If you send marketing email to anyone in the EU or UK, GDPR email marketing rules apply to almost every step of the process — because an email address is personal data, and the moment you collect one, store it, or press send, you are processing that data. GDPR is only half the picture, though. A second, more specific rulebook — the ePrivacy Directive across the EU, and the Privacy and Electronic Communications Regulations (PECR) in the UK — governs electronic marketing directly. This guide walks through how the two fit together: the lawful basis a send needs, what counts as valid consent, the narrow "soft opt-in" for existing customers, and the rights your subscribers keep for as long as you hold their address.
The two rulebooks behind GDPR email marketing#
It helps to keep two separate frameworks in mind, because they answer different questions and both have to be satisfied.
GDPR is the general data-protection regime. It says that any processing of personal data — collecting an address, storing it, segmenting it, sending to it — needs a lawful basis, and it gives the people behind those addresses a set of rights. An email address generally counts as personal data because it can identify a person; the companion guide on GDPR and email verification covers that threshold question and the data-residency angle in more depth, so this article takes it as read and focuses on the marketing itself.
ePrivacy is the specific regime for electronic communications. In the EU it is the ePrivacy Directive, transposed into each member state's national law; in the UK it is PECR. These rules deal head-on with unsolicited direct marketing by email, SMS, and similar channels. They are where the well-known "you generally need consent to email someone marketing" expectation actually lives — GDPR sets the backdrop, ePrivacy sets the channel-specific rule.
In practice you satisfy both at once. ePrivacy tells you whether you may send a marketing message down this channel to this person; GDPR tells you whether your underlying handling of their data is lawful and how you must honour their rights. A campaign that ignores either one has a gap.
Every send needs a lawful basis#
Under GDPR, processing personal data requires one of six lawful bases. For email marketing, two are realistically in play: consent and legitimate interests. The others (contract, legal obligation, vital interests, public task) rarely fit a promotional send.
Consent is the most straightforward and the one ePrivacy tends to steer you toward for marketing to individuals. Legitimate interests can support some marketing — particularly in narrow business-to-business situations — but it is not a free pass: you have to be able to show that your interest in marketing is not overridden by the recipient's interests and reasonable expectations, and you have to document that balancing exercise. Even where legitimate interests supports the GDPR side, the ePrivacy channel rules still apply on top, which is why consent (or the soft opt-in below) does most of the heavy lifting for email.
What valid consent looks like under GDPR#
When consent is your basis, GDPR is specific about what makes it valid. Consent has to be freely given, specific, informed, and unambiguous, and it has to be signalled by a clear affirmative action. Unpacking that:
- Freely given means the person has a genuine choice and isn't penalised for declining. Bundling marketing consent into terms someone must accept to buy, or making it a condition of an unrelated service, undermines it.
- Specific and informed means they know who is collecting the data and what they are agreeing to receive. Consent to hear from you is not consent to be passed to a list of unnamed "partners."
- Unambiguous, by affirmative action means an opt-in the person actively takes. Regulators and courts have been clear that pre-ticked boxes, silence, or inactivity do not count — the person has to do something deliberate, like ticking an empty box or completing a confirmation step.
Two more requirements matter for day-to-day operations. Consent must be as easy to withdraw as it was to give, which is part of why a working unsubscribe matters in every message. And you must be able to demonstrate that you have it — GDPR expects you to keep records showing who consented, when, and to what. A double opt-in flow, where the subscriber confirms via a follow-up email, is a common way to both improve list quality and create that evidence trail; the trade-offs are covered in the guide to single vs double opt-in. Consent is not forever, either — stale, years-old permission with no engagement is weaker than fresh, and many senders refresh or re-permission on a schedule.
The soft opt-in: a narrow route for existing customers#
ePrivacy and PECR carve out one limited exception often called the soft opt-in. It lets a business email marketing to an existing customer without a separate, fresh consent — but only when a specific set of conditions is met, and it is narrower than many senders assume. Broadly, the soft opt-in applies where:
- You obtained the contact details in the course of a sale (or negotiations for a sale) of a product or service to that person;
- You are marketing your own similar products or services — not unrelated lines, and not another company's offers;
- You gave the person a simple, free way to opt out when you collected the details, and you include an easy opt-out in every message you send.
The boundaries are where people trip up. "Similar products" is interpreted with care, "in the course of a sale" generally means a genuine transaction or active negotiation rather than a cold enquiry, and the exact scope can differ between jurisdictions because ePrivacy is implemented nationally. Treat the soft opt-in as a real but tightly bounded route, and check how it is framed in the specific country whose residents you are emailing — the overview of email marketing laws by country is a starting map, not a substitute for local advice.
| Route | What it generally requires | Typical use |
|---|---|---|
| Consent (opt-in) | Freely given, specific, informed, unambiguous opt-in by clear affirmative action; recorded | Newsletter and prospect lists; the default for marketing to individuals |
| Soft opt-in | Details obtained during a sale, your own similar products, easy opt-out at collection and in every message | Marketing to your existing customers |
| Legitimate interest | Documented balancing test; recipient's rights not overridden; ePrivacy channel rules still apply | Some narrow B2B / corporate scenarios |
Legitimate interest and B2B email#
Business-to-business email is where the picture gets more nuanced, and where it
is easiest to overreach. ePrivacy rules distinguish, in some jurisdictions,
between marketing to individuals and marketing to corporate subscribers, and
the rules for corporate recipients can be lighter. That has led to a common
belief that "B2B email is exempt from GDPR." It is not. Even when you email a
named person at a company, firstname@company.com is still that individual's
personal data, so GDPR — lawful basis, transparency, and the rights below — still
applies to how you handle it.
Legitimate interest can be a workable GDPR basis for some B2B outreach, provided you have done and documented the balancing test and the recipient would reasonably expect the contact. But it does not switch off ePrivacy, and the corporate-versus-individual distinction is jurisdiction-specific and easy to get wrong — precisely the kind of question to put to counsel for your target markets.
The rights your subscribers keep#
Because the addresses on your list are personal data, the people behind them hold GDPR rights for as long as you process that data — and two of them bear directly on email marketing.
The right to object to direct marketing is effectively absolute. When a person objects to being marketed to, you must stop processing their data for that purpose — full stop, no balancing test. In practice, an unsubscribe is an exercise of this right, which is why the mechanics of a compliant, low-friction opt-out matter so much; the guide to one-click unsubscribe covers how mailbox providers now expect that to work.
The right to erasure ("right to be forgotten") lets people ask you to delete their personal data in certain circumstances, and a marketing list is a common place that request lands. Alongside those sit the rights of access (a copy of what you hold), rectification (correcting it), and restriction. The operational takeaway is that a subscriber list is not a static asset you own — it is personal data you are accountable for, with living obligations attached. Note too that suppressing an address so you never email it again is different from erasing it entirely; many senders keep a minimal suppression record specifically to honour an opt-out, a nuance worth confirming with your own advisers.
Where records and list hygiene fit#
None of the above is a hygiene tool's job to guarantee, and it is worth being precise about the boundary. Verification and list cleaning do not create a lawful basis, obtain consent, or make a send compliant. What ordinary hygiene does do is keep the list you are lawfully mailing accurate and healthy: removing dead mailboxes and typos, and honouring unsubscribes and deletion requests promptly so you stop mailing people who have opted out. That discipline pairs with the wider routine of cleaning an email list — collecting with permission, keeping the consent and opt-out records GDPR expects, and not holding addresses longer than you need them.
Keeping those two threads separate keeps your thinking clear. The lawful-basis and rights questions here are legal ones for you and your counsel. The "is this address still valid and should we still be mailing it" question is the hygiene one — and it is where a verification step earns its place, keeping the permission-based list you do send to clean.
Frequently asked questions#
Do I always need consent to send marketing email under GDPR?#
Not always, but it is the most common basis. GDPR requires a lawful basis for processing, and for marketing to individuals that is usually consent, steered there by ePrivacy/PECR. Legitimate interest can support some sends — often in narrow B2B cases — and the ePrivacy soft opt-in allows marketing to existing customers about your own similar products under specific conditions. Which applies depends on your facts, so confirm your basis with a qualified adviser before relying on anything other than consent.
What makes email marketing consent valid under GDPR?#
GDPR consent must be freely given, specific, informed, and unambiguous, signalled by a clear affirmative action such as ticking an empty box. Pre-ticked boxes, silence, and inactivity do not count. Consent also has to be as easy to withdraw as it was to give, and you must be able to demonstrate you obtained it — so keeping records of who opted in, when, and to what is part of the requirement, not an optional extra.
Is B2B email exempt from GDPR?#
No. Some ePrivacy rules treat marketing to corporate subscribers more lightly than marketing to individuals, which is where the "B2B is exempt" idea comes from. But a work email address tied to a named person is still that person's personal data, so GDPR's lawful-basis, transparency, and rights obligations still apply. The corporate-versus-individual distinction is jurisdiction-specific, so it is a good question to raise with counsel for each market you email.
What is the soft opt-in?#
The soft opt-in is a limited exception in ePrivacy/PECR that lets a business email marketing to an existing customer without a separate fresh consent. It generally applies only where you obtained the details during a sale (or its negotiation), you are marketing your own similar products or services, and you offered an easy opt-out at collection and include one in every message. It does not extend to bought lists, cold prospects, or unrelated products, and its exact scope varies by country.
Clean lists and honoured unsubscribes are the operational side of any permission-based programme. Qualisend verifies the addresses on the list you are lawfully mailing and helps you keep opt-outs suppressed — start with the free email checker to test a sample, or see the pricing plans for regular list hygiene.