
The soft opt-in (existing customers) — under the ePrivacy rules that sit alongside GDPR, you may generally market similar products to your existing customers without fresh consent, if you offered an opt-out when you collected the address and in every message since. It's narrower than people want it to be: it covers customers, not leads who downloaded a whitepaper.
If you can't say which basis covers an address, don't mail it.
2. Be able to prove it
GDPR's sting is the accountability principle: consent you can't demonstrate may as well not exist. For every subscriber, keep:
- What they signed up for, and when
- Where (which form, which page)
- What the consent language said at the time
This is the compliance argument for double opt-in: a stored confirmation click is exactly this proof. If your list predates your record-keeping, the uncomfortable answer is a re-permission campaign — a smaller lawful list beats a large indefensible one.
3. Make leaving effortless
Every message needs an unsubscribe that works without logging in, without asking why, and takes effect promptly. GDPR's standard is that withdrawing consent must be as easy as giving it.
Deliverability agrees with the law here: every blocked exit converts an unsubscribe into a spam complaint, and complaints are the metric that gets you blocked. Keep a suppression list so unsubscribed addresses can never be accidentally re-imported.
4. Collect less, delete more
Data minimization is the least-followed article of GDPR. For a newsletter you need an email address — you don't need a birthday, phone number, and job title "for segmentation someday." Every extra field is liability with no open-rate attached.
And data has a shelf life: a subscriber who hasn't engaged in years is hard to justify keeping. A sunset policy — attempt re-engagement, then delete — is good law and good deliverability, since dead weight drags your engagement metrics down anyway.
5. Know where your data goes
Your email platform is a data processor; you're the controller. That relationship needs paper:
- A Data Processing Agreement (DPA) with your platform — if a vendor can't produce one, that's your answer about them
- Clarity on where data is stored and what safeguards cover any transfer outside the EU (post-Schrems II, "it's on servers somewhere" doesn't survive scrutiny)
- Your email vendor listed in your privacy policy as a processor
PristineSend publishes its DPA and GDPR documentation — as an EU-founded company, this is home turf rather than an afterthought.
6. Honor the rights requests
Subscribers can ask what data you hold (access), demand deletion (erasure), or ask for their data in portable form. For email marketers these are usually simple — the trap is having no process, and a 30-day clock that starts whether you're ready or not. Know how you'd export or delete one person's data today.
The bottom line
GDPR compliance in email reduces to a sentence: mail people who verifiably asked, make leaving trivial, and don't hoard. Every item on this list also improves deliverability — regulators and mailbox providers are, in effect, enforcing the same standard. Senders who treat consent as the product foundation don't experience GDPR as a burden at all.