Compliance

GDPR & email in 2026 : the complete compliance guide for marketing teams

Illustration: a GDPR compliance shield with a consent checkbox checked 'I agree to receive your emails'
Summary

The GDPR frames email marketing around four core obligations: a valid legal basis (consent for B2C, legitimate interest for B2B), clear information at the point of collection, a simple way to unsubscribe in every message, and a justifiable retention period. For teams sharing a sending account, a fifth obligation often goes overlooked: securing and restricting access to contact data. This guide walks through each rule, separates myth from law, and clarifies what actually changes, or does not, in 2026.

GDPR compliance is no longer a concern confined to the legal team. It has become a team-wide responsibility. Who collected that consent? How long have we been keeping this contact? Which of the five people sharing the account can export the entire list? These questions seem administrative until the day they are not.

This guide is written for marketing teams, not lawyers. It covers the essential CNIL and GDPR rules as they apply to email, flags two persistent misconceptions along the way, and addresses the particular case of a sending account shared across multiple teams. Let's start with the question that conditions everything else: do you actually have the right to email this person?

Key takeaways

  • B2C: consent is mandatory, freely given, specific, informed, and unambiguous, via an unchecked checkbox (CNIL, 2026).
  • B2B: legitimate interest is possible where the message relates to the recipient's professional activity, provided a right to object is offered.
  • Double opt-in is not mandatory: the GDPR requires you to prove consent (Art. 7.1), not to confirm it twice.
  • In 2025, the CNIL issued 10 sanctions targeting commercial prospecting, out of 83 total (CNIL, 2025 review).
Before you start reading

This article is an educational guide, not legal advice. It draws on CNIL publications and the GDPR text as of June 2026. For any specific situation, verify the cited source and, if necessary, consult your DPO or a qualified lawyer.

What legal basis applies to email marketing in 2026?

It depends on your recipient. In 2026, the CNIL maintains that prospecting by email to an individual requires their prior consent, while prospecting to a professional may rely on legitimate interest where the message relates to their professional activity (CNIL, Commercial prospecting by email, 2026). This B2C/B2B distinction drives almost every other decision.

On the consumer side, the rule is unambiguous. Electronic advertising "is possible provided that individuals have given their consent before being contacted," as the CNIL states. No pre-ticked boxes, no consent buried in terms and conditions: a dedicated, active step is required. That is the foundation of any healthy B2C list.

On the professional side, the regime is more flexible, but not without constraints. You may email firstname.lastname@company.com on the basis of legitimate interest, subject to two conditions: the message must relate to the recipient's professional role, and a simple way to object must always be provided. Generic addresses such as contact@ are a different matter entirely.

B2C and B2B: two email prospecting regimes, per CNIL guidance (2026). Educational summary. Verify CNIL doctrine for your specific situation.
 Individual (B2C)Professional (B2B)
Legal basisPrior consentLegitimate interest possible
CollectionOpt-in (unchecked checkbox)No prior opt-in required
Substantive conditionPositive and specific actionMessage related to professional activity
Right to refuseUnsubscribe link in every emailRight to object + unsubscribe link
What's new in 2026

The "ePrivacy" regulation promised since 2017 has never materialised. Nothing has been relaxed: the 2002 ePrivacy Directive and the GDPR remain the applicable framework for prospecting.

One development to watch: the "Digital Omnibus" package, proposed by the Commission on 19 November 2025, would shift some consent rules into the GDPR (European Parliament, Digital Omnibus, 2025). As of 2026, this remains a proposal only, not yet binding law.

What makes consent valid, and is double opt-in mandatory?

Valid consent is, according to the CNIL, "freely given, specific, informed and unambiguous," requiring "a positive and specific action by the individual concerned" (CNIL, 2026). In plain terms: a dedicated, unchecked checkbox. Accepting general terms and conditions never suffices.

The question that keeps coming up is whether double opt-in is required. The answer is no. Neither the GDPR nor the CNIL makes it mandatory. What Article 7.1 of the GDPR requires is that you be able to demonstrate that the person consented. Double opt-in, where a confirmation email must be clicked, is an excellent way to build that proof, but it remains a best practice, not a legal obligation.

Common myth

"The CNIL requires double opt-in." False. This claim circulates widely, but no CNIL publication establishes it as an obligation. The real requirement is proof of consent: keep a timestamped record of the checkbox ticked, the source, and the date. That audit trail is what protects you, not the number of clicks.

The distinction matters for a marketing team: you can choose single opt-in as long as you document the collection process properly. What is non-negotiable is the ability to reconstruct, contact by contact, how and when consent was given. Without that record, even genuine consent remains legally fragile.

That record gets built at the point of collection, not afterwards. We set out the five items to capture, and what Brevo and Mailchimp actually keep, in GDPR by design: what should you record at the point of collection?

How long can you keep a contact's data?

The CNIL recommends retaining data on a non-customer prospect for three years from their last interaction, whether a click, an enquiry, or an email open (CNIL, Reference framework for commercial activity data management, 2026). Crucially, this period is a recommendation, not a statutory requirement.

This means you may choose a different duration, provided you can justify it. A long sales cycle may support a longer retention period; a highly volatile contact base may warrant a shorter one. What is not negotiable is the underlying principle: data minimisation.

Article 5 of the GDPR requires that data be "adequate, relevant and limited to what is necessary" for the purpose. Practically speaking, keeping an address "just in case" for years without any contact or legal basis is a liability. A contact dormant for four years is a compliance risk and a drag on your deliverability.

Common myth

"The law requires deleting prospects after 3 years." Not quite. The CNIL presents these durations as "a reference point" from which organisations "may depart, provided they document their reasoning." The 3-year mark is a solid recommendation, but you are free to set your own retention period as long as it can be justified (CNIL, Data retention periods, 2026).

What must every email contain to be compliant?

Four elements, and they are cumulative. The CNIL specifically requires that "every communication" allow the sender to be identified and enable the recipient to "express, by a simple means, their refusal to receive further communications" (CNIL, 2026). The remaining requirements apply at the point of collection.

1

A valid legal basis

Consent for individuals, or legitimate interest with a right to object for professionals where the message relates to their professional role.

2

A clearly identifiable sender

The recipient must be able to recognise the organisation writing to them, without ambiguity or misleading sender details.

3

A simple way to unsubscribe

An unsubscribe link must appear in every message, be fully functional, and involve no unnecessary friction.

4

Information provided at collection

When collecting the address, state the intended use (prospecting) and inform the person of their rights.

None of these requirements is new, and that is precisely the trap: their apparent obviousness leads teams to overlook them. An unsubscribe link pointing to a broken page, a missing collection notice on a form added in haste by another team. These details, more than any grand principle, are what trigger complaints. Email compliance depends as much on rigorous execution as on knowing the rules.

Shared account across multiple teams: who is responsible, and how should access be secured?

Your organisation is the data controller, not each team in isolation. The data controller is the party that "determines the purposes and means of processing"; the ESP is the data processor (CNIL, How to identify your role correctly, 2025). Marketing, sales, and events are not separate controllers: they all operate under a single accountability.

One data controller, multiple teams One data controller, multiple teams Your organization data controller ESP (Brevo, Mailchimp) data processor Marketing Sales Events Restricted and logged access (art. 32) under a single accountability (art. 30)
Source: CNIL, identifying the controller/processor role, 2025; GDPR Art. 30 and 32.

This shared accountability has a direct consequence: securing access is a legal obligation. Article 32 of the GDPR requires "appropriate technical and organisational measures" and specifies that anyone with access to data may process it only "on the instructions of the controller." In practice, limiting who can view and export which data is part of compliance.

In a shared sending account, this is often the weakest link. When five people all have full access to the entire contact base, the segmentation required by Article 32 simply does not exist. Our Brevo multi-team governance guide details how to establish these perimeters; for Mailchimp, see Mailchimp multi-team governance. All of this must be documented in the record of processing activities required by Article 30.

From our audits

In the shared accounts we review, the most common GDPR gap is not consent: it is access. Everyone can see everything, export everything, and email the entire list. Restricting access by team is one of the simplest security measures to implement, and one of the first expected under Article 32.

What do you actually risk in the event of non-compliance?

More than in the past. In 2025, the CNIL issued 83 sanctions, of which 10 related specifically to commercial prospecting, reaffirming that consent is mandatory (CNIL, 2025 sanctions review, 2026). Email marketing is now an established area of enforcement.

The ceiling is sobering. Article 83 of the GDPR provides for fines of up to €20 million, or 4% of total annual worldwide turnover, whichever is higher. Less serious infringements fall under a first tier capped at €10 million or 2%.

Article 83: two sanction tiers Article 83: two sanction tiers €10 M or 2% Violations (art. 83.4) €20 M or 4% Major violations (art. 83.5) % of annual worldwide turnover, whichever is higher
Source: GDPR, Article 83, paragraphs 4 and 5.

Should you therefore fear the maximum fine for a broken unsubscribe link? No: sanctions are proportionate. But the real day-to-day risk for a marketing team is more mundane: a complaint from a recipient, a triggered investigation, and the burden of proving that everything was in order. That is where consent audit trails and access controls stop being theoretical.

In practice

The access controls Article 32 requires, Sendgate makes simple.

Sendgate sits on top of your existing sending account, with no migration required, and segments who can access which lists and email which contacts. You put a required GDPR security measure in place, while keeping a clear view of who does what with your data.

Try it free →

Brevo supported today, Mailchimp coming soon · This is not legal advice · Not affiliated with the brands mentioned

Key takeaways

GDPR compliance for email rests on four pillars: a legal basis suited to the recipient (consent for B2C, legitimate interest for B2B), clear information at the point of collection, a simple unsubscribe mechanism in every message, and a justifiable retention period. Two myths to set aside: double opt-in is not mandatory, and the "3-year" guideline is a recommendation, not a statute.

For teams sharing a sending account, a fifth obligation is added, and frequently overlooked: restricting and logging access to contact data, as required by Article 32. In 2026, with the CNIL stepping up sanctions on prospecting, this rigour in execution, proof of consent and control of access, is what protects you.

Frequently asked questions

Is consent required to send a marketing email in 2026?
For individuals (B2C), yes: the CNIL requires prior consent that is freely given, specific, informed and unambiguous, obtained through a positive action such as an unchecked checkbox (CNIL, 2026). For professionals (B2B), prospecting may rely on legitimate interest where the message relates to their professional activity, with a right to object.
Is double opt-in mandatory under the GDPR?
No. The GDPR does not require double opt-in. What it requires, under Article 7.1, is that you be able to prove valid consent. Double opt-in is a good practice for building that proof, but it is not a legal obligation, and no CNIL publication establishes it as a rule.
How long can you keep a prospect's email address?
The CNIL recommends three years from the prospect's last contact (CNIL, Reference framework for commercial activity data management, 2026). This is a recommendation, not an obligation: you may choose a different retention period as long as you can justify it in light of your business context.
Who is responsible for data in a shared sending account?
The organisation is the data controller, not each individual team. The ESP (Brevo, Mailchimp) is the data processor. Internal teams all act under a single accountability, which must maintain a record of processing activities (Art. 30) and secure access (Art. 32), as explained in our governance guide.
What must an email contain to be GDPR-compliant?
A valid legal basis, clear identification of the sender, a simple way to unsubscribe in every message, and information provided at the point of collection. The CNIL requires that every communication give recipients a straightforward way to express their refusal (CNIL, 2026).
What are the penalties for non-compliance?
Fines can reach €20 million or 4% of total annual worldwide turnover under Article 83 of the GDPR. In 2025, the CNIL issued 83 sanctions, of which 10 targeted commercial prospecting (CNIL, 2026). Sanctions remain proportionate to the severity of the infringement.

Sources

  1. CNIL, Commercial prospecting by email, SMS-MMS and automated calling, accessed 2026-06-22. cnil.fr
  2. CNIL, Reference framework for commercial activity data management (prospect retention: 3 years), accessed 2026-06-22. cnil.fr (PDF)
  3. CNIL, Data retention periods, accessed 2026-06-22. cnil.fr
  4. CNIL, GDPR: how to identify your role (controller / processor), accessed 2026-06-22. cnil.fr
  5. CNIL, The record of processing activities (Art. 30), accessed 2026-06-22. cnil.fr
  6. GDPR, Article 5, data minimisation (via CNIL), accessed 2026-06-22. cnil.fr
  7. GDPR, Article 32, security of processing (via CNIL), accessed 2026-06-22. cnil.fr
  8. GDPR, Article 83, administrative fines (via CNIL), accessed 2026-06-22. cnil.fr
  9. CNIL, Sanctions and corrective measures: 2025 review, accessed 2026-06-22. cnil.fr
  10. European Parliament, Digital Omnibus (Commission proposal, 19 November 2025), accessed 2026-06-22. europarl.europa.eu
Jean Rubens

Jean Rubens

Co-founder, Sendgate

Jean is co-founder of Sendgate. He writes about email sending governance for teams: GDPR compliance, compartmentalized access, list segmentation, and access security across shared sending accounts.