Skip to content
6 min read

Legal bases for processing data in direct marketing under European legislation

The General Data Protection Regulation (GDPR) is the backbone of data protection law in Europe, and it holds anyone handling personal data to strict standards. Marketers felt this shift more than most. Habits that once seemed harmless, like emailing a bought-in list, suddenly needed a legal justification. This article walks through the legal bases for processing personal data in direct marketing under the GDPR, paying particular attention to legitimate interests under Article 6(1)(f).

The regulation requires that personal data be processed lawfully, fairly and transparently, and it lists the specific legal bases on which any processing must rest. Two of them do most of the work in direct marketing: consent and legitimate interests. Consent has long been the default choice for marketers. Since the GDPR took effect, though, legitimate interests has attracted just as much attention, because it is every bit as important and considerably harder to apply well.

Consent under Article 6(1)(a) must be an active expression of the data subject's wishes, given voluntarily and on an informed basis. That is a demanding standard, and deliberately so; it builds lawfulness, transparency and accountability into the processing from the start. The trouble is that consent is binary. You either have it or you don't, and that sits awkwardly with marketing programs that run, adapt and grow over months. This practical friction explains why legitimate interests has moved to the center of the legal conversation for marketing professionals.

Legitimate interest. Article 6(1)(f) offers a more flexible route, though not a less accountable one: it permits the processing of personal data without explicit consent, on conditions. An organization may run direct marketing on the basis of its legitimate interests if it can show that the processing is necessary for those interests and does not disproportionately intrude on the rights and freedoms of the people concerned. The concept was drafted broadly on purpose. It covers a wide range of situations in which processing serves the activities of the controller or of a third party, and Recital 47 of the GDPR expressly acknowledges that direct marketing may qualify as such an interest. That is not a blank check. Before relying on this basis, a controller has to work through a Legitimate Interests Assessment (LIA), which has three parts. First, identify the legitimate interest. Second, show that the processing is genuinely necessary to achieve it. Third, run a balancing test against the interests, rights and freedoms of the data subjects. Done properly, the LIA confirms that the processing does not override anyone's fundamental rights, and the written record doubles as evidence of due diligence under the GDPR's accountability principle. The balancing test is where assessments succeed or fail. It asks a blunt question: do the individual's interests or rights outweigh the controller's? Answering it means weighing the nature of the data, the context in which it is processed and the likely impact on the people involved. The analysis must be thorough and it must be documented, so that a reasoned case for proceeding under legitimate interests sits on file before the first email goes out.


Example 1: B2C Marketing Misstep – "GlamifyMe Cosmetics"

Scenario: GlamifyMe Cosmetics, a fictional beauty and skincare company, launches a new product line and wants results fast. Rather than build its own audience, it buys a mailing list from a third-party vendor. The list holds detailed personal information: names, personal email addresses, even purchase histories. GlamifyMe sends mass emails showcasing the new products to everyone on it, reasoning that anyone interested in beauty products has, in effect, already consented.

Violation: The campaign fails on the most basic point, the consent requirement of Article 6(1)(a). Using personal data for direct marketing without the explicit consent of the individuals concerned is unlawful. The GDPR insists that consent be freely given, specific, informed and unambiguous. An assumption of implied consent meets none of those conditions, so GlamifyMe's direct marketing is illegal from the first send, with all the penalties that can follow a clear breach.

Example 2: B2B Marketing Success – "TechSolutions Ltd"

Scenario: TechSolutions Ltd, a fictional provider of IT infrastructure services, wants to promote its new cloud storage solutions to other businesses. The team builds its prospect list from publicly available sources: business names, general contact details published on company websites (e.g., info@company.com) and industry publications. Before anything goes out, they tailor the content to each sector's actual needs and make sure every email carries a clear, working opt-out.

Compliance: The B2B setting works in TechSolutions' favor, and the company uses it well. A generic address such as contact@company.com relates to a role or position within a company rather than to an identifiable person, and general contact information of that kind is not classified as personal data under the GDPR. That distinction between personal and non-personal data in a business context is precisely what the campaign rests on. Combine publicly available business contacts with an easy way to opt out, and the marketing respects both the letter and the spirit of the regulation. It is lawful, and it is fair to the people receiving it.

Example 3: Best Practice in Data Handling – "GreenEarth Organics"

Scenario: GreenEarth Organics, a fictional retailer of sustainable goods, wants to use customer data for personalized promotions and decides to do it properly. Step one is an updated privacy policy that spells out, in plain terms, how customer data will be used. Only then does the company ask its existing customers for explicit consent, through a clear and simple opt-in for marketing emails that explains what subscribers get in return: exclusive discounts and early access to new products.

Adherence to GDPR: This is what good practice looks like. Every piece of personal data used for marketing rests on lawful consent. Customers can see exactly what they are agreeing to, and withdrawing consent is as easy as giving it was. The payoff reaches beyond compliance, because people reward brands that treat their data with respect. By taking privacy seriously, GreenEarth Organics earns trust and loyalty while setting a high standard for ethical marketing.


Three fictional companies, three very different outcomes. The first scenario is a straightforward breach of the GDPR and would invite potentially severe penalties. The other two show that compliant, ethical marketing is entirely achievable in practice: it respects individual privacy rights, and it tends to build trust between a business and its clients rather than erode it.

One obligation deserves special emphasis. Even where processing rests on legitimate interests, the GDPR demands a high degree of transparency. People must be told that their data is used for direct marketing, which legitimate interest is being relied on, and that they have the right to object. That right, set out in Article 21(2), is absolute in the direct marketing context. Once someone objects, processing their personal data for these purposes must stop immediately. There is no balancing test at that point.

For marketers, legitimate interests offers a viable and genuinely flexible legal basis for direct marketing, one that balances the needs of organizations against the rights of individuals. It comes at a price: a rigorous assessment built on necessity, proportionality and transparency, done before the campaign rather than after the complaint. Get that groundwork right and direct marketing under the GDPR can be both effective and compliant. Treat legitimate interests as a shortcut around consent, and it will not survive scrutiny. The distinction matters more each year as privacy expectations, and enforcement, keep rising.

Sources:

EUR-Lex: The official website for European Union law. The full text of the GDPR (Regulation (EU) 2016/679) is published here, with its provisions, recitals and related legal interpretations.

European Commission - Data Protection: The Commission's site covers data protection and privacy in the EU in depth, including guidance on the GDPR, data protection rules for businesses and organizations, and the rights citizens can exercise.

European Data Protection Board (EDPB): An independent European body that works to keep the application of data protection rules consistent across the European Union. Its website publishes guidelines, recommendations and best practice advice on GDPR compliance.

National Data Protection Authorities: Every EU member state has its own data protection authority (DPA) responsible for enforcing the GDPR within its jurisdiction. The EDPB's website keeps a list of these national authorities, with links to their sites for localized guidance and resources.

The Official Journal of the European Union (OJEU): The OJEU is where EU legislation is formally published, directives, regulations and decisions alike. The GDPR itself appeared here, which makes it a primary source for the regulation's official text and related legal documents.

Related reading

More from the Verteco team.

Want help with this?

Tell us what you're building – we'll come back with a plan.