emailmarketing.net

EU ePrivacy Directive + GDPR — Email Marketing

The EU opt-in rule for email marketing: ePrivacy Art. 13 and its soft opt-in, the GDPR consent standard per EDPB 05/2020, lawful basis (consent vs. legitimate interests), tracking pixels under Art. 5(3) per EDPB 2/2023, and the member-state divergence table.

Reference12 min read

Who it is for Compliance teams, Senders

Applies to senders on any platform

Not legal advice. This reference summarizes the directives, the regulation and the guidance of the European Data Protection Board (EDPB) for deliverability practitioners. Penalties, national implementations and guidance change, so consult qualified counsel for compliance decisions.

If you send marketing email to people in the European Union, two instruments decide whether you may send it and how you must handle the data. Confusing them causes most of the misunderstandings:

  • ePrivacy Directive 2002/58/EC (as amended by Directive 2009/136/EC) is the sending rule. Its Article 13 says when marketing email may be sent at all: with prior consent, with one exception.
  • The GDPR (Regulation 2016/679) sets the processing rules. It defines valid consent (Art. 4(11) and 7), provides the lawful bases (Art. 6), and grants the absolute right to object to direct marketing (Art. 21(2)–(3)).

"GDPR requires consent for email marketing" is an oversimplification. The requirement for consent to send comes from ePrivacy Art. 13, while the GDPR sets the quality standard that consent must meet. In Guidelines 05/2020 ¶7, the EDPB confirms that references to consent under Directive 95/46/EC in the ePrivacy Directive are now read as GDPR consent, and that the GDPR conditions for consent apply in ePrivacy situations.

Because ePrivacy is a directive, each member state implemented it in national law, with real differences (see the table below). A proposed ePrivacy Regulation to replace the directive was negotiated for years and withdrawn by the Commission in early 2025. The directive of 2002, as amended in 2009, remains the law.

Article 13: unsolicited communications

Key provisions (the 2002 text; the 2009 amendment extended protection to "subscribers or users" and added provisions on enforcement, without changing the structure below):

  • 13(1): prior consent. "The use of automated calling systems without human intervention…, facsimile machines (fax) or electronic mail for the purposes of direct marketing may only be allowed in respect of subscribers who have given their prior consent." Opt-in is the default rule.
  • 13(2): the "soft opt-in" (the existing-customer exception). Email marketing without consent is allowed only where all of the following conditions hold:
    1. a natural or legal person obtains from its customers their electronic contact details for electronic mail,
    2. in the context of the sale of a product or a service (in accordance with data protection law),
    3. the same natural or legal person uses those details (not a group company, a partner or a list buyer),
    4. for direct marketing of its own similar products or services, and
    5. customers are clearly and distinctly given the opportunity to object, free of charge and in an easy manner, both when the details are collected and on the occasion of each message (provided the customer did not refuse initially).
  • 13(3): for direct marketing by other means (for example, post or live calls), member states choose between opt-in and opt-out nationally.
  • 13(4): whatever the consent, it is prohibited to send marketing email "disguising or concealing the identity of the sender on whose behalf the communication is made," or without a valid address to which the recipient may send a request to stop. (The 2009 amendment added a ban on emails that point to websites breaking the identity rules for e-commerce.)
  • 13(5): paragraphs 1 and 3 protect natural persons. Member states must also ensure that the legitimate interests of legal persons (corporate subscribers) are "sufficiently protected", which is why the treatment of business-to-business (B2B) mail varies by country (see the table).

"Electronic mail" (Art. 2(h)): "any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient." This covers email, SMS, voicemail and, according to regulators, direct messages in apps and on social media. It is as broad as the UK PECR definition, which is the UK's implementation of this directive.

Art. 4(11): consent is "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." The EDPB puts this into practice as follows:

Element EDPB requirements
Freely given A real choice without detriment. Consent bundled into terms and conditions (T&Cs) is presumed not to be free (Recital 43, Art. 7(4)). Making a service conditional on consent to processing that is not necessary ("tying") is presumed invalid, and exceptions are "highly exceptional". Contexts with an imbalance of power (employer and employee, public authorities) usually rule out consent. Incentives are allowed if refusing or withdrawing costs nothing (losing a permissible perk is not a detriment).
Specific and granular Separate consent for each purpose ("granularity"): one checkbox covering both "email me marketing" and "share my details with group companies" is invalid (Example 7). Specifying the purpose guards against function creep, and a new purpose needs new consent.
Informed Minimum content: (i) the controller's identity, (ii) the purpose of each operation, (iii) which data, (iv) the right to withdraw, (v) automated decision-making where relevant, (vi) transfer risks where relevant. Every controller that relies on the consent must be named; processors need not be. Clear, plain language, separate and distinct from the T&Cs, and not buried in a privacy policy.
Unambiguous A statement or a clear affirmative action. Pre-ticked boxes, silence, inactivity, or simply continuing to use a service are invalid, and scrolling or swiping can never be consent (Example 16). Consent must come before the processing.
Demonstrable (Art. 7(1)) The burden of proof is on the controller. Keep enough data to show a link to the processing, for example session information, the consent workflow, and a copy of the information presented at the time. Merely pointing to the current website configuration is not enough (¶108). Consent has no statutory expiry, but the EDPB recommends refreshing it at appropriate intervals. Keep proof no longer than needed after the processing ends.
Withdrawable (Art. 7(3)) As easy to withdraw as to give, at any time, free of charge and without any degradation of service. If consent took one click, withdrawal must be equally easy through the same electronic interface: an unsubscribe by phone only, for an online signup, violates Art. 7(3) (Example 22, a ticket agent for a music festival). After withdrawal, stop the processing and delete the data unless another lawful basis applies.

Two rules have direct consequences for list management:

  • No silent swapping of the lawful basis (¶¶121–123): a controller cannot fall back on legitimate interests when consent turns out to be invalid or is withdrawn. The lawful basis must be decided and disclosed before collection.
  • Consents given before the GDPR (¶¶166–171) remain valid only if they already met the GDPR standard. Presumed consents with no records, and consents given through pre-ticked boxes, "will automatically be below the consent standard". They had to be renewed or the processing stopped, which is the legal reason behind the 2018 wave of re-permission campaigns.

For children, Art. 8 sets the age of consent for information society services at 16, which a member state may lower to no less than 13.

Under the GDPR alone, processing for direct marketing may rest on consent (Art. 6(1)(a)) or on legitimate interests (Art. 6(1)(f)). Recital 47 says so expressly: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." But legitimate interests cannot override ePrivacy Art. 13: for the act of sending email, only consent under 13(1) or the soft opt-in under 13(2) will do. The stable pattern, which the Information Commissioner's Office (ICO) guidance for UK PECR mirrors, is:

  • sending under Art. 13(1) consent: the GDPR basis is consent;
  • sending under the Art. 13(2) soft opt-in: the GDPR basis is usually legitimate interests, documented with a balancing assessment.

Either way, Art. 21(2)–(3) grants an absolute right to object to processing for direct marketing: "the personal data shall no longer be processed for such purposes", with no balancing, no grounds required, and free of charge (Recital 70). This is the legal root of the obligation to suppress permanently.

Fines: infringements of the conditions for consent and of the rights of data subjects fall in the upper tier of the GDPR, up to €20 million or 4% of worldwide annual turnover, whichever is higher (Art. 83(5)). Other obligations of controllers and processors carry fines of up to €10M or 2% (Art. 83(4)). Penalties under ePrivacy are set nationally and vary widely.

Tracking pixels and Art. 5(3): EDPB Guidelines 2/2023 (v2.0, adopted 7 October 2024)

Art. 5(3) (as amended in 2009) requires consent, after clear and comprehensive information, for "the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user". There are two exemptions: technical storage or access for the sole purpose of carrying out the transmission, and storage or access strictly necessary for a service the user explicitly requested. The rule is technology-neutral (it is not limited to cookies) and applies to "information", not only to personal data.

The EDPB's three criteria for applicability are: (A) the operation concerns information; (B) it involves terminal equipment connected or connectable to a public communications network; (C) it constitutes storage or gaining of access, which need not happen in the same communication or be performed by the same party.

Email open and click tracking is clearly in scope (§3.1, ¶¶47–51):

  • A tracking pixel in an email exists to make the client open a connection to the pixel host that would not otherwise happen, which reveals when the email is read. It may carry identifiers unique to each recipient. Tracked links work the same way, with the identifier appended to the URL.
  • Distributing pixels or links to the device "does constitute storage, at the very least through the caching mechanism of the client-side software… even if this storage is not permanent" (¶50).
  • The added tracking identifier "constitutes an instruction to the terminal equipment to send back the targeted information", that is, a gaining of access (¶51).

As a result, the core engagement telemetry of an email service provider (ESP), which is opens through pixels and clicks through redirects with tokens unique to each recipient, requires consent under Art. 5(3) in the EU unless an exemption applies. The EDPB analyzes scope only, and leaves exemptions to national law and to assessment case by case (¶40), but neither exemption plausibly covers marketing analytics. Points with operational consequences:

  • Who obtains consent: the sender or controller (the ESP's customer), typically at signup alongside marketing consent, as a granular purpose that can be consented to separately under EDPB 05/2020.
  • The guidelines also bring tracking based only on IP addresses partly into scope (¶¶54–55), and note that the applicability of Art. 5(3) "does not systematically mean that consent needs to be collected", because the analysis of exemptions is separate (¶56).
  • Tension with deliverability practice: sunset policies based on engagement presume open and click data. Where there is no pixel consent, the alternatives are aggregate or log-based signals that the sender controls: click activity on consented links, delivery data at the SMTP level, complaint and unsubscribe events, and activity on the site or in purchases. Apple Mail Privacy Protection already pre-fetches pixels and makes opens less useful as an individual signal, so EU consent constraints speed up an existing shift away from automation based on opens.

Member-state divergence (Fieldfisher "Email Marketing Across Europe," January 2024)

National implementations of ePrivacy differ on three points: whether B2B email is exempt from opt-in, whether the soft opt-in requires a completed sale transaction or only a commercial relationship (an enquiry or a quote), and whether double opt-in is expected as proof. Definitions: "opt-in" means an unambiguous positive action, and "soft opt-in" means the four conditions of Art. 13(2) (collected in the context of a sale; the same legal entity; similar products or services; free objection at collection and in every message). Email marketing by third parties ("partners") effectively requires an opt-in that names the sender, everywhere.

Country B2C (first-party) B2B (first-party) Soft opt-in: sale needed? Notes
Austria Double opt-in; soft opt-in available Double opt-in; soft opt-in available No DOI should be used when relying on opt-in; national opt-out list (ECG-Liste) overrides soft opt-in
Belgium Opt-in; soft opt-in available Opt-in for individual B2B addresses; soft opt-in available Yes Royal Decree of 4 April 2003
Bulgaria Opt-in; soft opt-in available Opt-in; soft opt-in available No
Croatia Opt-in; soft opt-in available Opt-out Yes
Cyprus Opt-in; soft opt-in available Opt-in Yes
Czech Republic Opt-in; soft opt-in available Opt-in; soft opt-in available Yes
Denmark Opt-in; soft opt-in available Opt-in; soft opt-in available Yes Marketing Practices Act art. 10
Estonia Opt-in; soft opt-in available Opt-out Yes
Finland Opt-in; soft opt-in available Individualised address: opt-in; non-individualised or role-related: opt-out Yes
France Opt-in; soft opt-in available Opt-out Yes CPCE Art. L34-5; B2B allowed if message relates to the recipient's professional function
Germany Double opt-in (proof standard); soft opt-in exists but rarely relied on Double opt-in; no B2B exemption Yes See Germany: UWG §7
Greece Opt-in; soft opt-in available Opt-in; soft opt-in available No Law 3471/2006
Hungary Opt-in; no soft opt-in Opt-out n/a
Ireland Opt-in; soft opt-in available Opt-out if related to the recipient's professional role, else opt-in Yes S.I. 336/2011
Italy Opt-in; soft opt-in available (email only, not SMS) Opt-in Yes
Latvia Opt-in; soft opt-in available Opt-out Yes
Lithuania Opt-in; soft opt-in available (email only) Opt-in; soft opt-in available Yes
Luxembourg Opt-in; soft opt-in available Opt-out Yes
Malta Opt-in; soft opt-in available Opt-in; soft opt-in available Yes
Netherlands Opt-in; soft opt-in available Opt-in; soft opt-in available Yes
Norway Opt-in; soft opt-in available Individualised address: opt-in; non-individualised: opt-out Yes Marketing Control Act 2009
Poland Opt-in; no soft opt-in Opt-in n/a
Portugal Opt-in; soft opt-in available Individualised: opt-in; non-individualised: opt-out unless on the national opt-out list Yes National Opt-Out List updated monthly
Romania Opt-in; soft opt-in available Opt-in; soft opt-in available Yes
Slovakia Opt-in; soft opt-in available Opt-out where business contact details were made publicly available Yes
Slovenia Opt-in; soft opt-in available Opt-out Yes ZEKom-2
Spain Opt-in; soft opt-in available Opt-in; soft opt-in available Yes LSSI Law 34/2002
Sweden Opt-in; soft opt-in available Opt-out if related to the recipient's professional role, else opt-in Yes
Switzerland (non-EU) Opt-in; no soft opt-in Opt-in n/a Unfair Competition Act Art. 3(1)(o)
United Kingdom (non-EU) Opt-in; soft opt-in available Opt-out (corporate subscribers exempt) No See UK PECR

A practical reading for an ESP asked "can I email this EU list?": for lists that mix EU countries, treat the union of the rules as the baseline. Opt-in, documented for each person, with a working unsubscribe in every message satisfies every state. The soft opt-in is safe only within a single country, for first-party mail about similar products, with the offer to object at collection provably made. B2B exemptions are specific to each country and never cover sole traders, who are natural persons.

Staying current

The table above is a snapshot from January 2024. Check two living references before relying on any row:

  • DLA Piper, Data Protection Laws of the World (dlapiperdataprotection.com): 160+ jurisdictions, an "Electronic marketing" topic for each country, and side-by-side comparison. It is updated twice a year.
  • IAPP Global Privacy Directory (iapp.org/resources/global-privacy-directory): 240 jurisdictions, with links to each data protection authority (DPA) and to the underlying legislation for the long tail.

Deliverability relevance

The conditions of Art. 13 codify in law what mailbox providers reward anyway: addresses collected directly, a real commercial relationship, granular consent, an offer to object at collection, and an unsubscribe in every message (consent methods, foundations). The identity and valid-address requirements of 13(4) map to the sender transparency norms that every filter enforces. Law and deliverability diverge on consent for tracking: EU rules constrain the engagement telemetry that list hygiene driven by reputation assumes, so senders with mostly EU audiences should build sunset logic on clicks, conversions and complaints rather than on opens.