# EU ePrivacy Directive + GDPR — Email Marketing

> The EU opt-in rule for email marketing: ePrivacy Art. 13 and its soft opt-in, the GDPR consent standard per EDPB 05/2020, lawful basis (consent vs. legitimate interests), tracking pixels under Art. 5(3) per EDPB 2/2023, and the member-state divergence table.

Source: emailmarketing.net — https://emailmarketing.net/learn/compliance/eu-eprivacy-and-gdpr-email-marketing

> **Not legal advice.** This reference summarizes the directives, the regulation and the guidance of the European Data Protection Board (EDPB) for deliverability practitioners. Penalties, national implementations and guidance change, so consult qualified counsel for compliance decisions.

If you send marketing email to people in the European Union, two instruments decide whether you may send it and how you must handle the data. Confusing them causes most of the misunderstandings:

- **ePrivacy Directive 2002/58/EC** (as amended by Directive 2009/136/EC) is the **sending rule**. Its Article 13 says when marketing email may be sent at all: with prior consent, with one exception.
- **The GDPR (Regulation 2016/679)** sets the **processing rules**. It defines valid consent (Art. 4(11) and 7), provides the lawful bases (Art. 6), and grants the absolute right to object to direct marketing (Art. 21(2)–(3)).

"GDPR requires consent for email marketing" is an oversimplification. The requirement for consent to send comes from **ePrivacy Art. 13**, while the GDPR sets the quality standard that consent must meet. In Guidelines 05/2020 ¶7, the EDPB confirms that references to consent under Directive 95/46/EC in the ePrivacy Directive are now read as GDPR consent, and that the GDPR conditions for consent apply in ePrivacy situations.

Because ePrivacy is a **directive**, each member state implemented it in national law, with real differences (see the table below). A proposed ePrivacy **Regulation** to replace the directive was negotiated for years and withdrawn by the Commission in early 2025. The directive of 2002, as amended in 2009, remains the law.

## Article 13: unsolicited communications

Key provisions (the 2002 text; the 2009 amendment extended protection to "subscribers or users" and added provisions on enforcement, without changing the structure below):

- **13(1): prior consent.** "The use of automated calling systems without human intervention…, facsimile machines (fax) or electronic mail for the purposes of direct marketing may only be allowed in respect of subscribers who have given their **prior consent**." Opt-in is the default rule.
- **13(2): the "soft opt-in" (the existing-customer exception).** Email marketing without consent is allowed only where **all** of the following conditions hold:
  1. a natural or legal person **obtains from its customers their electronic contact details** for electronic mail,
  2. **in the context of the sale of a product or a service** (in accordance with data protection law),
  3. **the same natural or legal person** uses those details (not a group company, a partner or a list buyer),
  4. for direct marketing of **its own similar products or services**, and
  5. customers are **clearly and distinctly given the opportunity to object, free of charge and in an easy manner**, both **when the details are collected** and **on the occasion of each message** (provided the customer did not refuse initially).
- **13(3)**: for direct marketing by other means (for example, post or live calls), member states choose between opt-in and opt-out nationally.
- **13(4)**: whatever the consent, it is **prohibited** to send marketing email "disguising or concealing the identity of the sender on whose behalf the communication is made," or **without a valid address** to which the recipient may send a request to stop. (The 2009 amendment added a ban on emails that point to websites breaking the identity rules for e-commerce.)
- **13(5)**: paragraphs 1 and 3 protect **natural persons**. Member states must also ensure that the legitimate interests of **legal persons** (corporate subscribers) are "sufficiently protected", which is why the treatment of business-to-business (B2B) mail varies by country (see the table).

**"Electronic mail"** (Art. 2(h)): "any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient." This covers email, SMS, voicemail and, according to regulators, direct messages in apps and on social media. It is as broad as the [UK PECR definition](https://emailmarketing.net/learn/compliance/uk-pecr-email-marketing), which is the UK's implementation of this directive.

## The GDPR consent standard (EDPB Guidelines 05/2020, v1.1, adopted 4 May 2020)

Art. 4(11): consent is "any **freely given, specific, informed and unambiguous** indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." The EDPB puts this into practice as follows:

| Element | EDPB requirements |
|---|---|
| **Freely given** | A real choice without detriment. Consent bundled into terms and conditions (T&Cs) is presumed not to be free (Recital 43, Art. 7(4)). Making a service conditional on consent to processing that is not necessary ("tying") is presumed invalid, and exceptions are "highly exceptional". Contexts with an imbalance of power (employer and employee, public authorities) usually rule out consent. Incentives are allowed if refusing or withdrawing costs nothing (losing a permissible perk is not a detriment). |
| **Specific and granular** | Separate consent for each purpose ("granularity"): one checkbox covering both "email me marketing" and "share my details with group companies" is invalid (Example 7). Specifying the purpose guards against function creep, and a new purpose needs new consent. |
| **Informed** | Minimum content: (i) the controller's identity, (ii) the purpose of each operation, (iii) which data, (iv) the right to withdraw, (v) automated decision-making where relevant, (vi) transfer risks where relevant. Every controller that relies on the consent must be **named**; processors need not be. Clear, plain language, separate and distinct from the T&Cs, and not buried in a privacy policy. |
| **Unambiguous** | A statement or a clear affirmative action. **Pre-ticked boxes, silence, inactivity, or simply continuing to use a service are invalid**, and scrolling or swiping can never be consent (Example 16). Consent must come before the processing. |
| **Demonstrable** (Art. 7(1)) | The burden of proof is on the controller. Keep enough data to show a link to the processing, for example session information, the consent workflow, and **a copy of the information presented at the time**. Merely pointing to the current website configuration is not enough (¶108). Consent has no statutory expiry, but the EDPB recommends refreshing it at appropriate intervals. Keep proof no longer than needed after the processing ends. |
| **Withdrawable** (Art. 7(3)) | As easy to withdraw as to give, at any time, free of charge and without any degradation of service. If consent took one click, withdrawal must be equally easy **through the same electronic interface**: an unsubscribe by phone only, for an online signup, violates Art. 7(3) (Example 22, a ticket agent for a music festival). After withdrawal, stop the processing and delete the data unless another lawful basis applies. |

Two rules have direct consequences for list management:

- **No silent swapping of the lawful basis** (¶¶121–123): a controller cannot fall back on legitimate interests when consent turns out to be invalid or is withdrawn. The lawful basis must be decided and disclosed before collection.
- **Consents given before the GDPR** (¶¶166–171) remain valid only if they already met the GDPR standard. Presumed consents with no records, and consents given through pre-ticked boxes, "will automatically be below the consent standard". They had to be renewed or the processing stopped, which is the legal reason behind the 2018 wave of re-permission campaigns.

For children, Art. 8 sets the age of consent for information society services at **16**, which a member state may lower to no less than **13**.

## Lawful basis: consent vs. legitimate interests

Under the GDPR alone, processing for direct marketing may rest on **consent (Art. 6(1)(a))** or on **legitimate interests (Art. 6(1)(f))**. Recital 47 says so expressly: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." But legitimate interests **cannot override ePrivacy Art. 13**: for the act of sending email, only consent under 13(1) or the soft opt-in under 13(2) will do. The stable pattern, which the Information Commissioner's Office (ICO) guidance for [UK PECR](https://emailmarketing.net/learn/compliance/uk-pecr-email-marketing) mirrors, is:

- sending under **Art. 13(1) consent**: the GDPR basis is **consent**;
- sending under the **Art. 13(2) soft opt-in**: the GDPR basis is usually **legitimate interests**, documented with a balancing assessment.

Either way, **Art. 21(2)–(3)** grants an **absolute** right to object to processing for direct marketing: "the personal data shall no longer be processed for such purposes", with no balancing, no grounds required, and free of charge (Recital 70). This is the legal root of the obligation to suppress permanently.

**Fines**: infringements of the conditions for consent and of the rights of data subjects fall in the upper tier of the GDPR, up to **€20 million or 4% of worldwide annual turnover**, whichever is higher (Art. 83(5)). Other obligations of controllers and processors carry fines of up to €10M or 2% (Art. 83(4)). Penalties under ePrivacy are set nationally and vary widely.

## Tracking pixels and Art. 5(3): EDPB Guidelines 2/2023 (v2.0, adopted 7 October 2024)

Art. 5(3) (as amended in 2009) requires **consent**, after clear and comprehensive information, for "the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user". There are two exemptions: technical storage or access for the sole purpose of carrying out the transmission, and storage or access **strictly necessary** for a service the user explicitly requested. The rule is technology-neutral (it is not limited to cookies) and applies to "information", not only to personal data.

The EDPB's three criteria for applicability are: (A) the operation concerns **information**; (B) it involves **terminal equipment** connected or connectable to a public communications network; (C) it constitutes **storage** or **gaining of access**, which need not happen in the same communication or be performed by the same party.

**Email open and click tracking is clearly in scope** (§3.1, ¶¶47–51):

- A **tracking pixel** in an email exists to make the client open a connection to the pixel host that would not otherwise happen, which reveals when the email is read. It may carry identifiers unique to each recipient. **Tracked links** work the same way, with the identifier appended to the URL.
- Distributing pixels or links to the device "does constitute storage, at the very least through the caching mechanism of the client-side software… **even if this storage is not permanent**" (¶50).
- The added tracking identifier "constitutes an instruction to the terminal equipment to send back the targeted information", that is, a **gaining of access** (¶51).

As a result, the core engagement telemetry of an email service provider (ESP), which is opens through pixels and clicks through redirects with tokens unique to each recipient, requires **consent under Art. 5(3)** in the EU unless an exemption applies. The EDPB analyzes scope only, and leaves exemptions to national law and to assessment case by case (¶40), but neither exemption plausibly covers marketing analytics. Points with operational consequences:

- **Who obtains consent**: the sender or controller (the ESP's customer), typically at signup alongside marketing consent, as a granular purpose that can be consented to separately under EDPB 05/2020.
- The guidelines also bring **tracking based only on IP addresses** partly into scope (¶¶54–55), and note that the applicability of Art. 5(3) "does not systematically mean that consent needs to be collected", because the analysis of exemptions is separate (¶56).
- **Tension with deliverability practice**: [sunset policies](https://emailmarketing.net/learn/operations/list-hygiene-and-sunset-policies) based on engagement presume open and click data. Where there is no pixel consent, the alternatives are aggregate or log-based signals that the sender controls: click activity on consented links, delivery data at the SMTP level, complaint and unsubscribe events, and activity on the site or in purchases. Apple Mail Privacy Protection already pre-fetches pixels and makes opens less useful as an individual signal, so EU consent constraints speed up an existing shift away from automation based on opens.

## Member-state divergence (Fieldfisher "Email Marketing Across Europe," January 2024)

National implementations of ePrivacy differ on three points: whether B2B email is exempt from opt-in, whether the soft opt-in requires a completed **sale transaction** or only a commercial relationship (an enquiry or a quote), and whether **double opt-in** is expected as proof. Definitions: "opt-in" means an unambiguous positive action, and "soft opt-in" means the four conditions of Art. 13(2) (collected in the context of a sale; the same legal entity; similar products or services; free objection at collection and in every message). Email marketing by third parties ("partners") effectively requires an opt-in that names the sender, everywhere.

| Country | B2C (first-party) | B2B (first-party) | Soft opt-in: sale needed? | Notes |
|---|---|---|---|---|
| Austria | Double opt-in; soft opt-in available | Double opt-in; soft opt-in available | No | DOI should be used when relying on opt-in; national opt-out list (ECG-Liste) overrides soft opt-in |
| Belgium | Opt-in; soft opt-in available | Opt-in for individual B2B addresses; soft opt-in available | Yes | Royal Decree of 4 April 2003 |
| Bulgaria | Opt-in; soft opt-in available | Opt-in; soft opt-in available | No | |
| Croatia | Opt-in; soft opt-in available | **Opt-out** | Yes | |
| Cyprus | Opt-in; soft opt-in available | Opt-in | Yes | |
| Czech Republic | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | |
| Denmark | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | Marketing Practices Act art. 10 |
| Estonia | Opt-in; soft opt-in available | **Opt-out** | Yes | |
| Finland | Opt-in; soft opt-in available | Individualised address: opt-in; non-individualised or role-related: **opt-out** | Yes | |
| France | Opt-in; soft opt-in available | **Opt-out** | Yes | CPCE Art. L34-5; B2B allowed if message relates to the recipient's professional function |
| Germany | **Double opt-in** (proof standard); soft opt-in exists but rarely relied on | **Double opt-in**; no B2B exemption | Yes | See [Germany: UWG §7](https://emailmarketing.net/learn/compliance/germany-uwg-email) |
| Greece | Opt-in; soft opt-in available | Opt-in; soft opt-in available | No | Law 3471/2006 |
| Hungary | Opt-in; **no soft opt-in** | **Opt-out** | n/a | |
| Ireland | Opt-in; soft opt-in available | **Opt-out** if related to the recipient's professional role, else opt-in | Yes | S.I. 336/2011 |
| Italy | Opt-in; soft opt-in available (email only, not SMS) | Opt-in | Yes | |
| Latvia | Opt-in; soft opt-in available | **Opt-out** | Yes | |
| Lithuania | Opt-in; soft opt-in available (email only) | Opt-in; soft opt-in available | Yes | |
| Luxembourg | Opt-in; soft opt-in available | **Opt-out** | Yes | |
| Malta | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | |
| Netherlands | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | |
| Norway | Opt-in; soft opt-in available | Individualised address: opt-in; non-individualised: opt-out | Yes | Marketing Control Act 2009 |
| Poland | Opt-in; **no soft opt-in** | Opt-in | n/a | |
| Portugal | Opt-in; soft opt-in available | Individualised: opt-in; non-individualised: opt-out unless on the national opt-out list | Yes | National Opt-Out List updated monthly |
| Romania | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | |
| Slovakia | Opt-in; soft opt-in available | Opt-out where business contact details were made publicly available | Yes | |
| Slovenia | Opt-in; soft opt-in available | **Opt-out** | Yes | ZEKom-2 |
| Spain | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | LSSI Law 34/2002 |
| Sweden | Opt-in; soft opt-in available | **Opt-out** if related to the recipient's professional role, else opt-in | Yes | |
| Switzerland (non-EU) | Opt-in; **no soft opt-in** | Opt-in | n/a | Unfair Competition Act Art. 3(1)(o) |
| United Kingdom (non-EU) | Opt-in; soft opt-in available | **Opt-out** (corporate subscribers exempt) | No | See [UK PECR](https://emailmarketing.net/learn/compliance/uk-pecr-email-marketing) |

A practical reading for an ESP asked "can I email this EU list?": for lists that mix EU countries, treat the union of the rules as the baseline. **Opt-in, documented for each person, with a working unsubscribe in every message** satisfies every state. The soft opt-in is safe only within a single country, for first-party mail about similar products, with the offer to object at collection provably made. B2B exemptions are specific to each country and never cover sole traders, who are natural persons.

### Staying current

The table above is a snapshot from January 2024. Check two living references before relying on any row:

- **DLA Piper, *Data Protection Laws of the World*** (dlapiperdataprotection.com): 160+ jurisdictions, an "Electronic marketing" topic for each country, and side-by-side comparison. It is updated twice a year.
- **IAPP Global Privacy Directory** (iapp.org/resources/global-privacy-directory): 240 jurisdictions, with links to each data protection authority (DPA) and to the underlying legislation for the long tail.

## Deliverability relevance

The conditions of Art. 13 codify in law what mailbox providers reward anyway: addresses collected directly, a real commercial relationship, granular consent, an offer to object at collection, and an unsubscribe in every message ([consent methods](https://emailmarketing.net/learn/list-management/consent-methods), [foundations](https://emailmarketing.net/learn/foundations/foundations-of-email-deliverability)). The identity and valid-address requirements of 13(4) map to the sender transparency norms that every filter enforces. Law and deliverability diverge on consent for tracking: EU rules constrain the engagement telemetry that list hygiene driven by reputation assumes, so senders with mostly EU audiences should build sunset logic on clicks, conversions and complaints rather than on opens.
