Skip to main content

GDPR and email marketing: what you arrange yourself and what MailBlue arranges

This article explains what the GDPR means for email marketing and which responsibilities you and MailBlue have.

Written by Team MailBlue

In brief

  • You are the controller, and MailBlue is the processor. You determine which personal data is processed and for what purpose; we carry out that processing on your instructions.

  • You do not need to sign a separate data processing agreement. Our data processing agreement is Appendix 1 to the general terms and conditions and takes effect as soon as you accept them.

  • What we have documented about security, sub-processors, data storage, data breaches and retention periods is set out in the data processing agreement.

  • This article mainly covers what you arrange yourself: requesting and being able to demonstrate valid consent, collecting only necessary data, publishing a clear privacy policy and handling data subject requests.

You can find all legal documents at mailblue.nl/legal.


What does the GDPR entail?

The General Data Protection Regulation, hereinafter referred to as the 'GDPR', has applied throughout the European Union since 25 May 2018. The GDPR is designed to strengthen the protection of the processing of personal data belonging to data subjects in the European Union.

The GDPR applies to every organisation that processes personal data of European data subjects, regardless of whether that organisation is established in the European Union. If personal data of any kind, including email addresses, is collected, managed or analysed, the GDPR is likely to affect your organisation. If you do not comply with the GDPR, you may receive a fine of up to 20 million euros or 4% of your total worldwide turnover, whichever amount is higher.

Note: this article covers a number of GDPR requirements but is not an exhaustive list. We strongly recommend seeking independent advice to determine the extent to which the GDPR affects your business.


Controller and processor

The GDPR distinguishes between two roles. The specific responsibilities of each party are set out in Articles 24 through 43 of the GDPR.

Role

Who

What it entails

Controller

You

You determine whether personal data may be processed, which data is involved, for what purpose and by what means.

Processor

MailBlue

We process that personal data on your behalf and on your instructions, and follow your instructions when doing so.

We do not process the personal data for our own purposes, and it remains yours. Please note that one organisation may be both a processor and a controller. This depends on the processing activity you are considering.


Your data processing agreement is already arranged

Article 28 of the GDPR states that the controller must have a clearly documented agreement with the processor that defines the scope of the processing. You do not need to arrange anything yourself for MailBlue. Our data processing agreement is Appendix 1 to our general terms and conditions and takes effect when you accept those general terms and conditions. A separate signature is not required.

You can find the full and current text at mailblue.nl/legal/verwerkersovereenkomst. Among other things, it sets out which personal data we process, the categories of data subjects involved, the purpose and the duration.

Note: MailBlue works exclusively with its own data processing agreement and does not accept templates from other parties. If your organisation has specific requirements, you can discuss them with us via [email protected] or through your Customer Success Manager.


Consent and opt-in for email marketing

Under the GDPR, consent must be freely given, specific, informed and unambiguous. When you base processing on consent, Article 7 of the GDPR also requires you to be able to demonstrate that someone gave that consent. You are also required, at the time of collection, to clearly explain what you do with the data in language that is understandable and easily accessible.

In addition to the GDPR, the Dutch Telecommunications Act applies in the Netherlands to sending commercial email. In principle, it requires prior consent unless you can rely on the exception for existing customer relationships. If you are unsure whether that exception applies in your situation, consult a legal professional.

Set up an opt-in confirmation
Enabling double opt-in is a good starting point that can help you meet the requirement for unambiguous consent. When double opt-in is enabled, contacts must confirm their email address before receiving further messages. You can learn how to enable double opt-in in this help document.

Note: using double opt-in is not mandatory, but it is recommended.

Write a conclusive opt-in statement
State what someone is signing up for and mention that the emails contain tracking. You can include this text using an HTML block or text block in MailBlue forms. To record consent as well, you can add an extra checkbox using a custom field. Below are two suitable opt-in statements.

Yes, I would like to receive the newsletter and understand that opened emails and clicks are tracked for campaign measurement.

Yes, I agree to receive the newsletter and explicitly consent to measuring open and click behaviour for analysis and marketing purposes.

If you add a checkbox or selection box, it is recommended not to select the opt-in checkbox by default. A contact must actively opt in, which requires a deliberate action by the contact.

Obtain proof of consent from existing contacts
The burden of proof also applies to contacts whose personal information you collected before the GDPR was introduced. If you currently cannot demonstrate double opt-in consent from these contacts, you must contact them urgently and request consent again.


Request, use and retain only necessary data

Companies often still request unnecessary data. You should only request and store the data you need for the purpose for which you originally intended to collect it. For example, an online store needs address details to deliver an order but does not need those same details to send someone a newsletter.

When the data is no longer necessary, you can delete it. Therefore, also document how long you will retain the requested data and clean up unsubscribed contacts and lists that you no longer use.


Handle data subject requests

Under Articles 15 through 21 of the GDPR, your contacts have rights, including access, rectification, erasure, restriction of processing, data portability, and objection.

You handle these requests yourself because they concern your contacts. In almost all cases, you can find the required data directly in your email marketing account, for example, through an export or the contact profile. If you cannot find certain data in your account that is being requested on valid grounds, you can submit a request to us. What we do for you and within which timeframe is set out in Article 7 of the data processing agreement.

Practical options in your account:

  • Edit and delete contacts; see our help article about contact management.

  • Export contact data; see our help article about exporting.


Publish a privacy policy on your website

To collect email addresses, it is important to have a privacy policy on your website. In it, you state, among other things, which personal data you process, for what purpose and on what legal basis, how long you retain it, which parties you share it with and how someone can exercise their rights.


What MailBlue has arranged for you

The agreements below are fully set out in our general terms and conditions and data processing agreement. You can always find the current and applicable text there.

Subject

Summary

Read more

Information security

MailBlue complies with the ISO 27001 standard, the globally recognized international standard for information security. The technical and organizational measures are set out in Article 9 of the data processing agreement.

Sub-processors

We maintain a current, public overview of all engaged sub-processors, including data location and the nature of the processing. Changes are published in advance, and you can object to them. The timeframes and procedure are set out in Article 2 of the data processing agreement.

Storage and transfers

Depending on the data centre location of your account, personal data is stored in the United States or within the European Union. Appropriate safeguards are in place for transfers outside the EEA. See Article 8 of the data processing agreement.

Data breaches

We inform you without undue delay of a data breach that presents a real risk to data subjects. As controller, you are responsible for notifying the Dutch Data Protection Authority. See Article 4 of the data processing agreement.

Retention and deletion after termination

You can export data until the expiry date of your subscription and, after that, for a defined period through reactivation. The data is then permanently deleted. The timeframes are set out in Article 5 of the data processing agreement.

DPIA, records of processing activities and audits

We support you with a DPIA, maintain records of processing activities and cooperate with an audit under the conditions in Article 10 of the data processing agreement.

Tip: to stay informed about GDPR changes, such as changes to sub-processors or the data processing agreement, you can subscribe to our update using the form on the sub-processors page.

Consult a legal professional
DISCLAIMER: The content of this page is for information purposes and explicitly does not constitute advice to you as the reader. To fully understand the effects of the GDPR on your organisation, we strongly recommend seeking legal advice from a legal professional. MailBlue B.V. accepts no liability arising from consulting and using this specific article. Use of this article is entirely at the user's or users' own risk.

We will announce GDPR-related changes and updates on an ongoing basis through our website.

Did this answer your question?