Guide

GDPR Email Marketing Rules: What Rights Do Readers Have?

GDPR and electronic-marketing rules work together. GDPR requires a lawful basis to process personal data and gives you an absolute right to object to direct marketing (Article 21), erasure rights in defined circumstances (Article 17), and a rule that withdrawing consent must be as easy as giving it (Article 7(3)). Separate ePrivacy laws govern whether an email may be sent: in the UK, PECR normally requires consent for unsolicited marketing to an individual subscriber, unless a soft opt-in applies, while corporate subscribers are treated differently (ICO).

Verification note: This is a documentary guide checked against current sources on August 3, 2026. We did not hands-on test the named product or workflow during this review, so claims are limited to the cited documentation. Interfaces can vary by account, region, rollout, and app version.

The accurate one-sentence version is: GDPR controls the use of personal data, ePrivacy rules control much of the sending channel, and your direct-marketing objection is an absolute off-switch.

What does the GDPR actually say about marketing email?

Four provisions do most of the work for readers. Everything else is commentary.

Right Where it lives What it means for you
Lawful basis + channel rule Article 6 plus national ePrivacy law Personal-data processing needs a lawful basis; whether the email needs consent depends on the subscriber, jurisdiction, and any valid soft opt-in
Easy withdrawal Article 7(3) Unsubscribing must be as easy as subscribing was
Right to object Article 21(2)–(3) Say stop, and marketing must stop — no exceptions, no balancing test
Right to erasure Article 17 You can request erasure when an Article 17 ground applies; statutory exceptions and necessary suppression records can limit what is deleted

The penalties are not decorative. Breaching consent conditions or data-subject rights sits in the top fine tier: up to €20 million or 4% of worldwide annual turnover, whichever is higher.

Because when consent is the required route, it has to be real. Consent under GDPR is defined in Article 4(11) as "freely given, specific, informed and unambiguous," given by "a statement or by a clear affirmative action." Silence is not consent. A pre-ticked box is not consent. A vague "we may contact you" buried in terms is not consent — the ICO's consent guidance requires an active, specific choice, recorded and revocable.

Regulators enforce this literally. In January 2024 the ICO fined HelloFresh £140,000 over 79.8 million emails and 1.1 million texts sent under bundled and insufficiently informed consent language. France's CNIL fined Orange €50 million partly for displaying ads inside users' inboxes without consent, and later fined Google €325 million for ads inserted between Gmail messages without valid consent. The narrower lesson is not that consent is always the only lawful basis; it is that a sender choosing or required to use consent cannot manufacture it from ambiguity.

What is the GDPR right to object to marketing email?

The right to object is the reader's nuclear option, and it is the rare legal right with no counterargument built in. Article 21(2) lets you object to processing for direct marketing "at any time," including any profiling tied to that marketing. Article 21(3) then closes the door: once you object, your data "shall no longer be processed for such purposes."

Note what is missing. For most GDPR objections, the company can push back if it demonstrates "compelling legitimate grounds." For direct marketing, the ICO confirms there is no exception and no balancing test. You do not need a reason. You do not need to be polite about it. The objection wins automatically.

This matters because it applies regardless of the sender's lawful basis. A B2B sender relying on legitimate interest, a shop relying on the soft opt-in — the moment you object, the legal ground under their marketing evaporates.

Does unsubscribing really have to be as easy as subscribing?

When consent is the processing basis, Article 7(3) says: "It shall be as easy to withdraw as to give consent." The European Commission's guidance adds that withdrawal must be possible at any time and cannot be made harder than the original signup. If consent was given with one simple action, a mandatory three-page survey or preference-center maze is strong evidence that withdrawal has been made harder; a legal conclusion still depends on the actual consent and withdrawal flows. Our unsubscribe dark-pattern guide separates interface evidence from legal conclusions.

The engineering that can make withdrawal a single action is RFC 8058: List-Unsubscribe-Post signals an HTTPS POST to the URI declared in List-Unsubscribe, without a login, survey, or confirmation page. Google requires RFC 8058 support for covered marketing and subscribed mail from senders sending more than 5,000 messages a day to personal Gmail accounts and says subscription opt-outs must be processed within 48 hours. Yahoo's bulk-sender rule requires a functioning List-Unsubscribe route, highly recommends the RFC 8058 POST method but also accepts mailto, and sets the same two-day processing window. We wrote a full breakdown in one-click unsubscribe explained.

We build List-Unsubscribe parsing for a living. Flick (flicked.email) reads the advertised RFC 2369 route and uses RFC 8058 POST when the one-click signal is present. A header is a capability signal, not a guarantee, which is why it would be misleading to treat Flick's four current capability-only observations as compliance results. The Exit Gap page has 150 senders queued and zero published honor grades as of August 3, 2026. An honor result requires at least three probes across at least 48 hours with preserved evidence; the dedicated burner-mailbox observation cycle has not run.

How is GDPR stricter than CAN-SPAM?

Structurally, not just numerically. The US CAN-SPAM Act is an opt-out law. European email marketing sits under two layers: GDPR requires a lawful basis for personal-data processing, while ePrivacy rules commonly require consent for unsolicited consumer email subject to specific exceptions. Calling GDPR itself a universal opt-in email law collapses those two layers and hides the exceptions.

Question GDPR (EU) CAN-SPAM (US)
Consent before the first email? Often for unsolicited consumer email under ePrivacy rules, but soft opt-ins and subscriber categories matter (ICO) No — opt-out model (FTC guide)
Deadline to honor an opt-out Marketing "shall no longer be processed" once you object (Art. 21(3)) 10 business days
Can they demand more than an email address to opt out? Withdrawal cannot be harder than giving consent; any identity check must be proportionate to the original context (Art. 7(3)) No — nothing beyond a reply or one webpage visit (FTC)
Right to have your data deleted A qualified right with grounds and exceptions (Art. 17) No general CAN-SPAM erasure right
Using or sharing your address for more direct marketing after an objection The direct-marketing processing must stop; retaining a minimal suppression record can still be necessary CAN-SPAM generally bars transferring an opted-out address, except to an entity helping the sender comply (FTC)
Maximum penalty €20M or 4% of worldwide turnover Up to $53,088 per email

CAN-SPAM's per-email fines add up, and the FTC does use them. The European framework asks a prior question that CAN-SPAM usually does not: what lawful basis and channel permission justify this contact? The answer varies by jurisdiction and recipient type, but it comes before the unsubscribe.

Does "legitimate interest" let B2B senders skip consent?

Sometimes — and it is worth being honest about the carve-out rather than pretending the law is simpler than it is.

Recital 47 of the GDPR says processing for direct marketing "may be regarded as carried out for a legitimate interest" — the Article 6(1)(f) basis that does not require consent. But GDPR is only half the rulebook. Europe's ePrivacy rules (PECR in the UK) sit on top, and the ICO is blunt: where ePrivacy rules require consent for electronic marketing, legitimate interests cannot substitute for it.

The genuine B2B gap: UK PECR distinguishes individual from corporate subscribers. The ICO's current electronic-mail guidance says unsolicited marketing to individual subscribers needs consent or a valid soft opt-in, while corporate subscribers can be contacted without PECR consent. The sender must still identify itself and provide a valid unsubscribe address. Three honest caveats:

  1. A named person's work email is still personal data, so the sender still needs a GDPR lawful basis and must pass a legitimate-interest balancing test.
  2. The carve-out is jurisdiction-specific. The UK rule is not a safe shortcut for a campaign sent into every EU country.
  3. Article 21 still applies in full. Legitimate interest survives until you object. Then it doesn't.

So B2B legitimate interest is a real doctrine, not a loophole fantasy — but it is a narrow bridge with an absolute off-switch that you control.

The UK rules also changed recently. The Data (Use and Access) Act 2025 added a charitable-purpose soft opt-in to PECR regulation 22(3A); the ICO updated its guidance on April 28, 2026. Qualifying charities may now send electronic marketing without fresh consent only if they meet that exception's requirements. That is another reason to check the current channel rule instead of repeating "GDPR always requires opt-in."

Do these rights help readers outside the EU?

More than you would expect, for two reasons.

First, Article 3 has three relevant territorial routes. GDPR applies to processing in the context of an EU establishment, regardless of where the processing occurs. For a controller or processor without an EU establishment, it applies when the processing relates to offering goods or services to people who are in the EU or to monitoring their behavior there. Merely having an EU address somewhere on a US newsletter list does not, by itself, establish the targeting or monitoring test.

Second, an operator may choose to segment compliance by jurisdiction or apply one internal standard more broadly. The cited law establishes possible fine exposure of up to 4% of worldwide turnover; it does not establish how many global senders use either architecture or whether unsubscribe interfaces improved because of GDPR. A non-EU reader's rights still depend on the law and facts that apply to that reader.

What can you do when a sender ignores your rights?

In order of effort:

  1. Use the one-click route for a sender and subscription you independently verify. It avoids rendering a sender-controlled page, but it does not authenticate the endpoint or show whether the sender honored the request. For suspicious mail, report instead.
  2. Object explicitly. One sentence — "I object to processing of my data for direct marketing under Article 21 GDPR" — removes all legal wiggle room.
  3. Request erasure. Under Article 17, an objection to direct marketing is itself a ground for deletion, and the sender must respond within one month.
  4. Complain to the relevant regulator. Filing a complaint is generally free, but the regulator—not this page—decides jurisdiction, evidence, priority, remedy, and outcome. Preserve the objection, confirmation, headers, and later in-scope messages so the complaint is reviewable.

No current index result can tell you in advance whether a particular sender will comply. The Exit Gap page is presently a research queue, not an A–F lookup. Until a sender clears the multi-probe evidence bar, use the legal rights above and keep your own dated unsubscribe confirmation and post-objection mail.

Turn the next inbox decision into a finite deck.

Open Flick with an account you control, or practice first with fabricated sample mail. Provider results remain limited to the accounts, messages, and actions Flick actually confirms.

Open Flick with your inbox →

Practice with the sample deck · Get Flick for iPhone

FAQ

Article 7(3) requires withdrawal to be as easy as giving consent when consent is the processing basis; it does not, by itself, prescribe an identical footer for every message or jurisdiction. National ePrivacy rules and the sender-recipient context determine the channel-specific requirement. Separately, Google requires RFC 8058 one-click headers from its defined bulk senders, while Yahoo requires covered bulk senders to provide a functioning List-Unsubscribe route and highly recommends RFC 8058 POST. A missing easy exit can therefore implicate the applicable legal rule, a provider rule, or both—but the exact conclusion needs the jurisdiction, lawful basis, message type, and sender scope.

Can a sender make me log in or explain why before unsubscribing?

Not categorically. Article 7(3) says withdrawal cannot be harder than giving consent, so a login or extra identity demand is difficult to justify when the original signup needed neither; proportionate verification can still depend on the account and security context. A survey or retention offer should not obstruct withdrawal. The separate US CAN-SPAM rule is more mechanical: a covered opt-out may not demand anything beyond a reply email or a single webpage visit (FTC).

Does the GDPR right to object apply to B2B emails sent under legitimate interest?

Yes — the Article 21 objection right is absolute for direct marketing and does not care which lawful basis the sender chose (ICO). Legitimate interest lets a B2B sender start the conversation without consent in some jurisdictions; it never lets them continue it after you object. One clear "stop" ends the legal argument.

Does GDPR apply to emails I get from US companies?

It depends on Article 3, not the company's nationality. GDPR can apply through an EU establishment or, for a company without one, when the relevant processing relates to offering goods or services to people in the EU or monitoring their behavior there. A US sender with an incidental EU subscriber is not automatically in scope. People outside the EU should rely on their applicable law unless the sender voluntarily applies one global standard.

How fast must a sender stop emailing after I unsubscribe?

Under GDPR there is no grace period to keep marketing: once you object, your data "shall no longer be processed" for marketing (Article 21(3)). Google's subscription guidance and Yahoo's bulk-sender rules require covered senders to process unsubscribes within two days; US CAN-SPAM allows 10 business days. Mail continuing after the applicable window may breach the relevant legal or platform rule; which rule applies depends on the sender, message, recipient, and jurisdiction.

This guide is educational information, not legal advice. GDPR and ePrivacy implementation varies by jurisdiction; use the linked regulator guidance or qualified counsel for a compliance decision.

Keep reading