Right to Object and Right to Erasure in Marketing Operations
How GDPR/UK GDPR objection, opt-out, consent withdrawal, and erasure requests interact with marketing lists and suppression — ICO operational guidance plus enforcement patterns from the EDPB one-stop-shop case digest (551 Art. 17 and 80 Art. 21 decisions).
Operational11 min read
Who it is for Compliance teams, ESP operators
ContentsOn this page — 6 sections
When someone asks you to stop marketing to them or to delete their data, what you must do depends on which right they are using. Under GDPR, UK GDPR and the ePrivacy rules, a recipient has four distinct ways to stop marketing: objection (GDPR Art. 21), opt-out or unsubscribe (the mechanism from the ePrivacy rules), withdrawal of consent (Art. 7(3)) and erasure (Art. 17). They differ in scope and in what the sender must then do with the data.
They also seem to conflict: honoring an opt-out forever means keeping the address, while erasure means deleting it. The suppression list resolves that conflict. The guidance below combines the operational guidance of the UK Information Commissioner's Office (ICO) with the enforcement record in the one-stop-shop case digest of the European Data Protection Board (EDPB). For how to build the suppression list itself (hashing, the legal basis for keeping it, suppression at the ESP level), see GDPR and Suppression Lists.
The right to object (Art. 21)
- For direct marketing purposes, the right is absolute. There are no exemptions and no grounds for refusal, it can be used at any time, and it covers profiling related to direct marketing, including inferring interests for targeting and disclosing data to third parties for marketing.
- For processing based on a public task or legitimate interests, objection is not absolute. The individual gives reasons tied to their situation, and the controller may continue only if it has compelling legitimate grounds that override the individual's interests, or for legal claims. Marketing based on legitimate interests still falls under the absolute rule for marketing.
- Duty to inform: the right to object must be brought to people's attention at the latest at the time of the first communication, clearly and separately from other information, and also at collection, under the right to be informed.
How to handle an objection (ICO)
| Aspect | Rule |
|---|---|
| Form | Spoken or written. Any part of the organisation can receive it, and no special wording is needed: "I ask for a guarantee that this will not repeat itself" counts |
| Deadline | Without undue delay, and at the latest one calendar month after receipt. The month runs from the day of receipt to the same date in the next month, or to the last day of the month if there is no such date, or to the next working day if that date falls on a weekend or holiday. Setting yourself a fixed 28-day deadline guarantees compliance |
| Extension | +2 months for complex or numerous requests. Tell the individual within the first month, with the reasons |
| Fee | None, except a reasonable administrative fee (or a refusal) for manifestly unfounded or excessive requests. Assess each case on its own, never through a blanket policy. Repeated requests are not automatically excessive |
| Identity checks | Only what is necessary and proportionate to confirm identity (for example, confirming the email address to be suppressed). See the digest below on demands for ID documents |
| Refusal | Only for unfounded or excessive requests, or under an exemption (never for objections to marketing). Within one month, tell the individual the reasons, their right to complain to the supervisory authority, and their right to a judicial remedy |
| Staff readiness | Train staff who deal with customers to recognise objections, and keep a log of spoken objections |
Objection, opt-out and withdrawal compared (ICO, "respect people's preferences")
- An opt-out or unsubscribe works like an objection limited to one channel or activity. In the ICO's example, a customer texts STOP. SMS marketing must stop, but email marketing may continue, because the customer did not opt out of that channel. Make clear at collection which channels an opt-out covers.
- Withdrawal of consent must be as easy as giving consent. Stop the marketing that the consent covered immediately, or as soon as possible. You must not switch to another lawful basis (for example, legitimate interests) to keep marketing after consent is withdrawn, because that would be unfair.
- No win-back after an objection. Contacting someone later to ask whether they have changed their mind is itself direct marketing to a person who objected. Their most recent indication applies. An objection is overridden only if they specifically withdraw it or later agree to marketing. Failing to opt out again never overrides it.
- Contact that is allowed: an immediate confirmation message after an unsubscribe (with instructions for subscribing again) is fine, as long as the opt-out takes effect without any further action. Reminders of preferences are allowed only as a minor, incidental addition to a message sent anyway for another purpose (for example, a line at the end of an annual statement), with no marketing content and no encouragement to change the choice.
Suppression lists
According to the ICO, the suppression list is the concept everything else depends on:
- When someone objects or opts out, suppress their data instead of deleting it. Keep just enough information to make sure their preference is respected, and mark it clearly so that it is not used for the purposes they objected to.
- A suppression list is not processing "for direct marketing purposes". It exists to comply with a legal obligation. This ends the circular argument that keeping an objector's address is itself unlawful marketing, and it means there is no automatic right to have one's entry on a suppression list erased.
- What goes wrong if you delete instead, in the ICO's example: a company deletes the phone number of someone who objected, later buys a list screened against the Telephone Preference Service (TPS) that still (lawfully) contains that number, and calls again. That breaches PECR, and a suppression screen would have prevented it. The same thing happens with email lists that are purchased or imported again.
- Data minimisation applies: keep only the minimum needed to suppress the address.
- A suppression list is not a screening list. Screening out people who do not fit a campaign is itself processing for direct marketing purposes. Only suppression for compliance gets the special status. (Other channels have statutory suppression registers: TPS and CTPS for calls, MPS for post.)
Erasure requests (Art. 17) in marketing
Erasure is not absolute. In marketing, it applies when consent is withdrawn, when the data is no longer needed for its purpose, or when the person has objected to marketing. The ICO's guidance:
- You do not have to treat a withdrawal or an objection automatically as a request for erasure. In practice, though, once you can no longer use the data you will probably delete it, except for the minimal suppression entry.
- The model case: a customer objects and asks for deletion. The company stops marketing and deletes everything apart from a small amount of data kept on its suppression list, and the customer's rights are satisfied. Erasure may also be refused for data needed for other purposes, in which case the data must be clearly marked as not for marketing use.
- Under Art. 17(1), when consent is withdrawn or an objection succeeds, the controller has an independent obligation to delete the data that is not suppressed. The data subject does not need to make a specific request for erasure (EDPB digest, citing EDPB Opinion 39/2021).
Enforcement patterns in the EDPB one-stop-shop case digest
The digest was written for the EDPB's Support Pool of Experts by Prof. Alessandro Mantelero (first version December 2022, updated May 2026). It analyses the final one-stop-shop decisions under Article 60 in the EDPB's public register: 551 decisions on Art. 17 and 80 on Art. 21, adopted from 2018 through January 2026.
Cases under Art. 17 peaked in 2022–2023, mostly led by the Irish authority (84 in 2022, 150 in 2023, 35 in 2024), and then declined. The number of cases under Art. 21 stayed flat. In practice the two rights arrive together: most Art. 21 cases concern direct marketing, often combined with a request to erase the data collected earlier. One German decision (DEBE:OSS:D:2018:9) holds that an objection to marketing triggers a deletion obligation under Art. 17(1)(c), to be applied "immediately".
Recurring findings that apply directly to running marketing systems:
Failures of design and information
- No information was given about the right to object, which violates Art. 13(2)(b) (ES:2021:263). A bank sent marketing emails with no opt-out option at registration, and preferences could only be changed inside its online banking service or through customer service (NO:2021:292, which led to a reprimand, ordered measures, and compliance with the deadlines of Art. 12(3)).
- No-reply sender addresses: if replies are impossible, the body of the email must say so clearly, and say that objections sent by reply will not work (FR:2019:8). On the other hand (NL:2022:376), the GDPR does not require that people can unsubscribe by replying, but marketing emails must include a clear link to a page where unsubscribing is possible.
- Unsubscribe links that lead to a customer account page do not work for prospects who have no account. A link that unsubscribes directly is required (FR:2020:84). Design the flows for exercising rights for every type of recipient you mail.
- Cumbersome procedures and language barriers: giving a contact address for rights requests, but replying automatically with a redirect to a "Contact us" form on a website, was itself a violation (FR:2022:326).
- Acknowledgment emails must state when the request will be carried out, and the outcome must be communicated (EE:2019:55; FR:2019:41).
Process failures
- Backlogs and a lack of capacity in customer service (NO:2021:292). An objection recorded against only one of several accounts the person held (EE:2019:55). Technical errors in systems that delayed compliance (CZ:2021:312). Databases that were not synchronised, and old contact addresses that nobody monitored (MT:2021:212: an automatic reply or forwarding is required when a contact address is retired; FR:2023:999: an old support address that still works and is still listed on the web must not go unread). Requests forwarded to the wrong department (UK:2019:31), and requests classified incorrectly.
- The controller answers for its employees' mistakes. Individual fault makes no difference to accountability under GDPR (DEBE:2021:184).
- Requests made manually or outside the usual channels must be treated in the same way as automated ones (SE:2021:178: a request sent by post missed the notifications that the digital system would have sent). Semi-automated intake that discards requests that do not follow the instructions is unlawful (DK:2020:151). However, informal requests (a tweet) may be disregarded when formal channels exist (SE:2021:276, confirmed by SE:2024:1550: every official channel of the controller must work, but requests sent to random or incorrect addresses need not be honored).
- Keep records of objection requests and their outcomes, for accountability.
Identity verification
- Demanding an official ID document by default is not acceptable, and it violates data minimisation (Art. 5(1)(c)). Examples are Groupon's blanket policy of requiring an ID card (IE:2020:166), and FR:2019:3 (an online customer relationship does not in itself create reasonable doubt). Authentication must be "relevant, appropriate and proportionate" to the data, the request, the context and the risk of disclosure (FR:2024:1286).
- Requests sent from the email address used at registration normally need no further proof (CY:2024:1120). Alternatives to ID documents include unique identifiers issued at registration, a policy of accepting only the email address linked to the account, password hotlines, online calls, and knowledge questions (nicknames, registration date; EE:2021:294). Where sharing an ID is justified, protect the transfer (NO:2024:1126: an ID card sent by unencrypted email).
- For objections specifically, the Swedish supervisory authority notes that there is normally no reason to authenticate the person objecting at all, and sometimes not even to identify them (SE:2025:1757).
- Controllers are expected to comply even if their process is imperfect. Continuing to process data after a valid erasure request infringes Art. 6(1), since the data could have been deleted at the time of the request.
Erasure in particular
- Most erasure cases come from objections to marketing (including unsolicited email; NO:2022:314) and from cleaning up unused accounts. Self-service deletion tools are highlighted because they reduce both errors and the workload of regulators.
- Proof of erasure: the controller must be able to show that it complied, for example with a screenshot showing that the database returns no result for the person who made the request (DE:2023:929).
- Tell the data subject what action was taken within the deadlines of Art. 12(3). When you grant the request, it is enough to state that erasure has started and how long it will take at most. You do not need to confirm completion unless the person asks (SE:2021:303).
- Overriding grounds can prevent erasure: keeping payment identifiers to prevent fraud (SE:2021:196); statutory retention periods (DK:2021:210, although keeping an active account for two years only because the person has the right to complain was unnecessary, since complaints can be made by email or phone); obligations under anti-money-laundering and banking law (MT:2022:340; MT:2021:272, where the specific legal source must be cited to the person making the request); debts; storage of passenger name records (PNR); and public registers. Legal obligations must be interpreted in line with the principles of data protection, not abused, and data beyond what the obligation requires must still be deleted ("intermediate storage" has limits; FR:2021:279, FR:2021:310).
- Most cases end in amicable settlements and reprimands. Fines are rare, and usually reflect wider infringements. It is common for controllers to comply of their own accord once a supervisory authority opens an investigation.
Operational checklist for a marketing platform
- Treat an unsubscribe as an objection on that channel: suppress the address immediately, apply the suppression to all of the recipient's accounts and records, and never require a login or an account.
- Send objections written in free text (replies, support tickets, phone calls) into the same suppression pipeline as link clicks. Train support staff, and log spoken requests.
- Acknowledge each request with a timeframe, complete it within one month, and confirm the outcome.
- When a marketing contact asks for erasure, delete the profile data, keep a minimal suppression entry, and be able to prove both (evidence of deletion and a suppression record).
- Do not demand ID documents by default. Treat requests sent from the subscribed address as proof of identity in themselves.
- Keep suppression permanent, and screen every list import against it, including imports of lists you already had and lists you bought.
- When you refuse erasure because of a retention obligation, cite the specific legal basis.
These duties match good deliverability practice. Unsubscribes that are instant and effortless reduce the spam complaints that drive reputation. One-click unsubscribe under RFC 8058, which Gmail, Yahoo and Microsoft require of bulk senders, is exactly the direct mechanism, with no account needed, that data protection authorities keep ordering senders to build.
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- CAN-SPAM Act (United States)
- CAN-SPAM Rulemaking (16 CFR Part 316)
- CASL — Canada's Anti-Spam Legislation
- Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail