Most marketing teams move fast. You buy a list, launch a campaign, and watch the opens roll in. GDPR asks you to answer one question before any of that: do you actually have the right to send this message to this person? Get it wrong and you're not just risking a fine. You're spending the trust that makes marketing work at all.
Marketing is where privacy rules meet real revenue, and it's where a lot of companies quietly cut corners. This guide walks through what GDPR and the ePrivacy rules ask of email and electronic marketing, where the B2B nuances actually live, and how OptiTech turns your consent practices into evidence you can show a customer or a regulator.
Consent and the soft opt-in
Under GDPR, consent has to be freely given, specific, informed, and unambiguous. That rules out the shortcuts marketers reach for by habit. A pre-ticked box isn't consent. Bundling "sign me up for marketing" into your terms of service isn't consent. Silence or inactivity isn't consent. The person has to take a clear, affirmative action for a purpose you've spelled out.
There's one practical exception worth knowing: the soft opt-in. If someone bought from you, or started to, you can often email them about similar products of your own, as long as you offered an easy opt-out when you collected their address and you offer it in every message since. The soft opt-in is narrow. It doesn't cover cold prospects, it doesn't cover unrelated products, and it doesn't stretch to a brand they've never heard of.
Where ePrivacy overlaps GDPR
GDPR isn't the only rule in play. The ePrivacy rules, carried into national law across the EU, govern electronic marketing channels directly: email, SMS, and automated calls. The two work together. ePrivacy tells you whether you may use the channel at all, usually requiring prior consent for unsolicited marketing. GDPR governs the personal data behind it: the lawful basis, the transparency, the retention, and the rights.
You can't satisfy one and ignore the other. A campaign can be fine under GDPR's data rules and still break the ePrivacy requirement for consent to email in the first place. Treat them as a pair, and document how each message clears both.
Keep consent records you can prove
Accountability is the part teams forget until an audit or a complaint lands. If you rely on consent, you have to prove you got it. That means recording who consented, when, what they saw at the time, what they agreed to, and how they did it. "We're pretty sure they signed up" is not a record.
Withdrawal matters just as much. GDPR says pulling consent has to be as easy as giving it, and you have to honor it promptly. So your records need to capture the full lifecycle: the opt-in, any preference changes, and the opt-out, each with a timestamp and a source.
Log the context, not just the checkbox
A consent record is only useful if it captures what the person actually saw. Store the wording of the opt-in, the date, and the source alongside the yes. When a regulator asks "consent to what, exactly?", you'll have the answer instead of a guess.
Honor opt-outs and preferences
Every marketing message needs a clear, working way out. An unsubscribe link that dead-ends, or a preference update that quietly fails, isn't a minor bug. It's a compliance gap and a fast way to lose the reader for good.
Process opt-outs quickly and completely. Keep a suppression list so an unsubscribed contact doesn't reappear the next time someone imports a spreadsheet. A preference center helps here: instead of an all-or-nothing choice, let people pick the topics and the frequency they want. You keep more of your audience, and you show a regulator that respecting choice is built into how you operate.
B2B has nuance, not a free pass
A myth runs through a lot of sales teams: GDPR doesn't apply to B2B. It does. A named person at a company is still a person, and their work email is still personal data. What changes is the balance.
For some B2B outreach, you can lean on legitimate interest rather than consent, especially when your product is clearly relevant to the recipient's role. That's not a blank check. You still owe transparency about where you got their details, a genuine opt-out, and a real connection between your message and their job. Blasting a scraped list of every "manager" you could find isn't legitimate interest. It's the thing the rules exist to stop.
Lead data hygiene
Marketing runs on lead data, and lead data goes stale and murky fast. Every contact in your funnel should trace back to a source and a lawful basis you can name. Purchased and scraped lists are the danger zone, because you usually can't inherit someone else's consent, and you often can't prove the basis at all.
Good hygiene is ongoing, not a one-time cleanup. Collect only what you need, keep it accurate, and delete it when the purpose is done. Set retention limits so old prospects don't linger in your systems forever, and review your sources so you're not importing risk with every new campaign.
Turn consent into evidence with OptiTech
Here's where the work pays off. In the OptiTech Console, your marketing activity becomes a documented processing activity, linked to its lawful basis, its consent records, and its retention rules. The controls that keep you honest, like working opt-outs, suppression, and source tracking, map to evidence you collect on a schedule instead of scrambling for during a review.
Because OptiTech keeps your data in the EU only, in Stockholm and Frankfurt, you can answer the residency question that always comes up without a caveat. And when a buyer's security review asks how you handle marketing consent, you don't write a one-off email. Your trust center already shows your posture across GDPR and your other frameworks, so the answer is published and current.
Getting started
You don't have to fix everything at once. A realistic first pass looks like this:
- Map your marketing activity as a processing activity, with its lawful basis written down.
- Wire up consent records so every opt-in captures who, when, what, and how.
- Make opt-outs bulletproof with a suppression list and a preference center.
- Audit your lead sources and set retention limits on stale contacts.
- Publish your posture through a trust center so buyers stop having to ask.
Marketing and privacy aren't opponents. The teams that treat consent as a habit send to people who want to hear from them, and they can prove it on demand. That's better marketing and better compliance at the same time.
Ready to turn your marketing consent practices into evidence you can show? Book a demo and see how OptiTech connects your records, controls, and evidence.
