GDPR, the General Data Protection Regulation, is a comprehensive European Union law that governs how organisations collect, store, use, and share the personal data of individuals in the EU and European Economic Area.
It came into force in May 2018 and applies to any organisation that processes the personal data of EU residents, regardless of where the organisation itself is based. For UK businesses, the UK GDPR, which closely mirrors the EU version, applies following the UK’s departure from the EU. GDPR fundamentally changed the relationship between organisations and the people whose data they hold, placing significantly more control in the hands of individuals.
Under GDPR, organisations must have a lawful basis for processing personal data. For marketing purposes, the two most commonly used bases are consent (the individual has actively agreed to their data being used for a specific purpose) and legitimate interest (the organisation has a genuine business reason that outweighs the individual’s privacy interests). The regulation also grants individuals a set of rights over their data, including the right to access, correct, or erase information held about them.
For marketing teams, GDPR has practical implications at every stage of the customer relationship. Signup forms must be explicit about how data will be used. Email marketing requires a documented lawful basis. Data retention policies must be defined and enforced. And the systems used to collect, store, and process contact data must meet GDPR’s security and accountability standards. Non-compliance carries the risk of significant fines, up to 4% of global annual turnover or 20 million euros, whichever is higher.
Yes. GDPR applies to the processing of any personal data, and a business email address is personal data if it can be used to identify an individual. This means that email marketing to business contacts is subject to GDPR requirements. The lawful basis for B2B email marketing is often legitimate interest rather than consent, but this requires a documented legitimate-interest assessment and must still promptly respect opt-out requests.
Consent means an individual has actively agreed, through a clear and positive action, to have their data used for a specific purpose. It must be freely given, specific, informed, and unambiguous. Legitimate interest is a broader basis that allows processing when the organisation has a genuine and proportionate business reason that does not override the individual’s rights. For B2B marketing, legitimate interest is commonly used for direct marketing to professional contacts, but it requires a documented three-part test and must be balanced against the individual’s reasonable expectations.
GDPR grants individuals eight key rights: the right to be informed about how their data is used, the right of access to a copy of their data, the right to rectification of inaccurate data, the right to erasure (the right to be forgotten), the right to restrict processing, the right to data portability, the right to object to processing, and rights related to automated decision-making. Marketing teams must be prepared to respond to requests exercising any of these rights within the legally defined timeframes.
Discover why EU-based SaaS is gaining traction over US tech and why Spotler is the privacy-first, GDPR-compliant marketing cloud of choice.
Spotler Activate lets you manage your own data without using third-party cookies.
If you have built your business strategy around third-party cookies, the time has come to prioritise the transition to a zero & first-party data strategy.
By adopting a CDP, you can stay ahead of the privacy curve, managing data ethically from a central hub point while also taking advantage of what this data offers.
Visit E-Commerce Live! 2026 and discover the latest trends in e-commerce, AI and personalisation. Spotler will host an inspiring session.
Visit Digital Marketing Live 2026 and discover the latest trends in data, personalisation and automation. Spotler will host a session with Yelflow and Verfwinkel.nl.
Discover how Rinsma Modeplein increases customer loyalty with Spotler Activate. Join our session at the Digital Marketing Festival.
Learn how to design emails that hold up in dark mode, with practical tips, real examples, and code that works.
Learn how chatbots help municipalities take citizens from question to booked appointment, cutting errors and service team pressure.
Gmail and Outlook now use AI to filter, summarise and rank emails. Discover what the AI Inbox means for engagement, inbox placement and your campaigns.