Back to Blog

PolicifyAI

Published July 2026 · 4 min read

Privacy

Do You Need a Privacy Policy for a Newsletter?

Collecting email addresses makes you a data controller - even for a free Substack. What PECR and UK GDPR require before you hit send, and what your policy must actually say.

Yes - a signup form is enough to trigger the law

An email address is personal data. The moment you put up a signup form - on your website, a landing page, a Substack, or a Mailchimp-hosted page - you become a data controller under UK GDPR, and you owe your subscribers a clear explanation of what you do with their data. That explanation is your privacy policy, and it must be available at the point of signup, not buried somewhere after the fact.

It does not matter that the newsletter is free, that you are a sole trader, or that the platform is someone else's. The platform (Mailchimp, Kit, beehiiv, Substack) is your data processor; you remain the controller, and the legal duties sit with you.

Two laws apply, not one

UK GDPR governs the data itself: your lawful basis for holding the email address, transparency, retention, and subscriber rights.

PECR (the Privacy and Electronic Communications Regulations) governs the act of sending: regulation 22 says you may not send marketing emails to individuals without consent - unless the narrow "soft opt-in" applies. Since the Data (Use and Access) Act 2025, PECR breaches can be fined at UK GDPR levels rather than the old £500,000 cap, which is why email marketing has become an enforcement priority.

Getting consent right

For a typical newsletter, your lawful basis is consent, and PECR requires it too. Valid consent means:

  • A positive action: an unticked box or a deliberate form submission - never a pre-ticked box
  • Unbundled: not hidden inside terms acceptance or forced as a condition of downloading something unrelated
  • Specific: "Subscribe to our weekly newsletter"- the person should know what they are signing up for
  • Recorded: keep evidence of when, where, and how each subscriber opted in (good email platforms log this for you)

Double opt-in- the confirmation email - is not legally required in the UK, but it is the cleanest proof of consent you can have and it keeps mistyped and malicious signups off your list. If you can turn it on, do.

The soft opt-in is the one exception: you may email marketing to existing customers without fresh consent if they gave their details during a sale (or negotiations), you are marketing similar products, and you offered an opt-out at collection and in every message since.

The disclosure everyone forgets: open and click tracking

Almost every email platform tracks who opened which email and what they clicked, often using a tracking pixel. That is processing of personal data and your privacy policy must mention it. It is the single most common omission in newsletter privacy policies - and the easiest to fix.

What your newsletter privacy policy must cover

  • Who you are and how to contact you
  • What you collect: email address, name if asked, signup source, and engagement data (opens, clicks, approximate location from IP)
  • Your lawful basis: consent (or the soft opt-in for existing customers)
  • Your email platform, named as a processor - and where it stores data; US-based platforms mean an international transfer, covered by the UK–US Data Bridge or the UK Addendum/IDTA
  • Retention: how long you keep subscribers, and what happens after unsubscribe (keeping a minimal suppression record is normal - say so)
  • Rights: unsubscribe any time, access, correction, deletion, and complaint to the ICO

Every email you send needs two things

Under PECR you must identify yourself as the sender and provide a valid way to opt out - the unsubscribe link - in every single message. Honour unsubscribes promptly; "it takes up to 30 days" reads as a red flag to both subscribers and regulators when suppression is instant on every modern platform.

One rule that is not negotiable: never buy a list

Consent obtained by a list broker is almost never valid for you - the subscribers did not consent to your emails. Bought and scraped lists are behind most UK spam enforcement actions. Grow slower; sleep better.

Frequently asked questions

My newsletter runs on Substack. Isn't their privacy policy enough?

No. Substack's policy covers Substack's own processing. You are the controller of your subscriber list and owe readers your own explanation of what you collect and why - most writers add a short privacy notice page or section.

Is double opt-in required by law in the UK?

No. Single opt-in is lawful if it is a clear positive action and you keep records. Double opt-in is best practice because it gives you unbeatable proof of consent.

Can I email people who bought from me without asking again?

Usually yes, under the PECR soft opt-in - provided you collected the address during the sale, you market similar products, and every email carries an opt-out. It does not cover people who merely downloaded a freebie or followed you on social media.

Need a policy for your business?

Generate a legally-formatted, AI-reviewed policy in under 60 seconds.

Generate your policy

Keep reading

All articles