Email Marketing
GDPR and email consent turn what many marketers treat as a legal nuisance into something that's actually good practice: getting genuine permission before you email people. The regulation (and the wave of similar privacy laws worldwide) reshaped how you can collect and use email addresses — and while the compliance details matter, the underlying principle aligns neatly with what makes email work anyway. Here's what GDPR means for email marketing, the consent rules, and why compliance and good marketing point the same way. This is general guidance, not legal advice — consult a professional for your specific situation.
What GDPR changed for email
The core shift GDPR (and laws like it) brought: you need a lawful basis — usually genuine, informed consent — to collect and use someone's email for marketing, and that consent has real standards. The key requirements in spirit: consent must be freely given, specific, informed and unambiguous (a clear affirmative action — a ticked-by-choice box, not a pre-ticked one or a buried assumption — where the person actively agrees, knowing what they're agreeing to); no pre-ticked boxes or bundled consent (you can't sneak consent in or make it a condition of something unrelated); clear information (people must know who's collecting, why, and what they're signing up for); easy withdrawal (unsubscribing/withdrawing consent must be as easy as giving it); and records (you should be able to demonstrate you have valid consent). The regulation applies broadly (to EU residents' data regardless of where you are, and similar principles appear in laws globally), which is why permission-based practice has become the universal standard, not a regional quirk.
The consent rules in practice
What compliant consent looks like operationally: opt-in, not opt-out (people actively choose to join — the affirmative-action standard — rather than being added and left to opt out; this is exactly the permission-based list-building that good email requires anyway); clear signup language (the opt-in makes plain what they'll get — marketing emails, how often, from whom — so consent is informed, per the opt-in design); separate consents where needed (don't bundle "agree to terms" with "send me marketing" — keep marketing consent distinct and optional); honour preferences and withdrawal (an easy, honoured unsubscribe in every email, and a preference centre where people control what they get — respecting the person, and reducing complaints); be careful with bought/scraped lists (these almost never have valid consent and breach the rules — another reason never to buy lists, beyond the deliverability damage); and keep consent records (know when and how each subscriber opted in). Note that specifics vary by jurisdiction and law (GDPR, and others), and legitimate-interest bases exist in some contexts — so get proper advice for your situation — but opt-in, informed, withdrawable consent is the safe, standard practice.
Why compliance and good marketing align
The reassuring convergence: everything GDPR requires is also what makes email marketing work. Permission-based lists engage better and protect deliverability (people who consented want your email; people who didn't mark it spam). Informed consent and clear expectations reduce unsubscribes and complaints (people know what they signed up for). Easy withdrawal beats a spam complaint every time. Respecting preferences via a preference centre improves relevance and retention. Not buying lists avoids both legal risk and deliverability disaster. So compliance isn't a tax on good marketing — it is good marketing, formalised: the permission, honesty, and respect that build an engaged owned audience are exactly what the law requires. Treat consent not as a hurdle but as the foundation of a healthy, trusting list — the owned audience content and authority help you build, done right (our half). (Again: general guidance, not legal advice — consult a professional for compliance specific to your situation.)
Frequently asked questions
Do I need consent to send marketing emails under GDPR?
Generally yes — you need a lawful basis, usually genuine consent (freely given, specific, informed, unambiguous — a clear affirmative action, not a pre-ticked box), to collect and use email for marketing to people covered by GDPR. Some contexts allow a legitimate-interest basis, and specifics vary by jurisdiction, so get proper legal advice for your situation. But the safe, standard practice is opt-in, informed, withdrawable consent — which is also the permission-based list-building good email requires anyway. (This is general guidance, not legal advice.)
Are bought email lists legal under GDPR?
Almost never — bought or scraped lists lack the valid, specific, informed consent GDPR requires (those people didn't agree to hear from you), so emailing them typically breaches the rules and risks penalties. It's also a deliverability disaster (recipients mark you spam, wrecking your reputation). So there are two strong reasons never to buy lists — legal and practical — reinforcing that building a permission-based list from scratch is the only sound approach. (Consult a professional for your specific compliance situation.)
Isn't GDPR just a burden on email marketing?
It's less a burden than good practice formalised — everything GDPR requires (permission, informed consent, clear expectations, easy withdrawal, respecting preferences) is also what makes email work: permission-based lists engage better and protect deliverability, informed consent reduces complaints, and respecting preferences improves relevance and retention. Compliance and good marketing point the same way — the permission and respect that build an engaged, trusting owned audience are exactly what the law asks. Treat consent as the foundation, not a hurdle, for the audience content and authority build (our lane). (General guidance, not legal advice.)