ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

What are the 7 GDPR requirements?

Back to InsightsWhat are the 7 GDPR requirements?

What are the 7 GDPR requirements?

Key Facts

Most businesses don't ignore GDPR because they don't care — they ignore it because the rules feel abstract until a regulator comes knocking. Non-compliance can trigger fines of up to €20 million or 4% of global annual turnover, whichever is higher, and enforcement doesn't stop at EU borders. Google learned this the hard way when French authorities issued a €50 million fine for consent that was neither informed, unambiguous, nor specific — a direct violation of GDPR's requirement that consent be a clear affirmative action.

The regulation applies extraterritorially: any organization processing personal data of EU residents must comply, regardless of where the company is based. That means a Halifax-based service reaching out on behalf of US businesses still carries GDPR obligations whenever a contact list includes EU residents. The stakes compound when you consider that most customers forget a business within ~12 months, leaving companies sitting on valuable but legally untouchable dormant lists.

  • Consent must be freely given, specific, informed, and unambiguous — silence or pre-ticked boxes don't count
  • Separate consent is required for each processing operation (calls, texts, emails)
  • Withdrawal must be as easy as giving consent
  • Organizations must be able to demonstrate exactly when and how consent was obtained

This creates a genuine tension: reactivating past customers is ~5x cheaper than acquiring new ones, and ~60% of revenue often comes from repeat business, yet you can't legally just start messaging people who haven't heard from you in a year. CallMyCustomers navigates this by securing explicit consent during the booking flow and requiring client approval on every script, offer, and message before outreach begins — ensuring each touchpoint meets GDPR's standard for specific, informed, and unambiguous permission.

The 7 GDPR Requirements Explained

Understanding the seven GDPR requirements is essential for any business handling personal data, especially when reaching out to customers. These principles—lawfulness, fairness and transparency; purpose limitation; data minimisation; storage limitation; accuracy; integrity and confidentiality; and accountability—form the foundation of responsible data processing under EU law, as outlined by the European Commission. For marketing outreach, consent often serves as the key lawful basis, and it must meet strict criteria: it must be freely given, specific, informed, and unambiguous, requiring a clear affirmative action such as an unticked checkbox or explicit opt-in, with silence or pre-ticked boxes failing to qualify. Organizations must also be able to demonstrate that consent was obtained and ensure withdrawal is as easy as giving it.

CallMyCustomers integrates these requirements into its permission-based outreach model, where every script, offer, and message is approved by the client before sending, and explicit consent is collected during the booking flow. This approach aligns with GDPR’s emphasis on granularity and transparency, ensuring that consent is tied to specific processing operations and communicated in plain language. For instance, research shows that moving from automatic opt-ins to manual checkboxes reduced email volume by 46% while increasing open rates by 341% and click-through rates by 400%, demonstrating the value of compliant consent practices. Similarly, the National Garden Scheme cleaned its list from 41,530 to 15,215 active, consenting contacts and grew a targeted segment from 229 to 13,304, proving that respecting consent improves engagement and data quality.

To maintain compliance, CallMyCustomers ensures that consent mechanisms meet all four qualities: freely given (not a condition of service), specific (separate consent per channel like calls, texts, or emails), informed (clear explanation of purpose, data usage, and withdrawal rights), and unambiguous (requiring a clear affirmative action). Withdrawal is built into the process—customers can opt out easily, and requests are honored immediately, as required by GDPR. The company also applies data minimisation and storage limitation principles, collecting only what is necessary for each campaign and reviewing data retention regularly, especially given that many customers forget a business within 12 months. Accountability is reinforced through detailed records of when, how, and what consent was obtained, supporting demonstrable compliance.

By embedding these principles into its workflow—from list segmentation to message approval and follow-up—CallMyCustomers helps US service businesses reactivate customers responsibly, turning past connections into booked work without compromising privacy or trust. This permission-based approach not only meets regulatory standards but also strengthens customer relationships, proving that compliance and effectiveness can go hand in hand. For businesses seeking to re-engage inactive customers with full transparency and consent, the path forward is clear: respect the data, honor the choice, and let every outreach begin with permission. Industry case studies show that such methods yield higher engagement and cleaner lists over time. GDPR consent guidelines reinforce that valid consent requires active participation, not assumption. The European Commission’s principles remind us that accountability starts with clear, auditable practices—exactly what CallMyCustomers builds into every campaign.

Most businesses treat consent requirements like a tax — something that shrinks their list and costs them reach. The repermissioning case studies tell the opposite story: when companies cleaned their lists and asked for permission properly, engagement didn't just survive, it exploded.

Consider Formstack. When the company switched from automatic opt-ins to manual checkboxes, its email volume dropped by 46%. But according to the documented case study, open rates rose 341%, click-through rates rose 400%, and unsubscribe rates fell 33%. The "smaller" list dramatically outperformed the padded one.

The National Garden Scheme saw the same pattern. The organization trimmed a 41,530-subscriber list down to 15,215 active, consenting contacts — and then grew a "ticketed gardens and events" segment from 229 to 13,304 contacts. Cutting dead weight created room for genuine growth among people who actually wanted to hear from them.

LJ Strategies ran a phased repermissioning campaign on a 270,000-contact dormant list, validated down to 219,000 and sent in escalating waves. The result: a clean list of 125,000 contacts, a 57% retention rate on a list that had been sitting idle. That's 125,000 people reachable with confidence versus 270,000 names with no proof of interest.

The pattern across these cases is consistent:

  • Consenting contacts engage at dramatically higher rates than default opt-ins.
  • Re-engaged subscribers keep engaging — about 45% of recipients who respond to re-engagement campaigns continue opening future emails.
  • Honesty about compliance itself converts — a MECLABS Institute test found a repermissioning email that explained the compliance reason outperformed a value-only version by nearly 50%.

This is why permission-first outreach isn't just a legal posture — it's a revenue strategy. It's also the operating principle at CallMyCustomers, where every message is approved before it's sent and opt-outs are honored immediately. A smaller, permissioned list beats a big, non-compliant one every time.

The takeaway for any business running reactivation or retention campaigns: don't mourn the contacts you lose in a consent cleanup. The ones who stay are the ones who buy.

How CallMyCustomers Applies the 7 Requirements to Every Campaign

Most businesses treat GDPR compliance as a checkbox. CallMyCustomers treats it as the foundation of every campaign — because permission-based outreach isn't just safer, it performs better. When Formstack switched from automatic opt-ins to manual checkboxes, emails sent dropped 46%, but open rates rose 341% and click-through rates rose 400%, according to documented repermissioning case studies.

Here's how each of the seven requirements maps to the process.

Lawfulness, fairness and transparency. Every campaign runs only from lists of real customers — people who already know the business. The owner signs off on every script, offer, and message before anything is sent, so nothing goes out that the business hasn't seen and approved. That is transparency in practice, not just on paper.

Purpose limitation. The free list review segments each list by recency, old quotes that never became jobs, expiring memberships, and happy customers who could refer. Each segment gets one clear reason to reconnect — a renewal reminder, an old-quote follow-up, a seasonal check-in — so outreach stays tied to a defined purpose rather than blanket marketing.

Data minimisation and accuracy. Segmenting by recency (30 days, 6 months, 12+ months) means the campaign uses only what's needed: recent customers get one message, dormant ones get another. The European Commission's GDPR principles require data to be adequate, relevant, and strictly necessary — a targeted list review delivers exactly that, before a single dollar is spent.

Consent as affirmative action. The booking flow collects explicit consent, satisfying the standard that consent must be freely given, specific, informed, and unambiguous, with a clear affirmative action — silence, pre-ticked boxes, or inactivity don't count. The ICO's warning matters here: vague, sweeping, or confusing language invalidates consent, which is why consent explanations stay plain-language.

Easy withdrawal. Opt-outs are honored immediately. GDPR requires that withdrawal be as easy as giving consent, and an opt-out that takes effect on the spot — not after the next campaign wave — meets that bar.

The remaining principles round out the picture:

  • Storage limitation — dormant segments get reviewed and cleaned rather than mailed indefinitely, with retention periods kept as short as the campaign purpose allows.
  • Integrity and confidentiality — clinic and med spa outreach runs under the required privacy agreements (BAA/HIPAA, TCPA, A2P 10DLC in practice), with patient data handled to clinical standards.
  • Accountability — because the owner approves every message, there's a clear record of what was sent, when, and to whom.

The result is outreach that feels useful, not pushy — and holds up to scrutiny.

Your Action Plan: Running a Compliant Reactivation Campaign

Knowing the seven GDPR requirements is one thing; turning them into a working reactivation campaign is another. Here is a practical action plan that keeps your outreach compliant from list to launch.

Step 1: Audit and segment by recency. Split your customer list into recent contacts (last 30 days), warm contacts (up to 6 months), and dormant contacts (12+ months). The National Garden Scheme showed the value of this discipline: it cleaned a 41,530-subscriber list down to 15,215 active, consenting contacts — and grew its most engaged segment from 229 to 13,304 contacts, according to documented repermissioning case studies.

Step 2: Set storage-limitation policies. GDPR requires retaining personal data only as long as necessary, per the European Commission's data protection principles. Compliance guidance recommends erasing or reviewing data within 6 to 12 months of expiry — a natural fit for reactivation, since most customers forget a business within roughly 12 months anyway.

Step 3: Document every consent record. GDPR demands demonstrable consent under Article 7(1), so capture the essentials for each contact:

  • Date and time consent was given
  • Method — checkbox, booking flow, or verbal opt-in
  • The exact version of the consent statement shown
  • Which channels were covered (calls, texts, emails — separately)

Remember that consent must be freely given, specific, informed, and unambiguous — pre-ticked boxes and implied consent don't count, as legal experts make clear. Granularity matters too: separate consent per processing operation, per GDPR consent requirements.

Step 4: Choose a legitimate reason to reconnect. A seasonal reminder, an old-quote follow-up with a fresh angle, or a renewal notice before lapse gives the message genuine value. This is exactly how CallMyCustomers structures its campaigns — outreach that feels useful, not pushy, and that the business owner approves before anything goes out. The payoff is real: Formstack's shift from automatic opt-ins to manual checkboxes cut emails sent by 46% but lifted open rates 341% and click-through rates 400%, per the same case research.

Step 5: Approve every message before sending. A sign-off step keeps you accountable and keeps consent language consistent with what customers actually agreed to. And before you spend a dollar, get a free list review to see what your list can realistically produce — your rate, your setup, and your reactivation potential, mapped out in advance.

Frequently Asked Questions

What are the 7 GDPR requirements that businesses need to follow?
The seven GDPR requirements are lawfulness, fairness and transparency; purpose limitation; data minimisation; storage limitation; accuracy; integrity and confidentiality; and accountability. These principles form the foundation of responsible data processing under EU law, as outlined by the European Commission.
What does GDPR require for valid consent when contacting customers?
GDPR requires that consent be freely given, specific, informed, and unambiguous, involving a clear affirmative action such as an unticked checkbox or explicit opt-in—silence, pre-ticked boxes, or inactivity do not count as valid consent.
Can a business based outside the EU still be subject to GDPR rules?
Yes, GDPR applies extraterritorially: any organization processing personal data of EU residents must comply, regardless of where the company is based. This means a Halifax-based service reaching out on behalf of US businesses still carries GDPR obligations if the contact list includes EU residents.
How does getting proper consent actually improve marketing results?
Businesses that cleaned their lists and asked for permission properly saw dramatic engagement improvements—Formstack reduced email volume by 46% but increased open rates by 341% and click-through rates by 400%, while the National Garden Scheme grew a targeted segment from 229 to 13,304 contacts after list cleanup.
What happens if a business doesn't get GDPR consent right?
Non-compliance can trigger fines of up to €20 million or 4% of global annual turnover, whichever is higher. Google learned this the hard way when French authorities issued a €50 million fine for consent that was neither informed, unambiguous, nor specific.
How long should businesses keep customer data under GDPR?
GDPR requires retaining personal data only as long as necessary for the purpose it was collected. Given that most customers forget a business within ~12 months, data retention periods should be minimized, with data erased or reviewed within 6 to 12 months of expiry.

Permission Isn't a Barrier — It's Your Best-Performing List

The seven GDPR requirements — lawfulness, fairness and transparency; purpose limitation; data minimisation; storage limitation; accuracy; integrity and confidentiality; and accountability — aren't just legal checkboxes. As the case studies throughout this article show, they're a framework for better marketing. Formstack's shift to manual opt-ins cut email volume by 46% while lifting open rates 341%, and the National Garden Scheme turned a trimmed list into its most engaged segment ever, according to documented repermissioning research. The lesson is consistent: the contacts who explicitly consent are the ones who open, click, and buy. Start by auditing your list, documenting every consent record, and choosing a genuine reason to reconnect — then approve every message before it goes out. That's exactly how CallMyCustomers runs reactivation for US service businesses: explicit consent collected up front, owner sign-off on every script and offer, and opt-outs honored immediately. If you're sitting on dormant customers you can't legally (or confidently) reach, the first step costs nothing — get a free list review to see your rate, setup, and what your list can realistically produce before spending a dollar.

Stay in the Loop