How UK GDPR Has Changed Email Marketing

(and What Businesses Are Still Getting Wrong…)

It has been about a decade since GDPR came into force, replacing the 1995 Data Protection Directive. There are still mistakes being made that probably should have been sorted out on day one - and these are basic things that we get asked about all the time.

UK GDPR came into effect in 2018. And yet, if you open most small business email lists, you will still find contacts that have not properly consented, signup forms without clear opt-in language, and welcome emails that bear no relation to what the person actually signed up for.

Misunderstanding this is not just a legal problem, it also causes a very practical marketing issue.

What UK GDPR actually changed

Before GDPR, many businesses operated on an opt-out model. You collected someone's details, added them to your email list, and they could unsubscribe if they wanted to. GDPR flipped that. The burden is now on the business to demonstrate that the person actively chose to receive marketing communications, and to keep records of this.

  • No pre-ticked boxes are allowed, it has to be someone’s free will to choose

  • You can’t force someone to tick a box in order to submit the form (we see this often!)

  • No bundled consent hidden in terms and conditions

  • Clear, specific language about what they are signing up for

  • Easy access your data and privacy policy information

  • A record of when and how consent was given (usually captured through your email list or CRM system)

  • An easy, functioning way to withdraw consent at any time

  • The ability to request what data you have on file about someone

What businesses are still getting wrong in 2026

  • Imported lists from old CRM systems. Many businesses still have lists of contacts collected before 2018 whose consent does not meet GDPR standards. It’s really important to regularly cleanse your data lists.

  • Bought or rented lists. Purchasing a list of email addresses and sending unsolicited marketing to them is not compliant with UK GDPR or PECR, full stop. Generally we don’t recommend this as a tactic because the data you’re renting could be fake, out of date, forced consent or any number of other unethical reasons. It’s always best to slowly build your own list of targeted recipients.

  • Vague consent language. 'Subscribe to our news' is not sufficient if what you then send is a sales promotion. Consent must be opt-in, and specific. Consider segmenting the data in order to deliver specific and relevant content to each recipient.

  • No records of consent. If the ICO asks you to demonstrate consent, you need to be able to show when it was given, how, and what language was used.

  • Reactivation campaigns without a basis. Running a 'we miss you' campaign to people who have been inactive for two years, and who you have no valid consent to contact, is a GDPR violation.

The marketing case for getting this right

A list of 1,000 engaged subscribers is worth more than a list of 10,000 people who cannot remember signing up and do not care about what you send. Getting your GDPR house in order is not just a legal necessity. It is marketing improvement and just good business sense.

Need help auditing your email list and consent practices? It is one of the most practical things we help clients with. Get in touch, hello@ipsaconsulting.co.uk

Previous
Previous

Flexible working is not a perk. It's a stance.

Next
Next

The Most Ethical Marketing Tools Available in the UK (2026)