Skip to main content
Conversion
5 min readPublished on July 02, 2026Updated on September 09, 2026

GDPR in Email Marketing: What Is Actually Required

Simon Heistermann

Simon Heistermann

Owner

This article was written with AI assistance and editorially reviewed.

Most guides on GDPR and email marketing do one of two things: they scare without getting specific, or they wave the whole topic away because fear does not sell well. Neither helps. Here is what is actually required, what a narrow exception permits, and what is just caution nobody needs.

In short

A newsletter without a documented double opt-in cannot be proven in a dispute, regardless of how good the content is. The existing-customer exception under German law is narrow, not a general licence. This article is orientation, not legal advice.

Double opt-in is not a recommendation, it is the baseline

A plain form entry proves nothing. Anyone can type a colleague's address, a competitor's, or a bot can type one automatically. Double opt-in closes exactly that gap: after signup, the address receives a confirmation email with a unique link and no promotional content. Only the click on that link activates the address.

Using single opt-in because it feels simpler does not remove the risk, it grows it. In a dispute, the burden of proving valid consent sits with the sender, not the recipient. Without a confirmation click, that proof simply does not exist.

Consent that is not logged effectively does not exist. Four data points need to be recorded without gaps: the timestamp of signup, the IP address, the exact wording of the form at that moment, and the confirmation click itself. The third point is the one most often underestimated: form text changes over the years, and storing only "consent given" makes it impossible to later show what exactly was agreed to.

Our own lead magnet runs on versioned consent records for that reason: every signup stores which version of the form text was in effect at the time, together with timestamp, IP and confirmation click. If the form text changes later, the older records stay traceable unchanged. That is not extra ongoing work, it is a one-off technical decision that then runs automatically.

Mandatory disclosures in every promotional email

Regardless of consent, formal requirements apply to every promotional email, and missing them is already a risk on its own:

  • A full provider identification (imprint), included or easily reachable via link
  • An unsubscribe link that works in one click without login and takes effect immediately
  • An honest sender name without disguise
  • A subject line that does not obscure the promotional nature of the email

The unsubscribe link deserves particular attention, because it is the most commonly underestimated point: an unsubscribe that does not take effect immediately or needs several clicks is, in practice, nearly as risky as having no link at all.

The existing-customer exception - narrow, not generous

German law contains an exception that gets read too generously more often than not. If you obtained an email address in connection with selling a product or service, you may, under narrow conditions, advertise similar offerings of your own without separate consent. The condition is that the customer was clearly informed, at collection and with every subsequent use, of their free, immediate right to object, and has not exercised it.

Three words carry the entire caution in that paragraph: narrow, similar, and objected. The exception does not cover freshly acquired addresses without a purchase context, does not cover unrelated product categories, and ends the moment the customer objects once. Whether a specific plan falls under it is a case-by-case assessment this article cannot and does not attempt to make. When in doubt, a regular double opt-in is the safer route, and usually the faster one too, because it avoids any argument about interpretation.

Route to a listRequirementRisk if done wrong
Double opt-inConfirmation click after signup, documentedLow, as long as logging is complete
Existing-customer exceptionPurchase context, similar offering, clear objection noticeHigh, because the reading is narrow and case-specific
Bought or gifted listNo consent of your own existsVery high, regardless of what the seller claims

Concrete steps for the next 90 days

  • Days 1-30: Audit existing lists, flag every address without a documented double opt-in
  • Days 31-60: Move forms to double opt-in, set up logging of timestamp, IP, form version and click
  • Days 61-90: Check unsubscribe links and imprint in every campaign template, get individual existing-customer cases reviewed legally

Conclusion

Compliant email marketing is not a special project, it is a one-off technical decision: set up double opt-in, log without gaps, keep the mandatory disclosures in every email. The existing-customer exception is a narrow special case, not a substitute for that. What a clean setup costs overall is covered in Email Marketing Cost, and which tool fits your EU data protection needs in the tool comparison. For a no-obligation review of your current setup, get in touch. This article remains orientation, not legal advice - for your specific case, a lawyer specialising in IT and data protection law belongs at the table.

Not sure your newsletter setup would hold up?

Get in touch

Frequently asked questions

Simon Heistermann

Simon Heistermann

Owner

Heistermann Solutions is the web studio run by Simon Heistermann. We build custom websites for small and medium-sized businesses that want to achieve more online.

Every article grows out of day-to-day project work and is reviewed editorially before publication.

Get it for free

Enter your email address. You'll immediately receive a confirmation link - after clicking it the checklist is available right away.

Let's talk about your project

Free introductory call