EU ePrivacy Directive + GDPR — Email Marketing
The EU opt-in rule for email marketing: ePrivacy Art. 13 and its soft opt-in, the GDPR consent standard per EDPB 05/2020, lawful basis (consent vs. legitimate interests), tracking pixels under Art. 5(3) per EDPB 2/2023, and the member-state divergence table.
Not legal advice. This is a reference digest of the directives, the regulation, and EDPB guidance for deliverability practitioners. Penalties, national implementations and guidance change; consult qualified counsel for compliance decisions.
Two instruments govern EU email marketing, and conflating them causes most confusion:
- ePrivacy Directive 2002/58/EC (as amended by Directive 2009/136/EC) — the sending rule. Its Article 13 says when marketing email may be sent at all (prior consent, with one exception).
- GDPR (Regulation 2016/679) — the processing rules. It defines what valid consent is (Art. 4(11), 7), supplies the lawful bases (Art. 6), and grants the absolute right to object to direct marketing (Art. 21(2)–(3)).
"GDPR requires consent for email marketing" is an oversimplification: the consent-to-send requirement comes from ePrivacy Art. 13, while the GDPR sets the quality standard that consent must meet (the EDPB confirms in Guidelines 05/2020 ¶7 that references to Directive 95/46/EC consent in the ePrivacy Directive are now read as GDPR consent, and that GDPR consent conditions apply in ePrivacy situations). Because ePrivacy is a directive, each member state implemented it in national law — with real divergences (see the table below). A proposed ePrivacy Regulation to replace the directive was negotiated for years and withdrawn by the Commission in early 2025; the 2002/2009 directive remains the law.
Article 13 — unsolicited communications
Key provisions (2002 text; the 2009 amendment extended protections to "subscribers or users" and added enforcement provisions, without changing the structure below):
- 13(1) — prior consent. "The use of automated calling systems without human intervention…, facsimile machines (fax) or electronic mail for the purposes of direct marketing may only be allowed in respect of subscribers who have given their prior consent." Opt-in is the default rule.
- 13(2) — the "soft opt-in" (existing-customer exception). Email marketing without consent is allowed only where all of the following hold:
- a natural or legal person obtains from its customers their electronic contact details for electronic mail,
- in the context of the sale of a product or a service (in accordance with data protection law),
- the same natural or legal person uses those details (not a group company, partner or list buyer),
- for direct marketing of its own similar products or services, and
- customers are clearly and distinctly given the opportunity to object, free of charge and in an easy manner, both when the details are collected and on the occasion of each message (provided the customer did not refuse initially).
- 13(3) — for direct marketing by other means (e.g. postal, live calls), member states choose between opt-in and opt-out nationally.
- 13(4) — regardless of consent, it is prohibited to send marketing email "disguising or concealing the identity of the sender on whose behalf the communication is made," or without a valid address to which the recipient may send a stop request. (The 2009 amendment added a prohibition on emails pointing to websites that violate e-commerce identity rules.)
- 13(5) — paragraphs 1 and 3 protect natural persons; member states must also ensure the legitimate interests of legal persons (corporate subscribers) are "sufficiently protected" — which is why B2B treatment varies by country (see table).
"Electronic mail" (Art. 2(h)): "any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient." This covers email, SMS, voicemail, and (per regulators) in-app and social-media direct messages — the same breadth as the UK PECR definition, which is the UK implementation of this directive.
The GDPR consent standard (EDPB Guidelines 05/2020, v1.1, adopted 4 May 2020)
Art. 4(11): consent is "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." EDPB operationalization:
| Element | EDPB requirements |
|---|---|
| Freely given | Real choice without detriment; consent bundled into T&Cs is presumed not free (Recital 43, Art. 7(4)); making a service conditional on consent to unnecessary processing ("tying") is presumed invalid and exceptions are "highly exceptional"; imbalance-of-power contexts (employer/employee, public authorities) usually defeat consent. Incentives are allowed if refusal/withdrawal costs nothing (losing a permissible perk ≠ detriment). |
| Specific + granular | Separate consent per purpose ("granularity"): one checkbox covering both "email me marketing" and "share my details with group companies" is invalid (Example 7); purpose specification guards against function creep; new purpose → new consent. |
| Informed | Minimum content: (i) controller's identity, (ii) purpose of each operation, (iii) what data, (iv) the right to withdraw, (v) automated decision-making where relevant, (vi) transfer risks where relevant. All controllers relying on the consent must be named; processors need not be. Clear plain language, separate and distinct from T&Cs — not buried in a privacy policy. |
| Unambiguous | A statement or clear affirmative action. Pre-ticked boxes, silence, inactivity, or merely continuing to use a service are invalid; scrolling/swiping can never constitute consent (Example 16). Consent must precede the processing. |
| Demonstrable (Art. 7(1)) | Burden of proof is on the controller. Keep enough data to show a link to the processing — e.g. session information, the consent workflow, and a copy of the information presented at the time; merely pointing to the current website configuration is insufficient (¶108). No statutory expiry, but the EDPB recommends refreshing consent at appropriate intervals; keep proof no longer than needed after processing ends. |
| Withdrawable (Art. 7(3)) | As easy to withdraw as to give, at any time, free of charge, without service degradation. If consent was one click, withdrawal must be equally easy via the same electronic interface — a phone-only unsubscribe for an online signup violates Art. 7(3) (Example 22, music-festival ticket agent). After withdrawal, stop the processing and delete the data absent another lawful basis. |
Two rules with direct list-management consequences:
- No silent basis-swapping (¶¶121–123): a controller cannot fall back on legitimate interests when consent proves invalid or is withdrawn; the lawful basis must be decided and disclosed before collection.
- Pre-GDPR consents (¶¶166–171): remain valid only if they already met the GDPR standard. Presumed consents with no records and pre-ticked-box consents "will automatically be below the consent standard" and had to be renewed or the processing stopped — the legal driver behind the 2018 wave of re-permission campaigns.
For children, Art. 8 sets the information-society-service consent age at 16, lowerable by member state to no less than 13.
Lawful basis: consent vs. legitimate interests
Under the GDPR alone, direct marketing processing may rest on consent (Art. 6(1)(a)) or legitimate interests (Art. 6(1)(f)) — Recital 47 states expressly: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." But legitimate interests cannot override ePrivacy Art. 13: for the act of sending email, only 13(1) consent or the 13(2) soft opt-in works. The stable pattern (mirrored in ICO guidance for UK PECR):
- sending under Art. 13(1) consent → GDPR basis is consent;
- sending under the Art. 13(2) soft opt-in → GDPR basis is usually legitimate interests, documented with a balancing assessment.
Either way, Art. 21(2)–(3) grants an absolute right to object to direct-marketing processing — "the personal data shall no longer be processed for such purposes," no balancing, no grounds required, free of charge (Recital 70). This is the legal root of the permanent suppression obligation.
Fines: infringements of the consent conditions and data-subject rights fall in the upper GDPR tier — up to €20 million or 4% of worldwide annual turnover, whichever is higher (Art. 83(5)); other controller/processor obligations up to €10M/2% (Art. 83(4)). ePrivacy penalties are set nationally and vary widely.
Tracking pixels and Art. 5(3) — EDPB Guidelines 2/2023 (v2.0, adopted 7 October 2024)
Art. 5(3) (as amended in 2009) requires prior consent, after clear and comprehensive information, for "the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user" — with two exemptions: technical storage/access for the sole purpose of carrying out transmission, and storage/access strictly necessary for a service explicitly requested by the user. The rule is technology-neutral (not just cookies) and applies to "information," not only personal data.
The EDPB's three applicability criteria: (A) the operation concerns information; (B) it involves terminal equipment connected or connectable to a public communications network; (C) it constitutes storage or gaining of access — which need not occur in the same communication nor be performed by the same party.
Email open/click tracking is squarely in scope (§3.1, ¶¶47–51):
- A tracking pixel in an email exists to make the client establish a communication to the pixel host that would not otherwise occur, revealing when the email is read; it may carry per-recipient identifiers. Tracked links work the same way with the identifier appended to the URL.
- Distributing pixels/links to the device "does constitute storage, at the very least through the caching mechanism of the client-side software… even if this storage is not permanent" (¶50).
- The added tracking identifier "constitutes an instruction to the terminal equipment to send back the targeted information," i.e. a gaining of access (¶51).
Consequently the ESP's core engagement telemetry — opens via pixel, clicks via redirect with per-recipient tokens — requires Art. 5(3) consent in the EU unless an exemption applies (the EDPB analyzes scope only and leaves exemptions to national law and case-by-case assessment, ¶40, but neither exemption plausibly covers marketing analytics). Points of operational consequence:
- Who obtains consent: the sender/controller (the ESP's customer), typically at signup alongside marketing consent — a granular, separately-consentable purpose per EDPB 05/2020.
- The guidelines also bring IP-only tracking partly into scope (¶¶54–55) and note that the applicability of Art. 5(3) "does not systematically mean that consent needs to be collected" — the exemption analysis is separate (¶56).
- Tension with deliverability practice: engagement-based sunset policies presume open/click data. Where pixel consent is absent, alternatives are aggregate/log-based signals the sender controls: click activity on consented links, SMTP-level delivery data, complaint and unsubscribe events, and site/purchase activity. Note that Apple Mail Privacy Protection already pre-fetches pixels and degrades opens as an individual signal, so EU consent constraints accelerate an existing shift away from open-based automation.
Member-state divergence (Fieldfisher "Email Marketing Across Europe," January 2024)
ePrivacy national implementations differ on three axes: whether B2B email is exempt from opt-in, whether the soft opt-in requires a completed sale transaction or a mere commercial relationship (enquiry/quote), and whether double opt-in is expected as proof. Definitions: Opt-in = unambiguous positive action; Soft opt-in = the four Art. 13(2) conditions (collected in the context of a sale; same legal entity; similar products/services; free objection at collection and in every message). Third-party ("partner") email marketing effectively requires opt-in naming the sender everywhere.
| Country | B2C (first-party) | B2B (first-party) | Soft opt-in: sale needed? | Notes |
|---|---|---|---|---|
| Austria | Double opt-in; soft opt-in available | Double opt-in; soft opt-in available | No | DOI should be used when relying on opt-in; national opt-out list (ECG-Liste) overrides soft opt-in |
| Belgium | Opt-in; soft opt-in available | Opt-in for individual B2B addresses; soft opt-in available | Yes | Royal Decree of 4 April 2003 |
| Bulgaria | Opt-in; soft opt-in available | Opt-in; soft opt-in available | No | |
| Croatia | Opt-in; soft opt-in available | Opt-out | Yes | |
| Cyprus | Opt-in; soft opt-in available | Opt-in | Yes | |
| Czech Republic | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | |
| Denmark | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | Marketing Practices Act art. 10 |
| Estonia | Opt-in; soft opt-in available | Opt-out | Yes | |
| Finland | Opt-in; soft opt-in available | Individualised address: opt-in; non-individualised or role-related: opt-out | Yes | |
| France | Opt-in; soft opt-in available | Opt-out | Yes | CPCE Art. L34-5; B2B allowed if message relates to the recipient's professional function |
| Germany | Double opt-in (proof standard); soft opt-in exists but rarely relied on | Double opt-in — no B2B exemption | Yes | See Germany — UWG §7 |
| Greece | Opt-in; soft opt-in available | Opt-in; soft opt-in available | No | Law 3471/2006 |
| Hungary | Opt-in; no soft opt-in | Opt-out | n/a | |
| Ireland | Opt-in; soft opt-in available | Opt-out if related to the recipient's professional role, else opt-in | Yes | S.I. 336/2011 |
| Italy | Opt-in; soft opt-in available (email only, not SMS) | Opt-in | Yes | |
| Latvia | Opt-in; soft opt-in available | Opt-out | Yes | |
| Lithuania | Opt-in; soft opt-in available (email only) | Opt-in; soft opt-in available | Yes | |
| Luxembourg | Opt-in; soft opt-in available | Opt-out | Yes | |
| Malta | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | |
| Netherlands | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | |
| Norway | Opt-in; soft opt-in available | Individualised address: opt-in; non-individualised: opt-out | Yes | Marketing Control Act 2009 |
| Poland | Opt-in; no soft opt-in | Opt-in | n/a | |
| Portugal | Opt-in; soft opt-in available | Individualised: opt-in; non-individualised: opt-out unless on the national opt-out list | Yes | National Opt-Out List updated monthly |
| Romania | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | |
| Slovakia | Opt-in; soft opt-in available | Opt-out where business contact details were made publicly available | Yes | |
| Slovenia | Opt-in; soft opt-in available | Opt-out | Yes | ZEKom-2 |
| Spain | Opt-in; soft opt-in available | Opt-in; soft opt-in available | Yes | LSSI Law 34/2002 |
| Sweden | Opt-in; soft opt-in available | Opt-out if related to the recipient's professional role, else opt-in | Yes | |
| Switzerland (non-EU) | Opt-in; no soft opt-in | Opt-in | n/a | Unfair Competition Act Art. 3(1)(o) |
| United Kingdom (non-EU) | Opt-in; soft opt-in available | Opt-out (corporate subscribers exempt) | No | See UK PECR |
Practical reading for an ESP advising "can I email this EU list?": treat the union of rules as the baseline for mixed-EU lists — opt-in, individually documented, with a working unsubscribe in every message satisfies every state; the soft opt-in is safe only single-country, first-party, similar-products, with the objection offer at collection provably made; B2B carve-outs are country-specific and never cover sole traders (who are natural persons).
Staying current
The table above is a January 2024 snapshot. Two living references to check before relying on any row:
- DLA Piper, Data Protection Laws of the World (dlapiperdataprotection.com) — 160+ jurisdictions, an "Electronic marketing" topic per country, side-by-side comparison; updated twice per year.
- IAPP Global Privacy Directory (iapp.org/resources/global-privacy-directory) — 240 jurisdictions; links to each DPA and the underlying legislation for the long tail.
Deliverability relevance
The Art. 13 conditions are a legal codification of what mailbox providers reward anyway: directly-collected addresses with a real commercial relationship, granular consent, an objection offer at collection, and an unsubscribe in every message (consent methods, foundations). The 13(4) identity and valid-address requirements map to sender-transparency norms every filter enforces. Where the law and deliverability diverge is tracking consent: EU rules constrain the engagement telemetry that reputation-driven list hygiene assumes, so EU-heavy senders should build sunset logic on clicks, conversions and complaints rather than opens.
Sources
- https://eur-lex.europa.eu/eli/dir/2002/58/oj?locale=en
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
- https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en
- https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en
- https://www.fieldfisher.com/en/insights/eu-e-marketing-requirements
- https://www.dlapiperdataprotection.com/?t=electronic-marketing
- https://iapp.org/resources/global-privacy-directory