GDPR & consent
An overview of the GDPR — what it is, who it affects, and how eMarketeer helps you manage consent and stay compliant.
This article explains what the General Data Protection Regulation (GDPR) is, what eMarketeer does about it, and what you can do as a customer.
The GDPR has been in full effect since 25 May 2018 and sets a high bar for global privacy rights and compliance. eMarketeer complies with the regulation and has updated its business and compliance processes accordingly. This guide is informational only — it is not legal advice. We encourage you to work with legal and other professional counsel to determine how the GDPR applies to your organization.
What is GDPR?
GDPR is a European privacy law approved by the European Commission in 2016. It replaced an earlier EU privacy directive known as Directive 95/46/EC (the "Directive"), which had been the basis for European data protection law since 1995.
A regulation such as the GDPR is a binding act that must be followed in its entirety throughout the EU. It strengthens, harmonizes, and modernizes EU data protection law and enhances individual rights, consistent with the European understanding of privacy as a fundamental human right. Among other things, it regulates how individuals and organizations may obtain, use, store, and erase personal data. It has a significant impact on businesses around the world.
When did it take effect?
GDPR was adopted in April 2016 and became enforceable on 25 May 2018. There was no grace period.
Who does it affect?
The scope of GDPR is very broad. It applies to:
All organizations established in the EU.
All organizations involved in processing the personal data of EU citizens, regardless of where they are established and regardless of where the processing takes place. This is the principle of "extraterritoriality."
Every organization should assess whether it processes the personal data of EU citizens. GDPR applies across all industries and sectors.
What is considered "personal data"?
Personal data is any information relating to an identified or identifiable individual — any data that could be used, alone or with other data, to identify a person. That includes obvious identifiers such as names, addresses, and email addresses, but also IP addresses, behavioral data, location data, biometric data, financial information, and much more.
For eMarketeer customers, most of the information you collect about contacts will be considered personal data under the GDPR. Pseudonymized data is also considered personal data if the pseudonym can be linked back to a specific individual.
Sensitive personal data, such as health information or data revealing racial or ethnic origin, requires even greater protection. You should not store data of this nature in your eMarketeer account.
What does it mean to "process" data?
Per the GDPR, processing is "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction."
In practice, if you collect, manage, use, or store any personal data of EU citizens, you are processing EU personal data under the GDPR. If any of your eMarketeer contacts contain the email address, name, or other personal data of an EU citizen, you are processing EU personal data.
Even if you do not believe your business is affected, the underlying principles of GDPR remain relevant. European law tends to set the trend for international privacy regulation, and stronger privacy practices can be a competitive advantage.
How is GDPR different from the Directive?
GDPR preserves many principles of the Directive but introduces several ambitious changes. The most relevant for eMarketeer customers are:
Expanded scope. GDPR applies to all organizations established in the EU or processing the data of EU citizens, introducing extraterritoriality.
Expanded definitions of personal and sensitive data, as described above.
Expanded individual rights. EU citizens gain several important new rights:
Right to be forgotten — an individual may request that an organization delete all data about them without undue delay.
Right to object — an individual may prohibit certain uses of their data.
Right to rectification — individuals may ask for incomplete data to be completed or incorrect data to be corrected.
Right of access — individuals have the right to know what data about them is being processed and how.
Right of portability — individuals may request that personal data held by one organization be transferred to another.
Stricter consent requirements. Consent is a fundamental aspect of the GDPR. You must obtain consent for every use of personal data unless you can rely on a separate legal basis (see point 5). The safest route is explicit consent:
Consent must be specific to distinct purposes.
Pre-ticked boxes or inactivity do not constitute consent — contacts must explicitly opt in.
Separate consent must be obtained for different processing activities, so you must be clear about how data will be used.
Stricter processing requirements. Individuals have the right to receive "fair and transparent" information about the processing of their personal data, including:
Contact details for the data controller.
The purpose of the data, which should be as specific ("purpose limitation") and minimized ("data minimization") as possible.
The retention period, which should be as short as possible ("storage limitation").
The legal basis. You cannot process personal data just because you want to — you need a legal basis such as performance of a contract, the individual's consent, or your organization's "legitimate interest."
The GDPR introduces many more principles and requirements. Review the regulation in full to understand how it applies to you.
Does the GDPR cover cross-border data transfers?
Yes. The GDPR contains provisions for transferring personal data from EU member states to third-party countries such as the United States. These provisions do not differ radically from the Directive. The GDPR does not require personal data of EU citizens to be stored only in EU member states, but it does require certain conditions to be met before personal data is transferred outside the EU, and it lists several legal grounds organizations can rely on.
One such legal ground is an "adequacy decision" — a decision by the European Commission that an adequate level of protection exists for personal data in the country, territory, or organization where it is being transferred.
Do you need to comply with the GDPR?
Consult legal counsel about the full scope of your obligations. Broadly speaking, if your organization is established in the EU or processes the personal data of EU citizens, the GDPR applies to you. Even collecting or storing the email addresses of EU citizens is enough to bring you in scope.
What happens if you do not comply?
Non-compliance can result in fines of up to 20 million euros or 4% of global annual turnover, whichever is higher.
Controller or processor?
If you access personal data, you do so as either a controller or a processor. Different requirements apply to each.
A controller is an organization that determines the purposes and means of processing personal data, and which personal data is collected from the data subject for processing.
A processor is an organization that processes data on behalf of the controller.
The GDPR has not changed the fundamental definitions of controller and processor, but it has expanded the responsibilities of each party.
Controllers retain primary responsibility for data protection, including reporting data breaches to data protection authorities. The GDPR also places some direct responsibilities on the processor. In the context of the eMarketeer application and related services, our customers are usually the controller — they decide which contact information is uploaded to their account and which emails are sent. eMarketeer acts as the processor.
eMarketeer and GDPR compliance
eMarketeer complies with GDPR and views the regulation as an important milestone for data privacy. Our compliance work included reviewing — and updating where necessary — our internal processes, procedures, data systems, and documentation.
Among other things, we have:
Updated our Data Processing Agreement (DPA) to meet the requirements of the GDPR, so you can lawfully transfer EU personal data to eMarketeer and we can lawfully receive and process it.
Updated our third-party vendor contracts to meet GDPR requirements, so we can lawfully transfer EU personal data to those third parties.
Reviewed all features and templates for improvements that benefit users subject to the GDPR.
We are prepared to address requests related to expanded individual rights under the GDPR:
Right to be forgotten — you may terminate your eMarketeer account at any time, after which we permanently delete your account and all associated data.
Right to object — you can opt out of including your data in our data science projects by changing the Privacy Setting on your account.
Right to rectification — you can access and update your eMarketeer account settings at any time. You can also contact eMarketeer to access, correct, amend, or delete information we hold about you, as explained in our Privacy Policy.
Right of access — our privacy policy describes what data we collect and how we use it. For specific questions, contact privacy@emarketeer.com.
Right of portability — we will export your account data to a third party on request.
How can eMarketeer assist with your compliance?
There are several ways eMarketeer can help with your compliance.
Expanded individual rights. eMarketeer can help you respond to requests from your contacts under their expanded individual rights.
Right to be forgotten. You may delete individual contacts on request at any time. Individuals may also contact eMarketeer directly to request deletion of their data from individual accounts or across multiple accounts.
Right to rectification. You may update contact data in your account at any time. Any data subject may also contact eMarketeer directly to access, correct, or delete information we hold about them.
Right of access. Our Privacy Policy describes what data we collect and how we use it. Your contacts may contact us directly to request access to information we hold about them.
Right of portability. You can export contact information at any time from your eMarketeer account.
Stricter consent and processing requirements
You must lawfully obtain and process email addresses and other personal data from your contacts.
Personal data is typically collected through embedded forms designed in eMarketeer. These forms are one of the most important tools for GDPR compliance:
Design each form so that the body and footer language is clear, specific, and covers every purpose for using the information you collect.
It is your responsibility to obtain consent from your contacts to send their information to eMarketeer for processing. Make sure your forms, pop-ups, and similar elements include language that provides this consent.
We recommend double opt-in sign-ups for gathering contacts.
The ability to withdraw consent or change preferences should be easily accessible.
An unsubscribe option is automatically included in the footer of every standard template in eMarketeer, so any recipient can easily unsubscribe. This helps you comply with the GDPR when a contact withdraws consent.
Keep contact information up to date — names, contact details, and so on — when a contact requests changes.
Keep accurate records, especially of consent. eMarketeer stores a record of consent in your account. When you use an eMarketeer sign-up form, the email address, IP address, and timestamp are recorded for every submission, giving you proof of consent.
Any consent you obtain must comply with the GDPR, regardless of when it was obtained. Recital 171 indicates that pre-existing consent that meets GDPR standards can continue to be relied upon. You do not need to re-request consent automatically, provided the original consent met the requirements. Consult local counsel if you are uncertain, or contact your contacts to re-request consent or rely on a different lawful basis.
Review any eMarketeer integrations you use, along with their terms, to ensure you have disclosed the data processing activities associated with them. For example, if you use the Web Tracker to monitor contact behavior on your website, implement an appropriate cookie notice and consent mechanism for the cookies and pixels involved.
Review your organization's privacy statement to make sure it notifies contacts that their personal data will be transferred to and processed by eMarketeer. You may want to identify eMarketeer specifically as one of your processors and describe the processing activities we perform, such as collection via sign-up forms and storage within your eMarketeer account.
eMarketeer consent features
eMarketeer includes several features to help you collect, store, and manage consent:
Consent system — store and manage consent status per email address.
Form consent checkboxes — built-in consent fields in eMarketeer forms.
CRM sync — consent can sync automatically with integrated CRMs.
Audit logs — a record of consent changes for accountability.
Consent API — manage consent programmatically via the API.
Automations and Journeys — Journey steps can read and update consent as part of automated sequences.
If you have specific questions about GDPR and your use of eMarketeer, email support@emarketeer.com.
Last updated
Was this helpful?

