How does GDPR apply to email verification?

GDPR and email, defined
Under GDPR an email address is personal data, so sending marketing to someone in the European Union requires a lawful basis, most often consent or legitimate interest, recorded before the first message.

Consent must be freely given, specific, informed and unambiguous, which rules out a pre-ticked box or a checkbox bundled with the terms of service. It also has to be as easy to withdraw as it was to give.

Legitimate interest requires a balancing test: your interest in reaching this person, weighed against their expectations, documented before you send. Regulators look for the document, not the intention.

Processing a list through any third-party service makes that service a processor, and a data processing agreement is required. Where the servers sit matters for transfers outside the European Economic Area.

Verification itself is ordinary processing of data you already hold. The lawful basis you needed for the list covers checking it, and the checking creates no new basis for mailing anyone.

How ZapBounce reports it

Running a list through verification is processing, so it needs the same lawful basis as holding the list did. A valid result is a technical fact about a mailbox and never evidence that anyone agreed to hear from you.

One list, three sets of rules

Say you hold 12,000 business contacts and 3,100 of them are in Europe: 1,400 in the United Kingdom, 900 in Germany, 800 spread elsewhere. GDPR covers how you hold all 3,100. Whether you may email them is decided mostly by a second layer, the ePrivacy rules, which each country wrote into its own law.

Those national laws differ. In the UK, the regulations known as PECR don't require prior consent to email corporate subscribers, meaning people at limited companies, though you still have to identify yourself and offer an opt-out. Germany is much stricter and generally expects prior express consent for email advertising, to businesses as well as consumers.

So the honest plan for that list is a segmented one. Your legitimate interest assessment might support mailing the 1,400 UK corporate contacts. It probably won't carry the 900 German ones, and the remaining 800 need a country-by-country look. Talk to counsel before the send, since this is a summary and not legal advice.

Questions to put to any verification vendor

Uploading a list to a verifier hands personal data to a processor, and you're accountable for that choice. Before you upload, ask for the data processing agreement and read four things in it.

How long are uploaded files and results kept, and can you delete them yourself? Which sub-processors touch the data, and in which countries? If data leaves the European Economic Area, what transfer mechanism covers it? And is there a plain commitment that your addresses are never reused, resold or added to any dataset of the vendor's own?

A vendor that answers slowly or vaguely has told you something. Fines under GDPR can reach 20 million euros or 4% of worldwide annual turnover, whichever is higher, and regulators treat processor selection as your responsibility.

Keep one right in view as well. Anyone can object to direct marketing at any time, and that right is absolute. There's no balancing test to run. You stop, and you record that you stopped.

GDPR and email: common questions

Is email verification GDPR compliant?

It is processing personal data, so it needs a lawful basis and a processing agreement with the vendor. That is a requirement to meet, not a barrier.

Can I use legitimate interest for B2B email?

Often yes, with a documented balancing test and an easy opt-out. Consumer marketing is held to a stricter standard.

Does verifying an address create consent?

No. It confirms a mailbox accepts mail. Consent is about the person, and no technical check can establish it.

See this on your own list

100 free checks a month, and the unknowns come back labeled.