Table of Contents

Spam - GDPR

How does the GDPR affect email?

The GDPR requires organizations to protect personal data in all its forms.

It also changes the rules of consent and strengthens people’s privacy rights.

If a company collects, stores, or uses the data of people in the EU, then the GDPR applies to them.


Email marketing and spam

The GDPR Article 5 principles relate to lawfulness, fairness, and transparency.

This means someones data can only be used if it is allowed under one of six legal justifications, it must be fair to the data subject, and it must be based on transparent and unambiguous communication with the data subject.

GDPR Article 6 covers six lawful bases to allow processing, collecting, storing and using of someones data.

  1. Consent must be freely given, specific, informed and unambiguous.
  2. Requests for consent must be clearly distinguishable from the other matters and presented in clear and plain language.
  3. Data subjects can withdraw previously given consent whenever they want, and you have to honor their decision. Companies cannot simply change the legal basis of the processing to one of the other justifications.
  4. Children under 13 can only give consent with permission from their parent.
  5. They need to keep documentary evidence of consent.
  6. To have a legitimate interest to process someones data.

The ePrivacy Directive, specifically Article 13, presents organizations with another way to use someones data for marketing purposes that stems from the contractual basis of the GDPR.

What this means for email


References

https://gdpr.eu/email-encryption/

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN