GDPR and email: what is ours, and what is yours
No platform can make you GDPR compliant, and any vendor claiming otherwise is selling you comfort. Here is the division of responsibility, stated plainly, so you know which parts you still have to do.
Who is responsible for what
GDPR splits responsibility between the controller, who decides why and how personal data is processed, and the processor, who processes it on the controller's instructions. When you use an email platform, you are the controller and we are the processor.
That division decides the question people most often get wrong. Whether you have a lawful basis to email a given person is your responsibility, not ours. We provide the mechanics — consent capture, suppression, unsubscribe handling, deletion — but no platform can supply a lawful basis for contacts you already hold. Any vendor implying otherwise is selling comfort rather than compliance.
Lawful basis for marketing email
For direct marketing to individuals, the two bases that realistically apply are consent and legitimate interests, and which one is available depends as much on the ePrivacy rules in the member state as on GDPR itself.
Consent has to be freely given, specific, informed and unambiguous — an affirmative action, not a pre-ticked box and not buried in terms someone accepted to download something else. If you rely on consent, the evidence of it is what matters: when it was given, what the person was told they were signing up to, and how you would demonstrate that if asked.
The soft opt-in — marketing similar products to an existing customer who was given the chance to object — is narrower than most marketers assume. It concerns your own similar goods or services, and the opportunity to object must be offered at collection and in every subsequent message.
- Record the timestamp, the source, the IP address where available, and the exact wording the person agreed to.
- Do not repurpose data collected for one stated purpose into an unrelated marketing programme — that is a different purpose and the original consent does not cover it.
- Never import a purchased list. There is no consent, and there is no legitimate interest that survives contact with a supervisory authority.
- Make withdrawal as easy as giving consent was: a working unsubscribe in every message, honoured across your whole account rather than one list.
Data subject rights, in practice
GDPR gives individuals rights of access, rectification, erasure, restriction, portability and objection. For email marketing the ones that arrive in practice are access, erasure and objection — and the objection right is absolute for direct marketing, meaning there is no balancing test to apply. If someone objects, you stop.
In Bluey you can export a contact's full record including their event history, correct their attributes, and delete them permanently. Deletion removes them from segments and flows as well as from the contact list, so an erasure request does not leave the person sitting in an automation that will email them next week.
International transfers
If personal data leaves the EEA, you need a transfer mechanism. In practice that usually means standard contractual clauses, supported by a transfer impact assessment where the destination country lacks an adequacy decision.
EU data residency is available on request rather than by default. If your obligations require data to stay in the EEA, raise it before you sign — moving an existing account between regions is not something that can be done retrospectively.
Retention
GDPR does not set retention periods; it requires that you do not keep personal data for longer than necessary for the purpose. For email marketing that means having a policy and applying it, rather than keeping everything indefinitely because storage is cheap.
A practical approach: suppress and then delete contacts who have not engaged in a defined period, keep suppression records themselves indefinitely because you need them to honour an opt-out, and delete event history on a rolling window. Our re-engagement template is built around exactly this, and the deliverability benefit happens to point the same way as the legal one.
What we will sign
A data processing agreement is available on request, along with standard contractual clauses where transfers require them and documentation to support a data protection impact assessment. If you need something specific for your own compliance file, ask for it by name and we will tell you plainly whether we can provide it.
GDPR interacts with national ePrivacy rules that differ meaningfully between member states, and the right answer for your organisation depends on facts this page cannot know. Take advice on your own position — particularly on lawful basis, which is the question that actually decides whether you may send.
Keep exploring
Need a DPA before you can trial anything?
Ask, and we will tell you plainly what we can provide and how quickly, rather than routing you into a sales sequence.