IGSendMail
All articlesCompliance

GDPR Email Marketing Compliance Checklist

A practical GDPR checklist for email marketers: lawful basis, signup form rules, the consent records you must be able to produce, subscriber rights that actually work, DPAs with processors, retention limits, and a one-page audit you can run today.

GDPR Email Marketing Compliance Checklist
Erin Moore
Erin Moore
September 22, 20269 min read
Share:

GDPR applies to your email marketing whenever you process the personal data of people in the EU or UK, regardless of where your company is based. Compliance comes down to five things: a lawful basis for every send, consent that is freely given and provable, transparency about what you collect, working mechanisms for subscriber rights, and contracts with the vendors who touch the data.

A necessary caveat up front: this is a practical operating checklist, not legal advice. GDPR interpretation varies by member state and by industry, and enforcement priorities shift. Have qualified counsel review your specific setup before you rely on it.

1. Establish a lawful basis for every list

You cannot email anyone under GDPR without a lawful basis. For marketing, two are realistically available:

  • Consent. A freely given, specific, informed, unambiguous indication of wishes, given by a clear affirmative action. This is the default and the safest.
  • Legitimate interests. Available in narrow circumstances, most commonly for B2B mail to existing business contacts, and it requires you to document a balancing test weighing your interest against the recipient's rights. Note that the ePrivacy Directive layers additional consent rules on electronic marketing on top of GDPR, and those rules differ by country.

Write down which basis applies to which list. If you cannot name it for a given segment, you should not be mailing that segment. Full country-level detail is in our guide to GDPR email marketing for EU audiences.

2. Fix the signup form

RequirementCompliantNot compliant
Consent actionUnchecked box the user ticksPre-ticked box, or consent implied by form submission
GranularitySeparate box for marketing vs. service emailOne box covering everything you might ever do
ConditionalityDownload works whether or not they tickMarketing consent required to get the free resource
ClarityPlain language naming your company and content typeConsent buried in linked terms and conditions
Data collectedOnly fields you genuinely needPhone, company size, job title “just in case”
Privacy noticeLinked at the point of collectionOnly in the site footer

The conditionality rule catches many marketers off guard. If someone must accept marketing to receive an unrelated resource, the consent is not freely given, and a regulator will treat it as invalid.

3. Keep consent records you could actually produce

Article 7 requires you to demonstrate that consent was given. Store, per subscriber:

  • The email address and any other data captured
  • Date and time of consent, in a consistent timezone
  • IP address of the submission
  • The exact wording of the consent statement shown at the time
  • The source — specific form, page URL, or campaign
  • The method — single or double opt-in, and the confirmation click timestamp if applicable
  • Any later changes, including preference updates and withdrawal

Two practical points. First, save the consent wording, not just a boolean flag — when you change your form copy, old records need to reflect what those subscribers actually agreed to. Second, imported lists inherit nothing. If you acquire a list from a partner or an acquisition and cannot produce these records, you cannot lawfully mail those addresses.

4. Publish a privacy notice that says something

Articles 13 and 14 require specific disclosures at the point of collection. Your notice must cover: who you are and how to contact you; what data you collect; why you collect it and the lawful basis; how long you keep it; who else receives it, including processors and any transfers outside the EEA; the full list of data subject rights; the right to withdraw consent at any time; and the right to complain to a supervisory authority.

Link it directly from the signup form, not just the footer. Write it in language a normal person can read — GDPR explicitly requires clear and plain language, and a wall of legalese is itself a compliance weakness.

5. Make subscriber rights operable

Rights on paper are not compliance. Each of these needs a real process behind it, and the standard response window is one month:

  1. Access — can you export everything you hold on one person, including engagement history and tags?
  2. Rectification — can a subscriber correct their data without emailing support?
  3. Erasure — can you delete them fully, from your email platform and your CRM, analytics, warehouse, and backups?
  4. Portability — can you produce their data in a structured, machine-readable format?
  5. Objection — for marketing, this is absolute and must be honored immediately, with no balancing test.
  6. Withdrawal of consent — must be as easy as giving it. One click, no login required.

Test the erasure path yourself with a real address. Most teams discover the data survives in three systems they forgot about.

6. Get the unsubscribe right

  • Visible link in every marketing email — not hidden in a light gray 8-point footer
  • One click to unsubscribe, with no login and no “are you sure” gauntlet
  • Processed immediately, not on a monthly batch job
  • A preference center is good practice, but a full opt-out must always be available on the same page
  • List-Unsubscribe headers enabled so inbox-level unsubscribe buttons work

Unsubscribed addresses go on a permanent suppression list. Delete them from your active list, keep the suppression record — that record is how you prove you honored the request and how you avoid re-adding them in a future import.

7. Sort out vendors and transfers

You are the controller; your email platform, CRM, and analytics tools are processors. Article 28 requires a written data processing agreement with each. Confirm for every vendor: a signed DPA is in place, where the data is physically stored, what safeguards cover any transfer outside the EEA, what their sub-processor list looks like, and how quickly they notify you of a breach — you have 72 hours to notify a supervisory authority once you become aware of one.

8. Retention and minimization

GDPR requires you not to keep personal data longer than necessary. Set explicit rules:

DataSuggested rule
Unconfirmed opt-insDelete after 14 days
Inactive subscribersRe-engage at 12–24 months, then delete
Unsubscribe suppression recordsRetain indefinitely — needed to honor the request
Consent recordsRetain for the life of the subscription plus a defined period after
Engagement and click dataDefine a limit — 24 months is a common choice

Write these down, automate them, and review annually. An undocumented retention policy is the same as no policy.

The one-page audit

  1. Every list has a documented lawful basis
  2. No pre-ticked boxes anywhere
  3. Marketing consent is separate and never a condition of access
  4. Consent records include timestamp, IP, source, and wording
  5. Privacy notice is linked at every point of collection
  6. Access, erasure, and portability requests have a tested process
  7. Unsubscribe is one click and immediate
  8. Signed DPAs with every processor
  9. Retention rules exist and are automated
  10. Breach notification path is documented and someone owns it

Every item above should be doable inside your email platform without engineering work. IGSendMail is GDPR, CAN-SPAM, and CASL compliant out of the box, with consent logging, one-click unsubscribe, and export and erasure tooling built in.

Frequently asked questions

Does GDPR apply if my company is not in the EU?

Yes, if you offer goods or services to people in the EU or UK, or monitor their behavior. Location of your business is irrelevant — what matters is the location of the individuals whose data you process. This is general information and not legal advice.

Do I need double opt-in to comply with GDPR?

Not strictly. GDPR requires unambiguous consent you can demonstrate, and double opt-in is simply the most reliable way to produce that evidence. Single opt-in with thorough consent logging can satisfy the requirement, though several member states apply stricter national rules.

Can I email B2B contacts under legitimate interests?

Sometimes, particularly for corporate addresses at businesses relevant to what you sell, but you must document a balancing test and honor objections immediately. National ePrivacy rules layered on top vary considerably, so check the specific countries you are mailing.

What happens to my existing list if I cannot prove consent?

You should not continue mailing addresses whose consent you cannot evidence. The usual path is a re-permission campaign asking subscribers to opt in again, after which you delete everyone who does not respond.

How long can I keep subscriber data under GDPR?

Only as long as necessary for the purpose you collected it. There is no fixed number in the regulation, so you must set, document, and enforce your own retention periods — commonly 12 to 24 months of inactivity before deletion for marketing lists.

Compliance should be the default, not a project. Start with IGSendMail — consent logging, one-click unsubscribe, and GDPR-ready tooling from $19/mo.

Enjoyed this article?

Get email marketing tips delivered to your inbox every week.