← All articles

GDPR: what a marketing team has to keep in order, day to day

Records, retention periods, processors, deletion requests: the GDPR workstreams that land on marketing, and the checklist to know where you stand.

Dots Papers cover for the article on day-to-day GDPR work in a marketing team

In short

  • The record of processing is the first document you will be asked for. One line per processing activity: purpose, legal basis, retention. It lives in a spreadsheet, not at a law firm.
  • Retention periods are the weak point of marketing databases. A prospect with no sign of life for four years no longer belongs in your file.
  • Your marketing tools are processors. Email platform, analytics, ad network: each one needs a written contract and a known location.
  • The real risk is the absence of a procedure. A deletion request with no identified recipient blows through the one-month deadline without anyone noticing.

A request arrives on a Tuesday morning through the contact form: “delete everything you hold on me”. The person is in the email platform, in the CRM, in the order history, and in a file sent to an agency last year. Who handles the request, within what deadline, and how do you later prove the deletion happened everywhere?

In most of the small companies we work with, that question produces silence: nobody has written the procedure, and the data has scattered across a dozen tools.

The GDPR arrived in May 2018 as a legal subject. Eight years later it is an organisational one, and it lands on marketing: those are the teams that collect, segment, export and follow up.

The mistake to avoid Believing a cookie banner is enough to put you in order. It handles the setting of trackers, one box out of a dozen. It says nothing about your retention periods, your processing contracts, your file exports, or your ability to answer a deletion request.

Consent is covered separately here: how to write a consent request. Here are the five workstreams that come after.

The record of processing: the first document you will be asked for

The record is not a legal document. It is the inventory of what you do with personal data: one line per processing activity, kept by whoever actually knows the tools.

Article 30 provides an exemption below 250 employees, but it falls away as soon as processing is not occasional. A prospecting database fed continuously and a monthly newsletter are regular activities: a small company doing marketing therefore keeps a record.

It is the first document requested in an inspection because it shows within ten minutes whether you know what you are doing. A missing record opens the discussion onto your entire organisation; a record that is kept narrows it to a few points.

What goes into one line of the record

Column What you write in it Example: the newsletter
Purpose Why you process this data, in one sentence Sending commercial information
Legal basis Consent, contract, legal obligation or legitimate interest Consent collected at sign-up
People Who is in the file Customers and subscribed prospects
Data The fields actually stored Email, first name, date, opens
Recipients Who has access, which provider hosts it Marketing, email platform
Transfers outside the EU Yes or no, on which legal mechanism To be checked in the contract
Retention A figure and a trigger, never “as long as necessary” 3 years after the last contact
Security The concrete measures in place Named accounts, two-factor authentication
Structure of one record line, on the most common marketing processing activity in a small company.

The marketing lines are almost always the same: newsletter, prospecting, customer accounts, audience measurement, advertising audiences, competitions, forms, customer reviews. Writing those eight lines takes half a day and surfaces the orphan processing activities, the ones nobody can say why they still run.

Retention periods: the worst-kept workstream

This is the subject where we find the biggest gaps in audits: almost every database we open contains contacts inactive for five or six years, for lack of a written purge rule.

A retention period is not picked from a table, it is deduced from the purpose. As long as the purpose lives, the data is justified; when it dies, the data goes to deletion or to a restricted-access archive.

Type of data Retention logic and usual order of magnitude Deletion trigger
Unconverted prospect Justified as long as the relationship is alive. Common practice: 3 years Last contact coming from the prospect: open, click, reply
Inactive customer Out of prospecting databases once the relationship has died. Common practice: 3 years Last order or last exchange
Order history Imposed by accounting obligations, in a restricted-access archive rather than the marketing database. Common practice: 10 years Close of the financial year
Browsing and trackers The tracker lives far shorter than the statistics it feeds. Common practice: 13 months, around 25 months for the data Setting of the tracker
Proof of consent As long as the consent has effect, plus the time needed to prove it Withdrawal or unsubscribe
Usual orders of magnitude in a small company. None of these periods is an absolute rule: the purpose is what justifies it.

The trigger matters more than the period. “Three years” means nothing if nobody knows from which event the countdown starts, nor which process runs the purge. A rule no script applies remains an intention.

Your marketing tools process your data for you

Email platform, analytics, ad network, agency: they all handle data you remain responsible for. The regulation calls them processors and requires a written contract framing what they may do with it.

That contract exists at most vendors, as an addendum to accept in the interface. The work is to check that it has been accepted, and to read four points in it.

  • Instructions. The provider processes the data only on your behalf, never for its own purposes.
  • Sub-processors. There are almost always some: the list must be accessible and its changes notified.
  • Location. Where the data is hosted and, if it leaves the European Union, on which legal mechanism.
  • End of contract. Return or deletion, within what deadline, with what proof.

Two points not to miss: the provider must alert you without delay in case of an incident, since you are the one who will notify the authority. And on certain advertising functions, the platform acts as a joint controller rather than a processor, which needs documenting in writing.

Rights requests: the clock starts on receipt

Access, rectification, deletion, objection, portability: a person can write to you through any channel, including by replying to a newsletter. The deadline is one month from receipt, extendable by two months for a complex request, if you inform the person within the first month.

Objection to marketing is not open to discussion and needs no justification. It must be effective everywhere, including in a file already exported to a provider or in an advertising audience already uploaded.

The risk is not the request, it is the absence of a procedure. Four elements are enough:

  • A single receiving address, published in the privacy policy and watched by a named person.
  • A map of where the data lives, which is the record read the other way round.
  • Proportionate identity verification, without demanding an identity document out of reflex.
  • A log of requests: date received, date answered, what was done and where.

An ignored request ends up as a complaint to the supervisory authority. The examination that follows is no longer about the original request, but about your whole organisation.

Data breaches: more frequent than people imagine

A breach is not only a cyberattack. It is any incident leading to the destruction, loss, alteration, disclosure of, or unauthorised access to personal data.

A customer file sent to the wrong recipient is one. So is an email addressed to a whole list in visible copy instead of blind copy, a shared folder left public, or a former employee whose CRM access was never cut.

The reflex to have Every breach is documented internally, including the ones you do not notify: nature of the incident, data affected, number of people, likely consequences, measures taken. Notification to the supervisory authority happens within 72 hours of becoming aware of it, unless the incident presents no risk to people. If that risk is high, they are informed directly.

The breach register is often the second document requested. An empty register is not a good signal: mostly it says incidents are not being reported upwards.

The marketing checklist, ten points

To do this month

  1. List the tools holding personal data, forgotten spreadsheets and exports included.
  2. Write the eight record lines for your marketing processing.
  3. Set a period and a trigger for each database, in black and white.
  4. Check the data processing addendum is accepted at each provider.
  5. Create the single address for receiving requests and publish it.

To install over time

  1. Schedule the automatic purge of inactive contacts rather than promising it.
  2. Keep the rights request log, even if only three arrive a year.
  3. Open a breach register and record the first incident, however minor.
  4. Check every quarter that consent is correctly reported into your measurement tools.
  5. Re-read the record whenever a new tool is connected, before it goes live.

Point nine is more technical than it sounds: consent can be properly collected and badly transmitted to the platforms, with nothing showing on a dashboard. We describe the check in our article on tracking that lies in silence. Datafirefly Limited, the sister company of our agency, also publishes consent and compliance modules for PrestaShop, WooCommerce and Shopware on its marketplace.

Frequently asked questions

Is the record of processing mandatory below 250 employees?

The exemption is narrow: it falls away as soon as processing is not occasional, presents a risk to people, or covers sensitive data. A prospecting database fed continuously is not occasional. A small company doing marketing therefore keeps a record.

Does a small company need a data protection officer?

Designation is only mandatory in three cases: public bodies, regular and systematic monitoring at large scale, and large-scale processing of sensitive data. A typical small company is generally not required to. Naming an internal contact, who keeps the record and receives requests, remains the most effective route, and the role can be outsourced.

Can we keep a prospect who never replied?

Not indefinitely. Common practice is to keep the data around three years after the last contact coming from the prospect, then delete or anonymise it. Keeping a contact “just in case” is not a purpose, and a file of dead prospects damages your email deliverability as much as your compliance.

Is an email sent to a whole list in visible copy a data breach?

Yes: every recipient had access to the others’ addresses without authorisation. Document the incident internally, assess the risk to the people, then notify the supervisory authority if that risk exists, within 72 hours of discovery.

How long do we have to answer a deletion request?

One month from receipt, whatever channel it came through, with a possible two-month extension for a complex request if you inform the person. The clock starts on receipt, not when somebody internally picks it up.

Where to start if nothing exists today

Do not start with the privacy policy. Start with the list of your tools and with retention periods: those are the two points that produce the most effect in a day’s work, and they feed everything else.

The rest is built at the pace of projects: every tool connected, every export to a provider is an opportunity to add a line to the record rather than widen the gap. That is what separates compliance that holds from a file reconstructed in a hurry, and it is one brick of your digital transformation.

The record you keep for the GDPR now has a twin: since 2 August 2026, the AI Act asks for the same inventory work on your AI systems. Role, risk level, legal basis: both regulations ask the same questions, so handle them in one go.

Unsure what your marketing tools keep, and for how long? On a first engagement we list your tools, what goes in and out of each, and the retention periods actually applied: that is where the gaps appear. Let’s talk.

Want to apply this to your own business?

Get in touch →

Further reading

Leave a comment

Your email address will not be published. Required fields are marked *

16 − 4 =