imail just got bigger — AI translation · Drive · Calendar · Android & iOS apps. See what's new →

GDPR-compliant email: what it means and how to choose a provider

26/07/2026 · 4 min read · imail.com.tr

What the GDPR actually requires of email, which questions to ask a provider, and the practices that keep everyday correspondence lawful.

Email is where personal data quietly accumulates: names, addresses, order details, CVs, health notes forwarded "just this once". Under the GDPR, that correspondence is processing of personal data like any other, and the obligations that come with it apply to the mailbox as much as to the database.

What the regulation actually asks for

There is no such thing as a GDPR certificate for a mail provider, and any vendor claiming one is overselling. What the regulation asks is that processing has a lawful basis, that data is kept no longer than necessary, that it is protected by appropriate technical and organisational measures, and that people can exercise their rights over it.

For email in practice, that translates into a handful of concrete things:

  • Encryption in transit (TLS) between servers and clients, so messages are not readable en route.
  • Access control — strong passwords, two-factor authentication, and limits on who can open shared mailboxes.
  • Retention limits. Mail that no longer serves a purpose should not sit in an archive indefinitely.
  • A processor agreement with your provider, setting out what they may do with the data.
  • Breach readiness. You have 72 hours to notify a supervisory authority once you become aware of a qualifying breach.

Questions worth asking a provider

  • Where are the servers located, and where is data backed up?
  • Are messages scanned for advertising purposes? (If yes, walk away for business use.)
  • Is a data processing agreement offered as standard?
  • Are sub-processors listed, and are you told when they change?
  • What are the deletion timelines when an account is closed?
  • Are SPF, DKIM and DMARC supported so that mail sent in your name can be authenticated?

Practices that do most of the work

Compliance is mostly habit, not technology:

  • Do not send personal data to a wider circle than necessary — check the CC line before sending.
  • Prefer a secure link over an attachment for sensitive documents, and set an expiry on it.
  • Use aliases and role addresses so that inbound personal data lands where the responsible team can see it.
  • Delete or archive old correspondence on a schedule rather than by accident.
  • Train people on phishing: most breaches involving email start with a stolen password, not a broken cipher. Our guide on spotting phishing emails is a useful starting point.

Encryption: transit versus content

TLS protects mail while it travels between servers, and it is now near-universal — but it does not protect the message once it is stored, and it cannot guarantee the recipient's server is configured well. For genuinely sensitive material, add a layer at the content level: a password-protected file or a link that expires, with the password shared through another channel. Our guide to sending encrypted email covers the options.

Frequently asked questions

Does the GDPR apply if my company is outside the EU? It can. The regulation follows the data subject: if you offer goods or services to people in the EU, or monitor their behaviour there, it applies regardless of where you are established.

Is a free personal mailbox enough for business correspondence? It is rarely a good fit. You cannot sign a processing agreement for an employee's personal account, and you cannot control access to it.

Do I need to encrypt every message? No. Transport encryption is the baseline; add content-level protection where the material is genuinely sensitive.

How long may I keep old email? As long as there is a purpose and, where applicable, a statutory retention period. Set a policy and apply it consistently — "forever" is not a policy.

Privacy at imail.com.tr

imail.com.tr is operated from Türkiye and is ad-free: your mail is never scanned to target advertising. Connections use TLS, and outgoing mail is authenticated with SPF, DKIM and DMARC. Turkish data protection law (KVKK) — which follows the same principles as the GDPR — applies to the service; our privacy policy sets out what is processed and why.

> This article is general information, not legal advice. For an organisational compliance programme, consult a qualified data protection adviser.

GDPR privacy compliance business email

Free, ad-free email

15 GB of storage, KVKK compliant, your own @imail.com.tr address.

Create a free account