
Introduction
If your Shopify store ships to Europe or accepts EU customers at checkout, GDPR applies to your email marketing—full stop. It doesn't matter where your business is incorporated or whether you have a single EU employee.
The stakes are real: fines reach up to €20 million or 4% of global annual turnover for serious violations. Add in deliverability damage, spam complaints, and eroded customer trust, and non-compliance gets expensive fast.
GDPR compliance and high-performing email marketing actually point in the same direction. A smaller, fully consented list consistently outperforms a bloated one built on assumed opt-ins. Brands that treat compliance as a list-quality exercise rather than a legal checkbox come out ahead on every metric that matters.
This guide covers what GDPR actually means for email, which US brands it pulls in, the 7 core requirements, how to build a compliant program in Klaviyo, and a pre-send checklist you can use.
Key Takeaways
- GDPR covers any brand marketing to or collecting data from EU/UK residents—including US-based Shopify stores
- Marketing emails require explicit, active consent—pre-checked boxes and assumed opt-ins don't qualify
- The 7 GDPR principles govern how you collect, store, use, and delete subscriber data
- Unsubscribing must be as simple as subscribing—every marketing email needs a working opt-out
- Clean, consent-based lists reduce spam complaints, protect sender reputation, and drive higher revenue per send
What Is GDPR in Email Marketing?
GDPR—the EU's General Data Protection Regulation—has been in force since 25 May 2018. It governs how organizations collect, store, and use the personal data of people in the EU and UK, including for email marketing purposes.
What Counts as Personal Data
The definition is broader than it appears. Under Article 4(1) of the GDPR, personal data is any information relating to an identified or identifiable person. For email marketers, that includes:
- Personal email addresses (the Commission cites
name.surname@company.comas a direct example) - IP addresses
- Cookie identifiers
- Device and advertising IDs
- Behavioral tracking data—opens, clicks, pages visited—when linked to an identifiable person
Every tool in your email stack that touches this data—your ESP, CRM, popup platform—falls under GDPR's scope. That scope is wider than most US brands realize—especially those used to operating under CAN-SPAM.
GDPR vs. CAN-SPAM: A Critical Difference
The two frameworks take fundamentally different approaches to consent:
| CAN-SPAM (US) | GDPR (EU/UK) | |
|---|---|---|
| Model | Opt-out | Opt-in |
| Prior consent required? | No | Yes |
| Can you email cold contacts? | Yes, with opt-out option | No |
| Opt-out deadline | 10 business days | Immediate (within 1 month for data requests) |
| Governing body | FTC | National data protection authorities |

The FTC is explicit that CAN-SPAM requires no advance consent. GDPR operates on an opt-in basis instead—you cannot send marketing emails without prior, active agreement. That single distinction is the root of most compliance failures from US brands entering EU markets.
Does GDPR Apply to Your E-Commerce Store?
Three triggers pull any business under GDPR jurisdiction, regardless of where it's headquartered:
- EU establishment — You have an office, subsidiary, or operational presence in the EU or UK
- Offering goods or services to EU/UK residents — Even without an EU presence, if you accept EU customers, price in euros, offer EU-specific shipping, or have translated pages, you're intentionally targeting that market
- Monitoring behavior of EU/UK residents — Retargeting pixels, Google Analytics on EU traffic, and behavioral tracking of EU site visitors all qualify
The Shopify Store Reality
Consider a typical DTC scenario: a US-based brand with an international Shopify checkout, Klaviyo handling email flows, and Google Analytics running on all traffic. That brand almost certainly falls under GDPR—even without a single EU employee.
Simple website accessibility doesn't establish intentional EU targeting on its own. EU-priced products, active EU shipping options, or EU-focused ad campaigns are what tip the scale—and if any of those apply, you're in scope.
Start here: Pull your Klaviyo subscriber list and filter by EU/UK country data. If EU/UK contacts are there, GDPR applies. The real question is how well you're currently complying—not whether you need to.
What Are the 7 GDPR Requirements for Email Marketers?
The ICO's data protection principles guide outlines all seven. Here's how each one translates to email marketing practice:
| Requirement | What It Means for Email |
|---|---|
| 1. Lawful basis | Every send needs a documented legal reason—usually explicit consent for marketing, or contractual necessity for transactional emails |
| 2. Purpose limitation | Collect data for stated purposes only; don't repurpose a newsletter list for SMS without separate consent |
| 3. Data minimization | Collect only what you need—name and email for a newsletter, nothing more unless genuinely required |
| 4. Accuracy | Keep subscriber data current; honor corrections and suppression requests promptly |
| 5. Storage limitation | Don't retain subscriber data longer than necessary; define and enforce retention timelines |
| 6. Integrity & confidentiality | Protect subscriber data with encryption in transit (TLS), access controls, and staff training |
| 7. Accountability | You must be able to demonstrate compliance—not just claim it |

Three Areas Worth Expanding
Lawful basis varies by email type. Promotional campaigns and newsletters require explicit consent. Transactional emails (receipts, shipping confirmations) rest on contractual necessity.
The UK's "soft opt-in" exception allows marketing to existing customers about similar products, but only if a clear opt-out was offered at collection and appears in every subsequent message. This doesn't cover bought lists or cold prospects.
Beyond lawful basis, individual rights shape how you handle subscriber data day-to-day. EU subscribers can request access to, correction of, or deletion of their data. You need a documented process for responding within one month (Article 12 says "one month," not a fixed 30 days; a further two months is available for complex requests if the person is informed within the first month).
Breach notification follows its own strict timeline. If a breach occurs and risks individuals' rights and freedoms, you must notify the relevant supervisory authority within 72 hours of becoming aware. High-risk breaches—such as exposed financial data—also require direct notification to affected subscribers.
How to Build a GDPR-Compliant Email Marketing Program
Step 1: Audit Your Email Types and Lawful Basis
Before touching a single flow, list every email type your brand sends: promotional campaigns, newsletters, win-back sequences, abandoned cart reminders, post-purchase flows, transactional confirmations. Then document the lawful basis for each.
Create an internal "email lawful basis register"—a simple spreadsheet that maps each email type to its legal ground. This document is your first line of defense if a regulator or subscriber questions a send. Transactional emails belong under contractual necessity; everything promotional belongs under consent.
Step 2: Build Consent-First Opt-In Forms
A GDPR-compliant signup form has specific anatomy:
- Unchecked checkboxes for each communication type (email, SMS treated separately)
- Plain-language consent text: "I'd like to receive weekly promotional emails from [Brand]"
- A visible privacy policy link at the point of collection—not buried in a footer
- No bundled consent: don't attach marketing opt-in to terms of service acceptance
Non-compliant examples are common on Shopify stores: vague "sign up for updates" language, pre-ticked newsletter boxes at checkout, or a single checkbox that bundles email and SMS consent together. All of these fail under GDPR.
Double opt-in delivers stronger proof of consent than a single checkbox. After signup, send a confirmation email requiring a click before the subscriber hits your active list — this filters bots and typos while producing a more engaged audience.
As a Klaviyo Certified Partner, FluenceFlow builds popup and opt-in systems within clients' own Klaviyo accounts. Klaviyo's double opt-in configuration is manageable at the list level, though consent copy and form strategy matter as much as the technical setup.
Step 3: Record Consent with an Audit Trail
For every subscriber, store:
- Timestamp of signup and confirmation
- The exact consent text shown at signup
- Version number of that consent text
- Source form or page
- How they consented (form, popup, checkout)
These fields map directly to what ICO guidance requires: who consented, when, what they were told, and how. Klaviyo's native consent properties — $consent, $consent_form_id, $consent_form_version, $consent_timestamp — capture all of this when forms are configured correctly. If you can't prove consent existed, regulators treat it as if it never did.

Step 4: Make Unsubscribing Effortless
Every marketing email must include a visible, working unsubscribe link—no login required. Suppression must be immediate, and list-unsubscribe headers should be implemented for one-click compliance with Gmail and Yahoo.
A preference center—where subscribers can opt out of specific email types rather than all communications—reduces list churn while keeping you compliant. Letting someone turn off promotional emails while keeping transactional ones is both better UX and better compliance.
Step 5: Enforce Data Retention and List Hygiene
Set clear timelines and stick to them:
- Active subscribers: Retained while they engage
- Inactive subscribers (no opens/clicks in 6–12 months): Trigger a re-engagement campaign before suppression
- Hard bounces: Remove immediately
- Suppression list: Maintain a minimal list (hashed email only) to prevent accidental re-addition
This work is identical to good deliverability practice. Validity's 2025 Email Deliverability Benchmark Report identifies spam complaints as the single biggest factor depreciating sender reputation—Yahoo flags problems at 0.3% complaint rate, while best-in-class senders stay below 0.1%. Non-consented subscribers drive complaint rates up. Clean your list for GDPR, and you get better inbox placement as a direct result.
GDPR Violations: Fines and Hidden Costs
Fine Tiers
| Violation Severity | Maximum Fine |
|---|---|
| Lesser violations (poor consent records, inadequate retention) | €10 million or 2% of global annual turnover |
| Serious violations (unlawful processing, no valid consent) | €20 million or 4% of global annual turnover |
These aren't theoretical. In January 2024, the ICO fined HelloFresh £140,000 under UK PECR after it sent 79.7 million emails using unclear consent language that bundled email marketing with age confirmation and failed to mention SMS consent. The consent wording was the problem—not the volume.
In May 2025, the CNIL fined data broker CALOGA €80,000 for commercial email prospecting without valid consent—the forms used by source websites didn't produce consent that met GDPR standards for CALOGA and its named advertiser partners.
The Hidden Costs
Beyond fines, non-compliance generates costs that stack up fast:
- Deliverability damage: Non-consented subscribers report spam at higher rates, poisoning sender reputation across your entire list
- Blocklist risk: High complaint rates can trigger listings on major blocklists like Spamhaus
- Customer trust erosion: A breach notification email destroys confidence faster than almost any other brand event
- Enterprise sales friction: EU-based business buyers increasingly audit vendor privacy posture during procurement

Treating GDPR as a compliance cost is what makes it expensive. Brands that build consent into their email program from day one end up with cleaner lists, higher engagement rates, and better inbox placement—a compounding advantage over competitors who don't.
GDPR Email Marketing Compliance Checklist
Use this before every campaign send. Treat it as a living document, reviewing quarterly alongside your list hygiene audits.
Consent & Collection
- Lawful basis documented for every email type in your send calendar
- Explicit, granular consent collected via unchecked checkboxes with plain-language descriptions
- Double opt-in activated for new subscribers
- Privacy policy linked at every point of data collection
- Consent records stored with who, when, how, exact wording/version, and source form
List Management & Preferences
- Unsubscribe link present and functional in every marketing email
- Suppression applied immediately after opt-out; suppression list maintained
- Preference center available for subscribers to manage communication types
- Data retention timelines defined, with re-engagement triggered at 6–12 months of inactivity
- Hard bounces removed immediately
Security & Breach Readiness
- Team trained on phishing prevention and data security basics
- 72-hour breach notification workflow documented and assigned
Frequently Asked Questions
What is GDPR in email marketing?
GDPR is the EU's data protection law governing how brands collect and use subscriber data for email marketing. It requires explicit opt-in consent before sending promotional emails, transparency about how data is used, and simple opt-out options in every send.
What are the 7 GDPR requirements?
The seven principles are: lawful basis, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. All seven govern how you collect, store, use, and eventually delete email subscriber data.
Does GDPR apply to US-based e-commerce stores?
Yes. GDPR applies to any US brand that intentionally offers products or services to EU/UK residents, or monitors their behavior, meaning most Shopify stores with international shipping or EU traffic tracking pixels are covered.
What is the difference between single opt-in and double opt-in under GDPR?
Single opt-in adds a subscriber after one form submission; double opt-in requires email confirmation before they're added. Double opt-in is the recommended best practice under GDPR because it provides stronger proof of consent and yields a more engaged list.
What are the fines for GDPR email marketing violations?
Fines reach up to €10 million or 2% of global turnover for lesser violations, and up to €20 million or 4% for serious breaches. Indirect costs—deliverability damage, blocklist risk, and reputational harm—often exceed the fine itself.
How do I make my Klaviyo email list GDPR-compliant?
Enable double opt-in, add unchecked consent checkboxes to all signup forms, store consent timestamps via Klaviyo's native properties, and build suppression lists for inactive subscribers. A Klaviyo Certified Partner like FluenceFlow can audit and configure these systems correctly. Book a free Klaviyo audit at fluenceflow.io/apply.


