I am not a lawyer, and this article is not legal advice. I am a marketer who needs to design campaigns so their data flows can be explained to a client, a user and a person responsible for data protection. When a situation is disputed, involves sensitive data, extensive profiling or a high risk to people, consult a lawyer or data-protection officer.
The biggest misconception is that GDPR equals consent. Consent is only one legal basis. For every purpose I first ask: what exactly are we doing, with what data, why, for how long, to whom are we passing it, and what can a person reasonably expect?
Five steps before every marketing function
- Purpose: separate handling an enquiry, sending a newsletter, measuring traffic and remarketing.
- Data: collect only what the purpose requires.
- Rule: determine the GDPR legal basis and the special rule for the channel, such as commercial communications or cookies.
- Information: clearly tell the person who, what, why, to whom, for how long and what rights they have.
- Operations: set up evidence, security, deletion, objection, withdrawal and supplier management.
The basic principles and legal bases are in Articles 5 and 6 of the General Data Protection Regulation. They include lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation and security.
Consent must be a genuine choice
Consent must be freely given, specific, informed and unambiguous. A pre-ticked box or silence is not enough. Do not mix different purposes into one vague sentence, and withdrawal must not be harder than giving consent. The European Data Protection Board discusses the conditions and examples in its Guidelines 05/2020 on consent.
For a form, record the wording of the consent, time, source and version. Double opt-in helps verify an address and document registration, but it does not repair vague or forced consent.
Commercial communications in Czechia
Email and SMS rules do not rest on GDPR alone. Under the current FAQ from the Czech Data Protection Authority on Act No. 480/2004 Coll., commercial communications may be sent with prior consent or under the customer exception for the sender's own similar products and services, provided that the customer had a clear, free way to refuse when the address was collected and in every message. A publicly available address is not an automatic invitation to send mail.
In practice, separate:
- a service message necessary for an order or service,
- commercial communication to a customer within the statutory exception,
- a newsletter or other marketing communication based on consent.
Every message must match its category in content, recipient and opt-out option. I cover the technical side in the email marketing article.
Cookies and measurement scripts
In Czechia, opt-in has applied to non-technical cookies since 2022. The Czech DPA explains that without active consent, non-technical cookies must remain off, while technical cookies necessary for the service do not need consent. Accept and reject must be equally easy and on the same layer; see the official cookie questions and answers.
Divide tools according to their real function, not the supplier's name:
- necessary for the requested service,
- analytics,
- personalisation,
- advertising and remarketing.
A consent banner is not finished until it technically blocks the relevant scripts, passes the choice on and lets people change it. Check the implementation in a browser before consent, after refusal and after acceptance. Tools through Google Tag Manager must respect the same choice; the container itself does not make processing lawful.
Lead magnets, webinars and forms
If someone requests an e-book or webinar registration, you need their data to deliver the promised item. A further newsletter is a separate purpose unless it is an essential part of the service. Describe it separately and provide a genuine choice. Do not collect a phone number, job title or company size merely because a marketing tool offers those fields.
Give the form a short notice and a link to the full policy. A webinar recording may capture names, voices, images or chat; inform participants beforehand and set access and retention periods. I describe the practical webinar production page in the WebinarJam guide.
Audiences, remarketing and data sharing
A custom audience or Conversion API is not merely a technical list upload. Map the data source, purpose, legal basis, transparency, the parties' roles, transfers outside the EU and retention period. Use the platform's current contractual terms and documentation. A hashed email remains personal data if it can be linked to a person.
Do not use sensitive data categories or inferred vulnerabilities without specialist assessment. For extensive tracking or profiling, assess whether a data-protection impact assessment is needed.
Suppliers and internal access
List every system receiving data: forms, CRM, email service, hosting, analytics, chat, advertising platform and backups. For each, define the role, contract, data location, subprocessors, security, retention settings and offboarding procedure. Grant access according to the work, not automatically to the whole agency.
Rights, deletion and backups
A company must be able to find a person's data across systems and handle access, correction, deletion, restriction, objection or portability where applicable. Deletion does not mean blindly rewriting every backup. Use a retention regime in which a backup is not normally used, expires over time and, if restored, reapplies recorded requests.
An unsubscribed address may need to remain on a limited suppression list so it is not added to a mailing again. Store the minimum needed for that purpose and restrict access.
Checklist
- Does every purpose have its own description and legal basis?
- Is the special rule for email, cookies or advertising satisfied?
- Do we collect only necessary data and have a retention period?
- Is the information clear at the moment of collection?
- Can we document consent and withdraw it just as easily?
- Are scripts genuinely blocked before a choice?
- Do we have contracts, access controls and a supplier list?
- Can we handle rights requests and a security incident?
Do not hide GDPR in the footer. Good configuration removes data chaos, improves marketing and makes changing suppliers easier. For a technical and marketing audit, use the contact page; a qualified lawyer or data-protection officer must confirm the legal conclusion in a complex case.