GDPR · Compliance

GDPR-Compliant Email Marketing: What You Need to Know

By Valon Jusufi · July 19, 2026 · 7 min read

Email marketing is one of the most effective channels in e-commerce – but also one of the most legally sensitive, especially when you have European subscribers. Anyone collecting personal data and sending marketing emails to EU-based contacts falls directly within GDPR's scope. Here are the key points, explained practically, the way I implement them for client setups at sevclick.

Important note: This article is a practical overview, not legal advice. For questions specific to your situation, it's worth consulting a data protection attorney.

Legal basis: why "we have a list" isn't enough

The most common misconception: having an email address alone doesn't automatically authorize sending marketing. For newsletters and marketing emails, you generally need explicit consent under Article 6(1)(a) GDPR. This consent must be actively given – a pre-checked box or a hidden clause in your terms doesn't count.

There's an exception for purely transactional emails (order confirmations, shipping notifications) – those rely on contract performance (Article 6(1)(b) GDPR) and don't need separate marketing consent. Important: as soon as such an email includes marketing content (e.g. product recommendations), the distinction quickly blurs – when in doubt, keep them cleanly separated.

Double opt-in: the seatbelt for sign-ups

Double opt-in means: after signing up through a form, the person receives a confirmation email and must actively confirm the sign-up before receiving regular emails. Only this second step provides solid proof that the consent really came from the stated person – not from someone who accidentally or maliciously entered someone else's address.

Klaviyo supports double opt-in natively at the list level. It's important to consciously enable it for new lists – it isn't always the default, depending on how an account was set up.

Practical Checklist

What a clean double opt-in setup needs

• Clear wording in the sign-up form about exactly what the consent covers
• Confirmation email with a clear confirmation link
• Timestamp and proof of confirmation are stored
• No pre-checked boxes or hidden consent by default

The unsubscribe link: mandatory, not optional

Every marketing email needs a clearly visible, easy-to-use unsubscribe option. This follows both from GDPR (right to withdraw consent) and from anti-spam laws such as CAN-SPAM in the US. An unsubscribe link hidden three clicks deep in a submenu doesn't really satisfy this requirement, even if it technically exists. Klaviyo includes the unsubscribe link by default in every campaign – never manually remove it, even if it "disrupts" the design.

Data processing agreements: the piece often forgotten

As soon as an external tool like Klaviyo processes personal data of your contacts, you as the data controller need a Data Processing Agreement (DPA) under Article 28 GDPR with that provider. Most major email marketing tools offer a DPA for you to accept – but it has to be actively accepted, it doesn't happen automatically in the background.

The same applies to other connected services: scheduling tools, tracking scripts, form providers. Every service that processes personal data is worth checking once.

Privacy policy: complete, not a boilerplate

A privacy policy that just says "we use cookies" isn't enough. It should specifically name:

A generic template copied once, years ago, rarely covers the tools actually in use today – it's worth reviewing regularly, especially when new services are added.

List hygiene: GDPR meets performance

An often-overlooked benefit of clean GDPR practice: a list of genuinely interested, actively confirmed contacts tends to perform better than a bloated list of uncertain origin. High unsubscribe rates or spam complaints hurt not just legally, but also overall deliverability. GDPR compliance and good email marketing actually pull in the same direction here.

Practical note: Regularly filter out or actively re-engage inactive contacts who haven't opened or clicked in months from active sending lists. This improves both deliverability and the overall risk profile of your list.

Common mistakes in practice

1. Purchased or scraped address lists

Without verifiable consent from each individual, sending to such addresses isn't permitted – regardless of how the list was obtained.

2. Bundling newsletter sign-up with sweepstakes entry

Coupling both without separate consent makes the consent legally vulnerable. Both should be requested separately.

3. No record of when consent was given

In a dispute, the sender carries the burden of proof for valid consent. Without a timestamp and log, that becomes difficult.


Want your email marketing set up compliantly, without fighting through GDPR paragraphs yourself?

Book a free call →

As of July 2026. Does not substitute for individual legal advice.