Plans
Learn Library

Why Marketers Everywhere Need to Read One EU Law

An explainer on how the EU's GDPR reshaped digital marketing: consent-based data collection, large fines, Apple's Mail Privacy Protection making open rates unreliable, the shift to first-party and zero-party data, and practical steps like preference centers and easier opt-outs.

ai-marketing
2026-09-18SupaMarketers8 min read

A couple of days ago, I had dinner with a friend who runs a cross-border e-commerce business.

He sells into the European market, and business is decent. But when the conversation turned to email marketing, his face fell: open rates keep getting uglier. He assumed the copy was the problem and dragged his team through rewriting every subject line — nothing worked.

I told him: buddy, you're fighting the wrong opponent.

Your opponent isn't your copy. It's an EU law — and a company called Apple.

He looked up from his grilled fish: Huh?

Don't worry. Let's take it one piece at a time.

Ask First, Then Take

So what is the GDPR?

GDPR — the EU's General Data Protection Regulation — took effect on May 25, 2018.

In plain language, it does one thing: it hands ownership of data back to the user.

Before it came along, most companies played it simple: grab whatever you can. You sign up for an account, and your phone number, email, and browsing history get swept up in one go — to be used however they like.

After it, the rules changed: ask first, then take.

And the asking has to be genuine. No dumping a 20-page terms of service on users. It has to be crystal clear: here's what I'm collecting, here's what it's for — do you agree?

Users also hold four rights:

They can look: what data of mine do you hold?

They can correct: if it's wrong, you fix it.

They can delete: if they no longer want you keeping it, you erase it.

And you're on the hook for security: if something goes wrong, it's on you.

Put simply: the key to the data got fished out of the company's pocket and handed back to the user.

The Fines Really Hurt

Some people say: I don't even have an office in the EU — does this apply to me?

Yes, it does. If you serve users in the EU, you fall under its jurisdiction.

And what if you don't comply?

The maximum fine is the higher of two numbers: €20 million, or 4% of your global turnover.

Mind you: global turnover — not just the European slice.

And every EU country has a dedicated regulator for this. They hand out the fines; they also provide the guidance. Covered from both ends.

Think this is just scare talk?

In 2023, Meta was hit with a €1.2 billion fine for failing to adequately protect EU users' data when transferring it to the US.

€1.2 billion — over nine billion yuan. At 300,000 yuan for a family car, that's more than thirty thousand cars.

TikTok didn't dodge it either; it has been investigated over data compliance in several countries.

Good grief. This is not a slap on the wrist. This is a gash in the main artery.

Users Woke Up, and Cookies Died

But fines are only the noisiest part of this law.

The real impact is that it woke users up.

Before 2018, who cared who took their data, or what it was used for? Basically nobody.

After GDPR took effect, you've surely seen the popup: "We use cookies for personalized recommendations — do you agree?"

Annoying? Truly annoying. But there was a side effect: users around the world got a public masterclass in privacy, all at once.

Once users woke up, the rest followed, link by link.

First link: Apple moves. In 2021, Apple added Mail Privacy Protection (MPP) to email — whether a message was actually opened is no longer yours to see. The open rate as a metric is basically dead.

Second link: cookies fall on hard times. Third-party cookies have been blocked by default in Safari for ages, and Firefox too. Chrome spent years threatening a full ban, wobbled back and forth, and never truly pulled the trigger. But the trend is playing out in the open: chasing people across the internet to stick ads on them is a road that keeps getting narrower.

Third link: the foundation of your data has been swapped out.

Marketers used to build on purchased third-party data. Now the foundation comes in two kinds.

One is first-party data: the behavioral record users leave in your own store, your own app.

The other is zero-party data: what users tell you in their own words. They tick the box for "I only want Monday discounts" — that one sentence is worth more than ten thousand purchased browsing records.

Why?

Because they gave it willingly. If they give it, they'll actually read; if they read, they'll actually click; and if they click — that, finally, is marketing.

Data is shifting from something you buy to something you're given.

When Something Goes Wrong, You Have 72 Hours

One more detail, and you can weigh how heavy this law really is.

A data breach happens. Now what?

GDPR says: within 72 hours, report it, and notify the people affected.

72 hours. Three days. No room for negotiation.

Why so harsh?

Because keeping the lid on is human nature. When something breaks, the first instinct is always: keep it quiet, sort it out first.

But the data sits in your hands, and the user's trust sits in theirs. Every day you keep the lid on is a day they find out later, and a day the losses grow.

In March 2023, AT&T leaked the information of roughly 9 million users — names, phone numbers, email addresses, account numbers, all in there. When something like that breaks, the outrage is secondary; what's stripped away is a layer of trust, plain and real.

So you see, GDPR is really forcing every business to do one thing: think through "what do we do if it happens" before it happens.

Don't resent it for being a hassle. It's protecting your own brand.

One EU Law Became a Template for the World

More impressive still: its influence left the EU long ago.

After Brexit, the UK copied it into its own law, called UK GDPR — almost a mirror of the EU version. Anyone doing business on both sides has to follow both rulebooks.

The US has no single nationwide law. But California moved first with the CCPA (California Consumer Privacy Act), built on the same logic as GDPR, and other states have followed one after another.

Since then, Brazil, Canada, Japan, and South Korea have all passed their own versions. The skeleton is the same: transparency, consent, accountability.

Academia calls this the "Brussels Effect": whoever has the bigger market, their standards slowly become the standards of the whole world.

If you want to earn Europeans' money, you play by Europe's rules.

Want their money? Play by their rules.

AI Is Here. Did the Rules Change?

These past two years, AI is all anyone in marketing talks about.

And the algorithms are genuinely impressive — they can chew through the behavior of millions of people and work out what you'll want to buy tomorrow.

But pay attention: what they're chewing is data. And if it's personal data, every single GDPR rule applies, without exception:

To use it, you need a lawful basis.

Major decisions made automatically by machines have to be explainable.

And before deploying AI, one extra step: run a Data Protection Impact Assessment (DPIA). In plain terms, self-audit before launch: could this thing hurt users?

However new the technology, "ask first, then take" — that rule has never changed.

So Where Should Marketers Start?

Now for the practical part — three moves.

First: start banking data of your own.

Give users a preference center and let them choose: what to receive, how often, what they're interested in. Don't underestimate that page — every box a user ticks is a need they told you in their own words. You get a little less data, but every piece of it is real.

Second: stop chasing people; plant yourself where the content is.

Tracking is done, so do contextual targeting: whatever the user is already looking at, put the relevant message right there.

It used to be like tailing a customer down the street. Now it's like opening your shop on the street they were already going to stroll. They don't mind it, and you have nothing to feel guilty about.

Third: manage consent like a product.

Coming in, they can consent anytime; leaving, they can opt out anytime. Don't bury the unsubscribe link under three layers of menus. Every time you hide it, trust drops a notch.

Oh, and while you're at it — turn off that open-rate dashboard. Apple has already tampered with that signal. A click is a user actually lifting a finger.

Back to That Grilled Fish

My friend went on to do three things: shut down the open-rate dashboard and switch to clicks; launch a preference center and let users pick for themselves; move the unsubscribe link from under three layers of menus to the first one.

The volume of data shrank, visibly.

But click-through rates climbed.

He told me something that stuck with me: it used to be like broadcasting; now it's like a conversation.

GDPR has been in force for more than eight years now. It hasn't cost anyone a single cent — it just took a plain, simple truth and wrote it into the rules the whole world plays by:

Ask first, then take.

Cherish what you're given; be accountable for what you use.

And better yet — may you never have to learn this lesson from a fine.

Continue reading