Summary
- Legitimate Interests (Article 6(1)(f)) — Can apply to B2B marketing in some circumstances, but requires a documented Legitimate Interests Assessment (LIA) Most marketing software relies on cookies and tracking pixels. Under GDPR (read alongside the ePrivacy Directive), non-essential cookies require prior, informed consent. Article 30 GDPR requires organizations to document all data processing activities. For marketing software, your ROPA entry should include:
GDPR Requirements List for Marketing Software: A Complete Compliance Guide
Marketing software sits at the heart of how businesses collect, store, and use personal data. From email automation platforms to CRM systems and ad-targeting tools, these applications process enormous volumes of personal information every day. If your organization uses any form of marketing software — and operates in or targets the EU — GDPR compliance is not optional.
This guide breaks down the exact GDPR requirements your marketing software must meet, giving you a practical checklist to work through and avoid costly penalties.
Why Marketing Software Faces Heightened GDPR Scrutiny
Marketing tools are specifically designed to track behavior, build profiles, and send targeted communications. These activities sit squarely within GDPR’s scope because they involve:
- Processing personal data (names, emails, IP addresses, browsing behavior)
- Profiling and automated decision-making
- Cross-border data transfers (most SaaS tools are US-based)
- Third-party data sharing (ad networks, analytics providers)
Regulators have repeatedly fined companies for unlawful marketing practices. Meta received a €390 million fine in 2023 for unlawful behavioral advertising. The message is clear: marketing compliance is a priority enforcement area.
Core GDPR Requirements List for Marketing Software
1. Establish a Lawful Basis for Processing
Before collecting or using any personal data for marketing purposes, you must identify and document a lawful basis under Article 6 GDPR. For marketing software, the two most relevant bases are:
- Consent (Article 6(1)(a)) — Required for most direct marketing, email campaigns, and cookie-based tracking
- Legitimate Interests (Article 6(1)(f)) — Can apply to B2B marketing in some circumstances, but requires a documented Legitimate Interests Assessment (LIA)
Important: Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes do not qualify. Bundled consent (agreeing to marketing as a condition of service) is also invalid.
2. Obtain and Record Valid Consent
If consent is your lawful basis, your marketing software must support proper consent management:
- Double opt-in processes for email subscriptions
- Granular consent options (e.g., separate consent for email newsletters vs. SMS marketing)
- Consent timestamps and records — you must prove when, how, and what a user consented to
- Easy withdrawal mechanisms — unsubscribing must be as simple as subscribing
- Consent version tracking — if your privacy policy changes, existing consent may need renewal
Your CRM or email platform should store consent records automatically. If it doesn’t, you need a supplementary consent management solution.
3. Implement a Cookie Consent Management Platform (CMP)
Most marketing software relies on cookies and tracking pixels. Under GDPR (read alongside the ePrivacy Directive), non-essential cookies require prior, informed consent.
Your website must include:
- A cookie banner that appears before any tracking cookies are set
- Clear categories of cookies (functional, analytics, marketing)
- An equal-prominence option to reject all cookies (not just accept)
- A mechanism to withdraw cookie consent at any time
- A record of cookie consent decisions
Platforms like Google Analytics, Meta Pixel, and LinkedIn Insight Tag all set marketing cookies and must be blocked until consent is given.
4. Maintain a Record of Processing Activities (ROPA)
Article 30 GDPR requires organizations to document all data processing activities. For marketing software, your ROPA entry should include:
- The name and contact details of your organization
- The purposes of processing (e.g., email marketing, lead scoring, retargeting)
- Categories of data subjects (prospects, customers, newsletter subscribers)
- Categories of personal data (email, name, IP address, behavioral data)
- Data recipients (your email platform, CRM, ad networks)
- Data retention periods
- Security measures in place
This document must be kept up to date and made available to supervisory authorities on request.
5. Conduct Data Protection Impact Assessments (DPIAs)
Under Article 35, a DPIA is mandatory when processing is “likely to result in a high risk” to individuals. Marketing software often triggers this requirement due to:
- Large-scale profiling of individuals
- Systematic tracking of behavior (retargeting campaigns)
- Use of sensitive data categories in audience targeting
- Automated decision-making that produces significant effects
A DPIA must identify risks, assess their severity, and document the measures taken to mitigate them before processing begins.
6. Address Third-Party Data Processors
Every marketing tool you use is a data processor under GDPR. You, as the data controller, are responsible for ensuring they process data lawfully on your behalf.
This means you must:
- Sign a Data Processing Agreement (DPA) with every marketing vendor
- Review vendors’ security practices and sub-processor lists
- Verify that vendors provide adequate protections for data transfers
- Conduct due diligence before onboarding new marketing tools
Most major platforms (HubSpot, Mailchimp, Salesforce, Google) offer standard DPAs, but you must actively execute them — they are not automatically in place.
7. Manage International Data Transfers
Many marketing SaaS platforms are headquartered in the United States. Transferring personal data outside the EEA requires one of the following safeguards:
- EU-US Data Privacy Framework (DPF) certification (check if your vendor is certified)
- Standard Contractual Clauses (SCCs) — the most common mechanism, included in most vendor DPAs
- Binding Corporate Rules (BCRs) for intra-group transfers
You must document the transfer mechanism used for each marketing tool and conduct a Transfer Impact Assessment (TIA) where required.
8. Honor Data Subject Rights
Your marketing software must support the exercise of data subject rights under Articles 15–22 GDPR:
- Right of access — Provide individuals with copies of their marketing data on request
- Right to erasure — Delete contact records when requested (“right to be forgotten”)
- Right to object — Honor objections to direct marketing immediately and permanently
- Right to data portability — Export contact data in a machine-readable format
- Right to restriction — Pause processing while a complaint is investigated
Build processes around your CRM and email platform to handle these requests within the 30-day statutory deadline.
9. Apply Data Minimization and Retention Limits
Article 5 GDPR requires that personal data be:
- Adequate, relevant, and limited to what is necessary (data minimization)
- Not kept longer than necessary for the stated purpose (storage limitation)
For marketing software, this means:
- Only collecting fields you genuinely use (don’t collect date of birth if you don’t need it)
- Setting automatic suppression or deletion rules for inactive contacts
- Defining and documenting retention periods for each data category
- Regularly auditing your contact database for outdated records
10. Ensure Appropriate Security Measures
Article 32 requires technical and organizational security measures appropriate to the risk. For marketing software:
- Enable multi-factor authentication on all marketing platforms
- Use role-based access controls to limit who can view contact data
- Ensure data is encrypted in transit and at rest
- Regularly review and revoke access for former employees
- Include marketing tools in your data breach response plan
GDPR Marketing Software Compliance Checklist Summary
| Requirement | Key Action |
|---|---|
| Lawful Basis | Document basis for each marketing activity |
| Consent | Implement double opt-in and consent records |
| Cookie Consent | Deploy a compliant CMP before tracking |
| ROPA | Add all marketing tools to your records |
| DPIA | Assess high-risk profiling activities |
| Vendor DPAs | Execute agreements with all marketing vendors |
| Data Transfers | Verify SCCs or DPF certification |
| Data Subject Rights | Build request handling workflows |
| Data Minimization | Audit fields collected and retention periods |
| Security | Apply MFA, access controls, and encryption |
Frequently Asked Questions
Do I need consent for every email I send to a contact in my CRM?
Not necessarily. Consent is required for most B2C direct marketing emails. For B2B marketing, legitimate interests may apply in some EU member states, though this varies by jurisdiction. However, you must always honor opt-outs immediately, regardless of the lawful basis used.
Is double opt-in legally required under GDPR?
GDPR does not explicitly mandate double opt-in, but it is the most reliable way to demonstrate valid, verifiable consent. Many data protection authorities recommend it as best practice, and it provides strong evidence if consent is ever challenged.
What happens if my email platform has a data breach?
As the data controller, you are responsible for notifying your supervisory authority within 72 hours of becoming aware of a breach likely to risk individuals’ rights. Your processor (the email platform) must notify you without undue delay. This is why your vendor contract must include breach notification obligations.
Can I use purchased email lists for marketing under GDPR?
Almost certainly not. Purchased lists rarely meet GDPR’s consent standard because recipients did not specifically consent to receive communications from your organization. Using such lists exposes you to significant regulatory and reputational risk.
How often should I audit my marketing software for GDPR compliance?
At minimum, conduct a full compliance review annually and whenever you onboard a new marketing tool, change your data processing activities, or experience a significant change in applicable law or regulatory guidance.
Get Compliant Faster with Ready-to-Use Templates
Working through GDPR requirements for marketing software is complex — but you don’t have to build every document from scratch.
Our GDPR Compliance Template Bundle for Marketing Teams includes everything you need:
- ✅ Data Processing Agreement (DPA) template for marketing vendors
- ✅ Legitimate Interests Assessment (LIA) template
- ✅ DPIA template for marketing profiling activities
- ✅ Record of Processing Activities (ROPA) marketing module
- ✅ Consent management policy and procedures
- ✅ Data subject rights request workflow
- ✅ Data retention schedule template
- ✅ Cookie policy template
Stop spending weeks on documentation. Our attorney-reviewed, audit-ready templates are designed specifically for marketing software use cases and can be customized for your organization in hours, not weeks.
[Browse the GDPR Marketing Compliance Template Bundle →]
Trusted by compliance teams at over 500 SaaS companies. Instant download. Lifetime updates included.
Best for teams organizing privacy documentation and operating guidance.