GDPR, the General Data Protection Regulation, is a European Union law that governs how businesses collect, store, and use the personal data of individuals in the EU and EEA, including their email addresses.
What Makes GDPR the Strictest Baseline in This Space
What is GDPR requiring that sets it apart from most other privacy laws covered elsewhere in this glossary: unlike CAN-SPAM, which permits marketing email without upfront consent, GDPR treats consent as the default requirement before any personal data, including an email address, can be collected or used for marketing in the first place.
GDPR vs CAN-SPAM is a genuinely useful comparison for understanding the spectrum of email law, since CAN-SPAM sits at the permissive end and GDPR sits at the strict end, with laws like CASL somewhere in between.
What GDPR Consent Requirements Actually Look Like
GDPR consent requirements are specific about what counts as valid: consent has to be freely given, specific to the purpose it’s collected for, and given through a clear affirmative action, an unchecked box the subscriber actively checks, not a pre-checked box they’d have to notice and uncheck.
GDPR also grants individuals ongoing rights over data already collected, including the right to:
- See what data a business holds on them.
- Request its correction.
- Request its deletion entirely, sometimes referred to as the right to be forgotten.
What This Means for Email Marketing Specifically
GDPR email marketing compliance means every EU or EEA subscriber on a list needs to have given valid, documented consent before the first send, and that consent record needs to be genuinely retrievable if ever challenged, not just assumed to exist.
This applies regardless of where the business sending the email is physically located, GDPR reaches any business processing the data of EU residents, which is why stores selling internationally need to account for it even if they’re not based in Europe themselves.
Why GDPR Gets Taken More Seriously Than Most Privacy Laws
The regulation carries some of the most significant penalties in privacy law globally, with violations exposing a business to fines up to 20 million euros or 4 percent of global annual turnover, whichever figure is larger.
That scale of exposure, calculated against total global revenue rather than a fixed cap, is a large part of why GDPR compliance gets treated as a genuine legal priority by international businesses rather than a minor checkbox item, even relative to other consent-focused laws covered elsewhere in this glossary.
Related terms:
For Adflipr’s specific data handling and compliance practices, see our Privacy Policy. Adflipr’s signup forms include consent checkboxes that help stores collect GDPR-compliant consent at the point of signup.



