How to Make Your Email Marketing GDPR Compliant in 2026: A Step-by-Step Checklist

How to Make Your Email Marketing GDPR Compliant in 2026: A Step-by-Step Checklist

GDPR compliant email marketing requires explicit, documented consent from every contact, a clear and functioning unsubscribe mechanism, a lawful basis for all data processing, and a signed Data Processing Agreement (DPA) with every marketing platform vendor. Violations carry fines of up to €20 million or 4% of annual global turnover — whichever is higher. This checklist covers every requirement with implementation steps.

GDPR Email Marketing Checklist Summary: Obtain explicit opt-in consent (no pre-checked boxes), record the consent with timestamp and source, provide easy one-click unsubscribe, sign a DPA with your email platform vendor, store personal data within the EU or under Standard Contractual Clauses, and honor subject access requests within 30 days.

Step 1: Establish Your Lawful Basis for Email Marketing

GDPR requires a lawful basis for processing personal data. For marketing email, there are two commonly applicable bases:

  • Consent (Article 6(1)(a)) — the contact explicitly opted in to receive marketing emails from you. This is the clearest and most defensible basis for commercial marketing email.
  • Legitimate interests (Article 6(1)(f)) — applicable in limited B2B scenarios where there is a genuine pre-existing commercial relationship and the marketing is directly related to that relationship. Requires a Legitimate Interests Assessment (LIA) and is harder to defend than consent.

For most marketing teams, consent is the correct and safest basis. Document which basis applies to which segment of your list — a mixed-basis approach is valid but must be tracked precisely. For lists imported from a CRM or purchased from a third party, consent almost certainly cannot be claimed, and legitimate interests is rarely defensible. These contacts should be removed from marketing sends or re-permissioned before use.

GDPR requires that consent be freely given, specific, informed, and unambiguous. The specific requirements for email signup forms:

  1. No pre-checked boxes — consent requires a positive opt-in action. Pre-checked consent checkboxes are explicitly invalid under GDPR Recital 32.
  2. Separate consent checkbox from terms of service — consent to marketing cannot be bundled with consent to your terms of service. Each requires a separate checkbox.
  3. Clear description of what they’re consenting to — “I agree to receive marketing emails from [Company Name]” is sufficient. “I agree to terms and conditions” is not sufficient consent for marketing.
  4. No incentivized consent — offering a discount or resource download in exchange for marketing consent is technically a GDPR grey area. If you use this model, ensure the resource download occurs regardless of whether the marketing consent box is checked.
  5. Granular consent where relevant — if you send multiple types of marketing (weekly newsletter, product updates, promotional offers), consider separate consent checkboxes so contacts can choose what they receive.

CampaignOS’s signup form builder generates GDPR-compliant forms with separate consent checkboxes, timestamps, and IP logging built in. For teams migrating to a more compliant platform, see our Mailchimp to open-source migration guide which covers consent record migration.

Step 3: Maintain Consent Records

GDPR requires that you be able to demonstrate consent — not just claim it. This means maintaining a record for every subscribed contact that includes:

  • The timestamp of consent (when they opted in)
  • The source of consent (which form, page, or campaign)
  • The exact consent language shown at the time of opt-in
  • The IP address of the device used for consent (for web forms)
  • The specific processing activities consented to (e.g., “marketing email”)

If you cannot produce this proof when requested by a supervisory authority or data subject, your consent is not legally defensible. For legacy lists where consent records don’t exist, you must either obtain fresh consent through a re-permission campaign or establish a valid legitimate interests basis with a completed LIA. Delete contacts for whom neither is possible.

Step 4: Implement Compliant Unsubscribe Mechanisms

Every marketing email must contain a clear, functioning unsubscribe link that requires no more than one click to activate. GDPR requirements for unsubscribe mechanisms:

  • One-click unsubscribe — the unsubscribe process should require no additional steps beyond clicking a link. Requiring login, email re-entry, or confirming in a separate form is a violation.
  • 7-day processing limit — opt-outs must be processed within “without undue delay.” In practice, 7 days is the maximum acceptable window; most platforms process immediately.
  • Global suppression — unsubscribing from one list or campaign must suppress the contact from all marketing communications, not just that specific list.
  • No re-subscription without fresh consent — once a contact unsubscribes, they cannot be re-added to marketing lists without a new explicit consent event.

Your marketing platform must support List-Unsubscribe headers (both the mailto: and https: variants) in outgoing email headers. Gmail and Yahoo now require this for bulk senders and use it for one-click unsubscribe in their UI. CampaignOS inserts List-Unsubscribe headers automatically in all outgoing emails.

Step 5: Sign Data Processing Agreements with All Vendors

Any company that processes personal data on your behalf is a “data processor” under GDPR. This includes your email marketing platform, CRM, analytics tools, and marketing automation software. You must sign a Data Processing Agreement (DPA) with each processor before sending them personal data.

Key DPA requirements to verify:

  • The processor only processes data on your documented instructions
  • The processor implements appropriate technical and organizational security measures
  • The processor does not engage sub-processors without your authorization
  • The processor assists you in responding to data subject rights requests
  • The processor deletes or returns all personal data upon termination of the service

Most major email platforms (Mailchimp, Brevo, ActiveCampaign) provide DPAs through their settings or legal portals. For self-hosted platforms like CampaignOS, you are the data controller and data processor — no DPA is required with yourself, which eliminates a significant compliance complexity. This is one of the underappreciated GDPR advantages of self-hosting your marketing infrastructure.

Step 6: Review Data Storage and International Transfers

GDPR restricts transfers of EU personal data to countries outside the EEA unless adequate protections are in place. If you use a US-based SaaS email marketing platform, personal data from EU subscribers may be transferred to US servers — which requires either:

  • EU-US Data Privacy Framework (DPF) — US companies certified under DPF can receive EU personal data. Check if your vendor is DPF-certified at the US Department of Commerce DPF list.
  • Standard Contractual Clauses (SCCs) — contractual protections for data transfers, typically included in enterprise DPAs.
  • Data residency options — some vendors offer EU data residency (servers in EU/EEA). Check if this is available and enabled for your account.

Self-hosted platforms eliminate this entirely — your data stays on the server you choose, in the jurisdiction you choose. Hosting a CampaignOS instance on Hetzner (Germany) or OVH (France) keeps EU subscriber data in the EU with no international transfer concerns. See our self-hosted marketing automation guide for infrastructure options.

Step 7: Handle Subject Rights Requests

GDPR grants individuals the following rights regarding their personal data, all of which you must be operationally ready to fulfill:

  • Right of access (SAR) — subject can request all personal data you hold about them. Must be fulfilled within 30 days.
  • Right to erasure (“right to be forgotten”) — subject can request deletion of their personal data. Must be fulfilled unless you have an overriding legal basis to retain data.
  • Right to data portability — subject can request their data in a structured, machine-readable format (CSV is acceptable).
  • Right to rectification — subject can request correction of inaccurate data.
  • Right to object — subject can object to processing based on legitimate interests.

Build an operational process for receiving and responding to these requests before you launch email marketing at scale. A simple intake form, a designated DPO or data protection contact, and documented SLAs for each request type is sufficient for most SMBs.

Step 8: Conduct Regular Compliance Audits

GDPR compliance is not a one-time checkbox. Quarterly audits should cover:

  1. Review all active lists for valid consent records — delete or re-permission any contacts without documented consent
  2. Verify all signup forms still display correct consent language and capture required fields
  3. Confirm all vendor DPAs are current and in place
  4. Check that unsubscribe links are functioning in all email templates
  5. Review any data subject requests received and ensure they were fulfilled within SLA
  6. Update your privacy policy if any new data processing activities have been introduced

CampaignOS helps maintain GDPR compliance through built-in consent tracking, one-click unsubscribe management, automatic bounce suppression, and data export tools for subject access requests. For teams building their full marketing automation stack, see our marketing automation for small business guide which covers compliance requirements alongside workflow setup.

GDPR-Ready with CampaignOS: CampaignOS includes built-in consent tracking, one-click unsubscribe, bounce suppression, and data export for GDPR compliance — all in an open-source, self-hosted platform. Start free at campaignos.site.

FAQ

Is email marketing allowed under GDPR?

Yes. Email marketing is allowed under GDPR when you have a valid lawful basis for processing the recipient’s personal data. For most commercial marketing email, this means explicit consent — the recipient voluntarily opted in to receive marketing emails from you, and you have documented proof of that consent. Email marketing to contacts who have not consented is a GDPR violation regardless of opt-out instructions included in the email.

What counts as GDPR consent for email marketing?

GDPR consent for email marketing must be freely given, specific, informed, and unambiguous. In practice: no pre-checked boxes, a clear description of what the subscriber is consenting to (“I agree to receive marketing emails from X”), a separate consent action from any other agreement (like terms of service), and no coercion or inappropriate incentivization. You must retain a timestamped record of the consent event including the form used and the IP address.

What are the penalties for GDPR email marketing violations?

GDPR violations can result in fines of up to €20 million or 4% of annual global turnover, whichever is higher — for serious violations like unlawful processing or consent failures. Less severe violations carry fines up to €10 million or 2% of global turnover. Fines are calibrated to the severity, duration, and intentionality of the violation, as well as whether the organization cooperated with regulators and took steps to mitigate harm.

Do I need a DPA with my email marketing platform?

Yes. Any SaaS email marketing platform that processes EU personal data on your behalf is a data processor under GDPR, and you must have a signed Data Processing Agreement (DPA) with them before sending them personal data. Major platforms like Mailchimp, Brevo, and ActiveCampaign provide DPAs through their account settings or legal portals. Self-hosted platforms like CampaignOS eliminate this requirement since you control the infrastructure yourself.

Can I email existing customers under GDPR without new consent?

Possibly, under the “soft opt-in” rule or legitimate interests. In the UK (and some EU interpretations), you may email existing customers about similar products/services without new consent if they provided their contact details in the context of a previous transaction and you gave clear opt-out information at the time. This is called the soft opt-in exemption. For marketing unrelated to the original transaction, or for prospects who have not made a purchase, explicit consent is required. Requirements vary by EU member state — consult legal advice for your specific jurisdiction.

How long can I keep email subscriber data under GDPR?

GDPR’s storage limitation principle requires you to retain personal data only as long as necessary for the purpose it was collected. For email marketing, best practice is to retain active subscriber data as long as they remain subscribed, then delete or anonymize data within 30–90 days of unsubscribe. Implement automatic deletion rules in your marketing platform for contacts who have been inactive and unsubscribed for more than 12 months.

{
“@context”: “https://schema.org”,
“@type”: “FAQPage”,
“mainEntity”: [
{
“@type”: “Question”,
“name”: “Is email marketing allowed under GDPR?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Yes, when you have a valid lawful basis — typically explicit consent. Email marketing to contacts who have not consented is a GDPR violation regardless of opt-out instructions.”
}
},
{
“@type”: “Question”,
“name”: “What counts as GDPR consent for email marketing?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “GDPR consent must be freely given, specific, informed, and unambiguous: no pre-checked boxes, clear description of what they’re consenting to, separate from other agreements, with a timestamped consent record retained.”
}
},
{
“@type”: “Question”,
“name”: “Do I need a DPA with my email marketing platform?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Yes. Any SaaS platform processing EU personal data on your behalf requires a signed DPA. Self-hosted platforms like CampaignOS eliminate this requirement since you control the infrastructure.”
}
}
]
}