GDPR & email in 2026 : the complete compliance guide for marketing teams
The GDPR frames email marketing around four core obligations: a valid legal basis (consent for B2C, legitimate interest for B2B), clear information at the point of collection, a simple way to unsubscribe in every message, and a justifiable retention period. For teams sharing a sending account, a fifth obligation often goes overlooked: securing and restricting access to contact data. This guide walks through each rule, separates myth from law, and clarifies what actually changes, or does not, in 2026.
GDPR compliance is no longer a concern confined to the legal team. It has become a team-wide responsibility. Who collected that consent? How long have we been keeping this contact? Which of the five people sharing the account can export the entire list? These questions seem administrative until the day they are not.
This guide is written for marketing teams, not lawyers. It covers the essential CNIL and GDPR rules as they apply to email, flags two persistent misconceptions along the way, and addresses the particular case of a sending account shared across multiple teams. Let's start with the question that conditions everything else: do you actually have the right to email this person?
Key takeaways
- B2C: consent is mandatory, freely given, specific, informed, and unambiguous, via an unchecked checkbox (CNIL, 2026).
- B2B: legitimate interest is possible where the message relates to the recipient's professional activity, provided a right to object is offered.
- Double opt-in is not mandatory: the GDPR requires you to prove consent (Art. 7.1), not to confirm it twice.
- In 2025, the CNIL issued 10 sanctions targeting commercial prospecting, out of 83 total (CNIL, 2025 review).
This article is an educational guide, not legal advice. It draws on CNIL publications and the GDPR text as of June 2026. For any specific situation, verify the cited source and, if necessary, consult your DPO or a qualified lawyer.
What legal basis applies to email marketing in 2026?
It depends on your recipient. In 2026, the CNIL maintains that prospecting by email to an individual requires their prior consent, while prospecting to a professional may rely on legitimate interest where the message relates to their professional activity (CNIL, Commercial prospecting by email, 2026). This B2C/B2B distinction drives almost every other decision.
On the consumer side, the rule is unambiguous. Electronic advertising "is possible provided that individuals have given their consent before being contacted," as the CNIL states. No pre-ticked boxes, no consent buried in terms and conditions: a dedicated, active step is required. That is the foundation of any healthy B2C list.
On the professional side, the regime is more flexible, but not without constraints. You may email firstname.lastname@company.com on the basis of legitimate interest, subject to two conditions: the message must relate to the recipient's professional role, and a simple way to object must always be provided. Generic addresses such as contact@ are a different matter entirely.
| Individual (B2C) | Professional (B2B) | |
|---|---|---|
| Legal basis | Prior consent | Legitimate interest possible |
| Collection | Opt-in (unchecked checkbox) | No prior opt-in required |
| Substantive condition | Positive and specific action | Message related to professional activity |
| Right to refuse | Unsubscribe link in every email | Right to object + unsubscribe link |
The "ePrivacy" regulation promised since 2017 has never materialised. Nothing has been relaxed: the 2002 ePrivacy Directive and the GDPR remain the applicable framework for prospecting.
One development to watch: the "Digital Omnibus" package, proposed by the Commission on 19 November 2025, would shift some consent rules into the GDPR (European Parliament, Digital Omnibus, 2025). As of 2026, this remains a proposal only, not yet binding law.
What makes consent valid, and is double opt-in mandatory?
Valid consent is, according to the CNIL, "freely given, specific, informed and unambiguous," requiring "a positive and specific action by the individual concerned" (CNIL, 2026). In plain terms: a dedicated, unchecked checkbox. Accepting general terms and conditions never suffices.
The question that keeps coming up is whether double opt-in is required. The answer is no. Neither the GDPR nor the CNIL makes it mandatory. What Article 7.1 of the GDPR requires is that you be able to demonstrate that the person consented. Double opt-in, where a confirmation email must be clicked, is an excellent way to build that proof, but it remains a best practice, not a legal obligation.
"The CNIL requires double opt-in." False. This claim circulates widely, but no CNIL publication establishes it as an obligation. The real requirement is proof of consent: keep a timestamped record of the checkbox ticked, the source, and the date. That audit trail is what protects you, not the number of clicks.
The distinction matters for a marketing team: you can choose single opt-in as long as you document the collection process properly. What is non-negotiable is the ability to reconstruct, contact by contact, how and when consent was given. Without that record, even genuine consent remains legally fragile.
That record gets built at the point of collection, not afterwards. We set out the five items to capture, and what Brevo and Mailchimp actually keep, in GDPR by design: what should you record at the point of collection?
How long can you keep a contact's data?
The CNIL recommends retaining data on a non-customer prospect for three years from their last interaction, whether a click, an enquiry, or an email open (CNIL, Reference framework for commercial activity data management, 2026). Crucially, this period is a recommendation, not a statutory requirement.
This means you may choose a different duration, provided you can justify it. A long sales cycle may support a longer retention period; a highly volatile contact base may warrant a shorter one. What is not negotiable is the underlying principle: data minimisation.
Article 5 of the GDPR requires that data be "adequate, relevant and limited to what is necessary" for the purpose. Practically speaking, keeping an address "just in case" for years without any contact or legal basis is a liability. A contact dormant for four years is a compliance risk and a drag on your deliverability.
"The law requires deleting prospects after 3 years." Not quite. The CNIL presents these durations as "a reference point" from which organisations "may depart, provided they document their reasoning." The 3-year mark is a solid recommendation, but you are free to set your own retention period as long as it can be justified (CNIL, Data retention periods, 2026).
What must every email contain to be compliant?
Four elements, and they are cumulative. The CNIL specifically requires that "every communication" allow the sender to be identified and enable the recipient to "express, by a simple means, their refusal to receive further communications" (CNIL, 2026). The remaining requirements apply at the point of collection.
A valid legal basis
Consent for individuals, or legitimate interest with a right to object for professionals where the message relates to their professional role.
A clearly identifiable sender
The recipient must be able to recognise the organisation writing to them, without ambiguity or misleading sender details.
A simple way to unsubscribe
An unsubscribe link must appear in every message, be fully functional, and involve no unnecessary friction.
Information provided at collection
When collecting the address, state the intended use (prospecting) and inform the person of their rights.
None of these requirements is new, and that is precisely the trap: their apparent obviousness leads teams to overlook them. An unsubscribe link pointing to a broken page, a missing collection notice on a form added in haste by another team. These details, more than any grand principle, are what trigger complaints. Email compliance depends as much on rigorous execution as on knowing the rules.
Shared account across multiple teams: who is responsible, and how should access be secured?
Your organisation is the data controller, not each team in isolation. The data controller is the party that "determines the purposes and means of processing"; the ESP is the data processor (CNIL, How to identify your role correctly, 2025). Marketing, sales, and events are not separate controllers: they all operate under a single accountability.
This shared accountability has a direct consequence: securing access is a legal obligation. Article 32 of the GDPR requires "appropriate technical and organisational measures" and specifies that anyone with access to data may process it only "on the instructions of the controller." In practice, limiting who can view and export which data is part of compliance.
In a shared sending account, this is often the weakest link. When five people all have full access to the entire contact base, the segmentation required by Article 32 simply does not exist. Our Brevo multi-team governance guide details how to establish these perimeters; for Mailchimp, see Mailchimp multi-team governance. All of this must be documented in the record of processing activities required by Article 30.
In the shared accounts we review, the most common GDPR gap is not consent: it is access. Everyone can see everything, export everything, and email the entire list. Restricting access by team is one of the simplest security measures to implement, and one of the first expected under Article 32.
What do you actually risk in the event of non-compliance?
More than in the past. In 2025, the CNIL issued 83 sanctions, of which 10 related specifically to commercial prospecting, reaffirming that consent is mandatory (CNIL, 2025 sanctions review, 2026). Email marketing is now an established area of enforcement.
The ceiling is sobering. Article 83 of the GDPR provides for fines of up to €20 million, or 4% of total annual worldwide turnover, whichever is higher. Less serious infringements fall under a first tier capped at €10 million or 2%.
Should you therefore fear the maximum fine for a broken unsubscribe link? No: sanctions are proportionate. But the real day-to-day risk for a marketing team is more mundane: a complaint from a recipient, a triggered investigation, and the burden of proving that everything was in order. That is where consent audit trails and access controls stop being theoretical.
The access controls Article 32 requires, Sendgate makes simple.
Sendgate sits on top of your existing sending account, with no migration required, and segments who can access which lists and email which contacts. You put a required GDPR security measure in place, while keeping a clear view of who does what with your data.
Try it free →Brevo supported today, Mailchimp coming soon · This is not legal advice · Not affiliated with the brands mentioned
Key takeaways
GDPR compliance for email rests on four pillars: a legal basis suited to the recipient (consent for B2C, legitimate interest for B2B), clear information at the point of collection, a simple unsubscribe mechanism in every message, and a justifiable retention period. Two myths to set aside: double opt-in is not mandatory, and the "3-year" guideline is a recommendation, not a statute.
For teams sharing a sending account, a fifth obligation is added, and frequently overlooked: restricting and logging access to contact data, as required by Article 32. In 2026, with the CNIL stepping up sanctions on prospecting, this rigour in execution, proof of consent and control of access, is what protects you.
Frequently asked questions
Is consent required to send a marketing email in 2026?
Is double opt-in mandatory under the GDPR?
How long can you keep a prospect's email address?
Who is responsible for data in a shared sending account?
What must an email contain to be GDPR-compliant?
What are the penalties for non-compliance?
Sources
- CNIL, Commercial prospecting by email, SMS-MMS and automated calling, accessed 2026-06-22. cnil.fr
- CNIL, Reference framework for commercial activity data management (prospect retention: 3 years), accessed 2026-06-22. cnil.fr (PDF)
- CNIL, Data retention periods, accessed 2026-06-22. cnil.fr
- CNIL, GDPR: how to identify your role (controller / processor), accessed 2026-06-22. cnil.fr
- CNIL, The record of processing activities (Art. 30), accessed 2026-06-22. cnil.fr
- GDPR, Article 5, data minimisation (via CNIL), accessed 2026-06-22. cnil.fr
- GDPR, Article 32, security of processing (via CNIL), accessed 2026-06-22. cnil.fr
- GDPR, Article 83, administrative fines (via CNIL), accessed 2026-06-22. cnil.fr
- CNIL, Sanctions and corrective measures: 2025 review, accessed 2026-06-22. cnil.fr
- European Parliament, Digital Omnibus (Commission proposal, 19 November 2025), accessed 2026-06-22. europarl.europa.eu
