Back to Tools

GDPR Email Compliance Checker

Audit your email marketing practices against GDPR requirements with this interactive checklist. Check consent collection, subscriber rights, data processing, and more.

About this tool

GDPR compliance is not optional for any business sending emails to EU residents, and the fines for violations can reach 4% of annual global revenue. This interactive checklist covers the key requirements: consent collection, subscriber rights (access, deletion, portability), email content requirements, data processing agreements, and international transfers. Use this alongside our CAN-SPAM checker for US compliance, and make sure your emails include proper List-Unsubscribe headers. For technical compliance, verify your DMARC, SPF, and DKIM authentication.

Frequently Asked Questions

Does GDPR apply to my business?

GDPR applies if you process personal data of EU/EEA residents, regardless of where your business is located. If you have subscribers in Europe or send emails to European email addresses, GDPR applies to you. This includes businesses in the US, UK, Asia, and anywhere else.

What consent is required for email marketing under GDPR?

GDPR requires freely given, specific, informed, and unambiguous consent. This means: no pre-checked boxes, clear language about what they are signing up for, separate consent for marketing (not bundled with terms of service), and records of when and how consent was obtained.

What is the difference between GDPR and CAN-SPAM?

GDPR (EU) requires opt-in consent before sending marketing emails. CAN-SPAM (US) allows opt-out, meaning you can email someone until they unsubscribe. GDPR has stricter data rights (access, deletion, portability). GDPR fines can reach 20 million euros or 4% of global revenue. If you email EU residents, you must comply with GDPR regardless of your location.

Do I need double opt-in for GDPR compliance?

Double opt-in is not explicitly required by GDPR, but it is strongly recommended because it provides clear evidence of consent. A confirmation email with a click-to-confirm link creates a verifiable consent record. Some EU regulators consider it best practice.

How long can I keep subscriber data under GDPR?

GDPR does not specify exact retention periods. Data should be kept only as long as necessary for its stated purpose. For email marketing, this means you should regularly clean inactive subscribers and have a documented retention policy. Two years of inactivity with no engagement is a common threshold for data removal.

What happens if a subscriber requests data deletion?

You must delete their personal data from all systems within one month of the request. This includes your email platform, CRM, analytics tools, backups (where feasible), and any third-party tools that process their data. You may retain data required for legal compliance (e.g., transaction records) but must stop all marketing use.

Is this tool a substitute for legal advice?

No. This tool provides general guidance on GDPR requirements for email marketing. It is educational and informational only. GDPR compliance depends on your specific situation, data processing activities, and jurisdiction. Consult a qualified legal professional for advice specific to your business.

What are Data Processing Agreements and do I need them?

A DPA is a legally binding contract between you (the data controller) and any third party that processes personal data on your behalf (the data processor). If you use an email service provider, analytics platform, or CRM that handles subscriber data, you need a DPA with each one. Most major ESPs provide standard DPAs on request.