Summary
Whenever you use a marketing software vendor that processes personal data on your behalf, GDPR Article 28 requires a signed Data Processing Agreement. This is non-negotiable. Consent is the most commonly used legal basis in marketing, and it is also the most frequently challenged by regulators. GDPR Article 7 requires that you be able to demonstrate consent was freely given, specific, informed, and unambiguous. GDPR compliance is not a one-time project. Your documentation requires regular review:
GDPR Documentation for Marketing Software: A Complete Compliance Guide
Marketing software sits at the heart of personal data processing. Email platforms, CRM systems, analytics tools, ad-targeting solutions — all of them collect, store, and process personal data belonging to EU residents. That makes GDPR documentation not just a legal formality, but a critical operational requirement for any business running marketing technology.
This guide walks you through every document you need, what each one must contain, and how to keep your compliance stack audit-ready.
Why Marketing Software Requires Special GDPR Attention
Marketing tools are uniquely high-risk under GDPR for several reasons:
- They often collect data at scale, sometimes across multiple touchpoints
- They rely heavily on consent as a legal basis, which carries strict requirements
- They frequently involve third-party processors (email platforms, ad networks, analytics vendors)
- They enable profiling and automated decision-making, which triggers additional obligations under Article 22
A single misconfigured opt-in form or an undocumented data transfer can expose your organization to fines of up to €20 million or 4% of global annual turnover. The documentation you maintain is your primary defense.
Core GDPR Documents Every Marketing Software User Needs
1. Privacy Notice (Privacy Policy)
Your privacy notice is the public-facing document that tells users what you collect, why, and what rights they have. For marketing software specifically, your privacy notice must clearly disclose:
- What data is collected — email addresses, behavioral data, device identifiers, location data, purchase history
- Legal basis for processing — consent, legitimate interests, or contractual necessity
- Purpose of processing — email marketing, retargeting, lead scoring, analytics
- Data retention periods — how long you keep subscriber records and behavioral data
- Third-party sharing — names or categories of marketing platforms and data processors you use
- International transfers — if data flows outside the EEA, what safeguards apply (Standard Contractual Clauses, adequacy decisions)
- User rights — how subscribers can opt out, request deletion, or access their data
Keep your privacy notice written in plain language. Regulators and courts have consistently penalized organizations for burying key disclosures in legal jargon.
2. Records of Processing Activities (RoPA)
Under Article 30 of GDPR, most organizations must maintain a Record of Processing Activities. For marketing operations, this document maps every processing activity your software performs.
A marketing-focused RoPA entry should include:
| Field | Example |
|---|---|
| Processing activity | Email newsletter distribution |
| Controller/processor | Your company (controller), Mailchimp (processor) |
| Purpose | Promotional communications to opted-in subscribers |
| Categories of data | Name, email, open/click behavior |
| Legal basis | Consent |
| Retention period | 24 months from last engagement |
| Security measures | Encryption in transit and at rest |
| International transfers | USA — Standard Contractual Clauses |
Maintain a separate RoPA entry for each distinct marketing function: email campaigns, paid advertising audiences, lead capture forms, CRM data enrichment, and website analytics.
3. Data Processing Agreements (DPAs)
Whenever you use a marketing software vendor that processes personal data on your behalf, GDPR Article 28 requires a signed Data Processing Agreement. This is non-negotiable.
A compliant DPA for marketing software must specify:
- The subject matter and duration of processing
- The nature and purpose of the processing
- The type of personal data and categories of data subjects
- The obligations and rights of the controller (you)
- Restrictions on the processor using your data for their own purposes
- Sub-processor notification requirements
- Data breach notification timelines
- Deletion or return of data upon contract termination
Most major marketing platforms (HubSpot, Salesforce, Klaviyo, Google Ads) offer standard DPAs. However, you must actively sign or accept these agreements — they rarely apply automatically. Keep signed copies on file and review them when vendors update their terms.
4. Consent Records and Consent Management Documentation
Consent is the most commonly used legal basis in marketing, and it is also the most frequently challenged by regulators. GDPR Article 7 requires that you be able to demonstrate consent was freely given, specific, informed, and unambiguous.
Your consent documentation system should capture:
- Timestamp of when consent was given
- Version of the consent text displayed at the time
- Source — which form, landing page, or touchpoint collected the consent
- IP address or session identifier (where legally permissible)
- Opt-in mechanism — confirming it was an active action, not a pre-ticked box
If you use a Consent Management Platform (CMP) for cookie consent, ensure it logs granular consent by category (analytics, marketing, personalization) and integrates with your marketing tools to suppress non-consenting users.
5. Legitimate Interests Assessment (LIA)
Some marketing activities rely on legitimate interests rather than consent — for example, B2B prospecting or retargeting existing customers. If you use this legal basis, you must document a Legitimate Interests Assessment before processing begins.
A structured LIA covers three tests:
- Purpose test — Is the interest legitimate and clearly defined?
- Necessity test — Is processing necessary to achieve that interest?
- Balancing test — Do the individual’s rights and interests override your legitimate interest?
Document your reasoning for each test. If the balancing test is close, add safeguards such as easy opt-out mechanisms or data minimization measures, and record those too.
6. Data Retention and Deletion Policy
Marketing databases accumulate data quickly. Without a documented retention policy, you risk holding data far longer than necessary — a direct GDPR violation under the storage limitation principle.
Your retention policy for marketing data should define:
- How long active subscriber records are kept
- When inactive contacts are suppressed or deleted (common practice: 12–24 months of inactivity)
- How long consent records are retained (typically the duration of the relationship plus a reasonable period for legal defense)
- Procedures for honoring deletion requests within the 30-day deadline
- How deletion cascades to third-party processors and backup systems
7. Data Breach Response Plan
Marketing platforms are frequent targets for data breaches. A documented incident response plan ensures you can meet GDPR’s 72-hour notification requirement to supervisory authorities.
Your breach response documentation should include:
- Internal escalation contacts and responsibilities
- Steps to assess severity and scope
- Template notification letters for supervisory authorities and affected individuals
- A breach register to log incidents even when notification is not required
Maintaining and Updating Your Documentation
GDPR compliance is not a one-time project. Your documentation requires regular review:
- Annually — full audit of RoPA, DPAs, and privacy notices
- When onboarding new tools — add RoPA entries and execute DPAs before go-live
- When changing processing purposes — update privacy notices and reassess legal bases
- After a breach — review and update your incident response procedures
Assign a named owner for each document. Without ownership, documentation quickly becomes outdated.
FAQ: GDPR Documentation for Marketing Software
Do I need a DPA with every marketing tool I use?
Yes, if that tool processes personal data on your behalf. This includes email service providers, CRM platforms, advertising platforms, analytics tools, and lead generation software. If a vendor refuses to sign a DPA, you should not use them for processing EU personal data.
Can I use legitimate interests for email marketing?
Generally, no — not for unsolicited direct marketing to individuals. Recital 47 of GDPR notes that direct marketing can be a legitimate interest, but most supervisory authorities and national laws (like PECR in the UK) require consent for electronic marketing to individuals. Legitimate interests is more defensible for B2B marketing to business contacts.
How long should I keep consent records?
You should retain consent records for as long as you are relying on that consent, plus a reasonable period afterward to defend against complaints or regulatory investigations. A common approach is to retain records for the duration of the relationship plus three years.
What happens if a marketing software vendor has a data breach?
Your processor is required to notify you without undue delay after becoming aware of a breach. You then have 72 hours from when you become aware to notify your supervisory authority if the breach is likely to result in a risk to individuals’ rights and freedoms. This is why your DPA must specify breach notification timelines — ideally requiring the processor to notify you within 24–48 hours.
Is a cookie banner enough to cover marketing tracking?
A cookie banner handles consent for cookies and tracking technologies, but it is not a substitute for a full privacy notice. You need both: a CMP to capture granular cookie consent, and a comprehensive privacy notice that explains all your marketing data processing activities.
Build Your GDPR Documentation Stack Faster
Creating these documents from scratch is time-consuming, legally complex, and easy to get wrong. Missing a required clause in a DPA or using vague language in a consent form can invalidate your entire compliance position.
Our ready-to-use GDPR compliance template bundle for marketing software includes:
- ✅ Privacy Notice template with marketing-specific disclosures
- ✅ Records of Processing Activities (RoPA) template with pre-filled marketing examples
- ✅ Data Processing Agreement template compliant with Article 28
- ✅ Legitimate Interests Assessment (LIA) template
- ✅ Consent record-keeping framework
- ✅ Data retention and deletion policy template
- ✅ Breach response plan and incident register
Every template is written by compliance professionals, regularly updated to reflect regulatory guidance, and formatted for immediate use — just fill in your organization’s details.
[Download the GDPR Marketing Software Compliance Template Bundle →]
Stop building compliance documentation from a blank page. Get audit-ready today.
Best for teams organizing privacy documentation and operating guidance.