The General Data Protection Regulation is the anchor of European privacy law and the default legal framework for every marketing sender reaching an EU recipient. It requires a documented legal basis for every processing activity, extends to any organization worldwide that handles EU personal data, and lets supervisory authorities impose fines up to €20 million or 4% of global annual turnover, whichever is higher. Cumulative GDPR fines have crossed €7.1 billion since 2018.
General Data Protection Regulation (GDPR) · Regulation (EU) 2016/679 · In force since 25 May 2018 · Enforced by 30 national supervisory authorities across the EU/EEA (CNIL France, AEPD Spain, Garante Italy, BfDI Germany, DPC Ireland, DSB Austria, DPA Netherlands, plus 23 others), coordinated by the European Data Protection Board (EDPB) · Applies to any organization processing personal data of EU residents, regardless of the organization’s location · Max fine: €20M or 4% of global annual turnover, whichever is higher (Article 83).
Legal basis for email marketing
Under Article 6, every processing activity, including sending a commercial email, must rest on one of six legal bases. For email marketing to consumers, only two are practical:
Data subject rights that touch marketing
- Right of access (Article 15). A subject can request all personal data you hold on them within one month.
- Right to erasure (Article 17). Also known as the “right to be forgotten”, deletion within one month unless a legal ground overrides.
- Right to object to direct marketing (Article 21). Unconditional. As soon as a subject objects, sending must stop for direct marketing purposes.
- Right to data portability (Article 20). Structured, commonly-used, machine-readable format.
- Right to withdraw consent (Article 7(3)). Consent must be as easy to withdraw as it was to grant, a one-click unsubscribe link satisfies this for email marketing lists built on consent.
Who must comply
GDPR applies extraterritorially. Article 3 pulls in any organization outside the EU that offers goods or services to EU residents (paid or free) or monitors their behavior. A US SaaS with EU signups, a UK newsletter with continental subscribers post-Brexit, and an Asian retailer accepting EU shipping addresses all fall in scope. The location of your servers is irrelevant; the location of your data subjects controls.
Data controllers (who decide why and how personal data is processed) and data processors (who process on the controller’s behalf, like an ESP) share responsibility. Article 28 requires a written data processing agreement between them setting out the processor’s obligations, missing or inadequate DPAs are one of the most common triggers for supervisory-authority enforcement.
Penalties and enforcement
Two-tier ceiling. Article 83(4) violations (record-keeping, data-processor duties, notification failures) cap at €10M or 2% of global annual turnover. Article 83(5) violations (unlawful processing, consent failures, transfers, data subject rights) cap at €20M or 4%, whichever is higher. National regulators have grown steadily more aggressive: Meta €1.2B (transfers, May 2023), Amazon Luxembourg €746M (ad targeting without valid consent, July 2021, procedurally annulled March 2026 but underlying violations upheld), Meta €390M (consent-to-contract shift), TikTok €530M (2025). Beyond headline enterprise cases, France’s CNIL, Spain’s AEPD, and Italy’s Garante regularly issue mid-five to seven-figure fines against SMEs for cookie consent violations, missing DPAs, and improper email marketing lists.
Compliance checklist for email senders
- Identify the Article 6 legal basis for every list. Document it in your Record of Processing Activities (Article 30).
- Collect consent with an unchecked checkbox, plain-language purpose statement, and a clear identification of the sender. Store timestamp, source URL, and the exact consent language shown.
- Publish a privacy notice at the point of collection covering Articles 13 or 14 disclosures (identity, purposes, legal basis, retention, subject rights).
- Include a working unsubscribe link honored immediately in every marketing message. Delete or suppress within a documented retention window.
- Sign a written data processing agreement with every ESP, CDP, and marketing automation vendor. Confirm sub-processor lists and international transfer safeguards.
- For UK subscribers post-Brexit, apply UK GDPR + PECR (near-identical to EU GDPR but enforced separately by the ICO).
- For US or other international transfers, rely on the EU-US Data Privacy Framework certification for recipient organizations, or use Standard Contractual Clauses with a transfer impact assessment.
Common misconceptions
“Legitimate interest covers all B2B email.” No. Legitimate interest supports marketing to existing customers for similar products, not cold outreach. Cold B2B email in Germany, France, Italy, and most other member states requires prior consent under the ePrivacy Directive layered on top of GDPR.
“We are not in the EU so GDPR does not apply.” Article 3(2) explicitly reaches organizations outside the EU that offer goods or services to EU residents or monitor their behavior. A signup form in English available worldwide is not a defence.
“Our ESP handles GDPR for us.” ESPs are data processors. The controller (you, the sender) retains full responsibility for consent, legal basis, and data subject rights. The ESP is only responsible for what it does with the data you send it.
“GDPR only fines the giants.” The DLA Piper 2026 survey documents thousands of five- and six-figure fines against SMEs, primarily for cookie consent failures, missing DPAs, and improper email marketing lists. Regulators explicitly treat smaller organizations with proportional severity, not exemption.
Frequently asked questions
Does GDPR apply to B2B email?
Yes. Personal data under GDPR includes any information relating to an identified or identifiable natural person, work email addresses in the format firstname.lastname@company.com are personal data. Business generic addresses (info@, sales@) are outside GDPR scope but often still covered by national ePrivacy law and the EU ePrivacy Directive.
What is the soft opt-in exception?
Article 13(2) of the ePrivacy Directive allows email marketing without prior consent to existing customers for similar products or services, provided the address was collected in the context of a sale, the customer was given a clear opt-out at collection, and every subsequent message includes an easy opt-out. Individual member states implement the exception with slight variations; Germany and Italy interpret it narrowly, the UK PECR interpretation is broader.
Can I use pre-checked consent boxes?
No. The CJEU Planet49 decision (October 2019) and repeated CNIL enforcement have established that pre-ticked boxes do not constitute valid GDPR consent. A positive, unambiguous action from the subject is required.
How long can I keep marketing consent?
GDPR does not set a fixed expiry. The EDPB and national regulators expect controllers to refresh consent when the processing context materially changes, when the subject has been inactive for an extended period (commonly interpreted as 24 to 36 months for marketing lists), or when the legal basis or purpose changes. Retention periods must be published in the privacy notice.
What is a Data Processing Agreement (DPA)?
Article 28 requires a written contract between controller and processor covering processing scope, duration, purpose, categories of data and subjects, controller instructions, confidentiality, security measures, sub-processor engagement rules, data subject rights assistance, breach notification, and end-of-service data handling. Every ESP and marketing tool must provide one; missing or inadequate DPAs are one of the most common enforcement triggers.
Where to go next
- CNIL (France), the most active EU regulator on ad-tech and email marketing consent
- BfDI (Germany), federal DPA and 16 state DPAs with strict opt-in interpretation
- AEPD (Spain), highest volume of fines against SMEs across the EU
- CAN-SPAM Act (US), opt-out contrast with GDPR’s opt-in regime
Building a GDPR-compliant list? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate complaints from recipients who never gave valid consent. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.
About the Author

Alaa · LinkedIn
Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.
About SMTPedia
SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.
We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.

