Compliance

What does GDPR require for email and SMS marketing?

Two European instruments govern marketing messages, and conflating them is the source of most confusion about the subject.

The GDPR governs personal data: what makes processing lawful, what rights the person has, and what you must be able to show. The ePrivacy Directive, Directive 2002/58/EC, governs electronic communications, and it is Article 13 of that directive, as implemented in each member state's own law, that requires prior consent for unsolicited marketing by email and SMS and provides the narrow exception for a provider's own existing customers.

So the short answer to "does GDPR require consent for marketing email" is that GDPR is not the instrument asking that question. This page covers what GDPR does require, quoting the Official Journal text published by the EU Publications Office. It is not legal advice, and because ePrivacy is a directive rather than a regulation, its rules differ by member state; ask a lawyer about the countries you send to.

What does GDPR ask of a marketing programme?

A lawful basis for the processing, and evidence of it.

Processing personal data is prohibited unless one of six bases applies:

Processing shall be lawful only if and to the extent that at least one of the following applies:

(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

...

(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject

Both (a) and (f) are used for marketing, and the choice is more consequential than it looks. Legitimate interests requires you to have done and documented a balancing exercise, and it does not release you from the ePrivacy consent rule for the send itself. Choosing it because consent seems onerous solves the wrong problem.

An affirmative act, and the Regulation forecloses the shortcuts explicitly:

Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her ... Silence, pre-ticked boxes or inactivity should not therefore constitute consent.

Article 7 then sets four conditions, and each one rules out a common signup pattern:

1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.

2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.

3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.

4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.

Three practical readings:

  • Marketing consent buried in terms of service fails paragraph 2, because it is not clearly distinguishable from the other matters in the declaration.
  • A one-click subscribe with a multi-step unsubscribe fails paragraph 3. Withdrawal must be as easy as giving, which is a symmetry requirement, not a general reasonableness one.
  • Requiring marketing consent to use the product fails paragraph 4, when the marketing is not necessary to deliver the service.

Paragraph 1 is the one that shapes your schema rather than your form. You must be able to demonstrate consent, which means storing when it was given, what was said at the time, and by what act, not merely a flag saying yes.

What happens when someone objects?

Marketing stops, with no balancing and no exceptions.

Most GDPR rights are qualified. The right to object to direct marketing is not:

2. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.

3. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

Compare that with the general right to object in paragraph 1, where a controller may continue if it "demonstrates compelling legitimate grounds". No such clause exists in paragraph 2. This is why relying on legitimate interests does not make a marketing list more durable than consent does: an objection ends it either way.

There is also a disclosure duty attached:

4. At the latest at the time of the first communication with the data subject, the right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information.

At the time of the first communication, presented separately. A rights notice reachable only through a privacy policy link does not obviously satisfy that.

What else does this pull in?

Two things that are easy to treat as paperwork and are not.

A contract with your sending platform. A provider that sends on your behalf is a processor, and GDPR requires a specific written contract between you. What is a data processing agreement covers what Article 28 makes that contract contain.

Where the data sits. Transfers outside the EU need their own basis, which makes the region your data is stored and processed in a compliance question rather than an infrastructure preference. What is data residency covers how that works on Bird.

Construye sobre la misma red.

Obtén una clave API de prueba de inmediato. El acceso a producción se desbloquea cuando añades un método de pago y verificas un remitente.

Empieza con un canal.
Añade los demás cuando estés listo.

Una clave API de prueba es tuya de inmediato. El acceso a producción se desbloquea cuando añades un método de pago y verificas un remitente.

¿Usas Claude Code, Cursor o Codex? Copia un prompt de configuración y tu agente instalará el Bird CLI y las habilidades por ti. Elige el tuyo:

Cursor