CLOUD SERVER FOR EMAIL

EU Email Marketing Regulations

GDPR, ePrivacy Directive, and Country-Specific Requirements for EU Markets

European email marketing regulations combine GDPR's data protection framework with national implementations of the ePrivacy Directive (often called the 'Cookie Law' but equally applicable to email marketing). Understanding both layers — and the country-specific variations — is essential for organizations sending marketing email to EU residents.

EU email marketing regulations are complex, jurisdiction-specific, and subject to enforcement that varies by national Data Protection Authority (DPA). This guide provides a framework overview. Consult qualified EU data protection counsel for compliance advice specific to your organization and target markets.

The Two-Layer EU Regulatory Framework

Layer 1: GDPR — Data Protection

GDPR (General Data Protection Regulation, EU 2016/679) governs the processing of personal data — including the collection, storage, and use of email addresses. For email marketing, GDPR requires: a valid legal basis for processing (usually consent under Article 6(1)(a) for marketing), compliance with data subject rights, data minimization, purpose limitation, and data security.

Layer 2: ePrivacy Directive — Electronic Communications

The ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC) governs direct marketing by electronic means. Article 13 requires prior consent for unsolicited commercial email. The Directive allows member states to implement exemptions — this is why implementations vary significantly across EU countries.

Important: the ePrivacy Directive is being replaced by the ePrivacy Regulation, which has been under negotiation since 2017. As of 2026, the Regulation has not yet been adopted; member states continue under the existing Directive and national implementations.

Country-Specific Implementation: Key Markets

CountryRegulatorB2C EmailB2B EmailKey Notes
GermanyDatenschutzbehörden (state DPAs)Opt-in requiredOpt-in requiredStrictest implementation; double opt-in (confirmed opt-in) effectively required for legal certainty; BDSG supplements GDPR
FranceCNILOpt-in requiredOpt-out permitted (soft opt-in for existing customers)CNIL has issued guidance distinguishing B2B legitimate interest; active enforcement history
NetherlandsAutoriteit Persoonsgegevens (AP)Opt-in requiredSoft opt-in for existing customersTelecom Act supplements ePrivacy; AP actively enforces consent requirements
SpainAEPDOpt-in requiredOpt-in requiredLOPDGDD supplements GDPR; AEPD has issued significant fines for email marketing violations
ItalyGaranteOpt-in requiredOpt-in recommended (soft opt-in in practice)Garante has issued guidance on legitimate interest for B2B; individual assessment required
PolandUODOOpt-in requiredOpt-in requiredStrict implementation; Electronic Services Act requires consent for direct marketing
SwedenIMYOpt-in requiredSoft opt-in for existing customersElectronic Communications Act implementation; IMY applies GDPR consent standard
AustriaDSBOpt-in requiredOpt-in requiredStrict implementation; TKG supplements ePrivacy for electronic communications
BelgiumAPD/GBAOpt-in requiredSoft opt-in (legitimate interest for B2B)Market practices law supplements; APD has issued guidance on acceptable B2B interest

Consent Requirements by Recipient Type

B2C Marketing Email (Business to Consumer)

For marketing email to consumers (individuals acting in a personal capacity), virtually all EU member states require explicit consent before sending. The consent must be:

  • Freely given — not conditioned on product/service access
  • Specific — clearly stating what types of messages will be sent
  • Informed — recipient must understand what they're consenting to
  • Unambiguous — affirmative action required (pre-ticked boxes invalid)
  • Separate from other consent — marketing consent cannot be bundled with terms agreement

Double opt-in (confirmed opt-in) — where the subscriber must click a confirmation link after initial sign-up — is not legally required in all EU jurisdictions but provides the strongest consent documentation. In Germany, double opt-in has effectively become the practical standard for defensible consent. Cloud Server for Email configures MailWizz's double opt-in workflow for all clients targeting German-speaking markets.

B2B Marketing Email (Business to Business)

B2B email marketing is treated differently across EU member states. The key distinction is whether the recipient's email address belongs to an individual (even if in a professional capacity) or is a generic business address (info@company.com).

Individual professional email addresses (firstname.lastname@company.com) in the EU are generally treated as personal data under GDPR, requiring a legal basis for processing. Most DPAs accept legitimate interest under GDPR Article 6(1)(f) for B2B marketing where: the email is relevant to the recipient's professional role, the sender has a plausible interest, and the recipient's interests don't clearly override the sender's interest. Legitimate interest requires a documented balancing test.

Generic business addresses (info@company.com, sales@company.com) are generally not personal data and can be used for marketing without a specific GDPR legal basis — though the ePrivacy Directive's consent requirements may still apply depending on member state implementation.

EU Infrastructure for GDPR Compliance

Data Residency

GDPR restricts transfers of personal data outside the EU/EEA to countries that provide an adequate level of data protection or where appropriate safeguards are in place (Standard Contractual Clauses, Binding Corporate Rules, etc.). EU-based email infrastructure — like Cloud Server for Email's Estonian servers — keeps subscriber data within the EU, eliminating the need for cross-border transfer mechanisms.

Data Processor Requirements

Email infrastructure providers that process subscriber personal data on behalf of a business are Data Processors under GDPR Article 28. A written Data Processing Agreement (DPA) is legally required between the data controller (the organization sending email) and the data processor (the infrastructure provider). Cloud Server for Email's DPA covers: processing purposes, security measures, sub-processor disclosure, data subject rights support, and breach notification.

Enforcement Landscape: EU DPA Activity

DPACountryNotable Enforcement (Email)Enforcement Posture
Bundesdatenschutzbeauftragte / State DPAsGermanyMultiple fines for marketing without consent; €500K+ casesVery active
CNILFranceFines for email marketing without consent; landmark data broker caseActive
AEPDSpain€10K–€1M fines for marketing violationsVery active
ICOUK (post-Brexit)£1.35M fine for lead gen/email marketingActive
APNetherlandsEnforcement for consent violationsModerate-active
GaranteItalyMultiple marketing consent casesModerate-active
UODOPolandGrowing enforcement activityIncreasing

Practical Compliance Framework for EU Email Marketing

Step 1: Legal Basis Assessment

For every list segment and sending purpose, document the legal basis: Is this marketing or transactional? Are recipients B2C or B2B? What is the specific legal basis (consent, legitimate interest, contract)? If legitimate interest — document the balancing test. This documentation is required for GDPR Article 30 records of processing activities.

Step 2: Consent Documentation

For consent-based sending: document the consent moment (timestamp, IP, form URL), consent language (what exactly was displayed), and consent scope (what types of messages). MailWizz custom subscriber fields can store this data. For double opt-in: store the confirmation email timestamp separately from the initial opt-in. Retain consent records for the full duration of the relationship plus a reasonable period afterward (typically 3 years after last contact).

Step 3: Infrastructure Configuration

EU-compliant email infrastructure requires: EU-based servers for EU subscriber data (or SCCs if using US infrastructure), GDPR-compliant DPA with your infrastructure provider, unsubscribe mechanism that works immediately and for 60+ days, suppression list management to prevent re-mailing opt-outs, and data deletion capability to honor Article 17 right to erasure.

Step 4: Ongoing Compliance Monitoring

EU email compliance is not a one-time setup — it requires ongoing attention: reviewing new DPA guidance as it is issued, monitoring consent documentation for expiry (implied consent ages), updating processing records (Article 30) when practices change, and responding to data subject rights requests within 30 days.

EU-Compliant Infrastructure from Cloud Server for Email

All Cloud Server for Email managed infrastructure operates from EU servers (Estonia) with GDPR-compliant data processing. Data Processing Agreements under GDPR Article 28 are available for all clients. Our infrastructure supports CASL and CAN-SPAM compliance features in addition to EU requirements. Contact infrastructure@cloudserverforemail.com.

Discuss Infrastructure Requirements

Cloud Server for Email operates managed PowerMTA + MailWizz infrastructure from EU servers.
Dedicated IPs, daily monitoring, GDPR compliance by design.

Managed Infrastructure

PowerMTA + MailWizz. EU servers. Daily monitoring. GDPR by design.

Request Assessment