How Does GDPR Affect Email Marketing? A 2026 Compliance Guide
GDPR did not kill B2B email. It changed who you can contact, what you must record, and how fast you must delete. Here is the practical playbook, with a legal-basis comparison table and a 7-step compliance checklist.

How does GDPR affect email marketing? It limits who you can contact, what you must record, and how fast you must delete. It does not ban outreach.
TL;DR
- GDPR does not ban B2B cold email. It bans the use of personal data with no lawful basis, no transparency, and no way out.
- For B2B outreach, legitimate interest (Article 6(1)(f)) is usually the workable basis. You need a written balancing test, a tight target list, and a one-click opt-out.
- The ePrivacy Directive sits on top of GDPR and is stricter in some countries. Germany, Italy, and Austria still want consent first, even for work addresses.
- Your data source matters more than your copy. Bought lists and blind scrapes draw complaints. Sourced, dated, verified records hold up.
- Compliance is five artifacts: a legitimate-interest assessment, a records-of-processing entry, a privacy notice link, a working unsubscribe, and a deletion deadline.
How does GDPR affect email marketing? Start with the data#
GDPR regulates personal data, not email. That is where most teams get confused.
Think of GDPR as food safety law for a restaurant. It does not tell you what to cook. It tells you where the ingredients may come from, how long you may store them, and who may touch them. It also tells you what to say when a guest asks what is in the dish. Email marketing is the dish. Personal data is the ingredient list.
Under Article 4, personal data is any information about a person you can identify. That sweeps in:
- Named business addresses —
sarah.chen@acme.compoints to one person. Fully in scope. - Role addresses —
sales@acme.com,info@acme.com. Usually not personal data, because no one person is named. Most marketers miss this carve-out. - Enriched attributes — job title, LinkedIn URL, direct dial, company size tied to a named person. All in scope. The enrichment itself is processing you must justify.
- Behavioural data — opens, clicks, and location pulled from tracking pixels. In scope. Pixels also trigger ePrivacy consent rules in several states.
- Inferred data — an AI score such as "likely to buy" on a named contact. In scope. If it drives automated decisions, Article 22 may apply.
So the honest answer to "how does GDPR affect email marketing" is simple. It constrains your list, your records, and your exit path. It barely touches your subject line.
Is cold B2B email still legal under GDPR in 2026?#
Yes, in most of the EU, with conditions. GDPR itself does not pick a basis for you. Recital 47 says direct marketing "may be regarded as carried out for a legitimate interest." That line is the backbone of every compliant outbound program in Europe.
The catch is the ePrivacy Directive (2002/58/EC). Each member state wrote it into national law in its own way. ePrivacy covers unsolicited messages, and in some countries it overrides the legitimate-interest route for email.
| Jurisdiction | B2B cold email allowed? | Basis in practice | Opt-out required |
|---|---|---|---|
| United Kingdom (UK GDPR + PECR) | Yes, to corporate subscribers | Legitimate interest | Yes, every message |
| Ireland | Yes, to business addresses | Legitimate interest | Yes, every message |
| Netherlands | Yes, B2B carve-out | Legitimate interest | Yes, every message |
| France (CNIL) | Yes, if relevant to the recipient's job | Legitimate interest | Yes, at collection + every message |
| Germany (UWG §7) | No — prior consent required | Consent | Yes, plus consent proof |
| Italy | No — prior consent required | Consent | Yes, plus consent proof |
| Spain | Yes, with prior-relationship or B2B nuance | Legitimate interest | Yes, every message |
| United States (CAN-SPAM) | Yes, opt-out model | N/A | Yes, honoured in 10 days |
Two takeaways. First, "GDPR compliant" is not one switch. Your posture changes country by country, so split your list by recipient country before you split it by persona.
Second, Germany and Italy are not grey areas. If most of your buyers sit in DACH, build a consent-first inbound motion. Reach the rest through LinkedIn and events instead of cold email.
For the source text, the European Commission's data protection portal is the place to start. The EDPB publishes the guidelines national regulators actually cite.
What is legitimate interest, and how do you document it?#
Legitimate interest is a balancing test you write down before you send. It is not a label you add afterwards.
The test has three core parts. Regulators expect evidence for each one, plus the safeguards you put in place.
- Purpose test — What is the interest? "Contacting sales leaders at mid-market SaaS firms about a tool that cuts their bounce rate" is specific. "Growing revenue" is not.
- Necessity test — Is email a fair way to reach that goal? If a paid ad or an inbound offer would do the same job, your case gets weaker.
- Balancing test — Would the reader expect to hear from you? A VP of Sales getting a pitch about sales tooling at work: expected. A junior designer getting an ERP pitch at a personal address: not expected.
- Safeguards — What did you do to limit the impact? One-click unsubscribe, a permanent suppression list, a cap on follow-ups, no sensitive guesses, and deletion on a fixed clock.
Write this up as a one-page Legitimate Interest Assessment (LIA) for each campaign type. Date it. Store it with your Article 30 records of processing. Under the accountability principle, a basis you cannot show is the same as no basis at all.
The common failure is not picking the wrong basis. Teams pick a fair basis, then mail a list so broad that the balancing test falls apart. Relevance is the compliance control. A tight 400-contact list is easier to defend than a loose 40,000-contact one. It also converts better, which is why compliance and response rate tend to move together.
Which data sources are safe, and which get you fined?#
Provenance is the part of GDPR that hits your tooling budget. Article 14 says you must tell people when you got their data from somewhere else, and you must name the source. The deadline is one month, or your first message, whichever comes first. If you cannot name the source, you cannot meet Article 14.
| Data source | Article 14 source disclosure | Accuracy risk | Realistic GDPR posture |
|---|---|---|---|
| Purchased CSV from a broker | Usually impossible to trace | High — often 12+ months stale | Avoid. No provenance, no defence |
| Mass-scraped from social profiles | Traceable but scraped against ToS | Medium | Risky; several DPAs have acted on this |
| Public company website / domain search | Fully traceable, publicly published | Low if re-verified | Defensible with a dated log |
| Pattern-inferred + SMTP-verified addresses | Traceable to method + verification date | Low | Defensible; document the method |
| Opt-in inbound form | Consent recorded | Lowest | Strongest basis available |
| Event / webinar attendee list | Depends on the event's own notice | Medium | Check the organiser's consent scope |
Here is the distinction that matters. Finding a business address on a published page and verifying it is one story. Buying an undated file of unknown origin is another. The first has a method you can describe in a privacy notice. The second has a vendor invoice.
That makes tooling a compliance choice, not just a purchase. Use a domain search to pull addresses a company published on its own site, and you can state your source honestly. Tomba lists its data sources in public, which is what an Article 14 notice needs. You can cite where the record came from instead of writing "a third-party provider."
Verification matters for a second reason. Accuracy is a GDPR principle, not just a deliverability metric. Article 5(1)(d) says personal data must be accurate and current. A two-year-old list where 30% of people changed jobs is a data-quality failure with a legal edge on it. Running the list through an email verifier before each campaign controls bounces and accuracy at once.
What must every marketing email contain?#
How does GDPR affect email marketing at the message level? Five elements must appear in every send. Missing one is the most common finding in small-business enforcement, because a single complaint email proves it.
- Sender identity — the legal entity, not just a brand. "Acme Software Ltd, registered in Ireland" beats "The Acme Team."
- Physical address — required by most ePrivacy laws and by CAN-SPAM in the US. A registered office is fine.
- Purpose transparency — say why you are writing and how you found them in the first two lines. One sentence does it: "I found your details on your company site." That is a trust signal, not a conversion killer.
- Working unsubscribe — no login, no reply, no survey. Process it at once, then add the address to a permanent suppression list.
- Privacy notice link — a page covering Article 13 and 14: identity, purposes, legal basis, source, retention period, and rights.
Google and Yahoo already force one-click unsubscribe headers on bulk senders, so the technical work is mostly done for you. If you send through a mailbox provider, confirm the List-Unsubscribe and List-Unsubscribe-Post headers are present. Google's sender guidelines spell out the exact rules. Compliance and email deliverability meet here: the same header that satisfies a regulator keeps you out of the spam folder.
How long can you keep prospect data?#
GDPR sets no fixed number. It sets a rule. Keep personal data only as long as you need it, and be able to state that period up front.
Here is the schedule most compliant outbound teams use:
- Unengaged cold prospects — 6 to 12 months from last contact, then delete or anonymise. After a year of silence, "necessity" is hard to argue.
- Engaged but not converted — 24 months from last engagement, reset by each new interaction.
- Opted-out contacts — keep a hashed email on the suppression list for good. Delete the rest. Keeping the minimum needed to honour their objection is allowed.
- Customers — contract and tax law rule here, often 6 to 10 years for financial records. Marketing attributes should still expire on the schedule above.
- Enrichment attributes — expire these faster than the base record. Job titles decay 20–30% a year in fast-moving sectors, so a stale title is both wrong and needless.
Write the schedule down. Automate it in your CRM. Run the deletion job on a cron. A retention policy that lives only in a Notion doc is not a control.
How do you handle deletion and access requests at scale?#
Data subject requests are the operational tax of email marketing under GDPR. You have one month to reply, and complex cases can take two more. You must answer even when you hold nothing about the person.
Build three things before you scale sending volume:
| Capability | Minimum viable version | What "good" looks like |
|---|---|---|
| Find every copy of a contact | Search CRM + sequencer manually | Single lookup by email hash across all systems |
| Delete on request | Manual delete + suppression add | Automated cascade delete, suppression retained, audit logged |
| Export on request | Screenshot of CRM record | Machine-readable JSON export within 72 hours |
| Prove your basis | Point to a policy page | Per-campaign LIA linked to the campaign record |
| Track processors | Vendor list in a spreadsheet | Signed DPAs, SCCs for non-EU transfers, annual review |
The hidden risk is shadow copies. Deleting from your CRM does not touch the enrichment tool's cache, the sequencer's contact store, or the analytics warehouse. It also does not touch the CSV someone exported to a laptop in March.
Map every system that holds a copy before the first request lands. Check that each vendor's Data Processing Agreement gives you a deletion path. A vendor that cannot delete on request is a liability you are renting.
International transfers deserve one line. If your email tool stores EU personal data in the US, you need a transfer mechanism: the EU-US Data Privacy Framework, Standard Contractual Clauses, or both. Read your vendor's DPA instead of assuming.
What does a compliant outbound workflow look like end to end?#
Here is the sequence that meets the rules without stalling pipeline:
- Define the segment narrowly. Job function, industry, company size, country. Consent-only countries drop out at this step, not later.
- Write the LIA before sourcing. Purpose, necessity, balancing, safeguards. One page, dated, stored.
- Source from places you can name. Company sites, public directories, published team pages. Log the source and date for each record. A bulk email finder run on a domain list keeps that provenance attached to every row.
- Verify before sending. Drop invalids, unconfirmed catch-alls, and role addresses you do not plan to use. Bounces also damage sender reputation.
- Check the suppression list. Every send. No exceptions. Skipping it is the top cause of a complaint turning formal.
- Send with all five required elements. Identity, address, purpose, unsubscribe, privacy link.
- Honour objections within hours. Automate the deletion job and review it each quarter.
None of this needs legal spend beyond one review of your LIA template. What it needs is a data pipeline that records where each address came from. That is a tooling decision you make on day one, not a policy you bolt on at day 300.
Where do most teams actually get this wrong?#
Three patterns cause most of the risk at small and mid-sized B2B companies.
They treat the privacy policy as the compliance work. A published policy with no LIA, no records of processing, and no retention job is documentation theatre. Regulators ask for the operating evidence.
They buy volume and hope relevance follows. A 100,000-row list from an untraceable broker fails Article 14 on the first contact. Every message from it is a complaint waiting for a slow week. A 2,000-row list you sourced and verified yourself gets better replies, has documentable provenance, and gives you an argument you can make out loud.
They forget the tracking pixel. Open tracking counts as access to the reader's device under several ePrivacy laws. Track opens on EU contacts without consent and you add a second exposure on top of your email basis. The safe move is to turn open tracking off for EU contacts and measure replies instead. Replies are the better outbound metric anyway.
If you are comparing providers, weigh transparency about sourcing as heavily as coverage numbers. BookYourData publishes detailed sourcing and compliance docs, and Tomba does the same on its data page. That documentation is what you paste into your Article 14 notice. Sites like G2 help with feature parity, but read the DPA before the feature list.
Building a list you can defend#
GDPR did not end cold email. It ended lazy cold email.
So, how does GDPR affect email marketing in practice? It moves the work upstream. Pick your countries first. Write the basis down. Source addresses you can point to. Verify them. Delete on a clock.
Do that and outreach stays legal, and the reply rates usually improve too. You do not need a law firm on retainer. You need a list you can explain, one page per campaign, and a delete button that works.
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author