All articlesCompliance

    What Your Email Privacy Policy Needs to Say

    Your website privacy policy probably ignores your email program. Here is the full data inventory to disclose, how to handle legal basis and subprocessors, a retention schedule you can actually execute, and where the policy must be linked.

    What Your Email Privacy Policy Needs to Say
    Erin Moore
    Erin Moore
    September 14, 20269 min read
    Share:

    An email privacy policy tells subscribers exactly what personal data you collect, why you collect it, how long you keep it, who else touches it, and how to get it deleted. It must be written in plain language, linked from every signup form, and kept accurate as your tooling changes.

    This article is general information, not legal advice. Privacy law varies by jurisdiction and by the kind of data you handle. Have qualified counsel review your policy before you publish it.

    Why email needs specific coverage

    Most companies have a privacy policy that describes their website. Very few describe their email program, and that gap is where problems start. Email involves data practices your web policy probably never mentions: open tracking pixels, click redirection, engagement scoring, third-party sending infrastructure, and cross-border data transfer.

    A subscriber has a reasonable right to know that you record when they opened a message, which links they clicked, and that this behavior may determine what you send next. If your policy is silent on that, you have a transparency problem regardless of which regulation applies to you.

    The sections every email privacy policy contains

    SectionWhat it must answerCommon mistake
    Identity and contactWho is the controller, and how do people reach you?Only a web form, no postal address or named contact
    Data collectedExactly which fields and signals, including behavioralOmitting opens, clicks, IP, and device data
    PurposesWhy each category is collectedVague catch-alls like "to improve our services"
    Legal basisConsent, contract, or legitimate interest — per purposeClaiming consent for everything, including analytics
    SharingNamed categories of processors and why"Trusted partners" with no detail
    TransfersWhere data goes if it leaves the regionNo mention of US-hosted infrastructure
    RetentionHow long, and what triggers deletion"As long as necessary" with no schedule
    RightsAccess, deletion, portability, objection — and howListing rights with no working mechanism
    SecurityMeaningful summary of safeguardsMarketing language about "bank-level encryption"
    ChangesHow you notify people and version the documentNo effective date on the page

    Be specific about what you collect

    Write an inventory before you write prose. For a typical email program the honest list runs longer than people expect:

    • Provided directly: email address, name, company, any custom fields on your form.
    • Captured at signup: timestamp, IP address, the URL of the form, and the consent text shown at that moment.
    • Behavioral: opens (via tracking pixel), link clicks, unsubscribes, bounces, and complaint events fed back from mailbox providers.
    • Derived: engagement scores, lifecycle stage, segment membership, predicted interests.
    • Inferred from the above: approximate location from IP, device and mail client from user agent.

    That last category is the one most policies skip. If you use device or location data for send-time optimization, say so. The test is simple: would a subscriber be surprised to learn you had it? If yes, it belongs in the policy.

    Legal basis and consent language

    Under GDPR you need a lawful basis for each processing purpose, and marketing email to individuals in the EU generally relies on consent that is freely given, specific, informed, and unambiguous. In practice that means an unticked checkbox, wording that describes what you will send, and records proving when consent was given. Our guide to GDPR email marketing in the EU covers the consent mechanics in more depth.

    Other regimes work differently. CAN-SPAM in the United States does not require prior consent but does require accurate headers, a physical postal address, and a working unsubscribe honored promptly. CASL in Canada requires express or implied consent and puts the burden of proof on the sender. Several US state privacy laws add access and deletion rights that your policy must describe.

    Two rules hold up across all of them:

    1. Do not bundle. Marketing consent cannot be a condition of buying something or of accepting terms of service.
    2. Do not overclaim consent. If you rely on legitimate interest for security logging or fraud prevention, say legitimate interest. Labeling everything as consent creates an obligation you then break.

    Third parties, subprocessors, and where the data lives

    Your email platform is a processor acting on your instructions. So is your CRM, your analytics tool, your form builder, and any enrichment service you plug in. Subscribers are entitled to know these exist.

    Name categories at minimum, and maintain a linked subprocessor list you can update without republishing the whole policy. Include:

    • The email service provider that stores your list and sends your mail.
    • Any CRM or data warehouse that syncs subscriber records.
    • Analytics and attribution tools that receive click data.
    • Verification or enrichment services that touch addresses.
    • The countries where each of these stores data.

    If your data leaves the EEA or UK, state the transfer mechanism you rely on. And check the contract side, not just the policy: a data processing agreement with your provider is the document that makes the promise enforceable. IGSendMail is built for GDPR, CAN-SPAM, and CASL compliance and records consent metadata with every signup, but the policy describing what you do with that data is still yours to write.

    Retention and deletion that you can actually perform

    Vague retention language is the most common weak point. "We keep data as long as necessary" is not a schedule; it is a shrug. Write something you can defend and execute:

    • Active subscribers: retained while subscribed.
    • Unsubscribed contacts: minimal record retained on a suppression list indefinitely, because you need it to keep honoring the opt-out. Say this explicitly — people are often confused about why unsubscribing does not delete them.
    • Engagement event data: a defined window, for example 24 months, then aggregated or deleted.
    • Consent records: retained for as long as you might need to prove consent, plus your limitation period.
    • Bounced and invalid addresses: removed from sending, retained in suppression.

    Then make sure the schedule matches reality. A policy promising 24-month deletion while your data warehouse keeps everything forever is worse than no policy, because it is a documented broken promise.

    Rights requests, linking, and keeping it current

    Give people one clearly labeled route — a dedicated email address or a form — and describe your response timeline. Verify identity before acting on a deletion request, since acting on an unverified one is itself a breach. Log every request and its outcome.

    On placement: link the policy from every signup form, from your email footer, and from your site footer. A policy nobody can find at the moment of consent does not make consent informed. Add a plain effective date at the top, keep an archive of prior versions, and notify subscribers of material changes rather than silently editing.

    Review the policy whenever you add a tool, change what you collect, or expand into a new region — and at minimum once a year regardless. Most policies go stale because a new integration quietly started receiving data and nobody updated the document.

    Frequently asked questions

    Do I need a separate privacy policy for email marketing?

    Not necessarily a separate document, but your main policy needs a section that specifically covers email data practices such as open tracking, click tracking, engagement scoring, and your sending infrastructure.

    Do I have to disclose email open tracking?

    You should. Tracking pixels collect behavioral and technical data including IP address and mail client, and transparency about it is expected under GDPR and increasingly under US state privacy laws.

    Does unsubscribing mean I must delete someone's data?

    No. You generally need to keep a minimal suppression record so you can continue honoring the opt-out. Explain this in your policy so subscribers understand why the record persists.

    Where does the privacy policy link need to appear?

    On every signup form near the consent language, in your email footer, and in your website footer. Consent is not informed if the policy was not accessible at the moment it was given.

    How often should I update my email privacy policy?

    Any time you add a tool that touches subscriber data, change what you collect, or expand into a new jurisdiction, plus a scheduled annual review. Date every version and archive the previous ones.

    Compliance is easier when the platform handles the plumbing. IGSendMail records consent metadata, configures SPF/DKIM/DMARC automatically, and is built for GDPR, CAN-SPAM, and CASL. Get started.

    Enjoyed this article?

    Get email marketing tips delivered to your inbox every week.