GDPR-Compliant Email Marketing: The 2026 Rules
Quick answer: In Europe you may email people for marketing when you have a lawful basis — almost always consent for B2C, or a narrow “soft opt-in” for existing customers of similar products. Consent must be freely given, specific, informed and unambiguous, collected via a positive action (no pre-ticked boxes), logged with a timestamp and source, and revocable with a one-click unsubscribe in every message. The GDPR sets the floor; each country’s ePrivacy rules and marketing statutes add a layer on top — and Germany’s are the strictest.
Email is still one of the highest-ROI channels in Europe, but only if your list is clean and your consent holds up. A single complaint to a data-protection authority can turn a “growth hack” into a fine. Here’s how to run email that converts and survives an audit in 2026.
The two rules you’re actually complying with
Email marketing in the EU sits at the intersection of two laws, not one:
- The GDPR (and its national versions — DSGVO, RGPD, RODO, AVG…) governs the personal data: your lawful basis, records, and the recipient’s rights.
- The ePrivacy rules (the current ePrivacy Directive, transposed nationally) govern the act of sending an unsolicited electronic message. This is where “opt-in vs soft opt-in” lives.
You have to satisfy both. The GDPR tells you how to hold the email address; ePrivacy tells you whether you’re allowed to hit send.
Consent: what “valid” means in 2026
Under the GDPR, consent must be:
- Freely given — not bundled into terms you must accept to buy.
- Specific — separate consent for marketing, distinct from other processing.
- Informed — the person knows who’s emailing them and about what.
- Unambiguous — a clear affirmative action. No pre-ticked boxes (settled since the CJEU’s Planet49 ruling).
- Revocable — as easy to withdraw as to give.
- Documented — you can show who consented, when, how, and to what.
“Data is a toxic asset, so why not throw it out?” — Bruce Schneier, security technologist (schneier.com, 2016)
Schneier’s point is the compliance mindset in miniature: the safest personal data is the data you never collected or already deleted. GDPR data minimisation rewards exactly that — collect only what the campaign needs, keep consent records no longer than you must, and prune dormant contacts.
Single vs double opt-in
- Single opt-in: the address is added the moment someone submits the form. Legal in principle, but weak on proof and prone to typos and fake addresses.
- Double opt-in (confirmed opt-in): the subscriber clicks a confirmation link in a first email before being added. This is the gold standard across Europe — and in Germany it’s effectively required to prove consent.
Double opt-in also protects deliverability: it filters out mistyped and spam-trap addresses before they poison your sender reputation, which matters more than ever under the Gmail/Yahoo bulk-sender rules now enforced across major EU inboxes.
The per-country layer (this is where it gets local)
The GDPR is uniform; the marketing and ePrivacy rules are not. Localise, don’t assume.
| Market | Governing layer | B2C email | B2B email | Notable |
|---|---|---|---|---|
| Germany (DE) | DSGVO + § 7 UWG | Prior consent; double opt-in to prove it | Consent generally required too — Germany is stricter than most on B2B | Unsolicited email can trigger competitor Abmahnung (warning letters) |
| France (FR) | RGPD + CNIL | Opt-in required | Softer for B2B — professional addresses can be emailed about work-relevant offers with clear opt-out | CNIL bans dark patterns; opt-out must be effortless |
| Spain (ES) | RGPD + LOPDGDD + LSSI-CE | Opt-in required | Prior relationship exemption for similar products | LSSI-CE governs commercial electronic communications |
| Italy (IT) | GDPR + Garante | Opt-in required | Consent-based | Garante actively fines unsolicited marketing |
| Netherlands (NL) | AVG + Telecommunicatiewet | Opt-in required | Soft opt-in for existing customers/similar products | ACM + AP enforce |
| Poland (PL) | RODO + Prawo komunikacji elektronicznej | Opt-in required | Consent-based | UODO supervises; PKE modernised the ePrivacy layer |
| UK | UK GDPR + PECR | Consent, or soft opt-in | Soft opt-in for existing customers | ICO enforces; corporate-subscriber rules differ from individuals |
The recurring pattern: B2C is consent-first everywhere; B2B softens in some markets (France, UK, NL soft opt-in) but not in Germany, where § 7 UWG keeps the bar high even for business addresses. When in doubt, get consent.
The “soft opt-in” — the one exemption worth knowing
Most ePrivacy regimes allow you to email an existing customer about your own similar products/services without fresh consent, provided you collected the address during a sale, gave an opt-out at that point, and give an opt-out in every message. It does not cover cold prospects, purchased lists, or unrelated products. Treat it as a narrow lane, not a loophole.
Buying or renting lists: don’t
Purchased and rented lists are the fastest route to a GDPR breach: you can’t demonstrate that those individuals gave you valid, informed consent — and you almost never can. Beyond the legal exposure, bought lists tank deliverability and sender reputation. Build the list you own instead.
Your 2026 compliance checklist
- Positive-action sign-up, no pre-ticked boxes; marketing consent separate from other terms.
- Double opt-in as default (mandatory in practice for Germany).
- Consent log: who, when, how (form/source), and the exact wording shown.
- Clear sender identity and a real reply-to.
- One-click unsubscribe in every email, honoured promptly (and required by the bulk-sender rules for large senders).
- Privacy notice linked at point of collection, in the local language.
- Data minimisation & retention: collect only what you use; delete dormant contacts and re-permission where consent has aged.
- Right to be forgotten: erase on request across your ESP and backups.
- Correct per-country legal layer in the footer and privacy notice.
FAQ
Is double opt-in legally required under the GDPR?
The GDPR doesn’t name it, but it requires provable consent — and in Germany double opt-in is treated as the way to prove it. Elsewhere it’s strongly recommended and best for deliverability.
Can I email businesses (B2B) without consent in Europe?
It depends on the country. France, the UK and the Netherlands allow a soft opt-in for relevant B2B contact; Germany (§ 7 UWG) generally still requires consent even for business addresses. Never assume — check the market.
What’s the “soft opt-in”?
An ePrivacy exemption letting you email existing customers about your own similar products without fresh consent, as long as you offered an opt-out at collection and in every message. It doesn’t cover cold lists.
Can I buy an email list if the seller says it’s GDPR-compliant?
No. You can’t demonstrate valid consent for your processing of those individuals, and it wrecks deliverability. Build your own list.
How long can I keep consent records?
As long as you’re relying on that consent, plus a reasonable period to defend a complaint — then delete. Re-permission contacts who’ve gone cold.
Sources
- GDPR Articles 6 & 7; CJEU Planet49 (pre-ticked boxes invalid).
- iGDPR; TermsFeed — GDPR consent and double opt-in (2026).
- Overloop; Puzzle Inbox — Germany § 7 UWG / cold email compliance (2026).
- Warbble; TrustYourWebsite — country-by-country email consent rules.
- ICO (PECR); CNIL — national ePrivacy guidance.
Want an email programme that grows the list and passes an audit?
WiseGuyXL builds GDPR-first email marketing across European markets — correct consent flows, the right legal layer per country, deliverability that holds. It’s the same rigour behind 341% organic growth across 30+ projects in 9+ markets. See what email marketing actually costs, or explore more on the WiseGuyXL blog.
Author: WiseGuyXL Editorial. Researched and drafted with AI assistance; reviewed by a human editor before publication.
1 thought on “GDPR-Compliant Email Marketing: The 2026 Rules”