Blog

How does GDPR impact the way we send email marketing?

Welcome to part 3 of our email marketing blog series.

If you haven’t read the first two posts yet, we highly recommend you start at the beginning otherwise this may not make sense! 

Last time we looked at PECR – do you remember what it stands for?

Yes – Privacy & Electronic Communications Regulations 2003, well remembered!!

In our scenario, we discovered that All Things Stationery do not need to comply with PECR for ‘corporate subscribers’ and they can rely on the soft opt rule for their individual subscribers.

Now we’ve established that we need to look at what they need to do to comply with GDPR.

The first thing to remember is:

If you can identify someone, either directly or indirectly, then you are processing personal data and GDPR therefore applies. 

Let’s go back to our scenario.

All Things Stationery hold personal data about individuals because they have someone’s email address, and they want to send marketing emails to that person.

If that email address identifies someone by name, e.g. firstname.lastname@company.com then they are processing personal data. This is true even if the individual is acting in a professional capacity. So if we look back at our last blog on PECR, it doesn’t matter if the person is an individual or corporate subscriber, if they can be identified, GDPR applies.

It’s worth noting that if you don’t know the name of who you are sending your email marketing to, then you are NOT processing personal data and so GDPR does NOT apply, e.g. info@companyname.com

What do you need to do if you are collecting an individual’s personal data for direct marketing?

You must:

  • make them aware of this (otherwise known as your Privacy Notice); and
  • you must have a lawful basis for the processing.

Not sure if your Privacy Notice is up to scratch? Check out our 2 part blog which takes you through what you need and how to write your Privacy Notice.

GDPR Principles

There are a set of rules at the heart of UK GDPR, known as Principles, that you must comply with.

Principle 1 of GDPR tells us that “we must process personal data of an individual in a lawful, fair and transparent way”. 

This means we must identify a lawful ground to undertake the processing of the personal data.

UK GDPR gives us 6 lawful grounds to choose from which are:

  • Consent
  • Contractual obligation
  • Legal obligation
  • Vital interests
  • Public task
  • Legitimate interests

Now we have those, we need to decide which are the most appropriate to rely on for the activity of sending marketing by email.

Do you know which ones they are?

For direct marketing purposes you really only have a choice of 2 lawful grounds to rely on:

  • Consent
  • Legitimate Interest

Neither of these are an ‘easy option’ as both require work from you.

Which one we use also depends on what PECR allows you to do – see our last post for a refresh!

If PECR requires you to obtain consent to send direct marketing then your legal basis under GDPR must also be consent. 

You are not allowed to legitimise the processing under one law if it is unlawful to do so under another law.

What does that mean?

Basically, you cannot rely on legitimate interest under GDPR as your lawful ground for processing data if PECR dictates that you must get the consent of the individual.  

On the other hand, if you do not need consent under PECR because it is a “corporate subscriber” or you can rely on the soft opt-in rule, your lawful ground for processing under GDPR can be legitimate interest.

We’re not able to go into the difference between consent and legitimate interest and what you must do to comply with them in this post – the purpose of these blogs is to simplify things and not bamboozle you with another 3000+ words!! That could well be another post later down the line, so keep your eyes peeled.

That said, a key point to note when it comes to deciding which lawful ground to choose from, if you have the choice, is to think about it from your brand reputation and customer relationship point of view.

  • Consent – do you want to have customers who really want to know about you and are actively engaging with you; or
  • Legitimate Interest – do you want to market far and wide in the hope of reaching an additional few people?

Even if PECR does not require you to obtain consent, you can still choose to rely on consent for direct marketing. Some businesses prefer to use consent regardless in order to give the individual full choice in how their data is being used. Plus the ICO* has quite a strong opinion on this as they believe this is best practice for businesses.

However, as we said, you are not obliged by GDPR to only use consent for direct marketing if PECR allows, that is your choice.

Now it’s crunch time for All Things Stationery

What do you think they need to do to comply with GDPR?

We know that they can rely on soft opt in under PECR for their individual subscribers as they have met the 5 requirements of soft opt in and that they don’t need to comply with PECR for their corporate subscribers.

This means All Things Stationery can legitimise the processing of data for their email marketing under GDPR by relying on the Legitimate Interest lawful ground as they do not need to obtain consent under PECR. 

Those are the rules that you need to follow when it comes to sending marketing communications by email.

To help us understand this more, next time we will be looking at what happens if we don’t follow these rules.

What happens if we don’t comply with the laws?


As mentioned in our previous blog posts, we are applying UK data protection laws only as All Things Stationery only sells their products to businesses in the UK.  If you market to the EU or internationally you also have to comply with the domestic data protection and e-privacy laws applicable in the countries you specifically target. They do have different rules, so do be careful if you undertake marketing to customers or businesses in other countries.

Need a re-cap of the terminology used in GDPR & PECR, head to our blog here: Understanding the terminology used in GDPR & PECR

*Information Commissioners Office (ICO) is the UK Regulator that oversees and enforces how businesses comply with data protection laws. ALL businesses must be registered with the ICO, to find out more visit: https://ico.org.uk/for-organisations/data-protection-fee/register/