All articles

Our obligatory General Data Protection Regulation (GDPR) notice

Announcements·May 28, 2018·By Ajay Goel·3 min read

The General Data Protection Regulation (GDPR), a new law passed by the European Union two years ago with implications for email marketing, started enforcement on Friday, May 25th, 2018.

Some users have asked us whether SendHustle is GDPR-compliant, so let’s discuss that now.

First, the Bottom Line

Since SendHustle is just a plugin and we don’t help our customers collect any user/subscriber data, there is nothing SendHustle can do to make sure you are GDPR-compliant. Essentially, this law doesn’t apply directly to SendHustle itself, other than how we conduct our own email marketing for our own business.

However, SendHustle users need to take action on this individually. That’s because a typical marketing service might have a feature that helps its users create opt-in sign-up forms, but SendHustle doesn’t have that — our users have their own opt-in forms, and they have to get their data into a spreadsheet somehow in order to use SendHustle.

Making Sure You’re Compliant

There are a number of important issues to keep in mind to make sure your SendHustle marketing campaigns are GPDR-compliant (and, again, this applies regardless of whether you use SendHustle or some other service). Generally, all these rules are intended to prevent email marketers from collecting data about users without their explicit consent:

  • Be aware of which data is protected: GPDR does not only apply to data gathered after May 25, but data gathered before as well (in fact, it applies to any data collected after the passing of the law two years ago). And it applies only to data collected from clients living in Europe. Bear in mind, even if you are not based in Europe, the GPDR applies to you if any of your clients live in Europe.
  • Be aware of the risks of non-compliance: There are serious fines: “Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher”. And that’s for the “lesser” infractions!
  • Always obtain active consent for being on your email list, not just passive consent. This means for a user to grant consent, the user must, for example, check a checkbox. Pre-checked checkboxes don’t count!
  • Store your email recipients’ consent: This includes who they are, when they consented, and what they were consenting to.
  • Allow people to easily withdraw consent.
  • You don’t need consent to include organizations (companies, schools, etc.) on your mailing list. This is because the GDPR is meant to protect individuals, not organizations.

Although there has been much media coverage about GDPR, the good news is that by taking some basic precautions, you can continue to use SendHustle and Gmail without concerns. Not only will you be complying with these regulations, you’ll be enhancing your brand by assuring clients that you take their privacy seriously.

If you would like to learn more about the GDPR, here are some helpful resources:

Email marketing, cold email, and mail merge inside Gmail


Send incredible emails & automations and avoid the spam folder — all in one powerful but easy-to-learn tool


TRY SendHustle FOR FREE

Download Chrome extension - 30 second install!
No credit card required
Love what you're reading? Get the latest email strategy and tips & stay in touch.

Send your next campaign from Gmail

SendHustle brings mail merge, follow-ups, and tracking right into the inbox you already use.

Start free