hero background actito-dark
hero background actito-dark

The GDPR and email marketing: let’s set the record straight

The GDPR and email marketing: let’s set the record straight
The GDPR and email marketing: let’s set the record straight

GDPR and email marketing: let’s set the record straight

A recap for some, a clarification for others...

What is the GDPR? A quick refresher is in order...

Who hasn’t heard of the General Data Protection Regulation, more commonly known as the GDPR? Almost no one!

This regulation, which came into force on 25 May 2018, applies to all European organisations that process personal data. Its scope is broader than one might think (it covers everything from data collection to its erasure (if requested), including its storage, use, management, etc.) and applies to all sectors of activity. No marketer is exempt, with a few exceptions...

This regulation requires marketers to place the consumer at the heart of their communication strategy, offering them, amongst other things, consent-based and relevant offers. In itself, the GDPR is far more of an opportunity than a constraint, provided that one remains compliant with the law at all times.

Woe betide those who fail to comply with the regulation! Beyond the financial penalty (remember that the fine for non-compliance with the GDPR can reach 4 per cent of turnover), any breach of the GDPR will damage your brand’s reputation and image. What you have spent years, or even decades, building could be tarnished in the blink of an eye.

No newsletters without data. And where there’s data, there must be consent.

There can be no personalised (or even mass) marketing campaigns without processing personal data. And to process this type of data, consent is required – at least in B2C. The situation is different in B2B and varies from country to country*. In short, what does the law say?

B2B email marketing:

Even under the GDPR, prior consent is not required to process data and send marketing emails to businesses (source: https://www.cnil.fr/fr/la-prospection-commerciale-par-courrier-electronique). As companies, being legal entities, are necessarily represented by natural persons, it is therefore possible to send marketing emails to the holder of an email address such as prénom.nom@société.com.

It goes without saying that this must be done reasonably and that the recipient must, at any time, be able to exercise their right to opt out.

B2C email marketing:

To put it simply, the only situation in which it is possible to use email to send a marketing message to a consumer without specific prior consent is where the person has purchased a product or service, their email address was collected on that occasion, and it is used to promote similar products or services. In this specific case, this falls under the category of legitimate interest, and the opt-out regime applies. You should therefore ensure that you include an unsubscribe link in each of your newsletters.

As you will have realised, in B2C, without consent, you are not authorised to send an email to a consumer asking them to sign up to your loyalty scheme, for example.

Do not confuse consent with opt-in

Actito gestion opt in opt out

Consent and opt-in are often used as synonyms, yet they refer to different concepts. Consent is a general term relating to the marketing objective, whereas opt-in refers specifically to the communication channel (such as email, SMS or print).

Indeed, if a consumer gives their marketing consent but does not opt in to receiving email marketing, this does not mean they are not interested in receiving text messages. Opt-in therefore implies that marketing consent has been given. However, the reverse is not true: if a consumer has not given their marketing consent, no opt-in can be linked to their profile.

In the Actito platform, consent is managed at profile level, whilst the opt-in is linked to the subscriptions associated with that profile. Your contacts can therefore very easily unsubscribe (opt out) from a single channel, such as email or text messages, for example. Our user interface makes it easy to see what’s going on!

Active opt-in vs passive opt-in: what’s the difference and why does it matter?

webp Formulaire de consentement exemple

We talk about active opt-in when the consumer is aware that they are giving their consent to receive offers from a brand. This often takes the form of a tick box or a button to click on in a data collection form.

Passive opt-in is the exact opposite! The marketer uses the same form, with the difference that the box is pre-ticked. In this case, consent is implied, which contravenes the GDPR. This practice is therefore punishable by law. You’ve been warned…

What about double opt-in?

We sometimes hear it said that the double opt-in is the only way to guarantee valid consent under the GDPR. This is completely false: this requirement is not included in the text of the law! It is therefore not necessary to obtain double confirmation; a ‘simple’ opt-in is sufficient.

How can you manage customer data whilst remaining compliant?

Many marketers have had to review their marketing strategy and the way they process personal data, with varying degrees of guidance from their customer engagement software provider. As well as listening to our customers, Actito makes your job easier by providing you with a whole range of intuitive features:

Data collection forms

Formulaire donnees RGPD

Data collection forms have certainly not been exempt from the compliance requirements imposed by the GDPR. Fortunately for our customers, they did not have to wait for the European regulation to come into force on 25 May 2018 to be able to create GDPR-compliant forms.

The solution we offer, through our “Forms and Pages” module, involves recording the context of consent: namely, the source and exact time of collection, as well as the information provided to the consumer at the time consent was obtained.

In practice, once the form has been submitted, the database is updated with the form’s data and the time at which consent was given. Proof of consent can be provided by referring to the form.

Preference Management Form

webp Formulaire centre de preferences exemple

Our standard “Preference Centre” form template provides the necessary elements for obtaining compliant consent by implementing a “layered consent” system. The key information is available on the first page of the form. A link to the privacy policy, which includes all the information required by the GDPR, can be directly embedded in the form.

Keep in mind...

Your customers’ trust cannot be bought – it must be earned. Compliance with data protection law, as required by the GDPR, is the cornerstone of customer loyalty and, therefore, the long-term viability of your business. Stay compliant at all times (even if the temptation may be great); your customers will reward you for it (and so will the authorities!).

Want to find out more about our GDPR features? Need some advice?

*The Commission Nationale de l’Informatique et des Libertés, better known by its acronym CNIL, is the data protection regulator in France. In Belgium, it is the Data Protection Authority (APD). The websites of both organisations are full of resources on the subject:

CNIL: https://www.cnil.fr APD: https://www.autoriteprotectiondonnees.be