Five obligations, five misconceptions
The GDPR applies based on where your subscribers live — not where your company is based. Here is what it asks of you, and what it does not.
9 min read
If any of your subscribers live in the European Union, the GDPR applies to how you handle their data — whether you are based in the US, the UK, Canada or anywhere else. Three requirements run through everything: get consent or a legitimate basis, be able to prove it, and let people leave without friction. The five obligations below spell out what that means in practice. Everything here is sourced from the European data protection framework; nothing is inferred.
- 1
Consent — and when it is not required
The GDPR applies to you if your subscribers live in the EU — regardless of where your company is incorporated. A US LLC, a UK Ltd, a Canadian sole trader sending to European inboxes: the GDPR covers that data. The main difference from laws like CAN-SPAM is that opt-out after the fact is not enough; you need a lawful basis before sending.
You write to private individuals. Prior consent is the standard basis. It must be freely given, specific, informed and unambiguous: an unticked checkbox that the person actively checks. Pre-ticked boxes are invalid under EU law. An address scraped from a public website is not consent.
You write to professionals, at their work address. Prospecting on legitimate interest is allowed when the message relates to their profession — provided they were informed of that use at the time their address was collected, and can object easily.
You write to your existing customers. You can contact them about similar products or services without fresh consent, if there was an actual purchase or service relationship. Creating an account alone does not establish this.
- 2
Proof, the part everyone forgets
Obtaining consent is not enough: you must be able to demonstrate it. For every signup, keep the date, the origin — which form, which page — and the exact wording shown next to the checkbox. A tool that does not keep them leaves you defenceless the day you are asked.
That is what made email confirmation — double opt-in — the norm. No text requires it: it is simply the simplest way to produce dated proof, and it filters out mistyped addresses along the way.
The inherited list. You take over a file built before you, with no idea where it came from. The rule is unpleasant and simple: without proof of consent, you do not use it. The only defensible move is a re-permission campaign to the still-active part of the file, asking for explicit confirmation. Whatever does not answer is not kept.
- 3
The exit: simple, and honoured
Every message must let the reader identify who is sending it and refuse further messages by a simple means. A visible unsubscribe link — not light grey on white — that works immediately, without asking anyone to log in.
The request is honoured whatever channel it arrives by: a link, a reply to the message, a phone call. And on a request for access or correction, you have one month at most to answer.
On top of that comes the technical one-click unsubscribe header, which Gmail and Yahoo have required since February 2024 from senders above 5,000 messages a day. Mailcheer sets it on every send, and an address that unsubscribes enters the suppression list: no re-import can put it back.
The email footer carries two legally required items: who writes, and how to leave. - 4
Say who you are
Your identity and a postal address in the footer of every message. Strictly speaking that comes from anti-spam law rather than the GDPR — the effect is the same, and its absence also hurts deliverability.
You enter it once in Settings. As long as it is missing, the pre-send checklist flags it on every campaign.
- 5
The data itself — and what non-EU companies must know
Collect only what you use. Every field you ask for at signup must match a use you can name out loud. Ask for a name only if you actually use it in the email.
Say where it lives. The hosting country and your processors belong in your privacy policy. For Mailcheer: subscriber data is hosted in Germany, at Hetzner; sending goes out from Ireland. Both are in the EU — this matters for your privacy policy.
Non-EU companies with EU subscribers may need to appoint an EU representative under Article 27 GDPR, unless they process data only occasionally and on a small scale. This is a compliance question to raise with a lawyer, not a technical setting.
Do not keep data forever, and erase it properly. Mailcheer's delete function removes the subscriber record from the database — it does not merely mark them unsubscribed. An address that is deleted can reappear through a re-import: the suppression list prevents this by blocking re-addition even from a new file.
What the GDPR does NOT require — and how it differs from CAN-SPAM
It does not require double opt-in. It requires proof of consent; double opt-in is the most practical way to have that proof.
It does not forbid writing to professionals at their work address, when the message relates to their job and they can object.
It does not forbid open and click tracking. It requires disclosure in your privacy policy.
It does not force hosting in a specific country. Anywhere in the EU works; outside the EU you need a valid transfer framework (adequacy decision or Standard Contractual Clauses).
CAN-SPAM (United States) works on an opt-out model — you may send until someone objects, as long as you identify yourself, include a postal address, and honor opt-outs within ten days. The GDPR is stricter: for private individuals, you need a lawful basis before the first send. The two are not in conflict, but neither replaces the other: CAN-SPAM adds obligations the GDPR never mentions — a valid postal address in every message, a subject line that does not mislead, and opt-outs honoured within ten business days. Writing to Americans and Europeans means meeting both.
This guide gives you bearings, not legal advice. The GDPR landscape for non-EU companies is still evolving — for anything specific to your situation, the EDPB guidelines and a qualified lawyer are the right sources.
The legal framework described here draws on the EDPB and CNIL published guidelines on email prospecting. Nothing is inferred or rounded: on a subject where one approximation costs money, the primary sources are linked.
The one-click unsubscribe of obligation 3 is also a technical requirement from the inbox providers: the Gmail, Yahoo and Outlook rules say from what volume it becomes due, and in what form.
Words from this guide