If your business sends marketing or newsletter emails to contacts in the European Economic Area (EEA), the General Data Protection Regulation (GDPR) applies to you — no matter where your company is based. The good news: most of what GDPR asks you to do also happens to be exactly what keeps your emails out of the spam folder. This guide walks through what GDPR requires for email senders, in plain language, and how those requirements line up with good deliverability habits.
A quick note before we start: this article is general informational guidance for hosting and email customers, not legal advice. GDPR enforcement and interpretation can get complicated fast, especially for cross-border data transfers or unusual data uses. If you have specific compliance questions about your business, talk to a qualified privacy lawyer or data protection professional.
What is GDPR, and does it apply to my business?
GDPR is a European Union data protection law that took effect in May 2018. It covers how organizations collect, use, and store the personal data of people located in the EEA — and an email address counts as personal data. That means if you email anyone in the EEA for marketing purposes, GDPR applies to your business, even if your company itself is located outside Europe.
Each EU country has its own regulator (a Data Protection Authority) that enforces the rules, with a Europe-wide body coordinating overall guidance. Penalties for serious violations can be substantial, so this isn't a rule worth ignoring on the assumption it won't come up.
The core principles behind GDPR
GDPR is built around a handful of principles that apply to any use of personal data, including your email list:
- Be upfront and have a valid reason. You need a legitimate legal basis for emailing someone, and you need to be clear about what you're doing with their information.
- Don't repurpose data without justification. If someone gave you their email for a support ticket, you generally can't quietly add them to a sales newsletter without a separate basis for doing so.
- Collect only what you need. An email address is easy to justify for email marketing; asking for a birthdate or phone number when you don't actually use it is much harder to defend.
- Keep data accurate. If an address consistently bounces, it should be removed rather than retried indefinitely.
- Don't keep data forever. Contacts who haven't engaged in years should be reviewed and, in most cases, removed.
- Protect the data you hold. Reasonable safeguards against unauthorized access or loss are expected.
What GDPR actually requires for email marketing
Consent is usually your legal basis
GDPR allows a few different legal grounds for emailing someone, but for most marketing programs, consent is the most straightforward one to rely on. To count as valid under GDPR, consent needs to be:
- Freely given — the person had a real choice, without pressure
- Specific — they knew they were agreeing to marketing emails, not something vague
- Informed — they understood who would be emailing them and why
- Unambiguous — given through a clear action, like actively checking a box. A box that's pre-checked for them doesn't count.
You also need to be able to show, if asked, when and how someone consented and what they were told at the time — so keeping a simple record of opt-ins is worth building into your signup process from day one.
Legitimate interest: an option for some B2B outreach
Some businesses rely on “legitimate interest” rather than consent, particularly for professional B2B outreach. This isn't a free pass, though — it generally requires weighing your business reason against the recipient's rights, making sure the contact is relevant to their professional role, and always giving them an easy way to opt out. Because this legal basis involves more judgment than a simple opt-in, it's worth getting guidance from a privacy professional if you plan to rely on it broadly.
The right to unsubscribe
Every marketing email needs a working way for the recipient to opt out of future messages, and opt-out requests need to be honored promptly. Treating this as a box to tick rather than something to actually maintain is one of the most common ways businesses run into trouble.
You can't keep contact data forever
If someone hasn't engaged with your emails in a long time, you may no longer have a solid legal basis to keep emailing them. Reviewing and trimming inactive contacts isn't just good list hygiene — it's part of staying compliant.
Sending data to tools outside the EEA
If you use email platforms, CRMs, or marketing tools hosted outside the EEA, there needs to be a valid legal mechanism covering that data transfer, along with a proper data processing agreement with the vendor. Most established providers have this sorted out on their end, but it's worth confirming for any tool handling EEA contact data.
Why GDPR compliance also improves email deliverability
Here's the part that surprises a lot of senders: the habits GDPR requires are largely the same habits that inbox providers like Gmail, Outlook, and Yahoo use to judge whether your email belongs in the inbox or the spam folder.
- Consent lowers spam complaints. People who explicitly opted in are far less likely to hit “report spam” — and major providers now expect complaint rates to stay well under 0.3%.
- Accurate data lowers bounce rates. Removing addresses that consistently bounce (a GDPR accuracy requirement) also keeps your sender reputation healthy.
- Trimming stale contacts protects engagement rates. Inbox providers weigh engagement heavily, and a list full of people who never open your emails drags that average down.
- Honoring unsubscribes avoids blocking risk. Ignored opt-out requests turn into spam complaints, which is a fast way to get flagged by inbox providers.
- Transparency supports authentication. Clearly identifying your sending domain lines up with the authentication standards (SPF, DKIM, and DMARC) that major inbox providers now expect from bulk senders.
Technical basics: SPF, DKIM, and DMARC
Major inbox providers now expect these authentication records to be in place for anyone sending marketing volume:
- SPF is a DNS record listing which mail servers are allowed to send on behalf of your domain.
- DKIM adds a cryptographic signature to outgoing mail, proving it wasn't altered in transit and came from an authorized source.
- DMARC builds on SPF and DKIM, telling receiving servers what to do if a message fails authentication, and provides reporting back to you.
Without these in place, your email can be rejected or routed to spam regardless of how good your content or consent practices are.
A quick self-check before your next campaign
- Every contact on your list has a documented, valid reason to be there
- Pre-checked consent boxes have been removed from your signup forms
- Bounced and long-inactive addresses are reviewed and removed regularly
- Unsubscribe requests are processed promptly
- SPF, DKIM, and DMARC are correctly configured for your sending domain
- A privacy policy is published and accurately describes how you use email addresses
- Data processing agreements are in place with any third-party email or marketing tools you use
Frequently asked questions
Does GDPR apply if my company isn't based in Europe?
Yes. What matters is where the recipient is located, not where your company operates.
Is a pre-checked "subscribe" box ever acceptable under GDPR?
No. Consent has to come from a clear, active action by the person signing up.
How quickly do I need to act on an unsubscribe request?
Promptly — the sooner the better. Treat every opt-out request as time-sensitive.
Is this article legal advice?
No. It's general informational guidance to help you understand the basics. For specific compliance questions, especially around cross-border data transfers or unusual data uses, consult a qualified privacy lawyer.