Newsletter & GDPR 2026: What's Actually Allowed
Double opt-in, US tools, purchased lists — what's legal, what triggers warnings? The honest overview without legal jargon.
Running a legally compliant newsletter is more demanding in 2026 — but absolutely doable. Most warnings don't come from complicated edge cases but from three or four very typical mistakes. Here's the compact overview of what you can and cannot do.
The basic rule: Active consent
You need verifiable, active consent from every recipient before sending newsletters. This applies to private individuals AND companies (B2B). A pre-checked checkbox isn't enough. A 'hidden' newsletter opt-in in an order form isn't enough. A generic order-form note about newsletters being sent and unsubscribable is definitely not enough.
Double opt-in is mandatory
- →Step 1: User signs up on your website.
- →Step 2: Confirmation email with activation link is sent.
- →Step 3: Only after clicking the link does the address land in your list.
- →Step 4: You store timestamp, IP and the exact wording of the consent.
Mandatory information in every newsletter
- →Full legal notice or link to it in every email.
- →Working unsubscribe link with a single click (no login required).
- →Clear sender information — no anonymous 'no-reply@' addresses without imprint.
- →Reference to the privacy policy.
Which tools are allowed?
Mailchimp, ConvertKit, ActiveCampaign are US tools. After the EU court ruling on Privacy Shield, you need a data processing agreement and must describe the data transfer to the US transparently in your privacy policy. Safer and easier are EU tools: rapidmail, CleverReach, Brevo (formerly Sendinblue) or Mailjet — all with servers in Germany or the EU.
The most expensive mistakes
- →Sending to old contact lists without consent — €500–2,000 per recipient in damages possible.
- →Sending newsletters without double opt-in — warning practically guaranteed.
- →Treating B2B addresses as 'legally unproblematic' — wrong.
- →Contacting existing customers without explicit consent (outside the narrow §7 UWG exception).
The existing customer exception
You may contact existing customers without separate consent — but only under strict conditions: similar products/services, clear right-to-object notice at data collection AND in every email, and the customer hasn't objected. When in doubt: better get clean opt-in.
Conclusion
Legally compliant newsletters are achievable in 2026 with a few clear rules: double opt-in, EU tool, full mandatory information, clean unsubscribe link. Whoever follows this has an effective marketing tool without warning risk. More on GDPR in my checklist GDPR compliance 2026.
Related articles
GDPR Compliance in 2026: What Your Website Actually Needs
Cookie banners, privacy policies, data processing agreements — what's mandatory, what's overkill, and where do fines actually come from?
GDPR-Compliant Cookie Banners in 2026: What Actually Applies
Wrong cookie banners are the most common reason for legal warnings in 2026. Here's what's actually required — and what's expensive theater.
AI for Law Firms: Where It Actually Helps — and Where It Becomes a Liability Risk
Pre-qualify client inquiries, take routine off case files, speed up legal research — AI can save measurable hours in a law firm. But not everywhere. Honest 2026 overview for DACH firms.