Skip to content
Digital Marketing

Digital Marketing and Privacy Laws: The GDPR and You

By Jim Foreman| 9 Min Read | July 13, 2026
Add as a preferred source of Google
GDPR Compliance | Digital Marketing Privacy Laws | The GDPR and You

Six years is a long time in privacy law. Back in 2020 (when we first wrote on the topic), one state had a broad-based privacy law on the books, and Europe’s top court had recently struck down Privacy Shield. Today, more than twenty states regulate how you collect and use personal data, fines routinely land in the eight- and nine-figure range, and the rules for marketing consent, email lists, cross-border data, and AI disclosures have all shifted beneath your feet.

This guide covers where marketing data privacy stands right now: what changed, and what to fix first. No law degree required. We’ll flag the two or three places where you genuinely need a lawyer and skip the filler everywhere else.

Note: none of this is legal advice. The information here is meant for educational purposes only.

The Short Version

Read this table, then go deeper on whichever row touches your business.

Regime Who it affects What marketers need to do
GDPR Anyone who markets to people in the EU            Get real consent before tracking or emailing, and honor deletion requests
US state laws (20+ states) Businesses that meet a state’s revenue or data-volume threshold   Map your data by state, and watch for universal opt-out signals you’re required to honor
Cross-border transfers Anyone who sends EU data to US servers or tools   Confirm your vendors are certified under the Data Privacy Framework, and keep a backup plan
EU AI Act Marketers who use AI tools that reach EU users   Label AI-generated content and disclose chatbots by August 2, 2026

 

 

Marketing Consent: What It Means in 2026

“Consent” used to be a single solitary checkbox. Now it depends entirely on where your visitor lives.

Under GDPR, someone has to actively opt in, and that consent has to be a specific yes, not a blanket yes to everything. A pre-checked newsletter box doesn’t count (frankly, it never did). A meaningful number of sites still employ the checkbox or the ‘okay’ button.

Under most US state laws, the default goes the other way: businesses can collect and use data unless the person opts out. Sensitive categories like health or biometric data usually still require opt-in consent, regardless of which state they’re in.

Then there’s the thing a lot of marketers still haven’t dealt with: Global Privacy Control. It’s a browser signal that tells a website “treat me as opted out of data sale and sharing,” and Firefox and Brave already send it by default. Eleven or more states legally require you to honor it the moment it arrives, whether or not your cookie banner mentions it. If your site doesn’t detect and act on that signal, you’re likely out of compliance in a state you didn’t even know had a rule for it.

The practical fix is: audit your consent flows by region and confirm your cookie tool actually reads and respects GPC signals, rather than assuming a single global setting covers everyone.

Digital marketing privacy now means managing dozens of overlapping, sometimes conflicting consent rules.

GDPR and Marketing: What Actually Changed

GDPR itself hasn’t moved much since 2020. What’s changed is how seriously regulators enforce it, and how often marketing teams end up at the center of their enforcement.

A few things worth updating in your mental model:

  • The age at which a minor can consent to data processing on their own defaults to 16, but individual EU member states can lower it to as young as 13. Check the country you’re targeting before assuming a single age applies everywhere.
  • Fines aren’t theoretical. Regulators across the EU and the UK have gone after marketing-specific violations directly: consent flows, ad tracking, lead-gen forms, and cookie banners, among others.
  • Apple’s App Tracking Transparency, which seemed new in 2021, is now simply how iOS works. If your attribution model still assumes pre-ATT tracking behavior, that’s worth a second look.
  • Data protection authorities increasingly expect a documented legal basis for every marketing use of personal data, rather than a privacy policy that mentions the GDPR in passing.

If your team hasn’t updated your consent program since before 2021, it’s likely no longer compliant.

GDPR and Email Marketing

Email deserves its own section because it’s where GDPR mistakes most often occur and are caught the fastest.

Purchased lists and scraped contacts create exposure under GDPR, and so does “implied consent” claimed from, say, a business card at a trade show. Legitimate interest can cover some B2B email in narrow cases, but it’s not a blanket excuse to skip consent, and regulators have said so directly.

What holds up are proof of opt-in consent, and an unsubscribe link that works on the first click. What doesn’t work is any list you didn’t build with permission, no matter how you got it.

US State Privacy Laws and What They Mean for Marketers

This is the section that’s grown the most since 2020, when this page still only talked about California.

Twenty states now set these rules, and this used to be a California-only conversation. Indiana, Kentucky, and Rhode Island all came online January 1, 2026, and several more states are moving legislation through their statehouses right now.

The catch is that no two state laws work quite the same way. A few examples of how differently these thresholds work:

State Applies if you…
California Have $25M+ in revenue, or hold data on 100,000+ residents, or get half your revenue from selling data (any one triggers it)
Texas Process any amount of Texas resident data, with no revenue threshold at all
Rhode Island Control data on 35,000+ consumers, with no cure period if you get it wrong
Indiana Process data on 100,000+ residents, or 25,000+ if half your revenue comes from data sales


One detail specific for B2B marketers in the audience: California’s law is the only one that reaches employee and job applicant data, beyond consumer data alone. Every other state law excludes B2B and employment data from its scope. If your company operates in California and handles job applications online, that data privacy in marketing question extends past your customers and into your careers page.

Enforcement has teeth now, too, bigger and badder than it ever did before. Reported penalties against US companies topped an estimated $1.4 billion in 2025 alone, and the “we’ll fix it if you catch us” cure-period strategy that worked in 2023 mostly no longer works. Several states have let those grace periods expire on purpose.

The honest answer to “Does this apply to me?” is that it depends on your revenue and data volume, and on which states your customers live in, and that’s worth mapping out rather than guessing. That’s the kind of audit DOM does for clients before we touch a single ad campaign or landing page.

Cross-Border Data: Can You Still Send Data to the US?

If any part of your marketing stack routes EU data through US servers – and most marketing stacks do – this section is for you.

The short version: the EU-US Data Privacy Framework allows certified US companies to receive EU personal data without additional paperwork. More than 2,800 US organizations are currently certified under it.

The longer version is: privacy advocates have already challenged that framework in EU courts twice. It survived the first challenge in September 2025, but a June 2026 US Supreme Court ruling on the Federal Trade Commission’s independence reopened the question of whether the framework still meets the EU’s legal bar. An appeal is pending, and privacy advocates have already called for the framework’s repeal.

Treat this as routine risk management. Confirm that your vendors, from your CRM to your ad platforms, are DPF-certified, and keep Standard Contractual Clauses on hand as a backup.

Privacy Law Beyond the US and EU

A couple of things if you’re marketing internationally.

Brazil’s LGPD has been in full force since September 2020, and its regulator has been active for years. In January 2026, the EU granted Brazil a mutual adequacy decision, the first arrangement of its kind, which makes data flows between the two regions considerably simpler.

Thailand’s PDPA wasn’t in force back in 2020. It didn’t take full effect until June 2022, after multiple delays.

If your marketing is in either market, both laws are worth a dedicated look rather than a footnote.

AI Tools and Marketing Privacy: The New Frontier

This section didn’t exist the last time we touched this page because the technology it covers barely existed either.

The EU AI Act begins to require transparency from marketers on August 2, 2026. Marketers who use AI to generate ad creative, write copy, personalize landing pages, or run a chatbot on a site that reaches EU users will need to label AI-generated content and disclose when a bot, not a person, is answering.

The EU pushed back some of the heavier obligations around “high-risk” AI systems to December 2027 under a set of amendments agreed in principle in May 2026, but the transparency rules for everyday marketing tools are still on track for this August.

Fines for the most serious violations can reach €35 million or 7% of global turnover, whichever is higher. Most marketing AI use won’t land anywhere near that tier, but the disclosure requirements still apply, and they’re easy to miss because they seem like a legal problem rather than a marketing one.

Privacy-First Marketing: Your Next 90 Days

You don’t need to rebuild your entire stack this quarter but you should know where the troubling gaps are.

  • Pull up your consent flows by region and check whether your cookie tool actually reads and respects GPC signals.
  • Map which states your customer and lead data touches, then check each one’s threshold against your revenue and data volume.
  • Confirm your major vendors – CRM, ad platforms, email tool, and analytics platform – are certified under the EU-US Data Privacy Framework if you send any EU data through them.
  • Review any AI tools in your content or ad workflow and note where you’ll need a disclosure or label by August 2026.

A privacy-first marketing program comes down to knowing exactly where your risk is, not locking down every form on your site out of fear. Once you know that, the rest of your marketing budget can go toward growth instead of cleanup.

———————————–
A quick note before you go: we wrote this page for marketers, not lawyers, and it’s not legal advice. The stakes here are high enough that a proper compliance review from counsel is worth the cost for most growing businesses. What we can do is help you build a marketing program on top of that compliance.

If your team needs help auditing where your marketing data privacy gaps actually are, talk to DOM, and we’ll walk through it together.