If you send marketing email newsletters and you have anyone on your list who lives in the EU or UK, you need to care about GDPR. Even if you are based elsewhere. It is not just a box-ticking exercise. It affects how you collect email addresses, what you send, and how easy you make it for people to unsubscribe. This is a plain English guide to what you can and cannot do when it comes to marketing emails under the General Data Protection Regulation and the UK version, often called the UK GDPR.
What GDPR actually covers
GDPR is about personal data. An email address counts as personal data if it identifies a person, which most do. If you are storing it, using it to send newsletters, tracking opens, or profiling clicks, you are processing personal data. That means GDPR applies.
The legal bases for sending marketing emails
Under GDPR, you must have a lawful basis to process personal data. For marketing emails, the two most relevant ones are consent and legitimate interest.
Consent
Consent is the safest and most straightforward route for most newsletter lists. Valid consent must be:
- Freely given
- Specific
- Informed
- Unambiguous
In practice, that means:
- No pre-ticked boxes
- No bundling consent into terms and conditions
- Clear wording about what people are signing up for
- Clear explanation of who you are
If someone signs up to receive your monthly marketing newsletter, and you clearly explain what they will get, that is likely valid consent. You also need to keep records. If the regulator ever asks, you should be able to show when and how the person consented, and what they were told at the time.
And here is the important bit. People must be able to withdraw consent just as easily as they gave it. So your unsubscribe link needs to be obvious and actually work. No login walls, no hidden steps.
Legitimate interest
Legitimate interest is more nuanced. It allows you to process personal data without consent if you have a genuine business reason that is not overridden by the individual’s rights and interests. For email marketing, legitimate interest is often relied on in B2B contexts, especially when emailing corporate addresses like name@company.co.uk.
But you cannot just say “marketing is our legitimate interest” and call it a day. You need to do a balancing test:
- What is your interest
- Is the processing necessary for that interest
- Does it override the person’s privacy rights
You should document this assessment. It does not have to be complicated, but it does need to be thought through. Also, remember that in the UK and EU, you also have to consider ePrivacy rules, such as the UK’s PECR. These often require consent for unsolicited marketing emails, especially to individuals, even if you think you have a legitimate interest under GDPR. So GDPR is not the only law in play.
The soft opt-in
There is a concept known as the soft opt-in. In the UK, under PECR, you may be able to send marketing emails to existing customers if:
- They bought something from you, or negotiated to buy
- You are marketing similar products or services
- You gave them the chance to opt out at the time you collected their details
- You give them an opt-out in every message
This is not a free pass to add anyone who ever emailed you onto your newsletter. It is limited and specific.
What you definitely cannot do
- Buy random email lists and start blasting them. If you cannot prove valid consent, you are taking a serious risk.
- Scrape emails from websites and assume that because they are public, they are fair game. They are not.
- Hide who you are. Your emails must clearly identify your business and provide contact details.
- Ignore unsubscribe requests. Once someone opts out, you must stop. Promptly.
- Track people in secret. If you use tracking pixels to see who opens or clicks, that is personal data processing. You need to tell people in your privacy notice.
Privacy notices matter
You must provide a clear privacy notice at the point you collect someone’s email. It should explain:
- Who you are
- What data you collect
- Why you are collecting it
- Your lawful basis
- How long you keep it
- Their rights
Do not copy and paste a generic template and hope for the best. It needs to reflect what you actually do.
Data minimisation and retention
Only collect what you need. If all you need is an email address for a newsletter, do not ask for date of birth just because it might be useful one day. And do not keep data forever. If someone has not engaged with your emails for years, you should consider whether you still need to keep their details. Regular list cleaning is not just good marketing practice. It is good compliance.
Security
You are responsible for keeping your mailing list secure. Use reputable email service providers, strong passwords, two-factor authentication, and limit access internally. If you suffer a data breach involving personal data, you may have to report it to the regulator within 72 hours.
People’s rights
Under GDPR, individuals have rights. These include:
- The right to access their data
- The right to rectification
- The right to erasure
- The right to object to processing for direct marketing
The right to object is especially important. If someone objects to direct marketing, you must stop. There is no balancing test at that point. Marketing must cease.
What about fines
Fines under GDPR can be significant. Regulators such as the UK Information Commissioner’s Office take spam and unlawful marketing seriously. Enforcement often focuses on persistent offenders, but smaller businesses are not immune.
That said, most issues arise from sloppy processes rather than deliberate wrongdoing. Clear consent mechanisms, good record keeping, and respecting opt-outs will put you in a strong position.
A practical, low-drama approach
If you want to sleep at night:
- Use clear opt-in forms
- Keep evidence of consent
- Make unsubscribing easy
- Be transparent in your privacy notice
- Do not email people who did not ask to hear from you
GDPR is not about killing marketing. It is about respecting people’s data and choices.
If you focus on building a list of people who genuinely want your emails, you will not just be compliant. You will probably get better open rates too.
If you are collecting, storing or processing personal data – particularly special category data – you should seek professional legal advice to ensure you are meeting your obligations under the UK GDPR or other applicable data protection laws. This is especially important if you work in a regulated industry such as healthcare, legal services or finance, where the handling of sensitive information carries additional responsibilities and risks.
Neither the author nor the publisher accepts any liability for loss or damage arising from reliance on the information contained in this post. Always consult a qualified solicitor or data protection professional if in doubt.