GDPR and LGPD Email Compliance: A Practical Guide for Marketers

Consent, retention and the right to erasure — what GDPR and Brazil's LGPD really require from email marketers, and how clean data reduces your compliance risk.

GDPR and LGPD Email Compliance: A Practical Guide for Marketers

Every email address in your database is personal data. That single fact places your entire email program inside the scope of the world's two most influential privacy laws: the European Union's GDPR (General Data Protection Regulation, in force since 2018) and Brazil's LGPD (Lei Geral de Proteção de Dados, Law 13.709/2018). If you collect subscribers in Europe or Brazil — or simply market to people who live there — these laws govern how you obtain, store, use and delete those addresses.

The good news: the rules are more practical than they look, and most of them line up with what great email marketers already do — send to people who asked to hear from you, keep your data accurate, and let go of contacts you no longer need. This guide walks through both frameworks side by side, from legal bases and consent to retention limits and enforcement, and shows where clean, validated data materially reduces your risk.

Key Takeaway

GDPR and LGPD compliance for email rests on four pillars: a documented legal basis for every contact, provable consent collected without dark patterns, honored data subject rights (especially erasure and objection), and retention limits that are written down and enforced automatically. A validated, well-pruned list supports all four.

Why Email Marketers Cannot Ignore These Laws

Both regulations reach far beyond their borders. The GDPR applies not only to companies established in the EU, but to any organization offering goods or services to people in the EU or monitoring their behavior. The LGPD works the same way: it covers processing carried out in Brazil and processing aimed at offering goods or services to individuals located in Brazil — regardless of where the company sits.

For an email marketer, that means a newsletter list with French, German or Brazilian subscribers puts you in scope even if your business has no office in either region. And unlike laws such as the US CAN-SPAM Act, which mainly regulate the sending of email, GDPR and LGPD regulate the entire lifecycle of the address: collection, storage, use, sharing and deletion.

GDPR vs LGPD at a Glance

The LGPD was heavily inspired by the GDPR, so the two share the same architecture: principles, legal bases, data subject rights, and a supervisory authority with fining powers. The differences sit in the details:

GDPR (EU) LGPD (Brazil)
Regulator National supervisory authorities (CNIL, AEPD, Irish DPC and others), coordinated by the EDPB ANPD — Autoridade Nacional de Proteção de Dados, a single national authority
Legal bases 6 (Article 6) 10 (Article 7)
Maximum fine €20 million or 4% of global annual turnover, whichever is higher 2% of revenue in Brazil, capped at R$50 million per infraction
Key rights Access, rectification, erasure, portability, objection to direct marketing Confirmation, access, correction, anonymization or deletion, portability, revocation of consent
In force since May 2018 September 2020 (fines applicable from August 2021)
4%
of global annual turnover — the GDPR's top fine tier (or €20 million, whichever is higher)
R$50M
the LGPD's cap per infraction, at up to 2% of a company's revenue in Brazil
3 years
retention for inactive prospects recommended by France's CNIL before deletion

Legal Bases: Consent and Legitimate Interest

The GDPR's six bases — and the two that matter for email

Article 6 of the GDPR lists six lawful bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. For marketing email, only two are realistically available:

  • Consent — the default and safest basis for sending promotional email, and effectively mandatory for new prospects. The EU's ePrivacy rules layer on top of the GDPR here: unsolicited electronic marketing generally requires prior opt-in.
  • Legitimate interest — a narrower path, mostly defensible for communications with existing customers about similar products or services (the so-called soft opt-in), and only after a documented balancing test. Regulators and courts interpret legitimate interest restrictively for marketing, and the recipient's right to object always wins.

The LGPD's ten bases

Article 7 of the LGPD lists ten legal bases. Beyond consent, contract, legal obligation and legitimate interest, it adds bases with no direct GDPR equivalent — most famously credit protection, plus research, health protection and judicial process. For email marketing, however, the practical analysis mirrors Europe: consent is the standard basis for promotional messages, and legitimate interest can support communication with existing customers, provided you run and document a balancing test and offer an easy opt-out. LGPD consent must be free, informed and unambiguous, given for specific purposes — and the controller carries the burden of proving it.

What Valid Consent Actually Looks Like

Both laws define consent in nearly identical terms. To hold up under scrutiny, consent must be:

  • Freely given — not bundled with unrelated terms, and never a condition for a service that does not require it.
  • Specific — one purpose per checkbox. Consent to "receive our newsletter" does not cover sharing the address with partners.
  • Informed — the subscriber knows who is collecting the data, what they will receive, and how to withdraw.
  • Unambiguous — a clear affirmative action. The Court of Justice of the EU confirmed in its 2019 Planet49 ruling that pre-ticked boxes are not valid consent; the same logic applies under the LGPD.

Withdrawal must be as easy as giving consent — which is why every message needs a working one-click unsubscribe, and why consent records (timestamp, source form, IP, exact wording shown) belong in your ESP or CRM, not in a spreadsheet someone maintains by hand.

Double opt-in: best practice, and sometimes the expectation

Neither the GDPR nor the LGPD literally mandates double opt-in (confirmed opt-in). But because both laws make you prove consent, the confirmation click is the strongest evidence you can hold. In Germany, courts have long treated double opt-in as the de facto standard for proving email consent, and regulators across Europe recommend it. It also delivers a marketing bonus: it blocks typos, bots and fake signups from ever entering your list — addresses that would otherwise bounce, distort metrics and mean you are storing personal data of people who never subscribed at all.

Illustration comparing GDPR and LGPD requirements for email marketing: consent, data subject rights and retention limits

Data Subject Rights That Hit Your Email Program

Both laws give individuals enforceable rights over their data, and four of them land directly on marketing teams:

  • Access — a subscriber can ask what data you hold on them: profile fields, consent records, engagement history. You need to be able to export it within the legal deadline.
  • Erasure (right to be forgotten) — on request, personal data used for marketing must be deleted when there is no other lawful reason to keep it.
  • Portability — the subscriber can request their data in a structured, machine-readable format.
  • Objection — under the GDPR, the right to object to direct marketing is absolute: once someone objects, you stop. No balancing test, no exceptions. The LGPD reaches the same outcome through revocation of consent and opposition to processing.

Suppression list vs deletion: get the mechanics right

Here is the operational trap: if you fully delete an unsubscribed contact, nothing stops that address from being re-imported next quarter from a CRM sync or a partner list — and now you are mailing someone who explicitly told you to stop. The accepted practice is a suppression list: erase the marketing profile and history, but retain a minimal record (ideally a hashed email address) whose only purpose is to guarantee the person is never contacted again. Document this in your privacy notice; keeping minimal data to honor an opt-out is itself a recognized lawful purpose.

Retention: Keep Only What You Still Need

The storage limitation principle appears in both laws: personal data may be kept only as long as necessary for the purpose it was collected for. For email marketing, "forever" is not a retention policy — it is a liability. Practical guidance:

  • Define retention periods in writing. France's CNIL recommends deleting inactive prospect data around three years after the last meaningful contact — a widely used benchmark even outside France.
  • Automate the purge. A policy that depends on someone remembering to run a cleanup script will fail an audit. Retention should be enforced by the system, on a schedule.
  • Purge processing artifacts too. Uploaded CSVs, validation exports and campaign files all contain personal data. They need expiry dates just like database records.
  • Mind enforcement precedent. The French regulator has sanctioned companies specifically over disproportionate retention — in 2024 it fined the B2B data company Kaspr €200,000, citing among other issues contact data kept for years longer than justified.

International transfers, briefly

If subscriber data leaves the EU or Brazil — for example, to a US-based ESP — both laws require safeguards. Under the GDPR that typically means an adequacy decision or standard contractual clauses (SCCs); under the LGPD, the ANPD approved its own transfer framework and standard contractual clauses in 2024. For marketers the takeaway is simple: know where your email stack stores data, and confirm your vendors offer a valid transfer mechanism in their data processing agreement.

What Enforcement Looks Like

These are not theoretical risks. European authorities fine email-related violations regularly: in 2025, France's CNIL fined Solocal Marketing Services €900,000 for commercial prospecting without valid consent and for passing prospect data to partners without a lawful basis. Consent sourcing, list purchases and retention have all featured in recent sanctions. In Brazil, the ANPD began issuing fines in 2023 and has since sanctioned businesses of all sizes — and beyond fines, both regulators can order processing bans, which for a marketing database means the list itself becomes unusable.

Practical Compliance Checklist for Email Marketers

  • Map every source of email addresses and record the legal basis for each segment.
  • Use unbundled, unticked, purpose-specific consent checkboxes on every form.
  • Implement double opt-in, at minimum for EU and Brazilian audiences.
  • Store consent evidence: timestamp, form, IP address and the exact text shown.
  • Never buy or rent email lists — consent cannot be transferred to you.
  • Honor unsubscribes immediately and maintain a hashed suppression list.
  • Build a workflow for access, erasure and portability requests with deadlines.
  • Write down retention periods per data category and automate the purge.
  • Verify your ESP and validation vendors provide a data processing agreement with valid transfer safeguards.
  • Validate your list regularly, so you are not storing personal data that serves no purpose.

Where Email Validation Supports Compliance

Email validation is not a legal service, but it directly operationalizes three obligations both laws impose:

  • Data minimization. Dead, abandoned and invalid addresses are personal data you hold for no purpose. Identifying and removing them shrinks your compliance surface — every purged record is one less record to secure, disclose or breach.
  • Accuracy. Both laws require personal data to be kept accurate and up to date. Regular validation flags addresses that no longer exist, keeping your database factually correct.
  • Consent integrity. Real-time validation at signup blocks typos and fake addresses, reducing the risk of mailing people who never subscribed — signals regulators read as careless data governance.

AT Valid and Your Retention Policy

AT Valid was built by a Brazilian company with the LGPD in mind from day one. The platform runs 20+ verification checks at 99.5% accuracy, and supports configurable data-retention policies with automated purge of processed files — so uploaded lists and results are deleted on the schedule your policy defines, not whenever someone remembers. Start with 200 free credits and align your list hygiene with your retention rules.

Related reading: see how disciplined list maintenance works in practice in our guide to email list hygiene best practices, and how to keep large databases clean at scale in B2B email data quality for CRMs.

Disclaimer

This article is provided for informational purposes only and does not constitute legal advice. Privacy laws evolve and their application depends on your specific situation — consult a qualified privacy or data protection professional before making compliance decisions.

Conclusion

GDPR and LGPD compliance is not a one-time project — it is a way of running an email program: collect addresses transparently, prove consent, respect every opt-out, and keep data only as long as it earns its place. Marketers who internalize these habits consistently find that the same discipline improves deliverability, engagement and sender reputation. Privacy-respecting lists simply perform better.

Ready to shrink your compliance surface? Create a free AT Valid account with 200 validation credits, clean out the addresses you no longer need, and put your retention policy on autopilot.

AT Valid
Written by AT Valid Team

The AT Valid team is dedicated to helping businesses improve email deliverability and marketing ROI.