{"id":18962,"date":"2021-12-21T07:29:41","date_gmt":"2021-12-21T07:29:41","guid":{"rendered":"https:\/\/www.gmass.co\/blog\/?p=18962"},"modified":"2022-04-12T03:26:33","modified_gmt":"2022-04-12T03:26:33","slug":"gdpr-email","status":"publish","type":"post","link":"https:\/\/www.gmass.co\/blog\/gdpr-email\/","title":{"rendered":"GDPR Email Marketing: What You Need to Know"},"content":{"rendered":"<p><a href=\"#whatdoes\">Email marketing<\/a> in the European Union has gotten trickier thanks to <b>GDPR<\/b>.<\/p>\n<p>However, by adopting some <a href=\"#best\"><b>easy-to-follow practices<\/b><\/a>, you can ensure that you comply with the EU\u2019s GDPR email marketing requirements.<\/p>\n<p>In this article, I\u2019ll first briefly explain <a id=\"this\" href=\"#whatis\">what GDPR is<\/a>. I\u2019ll then cover its implications for email marketing and highlight five best practices for GDPR compliant email marketing. Later, I\u2019ll describe <a href=\"#how\">what impact GDPR may have on your email policy<\/a>.<\/p>\n<p>As a bonus, I\u2019ll also answer <a href=\"#faq\">two GDPR email FAQs<\/a>.<\/p>\n<h2>This Article Contains:<\/h2>\n<p>(Click on links to jump to specific sections.)<\/p>\n<ul>\n<li><a href=\"#whatis\">What Is GDPR?<\/a><\/li>\n<li><a href=\"#whatdoes\">What Does GDPR Say about Email Marketing?<\/a><\/li>\n<li><a href=\"#coldemail\">Is Cold Emailing Allowed under GDPR?<\/a><\/li>\n<li><a href=\"#best\">5 Best Practices for GDPR Compliant Email Marketing<\/a><\/li>\n<li><a href=\"#how\">How GDPR Affects Your Email Policy<\/a><\/li>\n<li><a href=\"#faq\">2 GDPR Email FAQs<\/a><\/li>\n<\/ul>\n<p><b><i>Disclaimer: <\/i><\/b><i>This article is meant to provide a high-level overview of how GDPR affects <\/i><i>emails<\/i><i>. <\/i><b><i>It\u2019s not a substitute for <\/i><\/b><b id=\"whatis\"><i>legal advice<\/i><\/b><i>.\u00a0<\/i><\/p>\n<p><i>For legal <\/i><i>advice<\/i><i> and specific <\/i><i>questions<\/i><i> on email regulations, please reach out to your attorney or talk to your <\/i><i>data protection officer<\/i><i>.<\/i><\/p>\n<p>Let\u2019s get started.<\/p>\n<h2>What Is GDPR?<\/h2>\n<p>GDPR means <b>General Data Protection Regulation<\/b>.<\/p>\n<p>It\u2019s a European Union data protection and privacy law that regulates how the user data of individuals in the EU can be collected, stored, and processed.<\/p>\n<p>There are <b>three<\/b> key things you should know about GDPR:<\/p>\n<ol>\n<li>GDPR applies to any organization (referred to as the &#8220;data processor&#8221; or &#8220;data controller&#8221;):\n<ul>\n<li>Operating within the European Union<\/li>\n<li>Outside the European Union, but offering goods and services to people in the EU<\/li>\n<li>Outside the European Union, but processing the personal data of EU individuals<\/li>\n<\/ul>\n<\/li>\n<li>Under GDPR, an EU individual (referred to as the &#8220;data subject&#8221;) can monitor, control, and delete any user data relating to them. These provisions are applicable even when an organization has a <a href=\"https:\/\/www.itgovernance.eu\/blog\/en\/the-gdpr-legitimate-interest-what-is-it-and-when-does-it-apply\">legitimate interest<\/a> in processing customer data. If a data subject were to object to data processing, the organization would have to respect the individual\u2019s choice and delete their data.<\/li>\n<li>Violation of this personal data protection law can result in <a href=\"https:\/\/www.forbes.com\/sites\/bernardmarr\/2018\/06\/11\/gdpr-the-biggest-data-breaches-and-the-shocking-fines-that-would-have-been\/\">hefty fines<\/a> \u2014 up to \u20ac20 million or 4% of the organization\u2019s total global turnover.<\/li>\n<\/ol>\n<p>Essentially, GDPR protects the data privacy and data security of individuals in the EU, levying hefty fines on organizations that violate its rules.<\/p>\n<p><a id=\"whatdoes\" href=\"#this\"><b>Go back to Contents<\/b><\/a><\/p>\n<p>Now, let\u2019s go over how GDPR impacts email marketing:<\/p>\n<h2>What Does GDPR Say about Email Marketing?<\/h2>\n<p>The connection between email marketing and GDPR may not be evident at first glance. And even when you explore GDPR, you don\u2019t see many references to email requirements <i>per se.<\/i><\/p>\n<p><b>Does that mean GDPR has nothing to do with <\/b><b>email marketing<\/b><b>?<br \/>\n<\/b><b>No<\/b> \u2014 GDPR does apply to email marketing.<\/p>\n<p>GDPR mandates that organizations must:<\/p>\n<ul>\n<li>Ask recipients for an affirmative <a href=\"#best1\"><b>opt-in<\/b><\/a> to receive direct marketing communications<\/li>\n<li>Provide recipients with a clear, unambiguous way to <a href=\"#best3\"><b>opt-out<\/b><\/a> of marketing communications<\/li>\n<li>Offer a method by which customers can request the <b>deletion <\/b>of their personal data<\/li>\n<\/ul>\n<p>In short, GDPR seeks to ensure that consumers receive only direct marketing communications to which they\u2019ve consented and that add value to their lives.<\/p>\n<p><b><i>Note: <\/i><\/b><i>If you email an <\/i><i>existing customer <\/i><i>about <\/i><i>similar products<\/i><i>, you <\/i><b><i>may<\/i><\/b><i> not require express <\/i><i>consent<\/i><i> according to a <\/i><a href=\"https:\/\/www.privacypolicies.com\/blog\/lawful-basis-gdpr\/\"><i>lawful basis<\/i><\/a><i> under GDPR. However, it\u2019s always better to stay on the safe side.<\/i><\/p>\n<p><a href=\"#this\"><b id=\"coldemail\">Go back to Contents<\/b><\/a><\/p>\n<p>Now that you know what GDPR says about email marketing, I\u2019ll go over what it says about cold emailing your prospects:<\/p>\n<h2>Is Cold Emailing Allowed under GDPR?<\/h2>\n<p>The answer is a <b>conditional yes<\/b>.<\/p>\n<p>Under GDPR, marketers can send <a href=\"https:\/\/www.gmass.co\/cold-email\">cold emails<\/a> to people at companies \u2014 aka <b>B2B <\/b><b>cold emails<\/b>. But this doesn\u2019t mean that you can send cold email campaigns to any person in some random company.<\/p>\n<p>Your business should be logically connected to the business activities of the prospect\u2019s company. And you\u2019ll need a solid basis to claim how the prospect\u2019s company can benefit from your services.<\/p>\n<p>Moreover, you\u2019ll need to add a disclaimer in your email copy informing the cold email recipients:<\/p>\n<ul>\n<li>What personal data you\u2019re collecting about them<\/li>\n<li>How you\u2019ll store their personal information<\/li>\n<li>How you intend to use customer data<\/li>\n<li>How the recipient can remove their user data from your email list<\/li>\n<\/ul>\n<p>That\u2019s not all.<\/p>\n<p>You shouldn\u2019t process or store the lead\u2019s personal data longer than necessary. To stay on the safer side, consider deleting the personal data of leads who don\u2019t respond to you after 30 days.<\/p>\n<p><b>Note:<\/b> While you\u2019re allowed to send B2B cold emails, <b>businesses<\/b><b> cannot send <\/b><b>cold emails<\/b><b> to individuals (B2C) \u2014 <\/b>for lead generation or other marketing purposes \u2014 according to GDPR.<\/p>\n<p><a id=\"best\" href=\"#this\"><b>Go back to Contents<\/b><\/a><\/p>\n<p>Next, we\u2019ll take a look at some email best practices you can follow to ensure that you\u2019re complying with GDPR.<\/p>\n<h2 id=\"best1\">5 Best Practices for GDPR Compliant Email Marketing<\/h2>\n<p>Here are <b>five<\/b> best practices you can follow for email compliance with the GDPR:<\/p>\n<h3>Best Practice #1: Get Re-Permission from Your Email Subscribers<\/h3>\n<p>Your mailing or subscriber lists may include EU residents you added before GDPR came into effect (May 25, 2018).<\/p>\n<p>These are your <b>legacy contacts<\/b>, and you\u2019ll need to check how you got these subscribers.<\/p>\n<p>You may encounter<b> two<\/b> categories of people in your mailing list:<\/p>\n<ol>\n<li>People who have <b>explicitly opted-in<\/b> to receive your marketing communications \u2014 in this case, you can continue to send them direct marketing emails and don\u2019t need to ask for permission again.<\/li>\n<li>People who got <b>automatically opted-in <\/b>(for example, from a pre-checked box or purchased email lists) \u2014 in this case, you\u2019ll need to ask for their explicit consent to send them marketing communication messages.<\/li>\n<\/ol>\n<p>To get GDPR consent in case #2, you have to send re-permission email campaigns asking subscribers whether they\u2019d like to re-opt to your email list.<\/p>\n<p>After your re-permission campaign, any subscriber who has consented to receive your email marketing messages should be added to your new mailing list. People who haven\u2019t responded will need to be removed.<\/p>\n<h4>How to Send Re-Permission Email Campaigns<\/h4>\n<p>When sending re-permission campaigns, <b>personalizing <\/b>your emails can encourage existing subscribers to re-subscribe to your mailing list. But doing all of this can be tedious and error-prone, which is why you would use a robust email marketing service like <a href=\"https:\/\/www.gmass.co\/\"><b>GMass<\/b><\/a>.<\/p>\n<p>With <a href=\"https:\/\/www.gmass.co\/blog\/gdpr\/\">GMass<\/a>, you can:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.gmass.co\/blog\/mail-merge-personalization\/\">Automatically personalize<\/a> your re-permission campaigns at scale<\/li>\n<li>Monitor your unsubscribes, open and response rates, and more through <a href=\"https:\/\/www.gmass.co\/blog\/reports\/\">detailed reports<\/a> inside your Gmail inbox<\/li>\n<li><a href=\"https:\/\/www.gmass.co\/blog\/auto-follow-up-emails-until-reply\/\">Automate your follow-ups<\/a> to improve chances of re-opt-ins and <a href=\"https:\/\/www.gmass.co\/#features\">so much more<\/a><\/li>\n<\/ul>\n<h3>Best Practice #2: Be Clear about Your Communication and Privacy Policies<\/h3>\n<p>Building a list of email addresses using lead magnets on landing pages is a common marketing strategy.<\/p>\n<p>For example, let\u2019s say your website offers a free ebook on \u201cHow to Do a Keto Diet.\u201d To gain access to the ebook, a visitor needs to complete an online form on your website by providing details such as their email address.<\/p>\n<p>Now, this raises a simple question: <b>does this violate GDPR?<br \/>\n<\/b>That depends.<\/p>\n<p>I\u2019ll cover <b>two<\/b> scenarios to illustrate when you may be in the clear concerning GDPR and when you violate GDPR:<\/p>\n<p><span style=\"text-decoration: underline;\"><b>Scenario A<\/b><\/span><\/p>\n<p>Your opt-in form includes:<\/p>\n<ol>\n<li>A link to your comprehensive communication policy, which <b>clearly <\/b>specifies the kind of emails you\u2019ll send (transactional emails, marketing or promotional emails, etc.)<\/li>\n<li>A link to your detailed data privacy policy, which <b>unambiguously <\/b>explains how you use and safeguard user data<\/li>\n<li>The relevant checkboxes (<b>not pre-ticked<\/b>) an individual can click to indicate that they consent with your communication policy, data privacy policy, and other terms &amp; conditions.<\/li>\n<\/ol>\n<p>In this scenario, you\u2019re <b>likely compliant<\/b> with the GDPR regulation.<\/p>\n<p><span style=\"text-decoration: underline;\"><b>Scenario B<\/b><\/span><\/p>\n<p>Your:<\/p>\n<ol>\n<li>Communication policy is ambiguous or is unnoticeably tucked in within your terms and conditions<\/li>\n<li>Privacy policy doesn\u2019t mention for what purpose you\u2019ll use user data<\/li>\n<li>Webform contains <a href=\"https:\/\/techcrunch.com\/2019\/10\/01\/europes-top-court-says-active-consent-is-needed-for-tracking-cookies\/\">pre-ticked boxes that indicate implicit consent<\/a> but don\u2019t ask for explicit consent<\/li>\n<\/ol>\n<p>In this scenario, you\u2019re <b id=\"best3\">likely violating<\/b> GDPR rules.<\/p>\n<p>Essentially, you need to provide \u2014 clearly and openly \u2014 all the details consumers may need to make an informed decision. Moreover, you shouldn\u2019t trick potential customers into agreeing to your terms and conditions.<\/p>\n<h3>Best Practice #3: Include an Unsubscribe Link in All Your Marketing Emails<\/h3>\n<p>GDPR emphasizes the consumers\u2019 right to reclaim ownership of their data and easily opt-out of marketing communications.<\/p>\n<p>Now, you probably send emails only to people who\u2019ve explicitly consented to receive your marketing communication messages.<\/p>\n<p><b>But what if an <\/b><b>existing customer<\/b><b> or subscriber wishes to opt-out?<br \/>\n<\/b>You need to give them the option to unsubscribe!<\/p>\n<p>Not just that. You must also make it <b>straightforward <\/b>for the existing customer (or subscriber) to opt-out.<\/p>\n<p>For this, you can include an <b>unsubscribe link <\/b>when you\u2019re marketing by email.<br \/>\nSomething along the lines of:<\/p>\n<ul>\n<li>Click here to stop receiving emails from us.<\/li>\n<li>Unsubscribe from all our marketing communications.<\/li>\n<li>Opt-out of our emails.<\/li>\n<li>You may unsubscribe to stop receiving our emails.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-18965\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Unsubscribe-option.png\" alt=\"Unsubscribe option\" width=\"350\" height=\"120\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Unsubscribe-option.png 394w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Unsubscribe-option-300x103.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Unsubscribe-option-24x8.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Unsubscribe-option-36x12.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Unsubscribe-option-48x16.png 48w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/><\/p>\n<p>And when someone clicks on the unsubscribe link, you must remove them from your email list and <b>delete all <\/b><b>data<\/b> you\u2019ve stored on the data subject for marketing purposes.<\/p>\n<p>Additionally, you can provide subscribers with options to customize their email subscriptions.<\/p>\n<p>You can let subscribers decide what kind of marketing communication (new products, offers, etc.) they\u2019d like to receive and how often they\u2019d like to receive them. This way, the subscribers have better <b>control <\/b>over the communications they receive from your marketers.<\/p>\n<h3>Best Practice #4: Rethink Your Marketing Automation Strategy<\/h3>\n<p>With the right tool, automating your email marketing activities is effortless.<\/p>\n<p>However, in light of the GDPR regulation, you may need to rethink how you leverage <a href=\"https:\/\/www.gmass.co\/blog\/marketing-automation-software\/\">marketing automation software<\/a> in your campaigns.<\/p>\n<p><b>Why?<br \/>\n<\/b>For starters, you can\u2019t send automated emails to people who haven\u2019t explicitly consented to receive your marketing emails.<\/p>\n<p>There\u2019s also the issue of how you may segment and process your mailing list.<\/p>\n<p>For example, let\u2019s say you\u2019re a company that offers a suite of marketing tools. Under the EU GDPR, you can send targeted emails to customers (who\u2019ve signed up for your mailing list) with location-specific special offers.<\/p>\n<p>However, let\u2019s assume that you use an algorithm to process the customer\u2019s personal data to identify users who\u2019ve been heavily using your tool and could benefit from your other offerings.<\/p>\n<p>As a result, you use marketing automation software to send targeted emails (with discount offers) to these people.<\/p>\n<p>Doing so <i>could <\/i>be a violation since the GDPR regulation limits how organizations and businesses can use user data to profile European customers and make automated decisions.<\/p>\n<p>But this is a gray area, and the legality can vary on a case-by-case basis.<\/p>\n<p>Anyhow, it\u2019s best to evaluate how you segment your mailing list and any associated info.<br \/>\nThen, check to see if there are any potential vulnerabilities in how you process consumer data for your automated marketing campaigns.<\/p>\n<h3>Best Practice #5: Create a GDPR Compliance Checklist<\/h3>\n<p>Ensuring that your email marketing efforts comply with GDPR rules can be tricky.<\/p>\n<p>That\u2019s why I strongly recommend you create a <b>GDPR compliance<\/b><b> checklist<\/b> to evaluate your email marketing strategy.<\/p>\n<p>Here is a list of questions you can use to get started:<\/p>\n<ol>\n<li>Have you received consent from subscribers to send them marketing emails?<\/li>\n<li>Are you aware of which data is protected under the EU GDPR?<\/li>\n<li>Do you maintain detailed records showing evidence of consent from your subscribers?<\/li>\n<li>Do you have a clear idea of how each contact ends up on your mailing list?<\/li>\n<li>Are you aware of where your email subscribers are located?<\/li>\n<li>Do you share your marketing communication and privacy policies with subscribers before signing them up?<\/li>\n<li>Does your communication policy clearly describe what kind of emails you\u2019ll send to subscribers?<\/li>\n<li>Does your privacy policy clearly explain how you\u2019ll collect, process, safeguard, and retain data relating to your email subscribers?<\/li>\n<li>Do all your marketing emails contain an opt-out link?<\/li>\n<li>Do you ensure that all your new email initiatives are in compliance with GDPR requirements?<\/li>\n<\/ol>\n<p><a id=\"how\" href=\"#this\"><b>Go back to Contents<\/b><\/a><\/p>\n<p>Next, I\u2019ll explain how GDPR requirements can impact your email policy.<\/p>\n<h2>How GDPR Affects Your Email Policy<\/h2>\n<p>Your organization may need to make some changes in its email policy to comply with GDPR rules.<\/p>\n<p>These changes include:<\/p>\n<h3>A. Email Encryption<\/h3>\n<p>The European Union\u2019s General Data Protection Regulation (GDPR) requires that your organization adopts suitable, proactive measures to ensure data security.<\/p>\n<p>And one feasible way to secure user data is through <b>encryption<\/b>.<\/p>\n<p><b>But is it possible to encrypt your <\/b><b>emails<\/b><b>?<br \/>\n<\/b>Email encryption is a given when you\u2019re using an end-to-end encrypted email provider like ProtonMail and Tutanota or other cloud-based, secure email services.<\/p>\n<p>Alternatively, you can send encrypted emails using Gmail or Outlook.<\/p>\n<p><b><i>Note:<\/i><\/b><i> Gmail uses TLS encryption preventing hackers from reading your message while en route to the recipient, but Gmail can still read your messages. With Outlook, you can use Message Encryption in Office 365 to ensure that only the recipient can read the email.<\/i><\/p>\n<h3>B. Organizational Email Security<\/h3>\n<p>Your organization must take proactive measures to protect the user data of EU residents and individuals <b>and <\/b>your employee data against a data breach, accidental loss or destruction, and so on.<\/p>\n<p><b>How is this different from email <\/b><b>encryption<\/b><b>?<br \/>\n<\/b>Unlike email encryption, email security isn\u2019t just about adopting technical measures to protect consumers\u2019 personal data. Instead, your organization needs to develop and put into practice internal policies regarding email safety best practices.<\/p>\n<p>For example, your email and data security policy can specify how to proceed when employees receive emails with a suspicious <i>From<\/i> address, or how to report phishing or malware emails.<\/p>\n<h3>C. Email Retention<\/h3>\n<p>Data erasure is one of the key data protection principles under the EU GDPR.<\/p>\n<p>And there are mainly <b>two<\/b> sides to this principle:<\/p>\n<ol>\n<li>Organizations may retain (or store) data only for as long as necessary for the purpose for which the consumer data was collected.<\/li>\n<li>People in the EU have a \u201cright to be forgotten,\u201d meaning that individuals can request immediate deletion of their personal data.<\/li>\n<\/ol>\n<p><b>Wondering how this impacts emails?<br \/>\n<\/b>We generally don\u2019t delete our emails, especially at work. And there are valid reasons for this, such as:<\/p>\n<ul>\n<li>We want to maintain a record of our activities.<\/li>\n<li>We wish to retain emails for any potential litigation.<\/li>\n<\/ul>\n<p>In any case, the more emails you store, the more sensitive data (consumers\u2019 personal data, employee data, etc.) you collect, and the higher the risk in case of a data breach. As a result, your organization might consider reviewing the emails it stores and deleting any non-essential emails.<\/p>\n<p><a id=\"faq\" href=\"#this\"><b>Go back to Contents<\/b><\/a><\/p>\n<p>Next, I\u2019ll answer some frequently asked questions connecting GDPR and email.<\/p>\n<h2>2 GDPR Email FAQs<\/h2>\n<p>Here are the answers to <b>two<\/b> commonly asked questions regarding GDPR requirements and how they affect emails:<\/p>\n<h3>1. Should All My Outbound Emails Include an Unsubscribe Link?<\/h3>\n<p>GDPR specifies that your outbound or email marketing message must provide an easy way for recipients to opt-out of receiving your emails.<\/p>\n<p>Now, GDPR doesn\u2019t explicitly state that you need an unsubscribe link.<\/p>\n<p>But including an unsubscribe link in your marketing message is <b>standard <\/b>practice. It allows your recipients to opt-out of receiving outbound and marketing emails. For that reason, I\u2019d recommend that you include the unsubscribe link in all your email marketing campaigns.<\/p>\n<h3>2. If I\u2019m Based in the United States, Do I Still Need to Be GDPR Compliant?<\/h3>\n<p>The answer to this question depends on <b>whose <\/b>data you may be processing.<\/p>\n<p>If your company has absolutely nothing to do with storing or processing the personal data of people in the EU, you don\u2019t need to be GDPR compliant. On the flip side, you\u2019ll need to comply with GDPR requirements if your company\u2019s subscribers, prospects, partners, or clients are EU residents or individuals.<\/p>\n<p>Moreover, if you\u2019re a data processor (or data controller) company processing the personal information of an EU citizen or individual, the GDPR applies to you. And this is regardless of whether the data processing activity occurs within the EU or outside.<\/p>\n<p>Not just that.<\/p>\n<p>Generally, GDPR also applies if you\u2019re a business in the EU, and your client is not an EU citizen or resident but has purchased your product\/service <b>while<\/b> in the EU \u2014 for example, a tourist traveling in France.<\/p>\n<h2>Final Thoughts<\/h2>\n<p>For email marketing in the EU, email marketers must obey the personal data protection law \u2014 the GDPR.<\/p>\n<p>And this includes sending re-permission campaigns to get explicit consent from your EU subscribers, telling recipients how you\u2019ll be processing customer data, adding unsubscribe links inside your marketing emails, and more.<\/p>\n<p>By implementing the <a href=\"#best\">best practices<\/a> I\u2019ve covered above, you\u2019ll have no trouble enacting GDPR compliant email marketing going forward!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Email marketing in the European Union has gotten trickier thanks to GDPR. However, by adopting some easy-to-follow practices, you can ensure that you comply with the EU\u2019s GDPR\u2026<\/p>\n","protected":false},"author":2,"featured_media":18977,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[8,4271],"tags":[],"class_list":["post-18962","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-marketing","category-legal"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\r\n<title>GDPR Email Marketing: What You Need to Know<\/title>\r\n<meta name=\"description\" content=\"Learn how to comply with EU\u2019s GDPR email marketing requirements and how it affects you.\" \/>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/www.gmass.co\/blog\/gdpr-email\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_US\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"GDPR Email Marketing: What You Need to Know\" \/>\r\n<meta property=\"og:description\" content=\"Learn how to comply with EU\u2019s GDPR email marketing requirements and how it affects you.\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/www.gmass.co\/blog\/gdpr-email\/\" \/>\r\n<meta property=\"og:site_name\" content=\"GMass Blog\" \/>\r\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/GmailMailMerge\/\" \/>\r\n<meta property=\"article:published_time\" content=\"2021-12-21T07:29:41+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2022-04-12T03:26:33+00:00\" \/>\r\n<meta property=\"og:image\" content=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Featured-image-GDPR-Email-Marketing-153kb.png\" \/>\r\n\t<meta property=\"og:image:width\" content=\"1001\" \/>\r\n\t<meta property=\"og:image:height\" content=\"467\" \/>\r\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\r\n<meta name=\"author\" content=\"Ajay Goel\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:creator\" content=\"@PartTimeSnob\" \/>\r\n<meta name=\"twitter:site\" content=\"@GMassForGmail\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Goel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/\"},\"author\":{\"name\":\"Ajay Goel\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\"},\"headline\":\"GDPR Email Marketing: What You Need to Know\",\"datePublished\":\"2021-12-21T07:29:41+00:00\",\"dateModified\":\"2022-04-12T03:26:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/\"},\"wordCount\":2793,\"commentCount\":1,\"image\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/Featured-image-GDPR-Email-Marketing-153kb.png\",\"articleSection\":[\"Email Marketing\",\"Legal\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/\",\"name\":\"GDPR Email Marketing: What You Need to Know\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/Featured-image-GDPR-Email-Marketing-153kb.png\",\"datePublished\":\"2021-12-21T07:29:41+00:00\",\"dateModified\":\"2022-04-12T03:26:33+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\"},\"description\":\"Learn how to comply with EU\u2019s GDPR email marketing requirements and how it affects you.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/Featured-image-GDPR-Email-Marketing-153kb.png\",\"contentUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/Featured-image-GDPR-Email-Marketing-153kb.png\",\"width\":1001,\"height\":467,\"caption\":\"GDPR Email Marketing\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/gdpr-email\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR Email Marketing: What You Need to Know\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/\",\"name\":\"GMass Blog\",\"description\":\"Tips and tricks for sending mail merge and mass email campaigns directly from Gmail\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\",\"name\":\"Ajay Goel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"caption\":\"Ajay Goel\"},\"description\":\"Ajay is the founder of GMass and has been developing email sending software for 20 years.\",\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/PartTimeSnob\",\"https:\\\/\\\/x.com\\\/PartTimeSnob\"],\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/author\\\/ajay-goel\\\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GDPR Email Marketing: What You Need to Know","description":"Learn how to comply with EU\u2019s GDPR email marketing requirements and how it affects you.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gmass.co\/blog\/gdpr-email\/","og_locale":"en_US","og_type":"article","og_title":"GDPR Email Marketing: What You Need to Know","og_description":"Learn how to comply with EU\u2019s GDPR email marketing requirements and how it affects you.","og_url":"https:\/\/www.gmass.co\/blog\/gdpr-email\/","og_site_name":"GMass Blog","article_publisher":"https:\/\/www.facebook.com\/GmailMailMerge\/","article_published_time":"2021-12-21T07:29:41+00:00","article_modified_time":"2022-04-12T03:26:33+00:00","og_image":[{"width":1001,"height":467,"url":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Featured-image-GDPR-Email-Marketing-153kb.png","type":"image\/png"}],"author":"Ajay Goel","twitter_card":"summary_large_image","twitter_creator":"@PartTimeSnob","twitter_site":"@GMassForGmail","twitter_misc":{"Written by":"Ajay Goel","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/#article","isPartOf":{"@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/"},"author":{"name":"Ajay Goel","@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8"},"headline":"GDPR Email Marketing: What You Need to Know","datePublished":"2021-12-21T07:29:41+00:00","dateModified":"2022-04-12T03:26:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/"},"wordCount":2793,"commentCount":1,"image":{"@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Featured-image-GDPR-Email-Marketing-153kb.png","articleSection":["Email Marketing","Legal"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.gmass.co\/blog\/gdpr-email\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/","url":"https:\/\/www.gmass.co\/blog\/gdpr-email\/","name":"GDPR Email Marketing: What You Need to Know","isPartOf":{"@id":"https:\/\/www.gmass.co\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/#primaryimage"},"image":{"@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Featured-image-GDPR-Email-Marketing-153kb.png","datePublished":"2021-12-21T07:29:41+00:00","dateModified":"2022-04-12T03:26:33+00:00","author":{"@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8"},"description":"Learn how to comply with EU\u2019s GDPR email marketing requirements and how it affects you.","breadcrumb":{"@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gmass.co\/blog\/gdpr-email\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/#primaryimage","url":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Featured-image-GDPR-Email-Marketing-153kb.png","contentUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2021\/12\/Featured-image-GDPR-Email-Marketing-153kb.png","width":1001,"height":467,"caption":"GDPR Email Marketing"},{"@type":"BreadcrumbList","@id":"https:\/\/www.gmass.co\/blog\/gdpr-email\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.gmass.co\/blog\/"},{"@type":"ListItem","position":2,"name":"GDPR Email Marketing: What You Need to Know"}]},{"@type":"WebSite","@id":"https:\/\/www.gmass.co\/blog\/#website","url":"https:\/\/www.gmass.co\/blog\/","name":"GMass Blog","description":"Tips and tricks for sending mail merge and mass email campaigns directly from Gmail","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gmass.co\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8","name":"Ajay Goel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","caption":"Ajay Goel"},"description":"Ajay is the founder of GMass and has been developing email sending software for 20 years.","sameAs":["https:\/\/twitter.com\/PartTimeSnob","https:\/\/x.com\/PartTimeSnob"],"url":"https:\/\/www.gmass.co\/blog\/author\/ajay-goel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/18962","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/comments?post=18962"}],"version-history":[{"count":14,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/18962\/revisions"}],"predecessor-version":[{"id":20135,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/18962\/revisions\/20135"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/media\/18977"}],"wp:attachment":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/media?parent=18962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/categories?post=18962"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/tags?post=18962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}