emailmarketing.net

EU ePrivacy Directive + GDPR — Email Marketing

The EU opt-in rule for email marketing: ePrivacy Art. 13 and its soft opt-in, the GDPR consent standard per EDPB 05/2020, lawful basis (consent vs. legitimate interests), tracking pixels under Art. 5(3) per EDPB 2/2023, and the member-state divergence table.

Referencecompliancesender

Not legal advice. This is a reference digest of the directives, the regulation, and EDPB guidance for deliverability practitioners. Penalties, national implementations and guidance change; consult qualified counsel for compliance decisions.

Two instruments govern EU email marketing, and conflating them causes most confusion:

  • ePrivacy Directive 2002/58/EC (as amended by Directive 2009/136/EC) — the sending rule. Its Article 13 says when marketing email may be sent at all (prior consent, with one exception).
  • GDPR (Regulation 2016/679) — the processing rules. It defines what valid consent is (Art. 4(11), 7), supplies the lawful bases (Art. 6), and grants the absolute right to object to direct marketing (Art. 21(2)–(3)).

"GDPR requires consent for email marketing" is an oversimplification: the consent-to-send requirement comes from ePrivacy Art. 13, while the GDPR sets the quality standard that consent must meet (the EDPB confirms in Guidelines 05/2020 ¶7 that references to Directive 95/46/EC consent in the ePrivacy Directive are now read as GDPR consent, and that GDPR consent conditions apply in ePrivacy situations). Because ePrivacy is a directive, each member state implemented it in national law — with real divergences (see the table below). A proposed ePrivacy Regulation to replace the directive was negotiated for years and withdrawn by the Commission in early 2025; the 2002/2009 directive remains the law.

Article 13 — unsolicited communications

Key provisions (2002 text; the 2009 amendment extended protections to "subscribers or users" and added enforcement provisions, without changing the structure below):

  • 13(1) — prior consent. "The use of automated calling systems without human intervention…, facsimile machines (fax) or electronic mail for the purposes of direct marketing may only be allowed in respect of subscribers who have given their prior consent." Opt-in is the default rule.
  • 13(2) — the "soft opt-in" (existing-customer exception). Email marketing without consent is allowed only where all of the following hold:
    1. a natural or legal person obtains from its customers their electronic contact details for electronic mail,
    2. in the context of the sale of a product or a service (in accordance with data protection law),
    3. the same natural or legal person uses those details (not a group company, partner or list buyer),
    4. for direct marketing of its own similar products or services, and
    5. customers are clearly and distinctly given the opportunity to object, free of charge and in an easy manner, both when the details are collected and on the occasion of each message (provided the customer did not refuse initially).
  • 13(3) — for direct marketing by other means (e.g. postal, live calls), member states choose between opt-in and opt-out nationally.
  • 13(4) — regardless of consent, it is prohibited to send marketing email "disguising or concealing the identity of the sender on whose behalf the communication is made," or without a valid address to which the recipient may send a stop request. (The 2009 amendment added a prohibition on emails pointing to websites that violate e-commerce identity rules.)
  • 13(5) — paragraphs 1 and 3 protect natural persons; member states must also ensure the legitimate interests of legal persons (corporate subscribers) are "sufficiently protected" — which is why B2B treatment varies by country (see table).

"Electronic mail" (Art. 2(h)): "any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient." This covers email, SMS, voicemail, and (per regulators) in-app and social-media direct messages — the same breadth as the UK PECR definition, which is the UK implementation of this directive.

The GDPR consent standard (EDPB Guidelines 05/2020, v1.1, adopted 4 May 2020)

Art. 4(11): consent is "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." EDPB operationalization:

Element EDPB requirements
Freely given Real choice without detriment; consent bundled into T&Cs is presumed not free (Recital 43, Art. 7(4)); making a service conditional on consent to unnecessary processing ("tying") is presumed invalid and exceptions are "highly exceptional"; imbalance-of-power contexts (employer/employee, public authorities) usually defeat consent. Incentives are allowed if refusal/withdrawal costs nothing (losing a permissible perk ≠ detriment).
Specific + granular Separate consent per purpose ("granularity"): one checkbox covering both "email me marketing" and "share my details with group companies" is invalid (Example 7); purpose specification guards against function creep; new purpose → new consent.
Informed Minimum content: (i) controller's identity, (ii) purpose of each operation, (iii) what data, (iv) the right to withdraw, (v) automated decision-making where relevant, (vi) transfer risks where relevant. All controllers relying on the consent must be named; processors need not be. Clear plain language, separate and distinct from T&Cs — not buried in a privacy policy.
Unambiguous A statement or clear affirmative action. Pre-ticked boxes, silence, inactivity, or merely continuing to use a service are invalid; scrolling/swiping can never constitute consent (Example 16). Consent must precede the processing.
Demonstrable (Art. 7(1)) Burden of proof is on the controller. Keep enough data to show a link to the processing — e.g. session information, the consent workflow, and a copy of the information presented at the time; merely pointing to the current website configuration is insufficient (¶108). No statutory expiry, but the EDPB recommends refreshing consent at appropriate intervals; keep proof no longer than needed after processing ends.
Withdrawable (Art. 7(3)) As easy to withdraw as to give, at any time, free of charge, without service degradation. If consent was one click, withdrawal must be equally easy via the same electronic interface — a phone-only unsubscribe for an online signup violates Art. 7(3) (Example 22, music-festival ticket agent). After withdrawal, stop the processing and delete the data absent another lawful basis.

Two rules with direct list-management consequences:

  • No silent basis-swapping (¶¶121–123): a controller cannot fall back on legitimate interests when consent proves invalid or is withdrawn; the lawful basis must be decided and disclosed before collection.
  • Pre-GDPR consents (¶¶166–171): remain valid only if they already met the GDPR standard. Presumed consents with no records and pre-ticked-box consents "will automatically be below the consent standard" and had to be renewed or the processing stopped — the legal driver behind the 2018 wave of re-permission campaigns.

For children, Art. 8 sets the information-society-service consent age at 16, lowerable by member state to no less than 13.

Lawful basis: consent vs. legitimate interests

Under the GDPR alone, direct marketing processing may rest on consent (Art. 6(1)(a)) or legitimate interests (Art. 6(1)(f)) — Recital 47 states expressly: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." But legitimate interests cannot override ePrivacy Art. 13: for the act of sending email, only 13(1) consent or the 13(2) soft opt-in works. The stable pattern (mirrored in ICO guidance for UK PECR):

  • sending under Art. 13(1) consent → GDPR basis is consent;
  • sending under the Art. 13(2) soft opt-in → GDPR basis is usually legitimate interests, documented with a balancing assessment.

Either way, Art. 21(2)–(3) grants an absolute right to object to direct-marketing processing — "the personal data shall no longer be processed for such purposes," no balancing, no grounds required, free of charge (Recital 70). This is the legal root of the permanent suppression obligation.

Fines: infringements of the consent conditions and data-subject rights fall in the upper GDPR tier — up to €20 million or 4% of worldwide annual turnover, whichever is higher (Art. 83(5)); other controller/processor obligations up to €10M/2% (Art. 83(4)). ePrivacy penalties are set nationally and vary widely.

Tracking pixels and Art. 5(3) — EDPB Guidelines 2/2023 (v2.0, adopted 7 October 2024)

Art. 5(3) (as amended in 2009) requires prior consent, after clear and comprehensive information, for "the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user" — with two exemptions: technical storage/access for the sole purpose of carrying out transmission, and storage/access strictly necessary for a service explicitly requested by the user. The rule is technology-neutral (not just cookies) and applies to "information," not only personal data.

The EDPB's three applicability criteria: (A) the operation concerns information; (B) it involves terminal equipment connected or connectable to a public communications network; (C) it constitutes storage or gaining of access — which need not occur in the same communication nor be performed by the same party.

Email open/click tracking is squarely in scope (§3.1, ¶¶47–51):

  • A tracking pixel in an email exists to make the client establish a communication to the pixel host that would not otherwise occur, revealing when the email is read; it may carry per-recipient identifiers. Tracked links work the same way with the identifier appended to the URL.
  • Distributing pixels/links to the device "does constitute storage, at the very least through the caching mechanism of the client-side software… even if this storage is not permanent" (¶50).
  • The added tracking identifier "constitutes an instruction to the terminal equipment to send back the targeted information," i.e. a gaining of access (¶51).

Consequently the ESP's core engagement telemetry — opens via pixel, clicks via redirect with per-recipient tokens — requires Art. 5(3) consent in the EU unless an exemption applies (the EDPB analyzes scope only and leaves exemptions to national law and case-by-case assessment, ¶40, but neither exemption plausibly covers marketing analytics). Points of operational consequence:

  • Who obtains consent: the sender/controller (the ESP's customer), typically at signup alongside marketing consent — a granular, separately-consentable purpose per EDPB 05/2020.
  • The guidelines also bring IP-only tracking partly into scope (¶¶54–55) and note that the applicability of Art. 5(3) "does not systematically mean that consent needs to be collected" — the exemption analysis is separate (¶56).
  • Tension with deliverability practice: engagement-based sunset policies presume open/click data. Where pixel consent is absent, alternatives are aggregate/log-based signals the sender controls: click activity on consented links, SMTP-level delivery data, complaint and unsubscribe events, and site/purchase activity. Note that Apple Mail Privacy Protection already pre-fetches pixels and degrades opens as an individual signal, so EU consent constraints accelerate an existing shift away from open-based automation.

Member-state divergence (Fieldfisher "Email Marketing Across Europe," January 2024)

ePrivacy national implementations differ on three axes: whether B2B email is exempt from opt-in, whether the soft opt-in requires a completed sale transaction or a mere commercial relationship (enquiry/quote), and whether double opt-in is expected as proof. Definitions: Opt-in = unambiguous positive action; Soft opt-in = the four Art. 13(2) conditions (collected in the context of a sale; same legal entity; similar products/services; free objection at collection and in every message). Third-party ("partner") email marketing effectively requires opt-in naming the sender everywhere.

Country B2C (first-party) B2B (first-party) Soft opt-in: sale needed? Notes
Austria Double opt-in; soft opt-in available Double opt-in; soft opt-in available No DOI should be used when relying on opt-in; national opt-out list (ECG-Liste) overrides soft opt-in
Belgium Opt-in; soft opt-in available Opt-in for individual B2B addresses; soft opt-in available Yes Royal Decree of 4 April 2003
Bulgaria Opt-in; soft opt-in available Opt-in; soft opt-in available No
Croatia Opt-in; soft opt-in available Opt-out Yes
Cyprus Opt-in; soft opt-in available Opt-in Yes
Czech Republic Opt-in; soft opt-in available Opt-in; soft opt-in available Yes
Denmark Opt-in; soft opt-in available Opt-in; soft opt-in available Yes Marketing Practices Act art. 10
Estonia Opt-in; soft opt-in available Opt-out Yes
Finland Opt-in; soft opt-in available Individualised address: opt-in; non-individualised or role-related: opt-out Yes
France Opt-in; soft opt-in available Opt-out Yes CPCE Art. L34-5; B2B allowed if message relates to the recipient's professional function
Germany Double opt-in (proof standard); soft opt-in exists but rarely relied on Double opt-in — no B2B exemption Yes See Germany — UWG §7
Greece Opt-in; soft opt-in available Opt-in; soft opt-in available No Law 3471/2006
Hungary Opt-in; no soft opt-in Opt-out n/a
Ireland Opt-in; soft opt-in available Opt-out if related to the recipient's professional role, else opt-in Yes S.I. 336/2011
Italy Opt-in; soft opt-in available (email only, not SMS) Opt-in Yes
Latvia Opt-in; soft opt-in available Opt-out Yes
Lithuania Opt-in; soft opt-in available (email only) Opt-in; soft opt-in available Yes
Luxembourg Opt-in; soft opt-in available Opt-out Yes
Malta Opt-in; soft opt-in available Opt-in; soft opt-in available Yes
Netherlands Opt-in; soft opt-in available Opt-in; soft opt-in available Yes
Norway Opt-in; soft opt-in available Individualised address: opt-in; non-individualised: opt-out Yes Marketing Control Act 2009
Poland Opt-in; no soft opt-in Opt-in n/a
Portugal Opt-in; soft opt-in available Individualised: opt-in; non-individualised: opt-out unless on the national opt-out list Yes National Opt-Out List updated monthly
Romania Opt-in; soft opt-in available Opt-in; soft opt-in available Yes
Slovakia Opt-in; soft opt-in available Opt-out where business contact details were made publicly available Yes
Slovenia Opt-in; soft opt-in available Opt-out Yes ZEKom-2
Spain Opt-in; soft opt-in available Opt-in; soft opt-in available Yes LSSI Law 34/2002
Sweden Opt-in; soft opt-in available Opt-out if related to the recipient's professional role, else opt-in Yes
Switzerland (non-EU) Opt-in; no soft opt-in Opt-in n/a Unfair Competition Act Art. 3(1)(o)
United Kingdom (non-EU) Opt-in; soft opt-in available Opt-out (corporate subscribers exempt) No See UK PECR

Practical reading for an ESP advising "can I email this EU list?": treat the union of rules as the baseline for mixed-EU lists — opt-in, individually documented, with a working unsubscribe in every message satisfies every state; the soft opt-in is safe only single-country, first-party, similar-products, with the objection offer at collection provably made; B2B carve-outs are country-specific and never cover sole traders (who are natural persons).

Staying current

The table above is a January 2024 snapshot. Two living references to check before relying on any row:

  • DLA Piper, Data Protection Laws of the World (dlapiperdataprotection.com) — 160+ jurisdictions, an "Electronic marketing" topic per country, side-by-side comparison; updated twice per year.
  • IAPP Global Privacy Directory (iapp.org/resources/global-privacy-directory) — 240 jurisdictions; links to each DPA and the underlying legislation for the long tail.

Deliverability relevance

The Art. 13 conditions are a legal codification of what mailbox providers reward anyway: directly-collected addresses with a real commercial relationship, granular consent, an objection offer at collection, and an unsubscribe in every message (consent methods, foundations). The 13(4) identity and valid-address requirements map to sender-transparency norms every filter enforces. Where the law and deliverability diverge is tracking consent: EU rules constrain the engagement telemetry that reputation-driven list hygiene assumes, so EU-heavy senders should build sunset logic on clicks, conversions and complaints rather than opens.

#compliance#legal#eprivacy#gdpr#european-union#consent#soft-opt-in#tracking-pixels