Quick answer: GDPR does not ban email marketing — it requires a lawful basis (usually consent) to email people in the EU or UK. Valid consent must be “freely given, specific, informed and unambiguous” (no pre-ticked boxes), easy to withdraw, and documented. Fines reach €20 million or 4% of global annual turnover, whichever is higher (GDPR.eu).
If any of your subscribers live in the EU or UK, the GDPR applies to you — even if your business is based elsewhere. It is less scary than the headlines suggest: good, permission-based email marketing is already most of the way to compliant. Here is what the regulation actually requires.
Disclosure: Bluey Email, mentioned near the end, is my own product. This is general information, not legal advice — consult a qualified professional for your situation.
Does GDPR ban email marketing?
No. As GDPR.eu’s Ben Wolford writes, “the GDPR does not ban email marketing by any means. The GDPR did not set out to be anti-business, just pro-consumer.” What it does is regulate how you collect and use personal data — and an email address is personal data. Any organisation that handles the personal information of EU residents is covered, “including organizations not in the EU but that offer goods or services to people there.” The requirements “basically boil down to two things: secure people’s data, and make it easy for people to exercise control over their data.”
You need a lawful basis to send
GDPR gives six “lawful bases” for processing personal data, listed in Article 6. For marketing email, two matter most: consent and legitimate interest. Consent is the cleanest and most common. Legitimate interest is, in GDPR.eu’s words, “the most flexible lawful basis, though the ‘fundamental rights and freedoms of the data subject’ always override your interests” — so it is harder to rely on and you must document a balancing assessment. There is also a narrow third path: under the ePrivacy Directive’s “soft opt-in,” you may email your own existing customers about similar products or services, provided they were clearly given the chance to object and every message includes an unsubscribe option.
What does valid consent look like?
Article 4(11) defines consent as “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement.” Unpack that into four tests:
- Freely given — you can’t make consent a condition of a service that doesn’t need it.
- Specific — separate consent for each purpose; you can’t bundle marketing and analytics into one checkbox.
- Informed — in plain language, stating who you are and what you’ll do with the data.
- Unambiguous — a clear opt-in. Recital 32 is explicit: “Silence, pre-ticked boxes or inactivity should not therefore constitute consent.”
This is why a single opt-in checkbox that isn’t pre-ticked, paired with a clear description, is the safe pattern — and why double opt-in, though not strictly required by GDPR, is widely used to prove consent. You must also “keep documentary evidence of consent,” so record when and how each subscriber agreed.
The right to withdraw and be forgotten
Consent is not permanent. Under Article 7, “the data subject shall have the right to withdraw his or her consent at any time,” and “it shall be as easy to withdraw as to give consent.” In practice that means a working, one-click unsubscribe in every email. Separately, the “right to be forgotten” (Article 17) lets people ask you to erase their data, and Article 5 says you shouldn’t keep personal data “longer than is necessary” — so pruning inactive subscribers isn’t just good for deliverability, it’s good for compliance. Our list-cleaning guide and deliverability guide both help here.
GDPR vs CAN-SPAM at a glance
| GDPR (EU/UK) | CAN-SPAM (US) | |
|---|---|---|
| Consent model | Opt-in (a lawful basis required before sending) | Opt-out (consent not required to send) |
| Unsubscribe | Required; easy withdrawal any time | Required; honor within 10 business days |
| Records | Must document consent | No consent record required |
| Maximum penalty | €20M or 4% of global turnover | Up to $53,088 per email |
If you mail people in both regions, comply with GDPR’s stricter opt-in standard and you will clear CAN-SPAM’s bar too. See our CAN-SPAM guide for the US rules, and how to build an email list for compliant collection. Any reputable platform, Bluey Email included, provides the consent-friendly signup forms, one-click unsubscribe and suppression handling that make this straightforward — but the lawful basis and honest data practices are the sender’s responsibility.
Frequently asked questions
Does GDPR require double opt-in? No. GDPR requires valid, provable consent, which single opt-in with a clear un-ticked checkbox can satisfy. Double opt-in is a best practice because it makes consent easier to prove, not a legal requirement.
Does GDPR apply to my business if I’m outside the EU? Yes, if you offer goods or services to, or process data of, people in the EU or UK. Location of your business doesn’t exempt you.
Can I email existing customers without fresh consent? Often yes, under the ePrivacy “soft opt-in” for similar products or services — provided they were given a clear chance to object and every email includes an unsubscribe.
What are the GDPR fines? Up to €20 million or 4% of total worldwide annual turnover, whichever is higher, plus possible compensation to affected individuals.
References
- Ben Wolford, GDPR.eu — How does the GDPR affect email?: https://gdpr.eu/email-encryption/
- GDPR.eu — What are the GDPR consent requirements?: https://gdpr.eu/gdpr-consent-requirements/
— Shivam