GDPR and your data

    Practical data protection for senders: lawful basis, consent records, prompt unsubscribes, subject requests, retention and footer rules.

    On this page

    What this page covers#

    The data protection work that falls on you as the sender: why you are allowed to email each person, what you can prove about it, how fast you act on an unsubscribe, what to do when someone asks for their data, and how long you keep it. You decide who is on your lists and what they receive, IGSendMail carries out those instructions, and the obligations sit with you.

    General guidance, not legal advice

    Nothing here is legal advice or a compliance certification. Data protection law varies by jurisdiction, by sector, and by where your recipients live rather than where you do. Take your own advice from a qualified professional before you rely on any of it.

    Under the GDPR you need a lawful basis for processing personal data. Marketing email usually rests on consent or legitimate interests, and you should be able to say which it is for each group of contacts, and why.

    Consent has to be a real choice:

    • Freely given and specific. Signing up for a webinar is not agreement to a weekly newsletter unless you said so at the time.
    • Unambiguous and affirmative. A pre-ticked box is not consent. Neither is a checkbox buried under a submit button.
    • Separate from your terms. Consent to marketing is not consent to a privacy policy or to a contract.
    • As easy to withdraw as it was to give.

    Two practices are not consent and cause real harm: buying or renting a list, and mailing scraped addresses. Both produce complaints and spam-trap hits, and both damage the reputation of the domain you spent time authenticating.

    Use double opt-in where you can. A timestamped confirmation from the address itself is the strongest consent record you can hold, and it keeps typos and malicious signups off the list. See Double opt-in.

    Keep a record of how each contact joined#

    If a subscriber or a regulator asks why you are mailing someone, "they must have signed up" is not an answer. A record is. Store the source alongside the contact, using Fields for anything the list does not capture on its own:

    • Where they came from: which form, import, event or integration.
    • When: the date, plus the confirmation date if you used double opt-in.
    • What they agreed to: the wording on screen at the time, or a reference to that version.

    Capture it at the point of collection. Reconstructing it a year later from memory is not a record.

    Imports are the weak spot. Uploading a list makes you responsible for its provenance, and the file carries none of that unless you put it there. Add a source and a date column before you import, and refuse lists whose origin nobody can explain.

    Honor unsubscribes promptly#

    Someone who unsubscribes must stop receiving marketing email. Not eventually, and not one more campaign because it was already queued.

    • Keep the unsubscribe link in every template. Removing it is the fastest route to complaints and legal exposure.
    • Make it one click. No login, no password, no preference maze a person has to navigate to be left alone. A preference center is fine as long as a plain unsubscribe is visible on it.
    • Let suppression do its job. Unsubscribed and hard-bounced addresses are suppressed, and re-importing an older export is how people accidentally mail someone who opted out. See Blacklist and suppression.
    • Do not require a reason. Ask if you want, but never make it a condition of leaving.

    Suppression is a feature, not an error

    Blacklist exists so a person who left stays gone. Never work around it by deleting a contact and re-adding them, or by uploading an older copy of a list. That is how a formal complaint starts.

    One-click unsubscribe is now expected

    Major mailbox providers, Gmail and Yahoo among them, expect bulk senders to support one-click unsubscribe in the message headers, so a recipient can opt out from the inbox without opening your email. They also expect authenticated sending and a low complaint rate, so keep your sending domain authenticated with SPF, DKIM and DMARC. Treat the complaint rate as a signal about your consent practices. Complaints rise when people do not remember agreeing to hear from you.

    Access and deletion requests#

    People can ask what you hold about them, ask for a copy, ask you to correct it, and ask you to delete it. These arrive by any route: a reply to a campaign, a contact form, a message to support. Your team has to recognize one, because a request need not cite a law to be valid, and there are time limits for responding.

    Access. Gather what you hold for that contact: address, custom Fields, list membership, subscription date and source, engagement history. Export it in a readable form.

    Correction. Update the contact record. If the data also lives in a CRM that syncs into your lists, correct it there too, or the next sync will undo you.

    Deletion. Delete the contact record and the associated data, across every list and system, not only the one you happened to open. One exception is worth understanding: if the person unsubscribed, you generally need to keep enough information to be sure you do not mail them again. If you are unsure how those two obligations interact where you operate, take advice on it.

    Retention#

    Keeping data forever because storage is cheap is not a retention policy, and it is what an auditor asks about. Decide how long you keep contact data and engagement history, write it down, apply it, and say so in your privacy notice. A workable habit:

    • Review contacts who have not opened or clicked in twelve to twenty-four months.
    • Ask whether they still want to hear from you, then remove the ones who do not respond.
    • Keep the suppression record when you remove someone who opted out.

    This helps deliverability too. Old, unengaged addresses turn into spam traps, and mailing traps damages the domain reputation your active subscribers depend on.

    Every marketing email has to carry a valid physical mailing address for the sender, alongside the unsubscribe mechanism. In the United States that is a CAN-SPAM Act requirement, and most other jurisdictions expect the same. Set your organization name and postal address once in account settings so the footer can use it, rather than typing it into each campaign.

    • You have no office. A registered office, a mailbox service, or another real address that reaches you is acceptable. It has to be genuine and current.
    • You run several brands. Use the address of the legal entity doing the sending.
    • The address changed. Update it in settings, then check a template preview.

    Last updated September 10, 2026

    Was this page helpful?