emailmarketing.net

Right to Object and Right to Erasure in Marketing Operations

How GDPR/UK GDPR objection, opt-out, consent withdrawal, and erasure requests interact with marketing lists and suppression — ICO operational guidance plus enforcement patterns from the EDPB one-stop-shop case digest (551 Art. 17 and 80 Art. 21 decisions).

Operationalcomplianceesp-operator

Four distinct mechanisms let a recipient shut off marketing under GDPR/UK GDPR + ePrivacy regimes: objection (GDPR Art. 21), opt-out/unsubscribe (the ePrivacy-layer mechanism), withdrawal of consent (Art. 7(3)), and erasure (Art. 17). They differ in scope and in what the sender must do with the data afterward — and the resolution of the apparent paradox ("honoring an opt-out forever requires keeping the address; erasure demands deleting it") is the suppression list. This article combines the ICO's operational guidance with the enforcement record from the EDPB's one-stop-shop case digest. For the suppression-list architecture itself (hashing, retention basis, ESP-level suppression), see GDPR and Suppression Lists.

The right to object (Art. 21)

  • For direct marketing purposes the right is absolute: no exemptions, no grounds for refusal, exercisable at any time, and it covers profiling related to direct marketing — including inferring interests for targeting and disclosing data to third parties for marketing.
  • For processing based on public task or legitimate interests, objection is not absolute: the individual gives reasons tied to their situation, and the controller may continue only with compelling legitimate grounds that override the individual's interests, or for legal claims. (Marketing under legitimate interests still falls under the absolute marketing rule.)
  • Duty to inform: the right to object must be brought to people's attention at the latest at the time of the first communication, presented clearly and separately from other information — plus at collection under the right to be informed.

Handling mechanics (ICO)

Aspect Rule
Form Verbal or written; any part of the organisation can receive it; no magic words — "I ask for a guarantee that this will not repeat itself" counts
Deadline Without undue delay, at latest one calendar month from receipt (day-of-receipt to corresponding date next month; last day of month if none; next working day if weekend/holiday — a fixed 28-day SLA guarantees compliance)
Extension +2 months for complex or numerous requests; individual told within the first month with reasons
Fee None, except a reasonable admin fee (or refusal) for manifestly unfounded or excessive requests — assessed case-by-case, never by blanket policy; repeat requests aren't automatically excessive
ID checks Only what is necessary and proportionate to confirm identity (e.g., confirming the email address to be suppressed); see the digest below on ID-document demands
Refusal Only for unfounded/excessive requests or an exemption (never for marketing objections themselves); tell the individual within one month: reasons, right to complain to the supervisory authority, judicial remedy
Staff readiness Train customer-facing staff to recognise objections; keep a log of verbal objections

Objection vs. opt-out vs. withdrawal (ICO "respect people's preferences")

  • Opt-out/unsubscribe works like an objection scoped to a channel or activity. The ICO example: a customer texts STOP — SMS marketing must cease, but email marketing may continue because that channel's opt-out wasn't exercised. Make clear at collection which channels an opt-out covers.
  • Withdrawal of consent: must be as easy as giving it; stop the consent-covered marketing immediately or as soon as possible; and you must not swap to another lawful basis (e.g., legitimate interests) to keep marketing after consent is withdrawn — that would be unfair.
  • No win-back after objection: contacting someone later to ask if they've changed their mind is itself direct marketing to an objector. Their most recent indication governs — an objection is overridden only if they specifically withdraw it or later agree to marketing; merely failing to opt out again never overrides it.
  • Permitted contact: an immediate confirmation message after an unsubscribe (with resubscribe instructions) is fine provided it requires no action to make the opt-out effective. Preference reminders are allowed only as a minor, incidental addition to a message being sent anyway for another purpose (e.g., a line at the end of an annual statement), without marketing content or encouragement to change the choice.

Suppression lists

The load-bearing concept, per the ICO:

  • On objection/opt-out, suppress, don't delete: keep just enough information to ensure the preference is respected, clearly marked so it isn't used for the objected-to purposes.
  • A suppression list is not processing "for direct marketing purposes" — it exists to comply with a statutory obligation. This kills the circular argument that keeping an objector's address is itself unlawful marketing processing, and it means there is no automatic right to have one's entry on a suppression list erased.
  • The failure mode of deleting instead: the ICO's example — a company deletes an objector's phone number, later buys a TPS-screened list that (lawfully) still contains that number, and calls again → PECR breach that a suppression screen would have prevented. The same mechanism applies to purchased or re-imported email lists.
  • Data minimisation applies: keep only the minimum needed to suppress.
  • Suppression list ≠ screening list: screening out people who don't fit a campaign is itself processing for direct marketing purposes; only compliance-driven suppression gets the special status. (Statutory suppression registers exist for other channels — TPS/CTPS for calls, MPS for post.)

Erasure requests (Art. 17) in the marketing context

Erasure is not absolute — in the marketing context it applies when consent is withdrawn, the data is no longer needed for the purpose, or the person has objected to marketing. The ICO's guidance:

  • A withdrawal or objection need not automatically be treated as an erasure request, but in practice once you can no longer use the data you'll likely delete it — except the minimal suppression entry.
  • The model transaction: customer objects and asks for deletion → company stops marketing, deletes everything apart from a small amount kept on its suppression list → the customer's rights are satisfied. Erasure may also be refused for data needed for other purposes (the data must then be clearly marked against marketing use).
  • Under Art. 17(1), when consent is withdrawn or an objection succeeds, the controller has an independent obligation to delete the (non-suppressed) data — a specific erasure request from the data subject is not required (EDPB digest, citing EDPB Opinion 39/2021).

Enforcement patterns — the EDPB one-stop-shop case digest

The digest (Support Pool of Experts, Prof. Alessandro Mantelero; first version December 2022, updated May 2026) analyses the final Article 60 one-stop-shop decisions in the EDPB public register: 551 decisions on Art. 17 and 80 on Art. 21, adopted 2018 through January 2026. Art. 17 cases peaked in 2022–2023 (Irish-led cases dominating: 84 in 2022, 150 in 2023, 35 in 2024) then declined; Art. 21 volumes stayed flat. The two rights arrive together in practice: most Art. 21 cases concern direct marketing, frequently paired with a request to erase the previously collected data — and one German decision (DEBE:OSS:D:2018:9) holds that a marketing objection triggers a deletion obligation under Art. 17(1)(c) to be applied "immediately".

Recurring findings directly relevant to running marketing systems:

Design and information failures

  • No information about the right to object, violating Art. 13(2)(b) (ES:2021:263); a bank sent marketing emails with no opt-out option at registration — preferences changeable only inside the online-banking service or via customer service (NO:2021:292 → reprimand plus ordered measures and Art. 12(3) deadline compliance).
  • No-reply sender addresses: if replies are impossible, the email body must say so clearly, and that objections by reply will be ineffective (FR:2019:8). Conversely (NL:2022:376): the GDPR does not require unsubscribing via reply — but marketing emails must include a clear link to a page where unsubscribing is possible.
  • Unsubscribe links pointing to a customer-account page fail for prospects who have no account; a link that directly unsubscribes is required (FR:2020:84). Design rights flows for every recipient type you mail.
  • Cumbersome procedures and language barriers: providing a rights contact address but auto-replying with a redirect to a website "Contact us" form was itself a violation (FR:2022:326).
  • Acknowledgment emails must state the implementation timeframe, and the outcome must be communicated (EE:2019:55; FR:2019:41).

Process failures

  • Backlogs and capacity gaps in customer service (NO:2021:292); objection registered against only one of multiple accounts the person held (EE:2019:55); system technical errors delaying compliance (CZ:2021:312); unsynchronised databases, unmonitored legacy contact addresses (MT:2021:212 — auto-reply or forwarding required when retiring a contact address; FR:2023:999 — an old support address still live and listed on the web must not go unread), requests forwarded to the wrong department (UK:2019:31), and misclassification of requests.
  • The controller answers for employee mistakes — individual fault is irrelevant to GDPR accountability (DEBE:2021:184).
  • Manual/off-channel requests must get the same treatment as automated ones (SE:2021:178 — postal request missed the notifications the digital system would have sent). Semi-automated intake that discards requests not following instructions is unlawful (DK:2020:151). But informal requests (a tweet) may be disregarded when formal channels exist (SE:2021:276, confirmed SE:2024:1550 — any official channel of the controller must work; requests to random/incorrect addresses need not be honored).
  • Keep records of objection requests and their outcomes (accountability).

Identity verification

  • Demanding an official ID document by default is not acceptable and violates data minimisation (Art. 5(1)(c)) — Groupon's blanket ID-card policy (IE:2020:166), and FR:2019:3 (an online customer relationship does not itself create reasonable doubt). Authentication must be "relevant, appropriate and proportionate" to the data, request, context, and disclosure risk (FR:2024:1286). Requests from the registration email address normally need no further proof (CY:2024:1120); alternatives to ID documents: unique identifiers issued at registration, account-linked-email-only policies, password hotlines, online calls, or knowledge questions (nicknames, registration date — EE:2021:294). Where ID sharing is justified, protect the transfer (NO:2024:1126 — ID card over unencrypted email). For objections specifically, the Swedish SA notes there is normally no reason to authenticate at all — sometimes not even to identify — the person objecting (SE:2025:1757).
  • Complying is expected even without perfect process: continued processing after a valid erasure request infringes Art. 6(1), since the data could have been deleted at the time of the request.

Erasure specifics

  • Most erasure cases stem from marketing objections (including unsolicited email — NO:2022:314) and unused-account cleanup; self-service deletion tools are emphasised as reducing both errors and regulator workload.
  • Proof of erasure: the controller must be able to demonstrate compliance, e.g., a screenshot showing the database returns no result for the requester (DE:2023:929).
  • Notify the data subject of the action taken within Art. 12(3) deadlines; when granting, stating that erasure has been initiated and its maximum duration suffices — no completion confirmation needed unless requested (SE:2021:303).
  • Overriding grounds can defeat erasure: fraud-prevention retention of payment identifiers (SE:2021:196), statutory retention periods (DK:2021:210 — but keeping an active account two years merely because complaint rights exist was unnecessary; complaints can be made by email or phone), anti-money-laundering and banking obligations (MT:2022:340; MT:2021:272 — the specific legal source must be cited to the requester), debts, PNR storage, public registers. Legal obligations must be interpreted in line with data-protection principles, not abused; data beyond what the obligation requires must still be deleted ("intermediate storage" is bounded — FR:2021:279, FR:2021:310).
  • Outcomes are dominated by amicable settlements and reprimands; fines are rare and usually reflect broader infringements. Spontaneous compliance once an SA opens an investigation is common.

Operational checklist for a marketing platform

  1. Unsubscribe = objection on that channel: suppress immediately, propagate to all of the recipient's accounts/records, never require login or account existence.
  2. Route free-text objections (replies, support tickets, phone) into the same suppression pipeline as link clicks; train support staff; log verbal requests.
  3. Acknowledge with timeframe; complete within one month; confirm outcome.
  4. On erasure requests from marketing contacts: delete profile data, retain a minimal suppression entry, and be able to prove both (deletion evidence + suppression record).
  5. Don't demand ID documents by default; treat requests from the subscribed address as self-authenticating.
  6. Keep suppression permanent and screen every list import against it — including re-imports and bought lists.
  7. Cite the specific legal basis when refusing erasure for retention obligations.

These duties align with deliverability practice: instant, friction-free unsubscribes reduce the spam complaints that drive reputation, and RFC 8058 one-click unsubscribe — mandatory at Gmail/Yahoo/Microsoft for bulk senders — is precisely the "direct, no-account-needed" mechanism the DPAs keep ordering senders to build.

#compliance#legal#gdpr#uk-gdpr#right-to-object#right-to-erasure#suppression-lists#data-subject-rights#edpb