What we do

50 GDPR Email Marketing Questions Answered for Ireland

BLOG

50 GDPR Email Marketing Questions Answered for Ireland

Email marketing is one of the most cost-effective digital marketing channels available to Irish businesses — and one of the most frequently misunderstood from a GDPR compliance perspective. The rules are specific, the DPC enforces them, and the gap between what most businesses think is compliant and what GDPR actually requires is significant.

This guide answers the fifty questions about GDPR and email marketing that Irish business owners, marketers, and compliance teams ask most often. It covers lawful basis, consent, list management, unsubscribe obligations, data retention, third-party tools, and what the Data Protection Commission expects. Each answer is written to be practical and directly applicable — not a recitation of legal text.

email markerting

Section 1: Lawful Basis for Email Marketing (Q1–10)

Q1: Do I need a lawful basis to send marketing emails under GDPR?
Yes. Every marketing email you send must have a lawful basis under GDPR Article 6. For direct marketing emails, the two most relevant bases are consent (Article 6(1)(a)) and legitimate interests (Article 6(1)(f)). For most marketing email scenarios, consent is the appropriate and safest basis.

Q2: What is the difference between consent and legitimate interest for email marketing?
Consent requires the recipient to have actively opted in to receive marketing emails from you. Legitimate interest allows you to email existing customers without specific consent, provided the emails relate to similar products or services to what they purchased, you gave them an opt-out at the point of collection, and you have conducted a Legitimate Interests Assessment. Consent is the cleaner and more defensible basis for most businesses. See the section below for a full comparison.

Q3: Can I use legitimate interest to send marketing emails to people who have not bought from me?
No. Legitimate interest as a basis for direct marketing email applies only to existing customers — people who have already purchased a product or service from you. Using it to email people with no prior relationship constitutes cold email marketing, which requires consent under GDPR and additionally under ePrivacy Regulations (the EU rules that specifically govern electronic direct marketing). Cold email marketing without consent is not lawful regardless of how compelling the business case.

Q4: Is the soft opt-in still available in Ireland after GDPR?
Yes. The soft opt-in — also called the existing customer exemption — allows you to send marketing emails to existing customers without explicit consent, provided: they purchased a similar product or service from you recently, you gave them a clear opportunity to opt out of marketing emails at the time of purchase, and each marketing email you send gives them an easy way to unsubscribe. The soft opt-in is not available for new contacts who have not transacted with you.

Q5: Do I need separate consent for each type of marketing email I send?
The consent must cover the specific type of marketing communication you are sending. If someone consented to receive a newsletter, that consent does not automatically cover promotional emails about new products or event invitations. The consent language at the point of sign-up should accurately describe what the person is agreeing to receive. Broad consent wording — “receive updates and information about our products and services” — is generally acceptable if it is specific enough that the subscriber knows what they are agreeing to. Vague or misleading consent wording is not valid.

Q6: Can I use consent given before GDPR came into effect?
Only if it meets GDPR’s standards. Pre-GDPR consent is valid if it was freely given, specific, informed, and recorded — and if you can demonstrate that it meets these standards with evidence. If your pre-GDPR sign-up process involved pre-ticked boxes, bundled consent, or vague wording, that consent does not meet GDPR standards and should not be relied upon. Many Irish businesses ran re-permissioning campaigns when GDPR came into effect precisely because they could not demonstrate that historical consent met the new standard.

Q7: Does GDPR apply to B2B email marketing as well as B2C?
GDPR applies to any processing of personal data, including business email addresses belonging to identifiable individuals. An email address in the format firstname.lastname@company.ie is personal data under GDPR regardless of the business context. That said, ePrivacy Regulations — which govern unsolicited electronic marketing specifically — take a more permissive approach to B2B than B2C, allowing legitimate interest to be used more broadly for genuine B2B marketing to relevant business contacts. Consent remains the safest and cleanest basis even in B2B contexts.

Q8: Is it lawful to buy an email list and send marketing to it?
No, in almost all circumstances. A purchased list consists of people who have not consented to receive marketing from your specific business. The fact that they may have consented to receive communications from the list seller does not make that consent transferable to you — GDPR consent must be specific to the controller sending the communications. Sending marketing to purchased lists without obtaining valid consent from those individuals is a breach of both GDPR and ePrivacy Regulations, and it exposes you to DPC complaints and enforcement action.

Q9: What is ePrivacy Regulations and how does it relate to GDPR?
The ePrivacy Regulations (implemented in Ireland through the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011, as amended) sit alongside GDPR and govern unsolicited electronic direct marketing specifically — including email, SMS, and automated calls. Where GDPR sets the general framework for personal data processing, ePrivacy adds specific rules for direct marketing communications. Both sets of rules apply to email marketing, and both must be complied with simultaneously.

Q10: What are the penalties for sending marketing emails without a lawful basis?
Penalties under GDPR can reach €20 million or 4% of global annual turnover — whichever is higher. Under ePrivacy Regulations, the Commission for Communications Regulation (ComReg) can investigate and prosecute unsolicited direct marketing. In practice, the most immediate consequence for Irish businesses is a complaint to the Data Protection Commission, which can investigate, issue reprimands, order remediation, and impose administrative fines. DPC investigations of email marketing complaints are not rare.

Section 2: Consent — What It Must Look Like (Q11–20)

Q11: What does valid consent look like under GDPR?
Valid consent under GDPR must be: freely given (no penalty or disadvantage for not consenting), specific (covering the particular type of marketing the person is agreeing to receive), informed (the person must know who they are consenting to, what they will receive, and that they can withdraw consent at any time), and unambiguous (requiring a clear affirmative action — a tick, a click, a signature — not inaction or a pre-ticked box).

Q12: Is a pre-ticked checkbox valid consent under GDPR?
No. A pre-ticked checkbox is specifically prohibited as a method of obtaining consent under GDPR. The subscriber must take an active step to opt in. A box that is ticked by default and requires the user to untick it to decline is not valid consent — it is the opposite of freely given, specific, informed, and unambiguous. This is one of the most common GDPR consent violations in email marketing.

Q13: Can I bundle consent for email marketing with consent for terms and conditions?
No. Bundling consent — requiring someone to agree to marketing emails as a condition of signing up for a service or accepting terms — is not valid under GDPR. Consent for marketing must be separate from other agreements and must be genuinely optional. If a user cannot access your service without consenting to marketing, that consent is not freely given and therefore not valid.

Q14: What should the consent language actually say?
It should clearly state: who they are consenting to receive emails from (your business name), what type of emails they will receive (newsletters, promotional offers, product updates — be specific), and that they can withdraw consent at any time. An example of acceptable wording: “I would like to receive marketing emails from [Business Name] about [specific content]. I understand I can unsubscribe at any time.” An example of unacceptable wording: “I agree to receive communications from [Business Name] and selected partners” — this is too vague and the “selected partners” element is particularly problematic.

Q15: Do I need a double opt-in to comply with GDPR?
GDPR does not specifically require double opt-in — a confirmation email that the subscriber must click to verify their email address and confirm their subscription. However, double opt-in provides a stronger evidence trail of consent and protects against fake email sign-ups that could damage your deliverability. It is best practice and is recommended by most email marketing platforms and compliance advisers, even if it is not explicitly mandated.

Q16: How long does consent last?
GDPR does not set a fixed expiry period for consent. Consent lasts as long as it remains valid — meaning it was freely given, has not been withdrawn, and the processing remains in line with what was agreed. In practice, most data protection authorities and compliance guidance suggests reviewing and potentially re-obtaining consent when a subscriber has not engaged with your emails for 12 to 24 months, as prolonged non-engagement may indicate that the relationship has effectively ended even if consent has not been formally withdrawn.

Q17: What records do I need to keep of consent?
You must be able to demonstrate that consent was obtained. This means recording: the date and time consent was given, the source or channel through which it was given (which web page, which sign-up form), the exact wording of the consent request at that time, and the email address or contact the consent relates to. Your email marketing platform should maintain this data automatically if it is properly configured. The DPC can request evidence of consent, and “we believe they consented” is not sufficient.

Q18: Can someone consent on behalf of another person?
No. Consent must be given by the individual whose personal data is being processed. You cannot add someone to a marketing list because their colleague, manager, or family member signed them up. Each subscriber must give their own consent through their own action.

Q19: What happens when someone withdraws consent?
When a subscriber withdraws consent — by unsubscribing, clicking an opt-out link, or explicitly requesting removal — you must stop sending them marketing emails promptly. You must also delete or suppress their data from your active marketing list. Withdrawal of consent must be as easy as giving it. You may retain a suppression record of their email address to ensure you do not inadvertently re-add them, but you may not continue marketing to them after withdrawal.

Q20: Can I ask someone who has unsubscribed to reconsider?
One final email confirming the unsubscription is generally acceptable. Sending follow-up emails asking someone who has unsubscribed to reconsider or re-subscribe — or continuing to send marketing emails while processing an unsubscribe request — is not compliant. Once someone has clearly indicated they do not wish to receive marketing from you, that decision must be respected immediately.

Section 3: Managing Your Email List (Q21–30)

Q21: Does GDPR apply to my existing email list?
Yes. If you have an existing email marketing list, every contact on it must have a valid lawful basis for receiving your emails. If your list was built through methods that do not meet GDPR standards — purchased contacts, pre-ticked checkboxes, bundled consent — those contacts should not be emailed until valid consent is obtained or another compliant lawful basis is established.

Q22: Do I need to tell subscribers what email platform I use?
Not explicitly — but your privacy policy should disclose that you use third-party email marketing software to process subscriber data, and that provider should be listed as a data processor in your records of processing activities. Your email platform operates as a data processor on your behalf, which means you need a Data Processing Agreement (DPA) in place with them. Most reputable email platforms — Mailchimp, Klaviyo, ActiveCampaign, Campaign Monitor — provide DPAs as standard.

Q23: Can I share my email list with a business partner or third party?
Only if your subscribers consented to their data being shared with that specific third party or category of third parties. Consent given to you does not transfer to another organisation. If you want to share subscriber data with a partner, you must either obtain separate consent for that sharing or have another valid lawful basis. Simply including “and selected partners” in your consent wording does not make that sharing compliant — the partners must be specifically identified or identifiable to the subscriber at the point of consent.

Q24: How long can I keep subscriber data?
GDPR does not set a fixed retention period for marketing subscriber data. The principle of storage limitation requires you to retain personal data only for as long as it is necessary for the purpose for which it was collected. For active subscribers, retention is justified by the ongoing marketing relationship. For subscribers who have unsubscribed or become completely disengaged, retention beyond what is needed for a suppression list is harder to justify. Your privacy policy should state your data retention periods, and you should review inactive subscriber records regularly.

Q25: What is list hygiene and is it a GDPR requirement?
List hygiene is the practice of regularly cleaning your email list — removing invalid addresses, suppressing unsubscribed contacts, and reviewing or removing long-inactive subscribers. While GDPR does not specifically mandate list hygiene as a labelled practice, the principles of data minimisation and storage limitation effectively require it: you should not retain personal data beyond its useful purpose. Regular list hygiene also improves deliverability, open rates, and sender reputation — making it both a compliance and a performance good practice.

Q26: Can I email someone who gave me their business card at a networking event?
Not automatically. Receiving a business card is not consent to add someone to a marketing list. You can use the contact details on a business card to follow up personally on a conversation you had — that is a legitimate use of the contact information. To add them to a marketing list, you need their consent, which should be obtained either at the time of exchange (“Can I add you to our newsletter?”) or through a subsequent specific request. Adding business card contacts to a marketing list without consent is a common GDPR violation.

Q27: Do I need to tell new subscribers what data I hold about them?
Yes — this is the transparency obligation under GDPR Articles 13 and 14. At the point of sign-up, subscribers must be informed about: who is collecting their data, what data is being collected, the purpose and lawful basis for processing, how long the data will be retained, their rights (access, erasure, portability, objection), and how to contact you or the DPC with a complaint. This information is typically provided through a link to your privacy policy at the point of sign-up, along with a brief summary in the sign-up confirmation.

Q28: Can I use subscriber data for purposes other than sending them emails?
Only if those additional purposes are compatible with the original purpose for which the data was collected and consented to, or if you have a separate lawful basis for the additional processing. If someone signed up for a newsletter, you can use their data to send them the newsletter — but using it for unrelated profiling, advertising targeting outside your email platform, or sharing with third parties for their own purposes requires separate justification.

Q29: What should I do if a subscriber makes a Subject Access Request?
A Subject Access Request (SAR) is a request from an individual to see all personal data you hold about them. You must respond within one calendar month. For email subscribers, this typically means providing: the email address and any other data you hold, the consent record including when and how it was obtained, the emails you have sent them, any segmentation data or behavioural data your platform holds, and information about any third parties their data has been shared with. Most email marketing platforms have data export functionality that makes this manageable.

Q30: Can I segment my list and use subscriber behaviour data for targeting?
Yes — using open rates, click behaviour, and purchase history to segment and target your email list is generally compatible with the purpose for which consent was given, provided this is disclosed in your privacy policy. Subscribers who consented to receive marketing emails from you would reasonably expect their engagement with those emails to inform what they receive. More complex behavioural profiling — particularly combining email behaviour with off-platform data — may require additional transparency and potentially additional consent.

Section 4: Unsubscribe Obligations (Q31–40)

Q31: Is it a legal requirement to include an unsubscribe link in marketing emails?
Yes. Under ePrivacy Regulations, every unsolicited marketing email must include a way for the recipient to opt out of future communications. Under GDPR, consent must be as easy to withdraw as it was to give. In practice, every marketing email must contain a clearly visible, functional unsubscribe mechanism. This is not optional regardless of your lawful basis.

Q32: Can I require someone to log in to unsubscribe?
No. Requiring a login to complete an unsubscribe is a barrier to withdrawal of consent and is not compliant. Unsubscribing must be straightforward and must not require the subscriber to take any action beyond clicking the unsubscribe link and, at most, confirming their email address. Asking for reasons, requiring account creation, or adding other friction to the unsubscribe process is not acceptable.

Q33: How quickly must I process an unsubscribe?
Promptly. While there is no specific number of days mandated, best practice guidance and most DPA expectations point to processing unsubscribes within ten business days at most — and ideally within one to two business days. Continuing to send marketing emails to someone who has unsubscribed while you are “processing” their request at length is not compliant. Most email marketing platforms process unsubscribes automatically and immediately, which is one of their key compliance benefits.

Q34: Can I offer a “manage preferences” option instead of a full unsubscribe?
Yes — offering subscribers the ability to reduce the frequency of emails or opt out of specific email types (promotional only, newsletter only) is a legitimate and often welcome alternative. However, this must always be alongside a complete opt-out option. You cannot force subscribers to go through a preferences page as the only way to stop all emails. The full unsubscribe must always be available alongside any preference management option.

Q35: Do I need to keep a record of unsubscribes?
Yes. You should maintain a suppression list of email addresses that have unsubscribed. This serves two purposes: it ensures you do not accidentally re-add unsubscribed contacts to your active list, and it provides evidence of compliance if you need to demonstrate that you respected unsubscribe requests. Deleting unsubscribed contacts entirely — rather than suppressing them — risks the contact being inadvertently re-added in future, which is a worse outcome from a compliance perspective.

Q36: What if someone unsubscribes from one list but I have them on another?
This depends on whether the lists have separate purposes and separate consent. If a subscriber signed up separately and specifically for two different mailing lists — a newsletter and a product update list, for example — an unsubscribe from one does not automatically apply to the other if the consent was genuinely separate and the subscriber understood they were signing up for distinct communications. However, if a subscriber tells you explicitly that they do not want to receive any marketing communications from you, you must respect that instruction across all lists.

Q37: Can I continue to send transactional emails to someone who has unsubscribed from marketing?
Yes. Transactional emails — order confirmations, delivery notifications, appointment reminders, password resets, account notifications — are not marketing communications and do not require marketing consent. An unsubscribe from marketing emails does not affect your right to send transactional communications to existing customers. The key distinction is that transactional emails must genuinely be transactional — they must not contain promotional content that makes them marketing communications in substance even if transactional in framing.

Q38: What is a suppression list and must I maintain one?
A suppression list is a record of email addresses from which unsubscribe requests have been received — used to ensure those addresses are never re-added to active marketing lists. Maintaining a suppression list is essential for compliance: without one, there is no reliable mechanism to prevent a contact who has unsubscribed from being added back to a list through a data import, a new sign-up form, or a CRM integration. Your email marketing platform should manage suppression lists automatically, but you should verify that the suppression list is being respected across all systems that feed into your email platform.

Q39: If someone re-subscribes after unsubscribing, do I need new consent?
Yes. If a subscriber unsubscribed and then returns to sign up again through your sign-up form, that new sign-up constitutes new consent, and you should treat them as a new subscriber with a fresh consent record. Do not automatically re-add their previous data or assume the re-subscription covers any communication types they did not specifically sign up for in the new subscription.

Q40: Can I send a re-engagement email to inactive subscribers before removing them?
Yes — a single re-engagement email to inactive subscribers asking if they still wish to receive your communications is generally considered acceptable practice, provided they have not unsubscribed (in which case they must not be emailed at all). The re-engagement email must make clear that if they take no action, they will be removed from the list. Do not send multiple re-engagement emails — one is appropriate, a sequence of re-engagement emails to people who are not responding is itself a compliance risk.

Section 5: The DPC, Fines, and What Happens When Things Go Wrong (Q41–50)

Q41: Who enforces GDPR email marketing rules in Ireland?
Two bodies are relevant. The Data Protection Commission (DPC) enforces GDPR in Ireland and handles complaints about personal data processing including email marketing. ComReg (the Commission for Communications Regulation) enforces ePrivacy Regulations and handles complaints specifically about unsolicited electronic direct marketing. A complaint about a non-compliant marketing email could go to either body, and both have enforcement powers.

Q42: How does the DPC investigate an email marketing complaint?
When the DPC receives a complaint about an organisation’s email marketing practices, it typically first writes to the organisation asking it to respond to the complaint. The organisation has an opportunity to explain its practices and provide evidence — including consent records — demonstrating compliance. If the DPC determines that a breach has occurred, it may issue a reprimand, require the organisation to bring its processing into compliance within a specified period, or impose an administrative fine. The DPC publishes decisions and case studies that provide useful guidance on how it approaches email marketing complaints.

Q43: How large are the fines for GDPR email marketing violations in Ireland?
GDPR fines can reach €20 million or 4% of global annual turnover — whichever is higher. In practice, the DPC has imposed a range of fines from relatively modest amounts for smaller organisations to tens of millions of euros for large multinationals. The severity of the fine depends on the nature of the breach, the number of people affected, how long the breach continued, whether it was intentional, and how cooperative the organisation was during the investigation. For email marketing violations, the most common DPC action is requiring the organisation to remediate its practices — formal fines are more likely where the breach was systematic or deliberate.

Q44: Can an individual complain to the DPC about receiving unwanted marketing emails?
Yes. Any individual who receives marketing communications they believe they did not consent to, or who has had an unsubscribe request ignored, can submit a complaint to the DPC at dataprotection.ie. The DPC takes direct marketing complaints seriously and has a dedicated complaints handling process. The volume of direct marketing complaints received by the DPC has increased year on year.

Q45: What should I do if I discover my email marketing list is not GDPR compliant?
Stop emailing non-compliant contacts immediately. Conduct a consent audit to understand which contacts have valid consent records and which do not. For contacts without valid consent, you have three options: run a re-permissioning campaign to obtain valid consent before emailing them further, remove them from your marketing list, or identify whether another lawful basis (such as the soft opt-in for existing customers) applies. Document what you find and what action you take. If you are concerned about potential exposure, seek legal advice from a data protection specialist.

Q46: Does using a reputable email marketing platform mean I am automatically compliant?
No. Platforms like Mailchimp, Klaviyo, Campaign Monitor, and others provide compliance-enabling infrastructure — double opt-in, automatic unsubscribe processing, consent timestamps, DPAs — but they do not make your practices compliant. Compliance depends on how you use the platform: the consent language you use, how you collect subscribers, whether you honour unsubscribes, how long you retain data, and what your privacy policy says. A non-compliant email sent through a compliant platform is still non-compliant.

Q47: Do I need a Data Processing Agreement with my email marketing platform?
Yes. Your email marketing platform processes personal data on your behalf, making it a data processor under GDPR. You are required to have a Data Processing Agreement (DPA) in place with every data processor. All major email marketing platforms provide DPAs — typically available in their terms of service or account settings. You should confirm that your DPA is in place and review it when your platform updates its terms.

Q48: My email platform is based in the US. Does that cause GDPR problems?
Potentially. Transfers of personal data from the EU to the US require an adequate transfer mechanism under GDPR. Most major US-based email platforms rely on Standard Contractual Clauses (SCCs) as the transfer mechanism, which is generally acceptable. However, following the Schrems II ruling and ongoing DPC scrutiny of US data transfers, you should verify that your platform’s SCCs are current, that the platform is committed to notifying you of law enforcement data requests, and that your privacy policy accurately describes where subscriber data is processed. Some businesses have moved to EU-based email platforms to eliminate transfer complexity.

Q49: What is a GDPR-compliant sign-up form and what must it include?
A compliant sign-up form must include: a clear explanation of what the subscriber is signing up to receive, the business name that will be sending the emails, an unticked opt-in checkbox (or equivalent active opt-in mechanism), a link to your privacy policy, and information about how to unsubscribe or withdraw consent. It must not bundle the marketing opt-in with any other agreement or make access to a service conditional on marketing consent. The form should also trigger a record of consent being stored in your email platform with a timestamp.

Q50: What is the single most important thing an Irish business can do to ensure its email marketing is GDPR compliant?
Conduct a consent audit. Review every contact on your email list and ask: when did this person consent, through what mechanism, with what wording, and do you have a record of it? The contacts you cannot answer these questions about are your compliance risk. Removing or re-permissioning those contacts is the most important single action most Irish businesses can take. Once your list is clean, maintaining compliance is straightforward: use active opt-in, record consent, honour unsubscribes promptly, keep your privacy policy current, and review your list regularly. Everything else flows from these fundamentals.

Compliance checklist
compliance checklist

  • Active opt-in only — no pre-ticked boxes anywhere on your sign-up forms
  • Marketing consent is separate from terms and conditions acceptance
  • Consent wording names your business and describes what will be sent
  • Consent records are stored — who signed up, when, through which form, and with what wording
  • No purchased or rented contact lists are in use
  • Existing list has been audited — every contact has a valid consent record or documented soft opt-in basis
  • Inactive subscribers (12–24 months no engagement) are reviewed and re-confirmed or removed
  • Subscriber data is not shared with third parties without a separate basis for that sharing
  • Every marketing email contains a one-click unsubscribe link
  • Every marketing email includes your business name and postal address
  • Every marketing email links to your current privacy policy
  • Unsubscribes are processed within 10 business days — no marketing emails sent in the interim
  • A suppression list is maintained so unsubscribed contacts cannot be accidentally re-added
  • A Data Processing Agreement is in place with your email marketing platform
  • Your privacy policy accurately describes your email marketing practices, lawful basis, and data retention
  • You have a process for responding to Subject Access Requests within one calendar month

If you need help auditing your email marketing practices for GDPR compliance, reviewing your consent processes, or understanding your obligations as an Irish business under both GDPR and ePrivacy Regulations, the GDPR compliance team at Matrix Internet works with businesses across Ireland to assess their current practices and put compliant frameworks in place. Get in touch to discuss your specific situation.

Stay in the loop New trends, interesting news from the digital world.