Skip to content

Marketing automation

How to build an email list under GDPR?

Read the articleQuestions and answers

Article cover: How to build an email list under GDPR?
Building a mailing list in line with GDPR comes down to collecting email addresses on a clear legal basis, in a transparent and demonstrable way. In practice, the biggest problems stem from ambiguous consents, an incomplete information obligation and a lack of a trail showing where and when a given contact was added to the list. An additional challenge is the fact that GDPR compliance alone may not close the matter, because email marketing is also subject to rules on electronic communications, which usually require prior consent. A well-designed sign-up process (form, checkboxes, privacy policy, logs) works like insurance in the event of a complaint and limits the risk of sending to people who were not interested in the newsletter. This guide shows how to collect addresses from safe sources and how to organise roles, documentation and the minimum scope of data. Read on if you want to grow your subscriber list without “taking shortcuts” that are later hard to defend.

Building a mailing list in line with GDPR starts with determining who the data controller is and on what legal basis you process email addresses. The controller is the entity that decides on the purposes and means of processing data from the list (e.g. the company running the newsletter), while the mailing system provider usually acts as a processor on your instructions. Joint controllers appear when two parties jointly agree on the purposes and means, for example in a joint webinar campaign with one form and a shared list. Such an arrangement requires a joint controllership agreement that allocates information obligations, handling of requests and rules for storing proof of consent.

Marketing newsletter communications to individuals are most often based on consent (Article 6(1)(a) GDPR), because this is the safest option and usually matches recipients’ expectations. “Legitimate interest” is sometimes used in marketing to existing customers, but it requires a balancing test and a simple objection mechanism, and in Poland there are also the PKE requirements concerning marketing communications. In practice, even if GDPR would allow you to rely on legitimate interest, email marketing may still require prior consent for electronic communications. At the same time, apply the principle of data minimisation: usually an email address is enough, and a first name may be used solely for personalisation, while additional fields (e.g. phone number, job title, date of birth) should have a genuine justification in the processing purpose.

Operational compliance also requires your documentation to be in order and risks to be assessed properly. In the record of processing activities (ROPA), describe the purpose (sending the newsletter), categories of data (e.g. email, name, consent history), categories of recipients (e.g. ESP provider), transfers outside the EEA and the retention plan. A DPIA should be considered when you plan advanced profiling, lead scoring, combining data from multiple sources or automated decisions, because this increases the risk to individuals. For a standard newsletter, a DPIA is usually not required, but automations such as “behavioural triggers” carried out at scale may justify an additional analysis.

GDPR legal basis Legal basis for building a mailing list in line with GDPR
  1. 01Data controllerDecides on the purposes and means of processing.
  2. 02Processor role (e.g. mailing system)Acts on your instructions.
  3. 03Legal basis: consentArticle 6(1)(a) GDPR for the newsletter.

The safest option for a newsletter to individuals is based on explicit consent.

How to effectively collect email addresses in line with the rules

Email addresses are easiest and safest to collect through your own sign-up forms on the website, landing page or in the online store, because then you retain full control over the wording of the consent and the information clause. Next to the form, add a short information notice (who the controller is, the purpose, how to unsubscribe) and a link to the full privacy policy. In the sign-up copy, it is worth stating clearly what the user will receive and how often (e.g. “1–2 emails a week with tips and offers”), so the scope of consent is transparent. As anti-spam mechanisms, use solutions such as reCAPTCHA, Cloudflare Turnstile or a honeypot, instead of collecting additional data “just in case”.

Lead magnet (ebook, webinar) can be lawful, provided that you do not make marketing consent a condition for receiving the material when it is not necessary. A good practice is a separate checkbox for the newsletter, and to send the material itself as part of service fulfilment (delivery of the file) and transactional communication. Collecting contacts offline requires particular caution: slips of paper with email addresses are risky, because it is later difficult to prove exactly what someone agreed to, so a tablet with a form and checkbox is a better solution. If you receive business cards, do not treat them as automatic consent to the newsletter — send at most one email asking them to opt in, rather than launching a campaign straight away.

  • Do not buy mailing lists: they usually do not provide valid consent “for you” as the controller and they carry the risk of complaints, high spam rates and domain blocks (e.g. in Google Postmaster Tools).
  • When dealing with B2B contacts, remember that GDPR still applies, because an e-mail address often identifies a person, and marketing to work inboxes is subject to consent/marketing communication requirements.
  • Joint campaigns with a partner require consent that expressly names your company or clearly defines the category of partners and the sending purpose.
  • When migrating a database (e.g. from CRM to ESP), transfer not only the addresses, but also the consent history: sign-up date, source, version of the clause/checkbox, unsubscribe status and other metadata, so that you do not “resurrect” people who unsubscribed.
  • In checkout, separate the consents: the newsletter must not be pre-ticked by default or hidden in the terms and conditions, and transactional communication must not smuggle in marketing without a legal basis.

In practice, compliant acquisition is not just about the sign-up channel itself, but also about being able to demonstrate that the whole process was transparent. The biggest risk arises when you have an “address list”, but no consent history and you cannot show where a given contact came from. That is why you should tag acquisition sources and versions of the wording from the outset, and when importing data make sure you also handle unsubscribe statuses. If you work with partners or use lead acquisition platforms, make sure the consent wording matches what you will actually send and who the sender will be.

Forms and consent wording are crucial for compliance, because this is where you precisely determine who sends the newsletter, by which channel and what type of content will reach the subscriber. Consent must be freely given and specific, so the user should not be forced to sign up for marketing if the newsletter is not necessary to use the service (e.g. to download material). In practice, this means clearly identifying the controller (your company), the channel (e-mail) and the scope of content (e.g. tips and information about products and promotions). The safest pattern is an unticked checkbox by default and a clear sign-up button, because consent cannot result from inaction.

The consent wording should be short and understandable, while still stating the specifics: who is sending, what they are sending and how to opt out easily. An example wording that meets these requirements is: “I want to receive an e-mail newsletter from [Company name] with tips and information about products and promotions. I understand that I can withdraw my consent at any time (link in the footer).”. Avoid legal jargon and overly broad phrases such as “marketing of third parties” if you do not specify exactly who would be sending the communication. If you specify a particular sending frequency, it is worth describing it directly so that the user knows exactly what they are signing up for.

Compliance is also strengthened by separating consents, because a subscriber may only want the e-mail newsletter, and not, for example, SMS communication or additional data use. If you plan to personalise based on behaviour (opens, clicks) or combine data with advertising (e.g. audience matching), consider a separate consent or at least a very clear description of this purpose in the information clause. Do not combine marketing consent with the terms and conditions, because the terms and conditions relate to the contract (e.g. a purchase), whereas marketing is a separate purpose and such “hiding” makes it harder to demonstrate freely given consent. Next to the form, show a short version of the clause (controller, purpose, link to the full policy, unsubscribe information), and place the full information in the privacy policy, including, among other things, the legal basis, retention period, recipients and any transfers outside the EEA.

Blog architecture Forms and consent wording – key compliance elements
  1. 01Precise definitionWho sends, which channel and the scope of content.
  2. 02Voluntary consentUnforced, separated from another service.
  3. 03Clear mechanismUnticked checkbox and a clear button.

The consent wording must be short, understandable and include specifics: the controller, channel and scope of information, to ensure full compliance without guesswork.

Double opt-in helps maintain compliance because it makes it easier to demonstrate that a given person really wanted to join the list, even though GDPR does not explicitly require this mechanism. GDPR does, however, place emphasis on accountability, i.e. the obligation to prove that consent was given, and DOI operates as a practical standard that reduces the risk of adding someone without their knowledge. The correct process looks like this: sign-up in the form → confirmation e-mail → click the link → only then is the subscription activated. The confirmation e-mail should be strictly technical in nature and should not contain offers or advertisements.

Proof of consent must be complete and quickly exportable, so that in the event of a complaint or inspection the full sign-up trail can be reconstructed. Keep at least:

  • the date and time of sign-up and the source (URL/landing page),
  • the consent wording or checkbox version and the form ID,
  • the date of confirmation (in the case of double opt-in) and information about withdrawal of consent.

An IP address can be a useful piece of evidence, but if you collect it, assess whether it is justified and include it in the clause and in the retention rules. Versioning consents (e.g. a “consent_version” field or tag) matters, because you must be able to show exactly what wording the person agreed to on a specific day. Also make sure that your mailing system allows you to export subscription logs (subscribe/unsubscribe) in report form, because a lack of available logs makes it harder to defend compliance.

Single opt-in can be acceptable in closed processes (e.g. a customer account with a confirmed email address), but in practice it increases the risk of typos, third-party sign-ups and complaints. If you stick with single opt-in, strengthen the evidence trail through logs, confirmation in the user panel and, where appropriate, a “welcome” email with a clear unsubscribe message. After unsubscribing, do not delete the address immediately if this could lead to it being re-added from an import; instead, maintain a suppression list with the minimum scope of data needed to respect the opt-out. This approach helps maintain consistency of statuses during integrations and imports and reduces the risk of sending unwanted emails again.

Email content and operational requirements for sending

Every newsletter sent in line with the GDPR and marketing communication requirements should clearly identify the sender and include a working unsubscribe mechanism. In the footer, provide the company’s full name and contact details (e.g. an address or a link to contact details), so the recipient has no doubt who is behind the message. Avoid masking the sender’s identity and “no-reply” setups without a genuine alternative contact method, as this increases the risk of complaints and deliverability issues. A link to the privacy policy in the footer makes it easier to meet the transparency standard.

Unsubscribe should be as simple as possible, because opting out of a subscription is one of the key operational obligations in email marketing. Place the unsubscribe link in the footer and make it a one-click opt-out, without logging in and without requiring a reason. An additional “preference centre” (e.g. managing topics or frequency) can be useful, but it must not create barriers to unsubscribing. If you promised a specific frequency (e.g. 1 email per week), sending significantly more often may go beyond the scope of consent.

Base segmentation and personalisation on data you process lawfully, and describe this clearly in the privacy policy. In practice, you can use preferences from the settings centre, purchase history (for customers) and newsletter clicks; however, when building interest profiles, provide the ability to object to marketing profiling. Separate transactional communication from marketing communication: emails such as “Your order has been dispatched” should remain operational, while promotional elements require an appropriate legal basis. If you implement automations such as abandoned cart emails, ensure you have a legal basis and a clear description of the logic in the privacy policy, and the safest approach is to limit them to logged-in customers who have agreed to communication.

Tracking opens and clicks is also an operational element that must be disclosed, because it involves processing behavioural data. Many email systems use a tracking pixel and link tracking by default, so describe this in the privacy policy and indicate ways to limit it (e.g. via settings or by objecting to profiling). When you have “old” contacts without clear evidence of consent or with very old sign-ups, rather than continuing regular marketing it is better to run a re-permission campaign. In such an email, ask for an explicit confirmation of the wish to continue the subscription, and treat no response as no basis for further sends.

Operational email requirements Email content and operational requirements for sending
  1. 01Sender identificationFull name and details
  2. 02Real contactAvoid masking and "no-reply"
  3. 03Simple unsubscribeOne click, no login
  4. 04Privacy policyLink in the footer for transparency

Key: Ensure transparency, easy contact and a simple opt-out in the footer of every newsletter to build trust and avoid complaints.

Data management and retention – how to keep your database clean

You will keep your database clean if you implement a retention policy and consistently delete or block inactive contacts. Set clear criteria, e.g. retain active subscribers until they unsubscribe, and remove inactive ones (no opens/clicks) after 12–24 months. Describe retention rules in the privacy policy and set up automated cleaning or reactivation campaigns in the system. This reduces the risk of processing data “just in case” and helps maintain consistent practices over time.

Inactive recipients and incorrect addresses reduce processing quality, so it is worth implementing a regular cleaning and email validation process. A sequence of 2–3 reactivation emails usually makes it possible to identify who still wants to receive messages, after which you should remove that contact or block sending. To reduce typos and hard bounces, use syntax validation and tools such as ZeroBounce, NeverBounce or Bouncer, remembering the data processing agreement and any data transfers. Fewer incorrect addresses mean less data processed without purpose and a lower risk of sending to unintended recipients.

Keeping the database orderly also requires consistent source tagging and monitoring data flows between systems. Add fields or tags such as “source”, “campaign” and “form_id” (e.g. “webinar_2026_01”) so you can reliably answer the question “where did you get my address from?” and manage consent depending on the purpose. Restrict access within the company through roles and permissions (e.g. no export of the whole database for most users), and where possible enable additional account security measures such as 2FA. If you measure campaign performance, move to aggregated statistics (open rate, CTR), and store identifying data only to the extent needed for sending and for exercising data subject rights.

Consistency between retention and the exercise of data subjects’ rights is made easier by a suppression list and clearly described rules for handling backups. The suppression list (objection, unsubscribe, complaints) should block sending regardless of imports and integrations, and the stored identifier can remain minimal (e.g. email hash) together with the date of unsubscribe or objection. In your procedures, describe how you carry out data deletion in the context of backups: deletion from production is immediate, while deletion from backups takes place when copies are rotated (e.g. 30–90 days). This reduces the risk of deleted data “coming back” after restoration, while at the same time preserving the technical ability to respect the sending block.

Data subjects’ rights and handling requests – practical steps

You will exercise data subjects’ rights in line with the GDPR if you have a data export process in place and clear rules on who responds to requests and how. In practice, a person may ask for information about what data you store about them and how you use it, so it is worth being able to generate a package: email, name, tags, consent history and sending logs. Also define a method for verifying identity, for example by accepting the request and sending the response from the same email address to which the request relates. In this way you reduce the risk of disclosing data to the wrong person.

You carry out rectification and erasure correctly when you update or delete information across all systems in which it is used for email marketing. When a request to correct data is made (e.g. changing an email address or name), make sure the change is also applied in integrated source systems (CRM, store), so that the data does not “come back to life” after synchronisation. When consent is the basis for processing and it has been withdrawn, as a rule you stop processing the data for marketing purposes and delete the contact, retaining only the minimal scope needed to respect the objection (suppression list). If there is also a customer relationship in parallel (e.g. billing data), you do not delete data required by law, but separate the purposes of processing and the systems.

Restriction of processing, data portability and objection to marketing primarily require a robust sending block and efficient operational handling. Restriction in email marketing means, for example, “do not send, but do not delete”, so from a technical perspective a “unsubscribed/blocked” status or a tag such as “do_not_mail” is useful. You can implement the right to data portability by preparing a CSV file with the data provided by the individual (e.g. email, name, preferences), if you hold it. Objection to marketing must be respected without undue delay, even if the person has not clicked the unsubscribe link.

You will most easily secure deadlines and document requests if you keep a request log and have response procedures prepared. Standardly, you have 1 month to respond, and any extension requires justification and informing the person. Keep a log of requests (date received, scope, date completed), as this helps maintain order and demonstrates due diligence. In tools such as Zendesk, Freshdesk or Jira Service Management, you can use macros and checklists, and the key point is that the sending block should be activated at the very start of handling the objection, so that automations do not send a marketing email during that time.

Data security and incidents – how to prevent leaks

You prevent leaks most effectively when you secure both email marketing tools and files with data stored outside the system. Require providers to encrypt connections (TLS) and to encrypt data at rest on servers, if available. If you keep database exports locally, encrypt the disk (BitLocker/FileVault) and narrow access, because CSV files are often a source of incidents. This minimum genuinely reduces the risk of unauthorised data access.

You will maintain account security when you enable 2FA and implement a consistent password policy for ESPs, CRM and email inboxes. 2FA reduces the risk of account takeover, which could enable a mass export of the database or phishing distribution. Introduce rules such as using a password manager (e.g. 1Password, Bitwarden), avoiding shared accounts and immediately removing access when an employee leaves. This is particularly important in teams where marketing, sales and support log into the tools.

You will reduce the risk of unauthorised disclosure of the database by applying the principle of least privilege and secure procedures for working with exports. Not every person in the company should be able to export the entire database, so narrow this permission to 1–2 roles and log administrative operations (e.g. actions on integrations and lists). Do not send databases as attachments. Instead, use tools such as SharePoint/OneDrive with access control or encrypted archives, and transfer the password via a different channel. Also introduce rules such as link expiry and a record of who downloaded the file and for what purpose.

You will minimise the impact of operational incidents and breaches if you test changes on a small sample and have a response procedure ready. When implementing templates and automations, work on test lists (e.g. 10–20 addresses) and use blocks such as “TEST only” so you do not trigger a workflow across the entire database. If an incident occurs (e.g. a database leak or unauthorised export), carry out a risk assessment and, if necessary, report the matter to the UODO within 72 hours, and in the event of high risk inform the individuals as well, along with recommendations (e.g. vigilance against phishing). In addition, provide short training and configure alerts for logins from new locations and mass exports, and detect abuse also by monitoring sudden spikes in bounces and spam complaints and changes in domain reputation in Google Postmaster Tools.

FAQ

Frequently asked questions

How do you collect email addresses in line with GDPR and marketing rules?

The safest way is through your own signup forms, with clearly explained consent, an information notice and a link to the privacy policy. GDPR compliance alone is not always enough, because email marketing may also require prior consent for electronic communication.

Can a newsletter rely on legitimate interest rather than consent?

This is sometimes used for existing customers, but it requires a balancing test and a simple objection mechanism. In practice, for email marketing, additional consent requirements arising from electronic communication rules may still apply.

Why should the newsletter checkbox not be pre-ticked by default?

Because consent must be freely given and cannot result from user inaction. The safest approach is an unticked checkbox and a clear signup button.

When is double opt-in needed when building an email list?

GDPR does not explicitly require it, but it helps demonstrate that the person really wanted to join the list. It is a practical standard that reduces the risk of adding someone without their knowledge.

What should be kept as proof of newsletter consent?

At minimum, the date and time of signup, the source of the contact, the consent wording or checkbox version, and the confirmation date in the case of double opt-in. It is also worth keeping information about consent withdrawal and the form identifier.

How long can inactive contacts be kept in an email list?

The article states that active subscribers can be kept until they unsubscribe, while inactive ones should be removed after 12–24 months without opens or clicks. Retention rules are worth setting out in the privacy policy and backing up with automatic list cleaning.

Contents