MAILCRAFT
Home Features Pricing About Blog Contact Log in Get Started →
Email compliance & security

GDPR in email marketing: the minimum you need

Biała koperta z napisem Subscribe na tle czerwonych kopert

GDPR in email marketing comes down to two questions someone will ask you sooner or later: where did you get this address, and who sent it. The first one comes from a regulator or from the subscriber. The second is asked by the receiving mail filter, only in its own technical way: it checks the DKIM signature, the DMARC policy and the IP reputation. You have to handle both sides at once, because a gap in one breaks the other. We run our own fleet of sending servers, so we see this every day: a second-hand list first produces complaints, then bounces, and in the end a block on the whole pool.

Below is the minimum list. Seven things you need before your first send, plus a few you do not need, whatever the internet says. This is not legal advice. It is a set from engineering practice, written by people who pick up the phone when a campaign gets stuck in the queue.

Legal basis: GDPR and article 398 of the Electronic Communications Law, in B2B too

Two acts, two different things. GDPR covers the processing of a subscriber’s personal data. The Electronic Communications Law, article 398, covers the act of sending commercial information to someone’s address. You can keep an exemplary register and still break that second rule.

Most of the confusion happens with company addresses. jan.kowalski@firma.pl is personal data, because it identifies a specific person. Generic mailboxes such as kontakt@ or biuro@ are not automatically exempt, because there is a person behind them too, and that person receives your offer. The requirement for consent applies in B2B as well. There is no exception for a cold email to a company. None.

Legitimate interest often gets stretched into a universal excuse. It is not enough for a marketing newsletter, because the Electronic Communications Law requires consent no matter what basis you write into your record of processing activities. Buying a ready-made list or scraping websites gives you neither a legal basis nor sender reputation. Addresses like these hide spam traps, and those go straight to blocklists. Then you spend weeks rebuilding trust.

Consent that holds up: what you record at signup

Consent has to be freely given, specific, informed and demonstrable. That last condition is a technical problem, not a legal one: the burden of proof sits with you, so the data has to be captured at the moment of signup. You will not reconstruct it afterwards.

The evidence record should contain:

  • the date and time of signup with the time zone,
  • the IP address the submission came from,
  • the full text of the consent clause in the version in force that day,
  • the signup source: the specific form, a file import or an integration,
  • the confirmation status together with the time the activation link was clicked.

Separate purposes mean separate checkboxes. A newsletter is not profiling, and profiling is not passing the address to a commercial partner. One field covering all three falls apart at the first complaint. Pre-ticked boxes are out, and so is making a purchase conditional on joining the list.

Treat double opt-in as standard, not as a quirk of the overly cautious. Email confirmation filters out typos in the domain, other people’s addresses entered maliciously and spam traps. It costs a few percent of the list at the start. It saves you a crisis later. If signups come from your CRM or your shop, check whether the integration passes consent data, not just the address.

Tip: version the text of the consent clause and store the version identifier with the record. In two years you will not recall from memory what exactly someone signed up for.

The information notice and subscriber rights in practice

Four things have to be visible at the form: who the data controller is, why you collect the address, how long you keep it and who you pass it to. Put the link to the privacy policy next to the address field, not in a footer three screens further down. The recipient should make an informed decision where the decision is actually made.

Withdrawing consent has to be as easy as giving it. That means one click on the unsubscribe link, no login, no exit survey, no “are you sure” prompt. Every extra field turns an unsubscribe into a complaint at the mailbox provider, and a complaint weighs far more in reputation than a plain opt-out.

The List-Unsubscribe header with the One-Click variant handles two things at once. Large mailbox providers require it from bulk senders, and it also delivers the right to object without opening a browser. The recipient clicks a button in the mailbox interface, your server receives a POST request and removes the address. That is all.

Decide in advance who in the company handles requests for access, rectification and erasure, and through which channel. A mailbox checked once a quarter is not a procedure. The deadlines run from the day a request arrives, not from the day someone finally looked.

Tip: an unsubscribe has to take effect in the sending queue immediately. If the opt-out only lands after an overnight sync, a campaign launched in the morning will reach someone who already said no.

The technical side of compliance: authentication and headers

Sender identity starts with three DNS records. SPF says which servers may send on behalf of the domain. DKIM signs the message with a key whose public part sits in DNS. DMARC ties the two together and tells the recipient what to do with mail that fails verification. Without that set you cannot prove to anyone that the message really came from you.

Return-Path points to the address bounces come back to, and it has to match the domain in the From header at the organisational level. Otherwise DMARC will not count SPF alignment. The bounce domain is also where you collect hard returns and where you clean the list from. The PTR record for the sending server IP and the matching A record are set by our fleet, not by the customer. You take care of DNS for your domain, we are responsible for what is visible on the IP side.

Beyond authentication, four things remain:

  • TLS in transport plus encryption of subscriber database backups,
  • separating the transactional stream from the marketing one, so a campaign does not take down password resets,
  • roles and permissions in the panel instead of one account shared by the whole team,
  • an export log: who downloaded which list, and when.

Retention, list hygiene and getting out of blocks

Minimisation is a legal principle with a very practical effect. Collect only the fields you really use in segmentation. A phone number in a newsletter form lowers conversion and widens your exposure in a breach. What do you need it for?

Set a retention period and stick to it. A list kept “forever” is a pile of dead records that drag your metrics down. Remove hard bounces after the first return, soft ones after a run of them. That is data hygiene and sender reputation protection in one, because filters count the share of nonexistent addresses in a send.

Send inactive contacts a reactivation campaign, then unsubscribe them. Stubbornly mailing inboxes that never open is a negative signal no matter how good your content is.

We warm up a new IP pool and a new domain in stages. Volume grows gradually, first to the most engaged recipients, only then wider. Cutting that process short ends predictably.

When a block at a large filter arrives, the procedure is always the same: diagnosis from the SMTP logs and the text of the server response, sending cut to a minimum, a delisting request, then patient rebuilding of reputation. Nobody here promises to get around filters, because it cannot be done. What we do not have today we say plainly and put on the roadmap, instead of adding a nonexistent feature to the price list.

Entrusting processing: the agreement, subprocessors, server location

The platform provider processes your subscribers’ data on your behalf. A data processing agreement is then mandatory, not optional, and it should be signed before the first list import. Not having one is the easiest failure to prove that exists.

Ask about two specific things. First: the list of subprocessors, meaning who else touches the data when you click send. Second: the country where the servers and the backups physically sit. A transfer outside the European Economic Area needs an extra legal basis and paperwork. Processing inside the EU is simply easier procedurally.

Our fleet of sending servers means a known IP address, a known operator and one entity responsible for delivery. When something goes wrong, there is no passing you back and forth between the platform provider and an anonymous SMTP intermediary. If you are looking for that kind of setup, see this Polish email marketing platform with its own sending servers. It is also worth checking the platform’s compliance features: proof of signup, one-click unsubscribe and domain authentication.

To complete the set you also need a record of processing activities and a procedure for reporting a breach within 72 hours. The procedure has to answer three questions: who calls, whom they call and with which logs. Written after the incident, it is useless.

The minimum you must have: a checklist before your first send

  1. A legal basis for consent compliant with GDPR and article 398 of the Electronic Communications Law, for B2B recipients too.
  2. Proof of signup: date, IP, clause version, source, double opt-in confirmation.
  3. The information notice visible at the form, with a link to the privacy policy next to the field.
  4. A working one-click unsubscribe plus the List-Unsubscribe header with the One-Click variant.
  5. SPF, DKIM and DMARC set up for the sender domain, with a matching Return-Path.
  6. A retention policy with a specific period and automatic bounce cleanup.
  7. A data processing agreement with the provider, including the subprocessor list and server location.

The order of implementation matters. Domain authentication first, because without it even a legally flawless campaign lands in spam. Then the form and the consent mechanics. The first send last, at a small volume, to the most engaged part of the list.

Treat compliance as a technical parameter of the product, next to delivery time and bounce rate. A document in a drawer will not sign a message with a DKIM key. If you are configuring a domain or warming up a new pool, write to us and let us do it together, before the first campaign goes out.