GDPR Email Marketing Rules: What Rights Do Readers Have?
GDPR and electronic-marketing rules work together. GDPR requires a lawful basis to process personal data and gives you an absolute right to object to direct marketing (Article 21), erasure rights in defined circumstances (Article 17), and a rule that withdrawing consent must be as easy as giving it (Article 7(3)). Separate ePrivacy laws govern whether an email may be sent: in the UK, PECR normally requires consent for unsolicited marketing to an individual subscriber, unless a soft opt-in applies, while corporate subscribers are treated differently (ICO).
The accurate one-sentence version is: GDPR controls the use of personal data, ePrivacy rules control much of the sending channel, and your direct-marketing objection is an absolute off-switch.
What does the GDPR actually say about marketing email?
Four provisions do most of the work for readers. Everything else is commentary.
| Right | Where it lives | What it means for you |
|---|---|---|
| Lawful basis + channel rule | Article 6 plus national ePrivacy law | Personal-data processing needs a lawful basis; whether the email needs consent depends on the subscriber, jurisdiction, and any valid soft opt-in |
| Easy withdrawal | Article 7(3) | Unsubscribing must be as easy as subscribing was |
| Right to object | Article 21(2)–(3) | Say stop, and marketing must stop — no exceptions, no balancing test |
| Right to erasure | Article 17 | You can demand your data be deleted, not just suppressed |
The penalties are not decorative. Breaching consent conditions or data-subject rights sits in the top fine tier: up to €20 million or 4% of worldwide annual turnover, whichever is higher.
Why does opt-in consent matter so much?
Because when consent is the required route, it has to be real. Consent under GDPR is defined in Article 4(11) as "freely given, specific, informed and unambiguous," given by "a statement or by a clear affirmative action." Silence is not consent. A pre-ticked box is not consent. A vague "we may contact you" buried in terms is not consent — the ICO's consent guidance requires an active, specific choice, recorded and revocable.
Regulators enforce this literally. In January 2024 the ICO fined HelloFresh £140,000 over 79.8 million emails and 1.1 million texts sent under bundled and insufficiently informed consent language. France's CNIL fined Orange €50 million partly for displaying ads inside users' inboxes without consent, and later fined Google €325 million for ads inserted between Gmail messages without valid consent. The narrower lesson is not that consent is always the only lawful basis; it is that a sender choosing or required to use consent cannot manufacture it from ambiguity.
What is the GDPR right to object to marketing email?
The right to object is the reader's nuclear option, and it is the rare legal right with no counterargument built in. Article 21(2) lets you object to processing for direct marketing "at any time," including any profiling tied to that marketing. Article 21(3) then closes the door: once you object, your data "shall no longer be processed for such purposes."
Note what is missing. For most GDPR objections, the company can push back if it demonstrates "compelling legitimate grounds." For direct marketing, the ICO confirms there is no exception and no balancing test. You do not need a reason. You do not need to be polite about it. The objection wins automatically.
This matters because it applies regardless of the sender's lawful basis. A B2B sender relying on legitimate interest, a shop relying on the soft opt-in — the moment you object, the legal ground under their marketing evaporates.
Does unsubscribing really have to be as easy as subscribing?
Yes — that is the letter of the law, not a paraphrase. Article 7(3) says: "It shall be as easy to withdraw as to give consent." The European Commission's guidance adds that withdrawal must be possible at any time and cannot be made harder than the original signup. If you subscribed with one click, a three-page survey-guarded "preference center" is not compliant.
The engineering that makes "as easy as subscribing" literal is RFC 8058: the List-Unsubscribe and List-Unsubscribe-Post headers that let a mail client unsubscribe you with a single action, no login, no survey, no "are you sure." Google and Yahoo now require these headers from bulk senders — anyone sending more than 5,000 emails a day to their users — and require the request honored within two days. We wrote a full breakdown of how the mechanism works in one-click unsubscribe explained.
We build List-Unsubscribe parsing for a living. Flick (flicked.email) reads those RFC 8058 headers so that leaving a list takes one swipe — the same standard Gmail's native unsubscribe button uses. And because a header is a promise, not a guarantee, the Exit Gap Index grades real senders A–F on whether they actually honor the unsubscribe they advertise.
How is GDPR stricter than CAN-SPAM?
Structurally, not just numerically. The US CAN-SPAM Act is an opt-out law. European email marketing sits under two layers: GDPR requires a lawful basis for personal-data processing, while ePrivacy rules commonly require consent for unsolicited consumer email subject to specific exceptions. Calling GDPR itself a universal opt-in email law collapses those two layers and hides the exceptions.
| Question | GDPR (EU) | CAN-SPAM (US) |
|---|---|---|
| Consent before the first email? | Often for unsolicited consumer email under ePrivacy rules, but soft opt-ins and subscriber categories matter (ICO) | No — opt-out model (FTC guide) |
| Deadline to honor an opt-out | Marketing "shall no longer be processed" once you object (Art. 21(3)) | 10 business days |
| Can they demand more than an email address to opt out? | No — withdrawal as easy as consent (Art. 7(3)) | No — nothing beyond a reply or one webpage visit (FTC) |
| Right to have your data deleted | Yes (Art. 17) | No |
| Selling your address after you opt out | Prohibited processing | Prohibited |
| Maximum penalty | €20M or 4% of worldwide turnover | Up to $53,088 per email |
CAN-SPAM's per-email fines add up, and the FTC does use them. The European framework asks a prior question that CAN-SPAM usually does not: what lawful basis and channel permission justify this contact? The answer varies by jurisdiction and recipient type, but it comes before the unsubscribe.
Does "legitimate interest" let B2B senders skip consent?
Sometimes — and it is worth being honest about the carve-out rather than pretending the law is simpler than it is.
Recital 47 of the GDPR says processing for direct marketing "may be regarded as carried out for a legitimate interest" — the Article 6(1)(f) basis that does not require consent. But GDPR is only half the rulebook. Europe's ePrivacy rules (PECR in the UK) sit on top, and the ICO is blunt: where ePrivacy rules require consent for electronic marketing, legitimate interests cannot substitute for it.
The genuine B2B gap: UK PECR distinguishes individual from corporate subscribers. The ICO's current electronic-mail guidance says unsolicited marketing to individual subscribers needs consent or a valid soft opt-in, while corporate subscribers can be contacted without PECR consent. The sender must still identify itself and provide a valid unsubscribe address. Three honest caveats:
- A named person's work email is still personal data, so the sender still needs a GDPR lawful basis and must pass a legitimate-interest balancing test.
- The carve-out is jurisdiction-specific. The UK rule is not a safe shortcut for a campaign sent into every EU country.
- Article 21 still applies in full. Legitimate interest survives until you object. Then it doesn't.
So B2B legitimate interest is a real doctrine, not a loophole fantasy — but it is a narrow bridge with an absolute off-switch that you control.
The UK rules also changed recently. The Data (Use and Access) Act 2025 added a charitable-purpose soft opt-in to PECR regulation 22(3A); the ICO updated its guidance on April 28, 2026. Qualifying charities may now send electronic marketing without fresh consent only if they meet that exception's requirements. That is another reason to check the current channel rule instead of repeating "GDPR always requires opt-in."
Do these rights help readers outside the EU?
More than you would expect, for two reasons.
First, the law travels. Article 3 applies the GDPR to companies with no EU presence at all, whenever they offer goods or services to people in the EU or monitor their behaviour there. A US newsletter with EU subscribers is already inside the regulation.
Second, one list is cheaper than two. A global sender can either segment its audience by jurisdiction and maintain separate consent, retention, and unsubscribe logic for each — or apply the strictest standard to everyone. Given fine exposure of up to 4% of worldwide turnover, many choose one standard. When a sender builds GDPR-grade consent and one-click unsubscribe into its platform, readers in Ohio get the benefit alongside readers in Berlin. That is a structural tendency, not a legal guarantee — your rights as a non-EU reader depend on your own law — but it is why unsubscribe links got noticeably more functional once the regulation took effect.
What can you do when a sender ignores your rights?
In order of effort:
- Use the one-click unsubscribe first. For legitimate senders it works, and it is safe to use — the "never click unsubscribe" advice applies to obvious spam, not newsletters you once signed up for.
- Object explicitly. One sentence — "I object to processing of my data for direct marketing under Article 21 GDPR" — removes all legal wiggle room.
- Request erasure. Under Article 17, an objection to direct marketing is itself a ground for deletion, and the sender must respond within one month.
- Complain to a regulator. It is free, and it works: the ICO fined Flybe £70,000 for 3.3 million emails sent to people who had deliberately said no.
And if you want to know whether a sender honors unsubscribes before you invest the effort — that is precisely what the Exit Gap Index measures.
Stop reading your inbox. Start flicking it.
Flick turns every inbox into a finite swipe deck — archive, "no reply needed," or AI-draft → approve, one card at a time. Inbox flicked.
Try the live demo — no signup →FAQ
Does GDPR require an unsubscribe link in every marketing email?
GDPR requires that withdrawing consent be as easy as giving it, which in practice means a working, frictionless unsubscribe path in every message (Article 7(3)). On top of the law, Google and Yahoo require RFC 8058 one-click unsubscribe headers from bulk senders as a deliverability condition. A sender with no easy exit is failing both the regulator and the mailbox provider.
Can a sender make me log in or explain why before unsubscribing?
No — any step harder than the original signup breaks Article 7(3)'s "as easy to withdraw as to give" rule (GDPR text). Surveys, logins, and retention offers may appear after the unsubscribe is processed, but they cannot gate it. Even the more permissive US regime forbids demanding anything beyond a reply email or a single webpage visit.
Does the GDPR right to object apply to B2B emails sent under legitimate interest?
Yes — the Article 21 objection right is absolute for direct marketing and does not care which lawful basis the sender chose (ICO). Legitimate interest lets a B2B sender start the conversation without consent in some jurisdictions; it never lets them continue it after you object. One clear "stop" ends the legal argument.
Does GDPR apply to emails I get from US companies?
If the company offers goods or services to people in the EU, yes — Article 3 extends the GDPR to controllers with no EU establishment. If you live outside the EU, GDPR does not directly protect you, but global senders often apply one compliance standard to their whole list, so its mechanics — real consent, working unsubscribes — tend to reach you anyway.
How fast must a sender stop emailing after I unsubscribe?
Under GDPR there is no grace period to keep marketing: once you object, your data "shall no longer be processed" for marketing (Article 21(3)). Gmail and Yahoo require one-click unsubscribes honored within two days; US CAN-SPAM allows 10 business days. If emails continue past those windows, you are looking at a violation, not a delay.
This guide is educational information, not legal advice. GDPR and ePrivacy implementation varies by jurisdiction; use the linked regulator guidance or qualified counsel for a compliance decision.