LGPD and Email Marketing: What Your Company Needs to Do Now
Este artigo faz parte do tópico: E-mail Marketing
The General Data Protection Law (LGPD) came into effect in 2020 and changed the rules of the game for email marketing in Brazil. But four years later, most companies still operate in a gray area — either due to ignorance of the law or the belief that “small businesses are not subject to inspection.”
This reasoning is wrong on two points: the LGPD applies to any company that processes personal data in Brazil, regardless of size; and compliance is not just a legal obligation — it is a competitive advantage. A company with a permission-based and well-maintained list has higher deliverability, higher open rates, and lower tool costs. Compliance and results go hand in hand.
What the LGPD Requires for Email Marketing
The LGPD does not prohibit email marketing — it defines the legal conditions for sending communications. For email marketing, the two most relevant legal bases are:
- Consent (Art. 7, I): the data subject has expressly authorized the receipt of communications — the standard mechanism for newsletters and email marketing lists
- Legitimate interest (Art. 7, IX): a legal basis that allows communication with existing customers without explicit consent, provided that the communication is relevant and expected in the context of the relationship — for example, sending emails about contracted services to active customers
What the LGPD explicitly prohibits for email marketing: sending emails to purchased lists (without the data subject’s consent), using data collected for one purpose and sending it for another, and retaining data from individuals who requested removal.
Opt-in: What Counts as Valid Consent
Valid consent under the LGPD must be: free (without coercion), informed (the person knows what they are authorizing), unequivocal (a positive action — it cannot be pre-checked), and specific (for the stated purpose).
Practices that DO NOT constitute valid consent:
- Pre-checked checkbox (“I want to receive offers” already checked by default)
- Terms hidden in the contract or terms of use with ambiguous language
- Registration for one purpose (e.g., quote) without mentioning that they will also receive a newsletter
- Silence as consent (“If you do not respond, it is assumed that you accept receiving communications”)
Practices that constitute valid consent:
- Checkbox unchecked by default that the user actively checks, with clear text: “I want to receive news and content from Focofy by email”
- Double opt-in: confirmation via a link sent to the email — adds an extra layer of verification and documents consent
- Form with a clear purpose: “Register your email to receive the free guide and our weekly digital marketing newsletter”
Rights of the Data Subject That Your Company Needs to Ensure
The LGPD guarantees the data subject a set of rights that the company must be able to exercise when requested:
- Access: the data subject can request what data you have about them
- Correction: can request to correct incorrect data
- Deletion: can request the removal of all data — and you must remove it within a reasonable time (generally considered up to 15 days)
- Revocation of consent: can withdraw authorization at any time — unsubscribing from email is the practical exercise of this right
- Portability: can request the data in a structured format for transfer
In practice for email marketing: ensure that the unsubscribe link works immediately, process list removals within a maximum of 10 business days, and document who requested removal and when.
What to Do with Old Lists
If your company has email lists collected before the LGPD or without clear documentation of consent, there are two options:
Option 1: Reconfirmation Campaign
Send a single email explaining that your policy has changed and asking the contact to confirm that they wish to continue receiving communications. Those who click “Continue receiving” are added to the list with documented consent. Those who do not respond are removed. This usually results in a list that is 30–50% smaller — but 100% compliant.
Option 2: Evaluation by Legal Basis
If the list consists of active customers, it may be possible to classify it under the legitimate interest basis for communications related to contracted services. This requires legal evaluation on a case-by-case basis — it is not a generic rule applicable to all contacts.
Documentation: What You Need to Keep
In case of questioning by the ANPD (National Data Protection Authority) or by a data subject, you need to be able to prove that consent was given. Keep:
- Log of date, time, and IP of the registration (most email tools keep this automatically)
- Copy of the opt-in form that was active at the time of registration (dated screenshot or historical version of the page)
- Record of double opt-in confirmation when applicable
- Log of unsubscriptions with processing date
Tools like ActiveCampaign, Mailchimp, and RD Station automatically maintain this log — but it is the company’s responsibility to know where to find and how to export this data.
Privacy Policy and Cookie Notice
In addition to email practices, the LGPD requires that the website has:
- Public privacy policy: explaining what data is collected, for what purpose, how long it is kept, and how the data subject can exercise their rights — including a contact email for requests
- Cookie notice: informing which cookies the site uses and asking for consent for non-essential ones (Analytics, remarketing pixels)
- Functional unsubscribe link: in every email sent — required by the LGPD and good deliverability practices
Penalties: What’s at Stake
The ANPD can impose fines of up to 2% of the company’s revenue in the last fiscal year in Brazil, limited to R$ 50 million per infraction. For SMEs, the absolute amount may be lower — but the reputational damage and the cost of a forced compliance process often outweigh any savings from not complying earlier.
In addition to fines, there is the risk of complaints from data subjects that can be publicized — the reputational impact of a company identified as a violator of personal data is difficult to measure and even harder to reverse.
Conclusion
LGPD and compliant email marketing are not opposites — they are complementary. Lists built with real consent have better deliverability, higher open rates, and lower maintenance costs than purchased lists or those collected without transparency.
The minimum checklist for compliance: explicit and documented opt-in, functional unsubscribe link in all emails, public privacy policy on the website, and a defined process to handle data subject requests. With these four elements, your email marketing operation is within the law and positioned to grow solidly.
For the complete email marketing strategy — from list building to automation — visit the Email Marketing hub or learn how Focofy implements email marketing with LGPD compliance from the initial setup.