A necessary caveat. We build email infrastructure; we are not lawyers, and this is not legal advice. GDPR interacts with national rules, enforcement varies, and your circumstances matter. What follows is a practical orientation for people running campaigns — take proper advice before relying on any position here.
Email addresses are personal data
That is the starting point everything else follows from. An email address identifies a person, so collecting, storing and using one is processing personal data, and processing requires a lawful basis. For marketing, that basis is usually consent or legitimate interest.
Consent, and what makes it valid
GDPR sets a high bar. Consent must be freely given, specific, informed and unambiguous, given by a clear affirmative action. In practice:
- No pre-ticked boxes. Silence and inactivity are not consent.
- Not bundled. Consent to marketing cannot be a condition of accepting terms or completing an unrelated purchase.
- Specific. "We may contact you" is too vague. Say what they will receive and roughly how often.
- Separated by purpose. Consent to a product newsletter is not consent to share the address with partners.
- Demonstrable. You must be able to show when consent was given, what was shown at the time, and how.
- Withdrawable. As easy to withdraw as it was to give.
That last requirement on record-keeping catches people out. If a regulator asks how you obtained a particular address, "it was on the list we imported" is not an answer.
Legitimate interest
GDPR permits processing where you have a legitimate interest that is not overridden by the individual's rights. Marketing is explicitly acknowledged as capable of being a legitimate interest — but it is not a way around consent, and treating it as one is the most common misuse.
Relying on it requires a documented three-part assessment: that the interest is legitimate, that the processing is necessary for it, and that it is balanced against the individual's interests and reasonable expectations. The balancing test is where most B2C marketing fails — a consumer who bought a product once does not reasonably expect unrelated marketing indefinitely.
It is on stronger ground for relevant business-to-business contact, where the recipient's professional role makes the message plausibly useful to them.
PECR: the part people forget
In the UK and equivalents across the EU, GDPR is not the only rule. PECR governs electronic marketing specifically and generally requires prior consent for marketing email to individuals — regardless of whether you could argue legitimate interest under GDPR.
The narrow exception is the soft opt-in: you may email an existing customer about similar products, provided you obtained the address during a sale or negotiation, and offered an opt-out at that point and in every message since.
The practical consequence is that for consumer marketing in the EU and UK, consent is the safe default, and legitimate-interest arguments rarely survive contact with PECR.
What every message must carry
- Clear identification of who is sending it.
- A working opt-out, honoured promptly — under the Google and Yahoo bulk sender rules, within two days.
- A route to your privacy information explaining what you hold and why.
- No misleading subject line or header information.
Individual rights that affect your list
Contacts can request access to what you hold, correction, erasure, and can object to direct marketing outright. The right to object to marketing is absolute — there is no balancing test and no legitimate interest that overrides it. An objection must be honoured, full stop.
In practice that means suppression must be reliable and permanent, and it must survive re-importing an old list. Storing suppression entries as hashes lets you enforce that without retaining readable contact data for someone who asked you to stop, which is a neat resolution of an otherwise awkward tension.
Where this overlaps with deliverability
Most of what GDPR requires is what protects your sending reputation anyway: contact only people who want to hear from you, make opting out trivial, honour it immediately, and do not hoard data indefinitely. The sunset policy that improves engagement rates is also the retention policy GDPR expects you to have.
Purchased lists fail on both counts simultaneously. There is no lawful basis for mailing someone whose consent you never obtained and cannot demonstrate, and the bounce and complaint rates will damage your domain regardless.