Email marketing and GDPR — what a European business actually has to do
Consent, the duty to demonstrate it, and data location. We went through the privacy policies of seven email tools and looked at where your list really is — five of seven keep it in the EU.
The short answer
Five of the seven tools we compare store the list data in the EU — Brevo (France), GetResponse (Poland), Systeme.io (AWS Ireland), MailerLite (EEA contracting party in Ireland) and EmailOctopus (AWS Ireland). Outside the EU go Mailchimp (United States) and ActiveCampaign (transfers to five countries).
Neither is prohibited. The difference is the amount of work: a non-EU service has to be recorded in your own privacy documentation with its transfer basis. If you want to avoid that entirely, choose from the first five. The information was read from the services’ own privacy policies on 3 September 2026 — many comparisons wrongly mark Systeme.io and MailerLite as non-EU.
- You want the list to stay in the EU and nothing else special → Brevo: French, data in the EU, and the free plan is based on sending volume rather than contact count. Try it free
- You want the EU and the most generous free plan possible → EmailOctopus: lists in AWS’s Irish data centre, free up to 2,500 subscribers. Try it free (ad)
- You want the EU and funnels in the same price → Systeme.io: Irish contracting party, data in AWS Ireland, free plan of 2,000 contacts. Try it free (ad)
GDPR does not prohibit email marketing. It requires three things: that the subscriber has given consent, that you can demonstrate it afterwards, and that you know where the list physically is. The first two are practice, the third is a tool choice — and that is where the most common assumption goes wrong.
1. Consent: what it is and what it is not
Consent has to be freely given, specific, informed and unambiguous. In practice that means four things on the form:
- Say what is being subscribed to. “Subscribe to the newsletter” is enough if it says next to it what the newsletter contains and how often it comes.
- No pre-ticked boxes. Consent is an active act, not a default.
- No bundling. Subscribing to the newsletter may not be a condition for placing an order or downloading a guide in a way that cannot be skipped.
- Unsubscribe in every message. One click away, not behind a login.
Double opt-in (the subscriber also clicks a confirmation link in an email) is not mandatory, but it is the most straightforward way to meet the duty to demonstrate consent — and it keeps the list clean of typos and sign-ups made with other people’s addresses.
The rule comes from two places, and the confusion usually stems from that. The quality requirements for consent are in the GDPR, but when consent is needed for email marketing at all is set by the ePrivacy Directive (2002/58/EC), which every EU country has written into its own national law. Article 13(1) says it in these words:
“The use of automated calling and communication systems without human intervention (automatic calling machines), facsimile machines (fax) or electronic mail for the purposes of direct marketing may be allowed only in respect of subscribers or users who have given their prior consent.”
Text read from the consolidated directive on EUR-Lex on 14 September 2026. The wording is the 2009 amended version, still in force.
The definition of consent comes from the GDPR itself, Article 4(11): “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”.
The exception is narrower than it is usually repeated
The existing-customer exception is often repeated as “you may market to customers”. Article 13(2) of the directive lets a seller use a customer’s email address without prior consent only if all of these conditions are met:
- the contact details were obtained “from its customers” (an existing customer relationship),
- they were obtained “in the context of the sale of a product or a service”,
- they are used “for direct marketing of its own similar products or services” and
- the customer is “clearly and distinctly … given the opportunity to object, free of charge and in an easy manner … at the time of their collection and on the occasion of each message”.
Quotations: Article 13(2) of Directive 2002/58/EC, consolidated text on EUR-Lex, read 14 September 2026. National laws implement the article and may be stricter; check your own country’s data protection authority.
The conditions are the text of the directive, not an authority’s interpretation — and the last one sets the duty that is forgotten most often: the right to object has to be offered twice, both at the moment the address is collected and in every message sent.
The word all decides, and two common situations fail on it. An address left for a prize draw or a guide download does not meet the second condition, because it was not obtained in the context of a sale. Marketing a partner’s product or your own new product line does not meet the third. In both cases consent is needed, and it is easier to ask for at the moment of collection than to repair afterwards.
Marketing to businesses is a different matter. Article 13(5) applies the consent rule to subscribers who are natural persons; for legal persons it leaves the rule to national law, which is why some EU countries allow opt-out marketing to company addresses and others do not. The line is not always clear: a work email address with a person’s name in it is personal data, so the interpretation depends on whether the marketing targets the organisation or the named person. In an unclear case the source is your country’s data protection authority, not another marketer’s practice.
A third rule applies to both. Article 13(4) prohibits direct marketing email that disguises or conceals the identity of the sender or lacks “a valid address to which the recipient may send a request that such communications cease”. This hits the subject line and the sender name: a message disguised as a personal reply, an invoice or a system notification breaches the rule regardless of whether consent is in order.
2. Demonstrating consent: store the date and the source
Consent you cannot prove is the same as no consent — Article 7(1) of the GDPR says the controller “shall be able to demonstrate that the data subject has consented”. For every contact you need at least the subscription date and which form the subscription came from.
From this follows one practical rule that is forgotten most often: when you switch tools, include the subscription date and source in the export file. If you move only the email addresses, after the move you are in a situation where the list exists but consent cannot be demonstrated in any way.
3. Data location — where the assumption goes wrong
The common belief is that email tools are American and the list automatically goes across the Atlantic. We went through seven tools’ own privacy policies on 3 September 2026, and the picture is different: five of seven store the list data in the EU.
| Tool | Contracting party | Where the list is |
|---|---|---|
| Brevo | French company | EU |
| GetResponse | Polish company | EU |
| Systeme.io | ITACWT Limited, Ireland | AWS Ireland; according to the policy no transfer outside the EU |
| MailerLite | MailerLite Limited, Ireland (EEA customers) | EU data centre, ISO 27001 |
| EmailOctopus | Three Hearts Digital Ltd, United Kingdom | AWS Ireland, EEA |
| ActiveCampaign | ActiveCampaign, LLC, United States | Transfers to the United States, Australia, Ireland, Brazil and Costa Rica |
| Mailchimp | Intuit, United States | Outside the EU |
← scroll →
Source: each service’s own privacy policy, read 3 September 2026. Checked again every 90 days — the services’ company structures and data centres change.
Note one nuance: the contracting party and the data location are different things. EmailOctopus is a British company, but the lists are in Ireland; at MailerLite an EEA customer’s contract is with an Irish company, even though the group also has a US company. Neither fact alone tells you where the list is — that is in the policy.
What to check in a tool before you adopt it
- Can you find the subscription date and source in an individual contact’s details? Look for it once now, not at the moment someone asks.
- Is a contact deleted entirely or only removed from the list? The right to erasure means deleting the data, not ending the subscription.
- Can you get the list out, and in what format? If there is no export, you are locked in.
- Is a data processing agreement (DPA) available? Look for it in the account settings or the terms of service — at some it is part of the terms, at others it is accepted separately.
- Where the data is — the table above, or the service’s own policy if the tool is not in our comparison.
Tools that keep the list in the EU
| Tool | Free plan | 500 contacts | 2,500 | 10,000 | GDPR settings | Data in the EU | English interface | |
|---|---|---|---|---|---|---|---|---|
| Brevo Our pickSee prices | 300 emails/day | €7 | €21 | €28 | Yes | Yes | Yes | Try |
| EmailOctopusSee prices | 2,500 subscribers, 10,000 emails/month (EmailOctopus branding in the emails) | €9 | €16 | €36 | Yes | Yes | Yes | Try (ad) |
| Systeme.ioSee prices | 2,000 contacts, unlimited sending | $17 | $17 | $47 | Yes | Yes | Yes | Try (ad) |
| MailerLiteSee prices | 250 subscribers, 2,500 emails/month | €11 | €29 | €79 | Yes | Yes | Yes | Try |
| GetResponseSee prices | No free plan (14-day trial) | €16 | €27 | €69 | Yes | Yes | Yes | Try |
← scroll →
Prices exclude VAT, billed monthly unless stated otherwise.(ad) = ad link
- The price is the monthly price of the cheapest paid plan at that list size. The Free plan column shows when you do not have to pay.
- EmailOctopus: the price list only shows the monthly price on annual billing. Monthly billing costs more.
- GetResponse: the smallest list sold is 1,000 contacts, so the 500-contact column shows that price.
The processing agreement: the paper nobody remembers
When you use an email tool, it processes your subscribers’ personal data on your behalf. You are the controller, the service is the processor — and between the two there has to be a written agreement on what the processor may do. Article 28(3) of the GDPR requires that processing by a processor “shall be governed by a contract or other legal act”. The agreement goes by the abbreviation DPA (data processing agreement).
The agreement does not always take effect by itself: at some services it is part of the terms of service, at others it has to be accepted separately in the account settings. We have not gone through every service’s agreement at account level and therefore claim nothing about it for all of them — check this when you adopt the tool, not at the moment a customer asks.
The same goes for your own record of processing activities. Article 30(5) of the GDPR exempts an organisation with fewer than 250 employees from keeping the record, but the exemption lapses for three reasons: if the processing is likely to result in a risk to the rights of data subjects, if the processing is not occasional, or if special categories of data are processed. A regularly maintained marketing list hits the middle one, so the exemption does not apply to it.
Three things worth reading in the agreement:
- Sub-processors. The processor uses its own sub-processors (data centre, support tools, AI services). The list is usually on a separate page and it changes — the service has to notify you of changes, and you have to update your own policy accordingly.
- Transfers outside the EU. The agreement says on what basis data is transferred to third countries. This is the section that is shortest at services that store in the EU.
- What happens after termination. How long the data is kept after the account is closed and whether you can get it out before then.
A practical reminder: if you switch tools, the processor changes — and the processor is named in your own privacy policy. The policy is updated in the same job, not later.
One-click unsubscribe is no longer just a legal requirement
The law requires that marketing can be stopped easily and free of charge in connection with every message. Since February 2024 the same thing is also a technical requirement of the mailbox providers, and that is an interesting combination: the same measure meets both the legal obligation and the deliverability condition.
Google and Yahoo require anyone sending more than 5,000 emails a day to support one-click unsubscribe in marketing emails in accordance with RFC 8058. In practice that means the unsubscribe happens straight from a button in the email client, and the recipient may not be required to confirm separately on a landing page. Yahoo also sets a deadline: the unsubscribe must be processed within two days. Both also require that the spam complaint rate stays below 0.30 per cent.
For the reader this leads to one check: look at what your own unsubscribe link does. If it goes to a page where you still have to log in or confirm the choice, it is a legal problem and a deliverability problem at the same time. The requirements and their effect on the tool choice are covered in the comparison: what Gmail and Yahoo require of senders.
The four most common mistakes
- The old list into the new tool as is. The unsubscribed and dead addresses that come along damage deliverability exactly when the new sender is building its reputation.
- Consent collected for one purpose, used for another. Entering a competition is not a newsletter subscription unless that was said separately.
- An unsubscribe link that requires logging in. Unsubscribing has to work in one click.
- Tool switched, policy not. The processor is named in the policy; when the tool changes, the policy is updated in the same job.
What this page is not
This is a practical checklist, not legal advice. The rules for electronic direct marketing come from the ePrivacy Directive as implemented in each country’s national law and from the GDPR, and their application depends on whom you market to and how the addresses were collected. In an ambiguous situation the source is your country’s data protection authority — and interpretations get updated.
Deeper into two questions: seven services’ policies side by side on where email tools store their data, and the background to transfer bases on Schrems II and moving an email list outside the EU.
300 emails/day.