top of page

Electronic direct marketing is a key part of sales and customer communications for many companies. However, newsletters, promotional emails and marketing automation only work when there is also a valid legal basis for sending them. Recently, automated marketing calls have attracted particular attention in supervisory practice. In practice, a company should answer three questions before sending a message: who is the recipient, does the message constitute marketing or customer communication, and what is the legal basis for sending it? Electronic direct marketing includes emails, text messages, multimedia messages, voice messages and automated calls used to market products or services to the recipient. The format of the message is not decisive. What matters is its purpose and content. If the objective is to promote the sale of a product or service, the message will generally constitute direct marketing.


A newsletter will usually constitute direct marketing if it contains offers, presentations of services, invitations to events, campaigns or other content intended to promote sales. Even content that appears purely informative may constitute marketing if its main purpose is to encourage the recipient to make a purchase, book a demonstration, download sales materials or attend a commercial event.

However, not every message sent to customers constitutes direct marketing. Order confirmations, delivery notifications, service interruption notices and other messages relating to the performance of a contract or the provision of a service are generally considered customer communications. If sales-oriented content is added to the message, it may nevertheless become direct marketing. For example, adding an offer to “upgrade to the premium version” to a service interruption notice may change how the message is assessed.


Marketing to a personal address generally requires prior consent


As a general rule, electronic direct marketing may only be sent to a natural person if they have given their prior consent. This is the main rule for electronic direct marketing aimed at consumers. The same applies, for example, to automated calling systems. Marketing through automated calls requires the recipient’s prior consent.


Consent must be freely given, specific, informed and unambiguous. In practice, the recipient must take an active step themselves, such as ticking a box to subscribe to a newsletter. A pre-ticked box, silence or the fact that the individual has not specifically objected to marketing does not constitute valid consent.


The requirement that consent be freely given does not necessarily prevent direct marketing consent from being linked to participation in a voluntary prize draw. The Finnish Data Protection Ombudsman has considered that consent to direct marketing requested as a condition for participating in a prize draw may be valid if participation is genuinely voluntary, choosing not to participate causes no detriment and the prize draw is not connected to a service that is essential to the data subject. However, the assessment must always be made on a case-by-case basis.


Separate consent is not always required. If a customer has purchased a product or service from a company and provided their electronic contact details in connection with the purchase, the company may, subject to certain conditions, market its own similar products or services to that customer.

However, this exception cannot be treated as a general authorisation for all marketing. It requires that the contact details were obtained directly from the customer in connection with a sale, that the marketing concerns the same company’s own products or services, and that the products or services being marketed are similar to the customer’s previous purchase. For example, if a customer has purchased a particular software service, it may, depending on the circumstances, be permissible to market additional features within the same service package or other similar services to them. The same contact details do not, however, permit the marketing of services offered by an entirely different group company, products offered by a business partner or products belonging to a completely different category.


The customer must also be given an easy and free opportunity to object to marketing both when their contact details are collected and in every subsequent marketing message.


In B2B marketing, it is not enough that the recipient works for a company


In business-to-business marketing, the assessment depends on the type of address to which the message is sent and the recipient’s role. As a general rule, electronic direct marketing may be sent without prior consent to general company addresses, such as info@company.com or sales@company.com. However, the message must still provide an opportunity to object to further marketing.


If the message is sent to a named individual, such as firstname.lastname@company.com, the sender must assess whether the product or service being marketed is materially related to the recipient’s professional duties. For example, marketing financial administration services to a person responsible for financial decision-making may be justified. The same message cannot, however, be sent as a precaution to every individual whose contact details can be found at the company.


The essential point is that the recipient’s role and the content being marketed must correspond with one another. A mere assumption that the recipient might be interested is not enough. In B2B marketing, it is also important to remember that a personal work email address does not become a freely available marketing channel simply because the address is publicly available or can be found on LinkedIn, a website or an event participant list. The sender must still be able to explain why the message sent to that particular person relates to their professional duties and why the marketing has been appropriately targeted.


Companies must be able to demonstrate consent


A company must be able to demonstrate the basis on which it sends electronic direct marketing. If the marketing is based on consent, the documentation should indicate at least when the consent was given, through which channel it was given, the type of marketing to which it applies and the information provided to the recipient when consent was requested.


Every electronic direct marketing message must include an easy and free method of objecting to the marketing or withdrawing consent, such as a functioning unsubscribe link. Withdrawing consent must be as easy as giving it. In practice, recipients should not be required to contact customer service separately or log in to a complicated system merely to unsubscribe from a newsletter.


Electronic direct marketing usually involves the processing of personal data, which means that the requirements of the General Data Protection Regulation also apply. The recipient must therefore be clearly informed about how their personal data is processed.


In practice, a company should ensure that its privacy notice explains who processes the personal data, the purposes for which the data is used, the legal basis for the processing, the source of the data, how long the data is retained and how the recipient can exercise their rights.


The regulation of electronic direct marketing does not prevent effective marketing, but it does require companies to handle the fundamentals carefully. Before launching a campaign, a company should verify where the recipients’ contact details came from, the legal basis for sending the messages and how marketing objections and withdrawals are implemented in practice.


Hymyilevä nainen valkoisessa paidassa nojaa tiiliseinään, kädet ristissä.


Lila Kallio

Counsel

+358 41 465 1365








To receive our articles directly in your inbox, subscribe to the Folks newsletter here.

The EU General Data Protection Regulation (GDPR) and Its Future: Striking a Balance Between Innovation and Privacy


The GDPR is known as one of the strictest data protection laws in the world. It is an ambitious project that strengthens fundamental rights and gives individuals greater control over their personal data. At the same time, it has introduced a new culture of enforcement. Supervisory authorities have adopted a strict approach to assessing the lawfulness of personal data processing.


The landscape is now changing. The European Commission’s Digital Omnibus package aims to simplify and clarify the EU’s digital regulatory framework, including the GDPR. Reform is needed, as the current framework is widely regarded as overly burdensome and as an obstacle to innovation. This raises an important question. Are we moving from a fundamental-rights-based culture of caution to the opposite extreme, where competitiveness takes precedence over data protection? Or are we finally finding a balance in which innovation and privacy can coexist?


Strict interpretations have limited opportunities for innovation


The interpretation of the definition of personal data is central to determining whether the GDPR applies. In the Court of Justice of the European Union’s judgment in Breyer v Federal Republic of Germany (C-582/14), the Court considered whether dynamic IP addresses stored in a website’s log files constituted personal data. The service provider could not identify the user without additional information held by the telecommunications operator. The Court found that information may constitute personal data even where the additional information required for identification is held by a third party.


The key consideration was whether the controller had means reasonably likely to be used to obtain the additional information. Although the judgment itself leaves room for a case-by-case assessment of whether the controller has reasonable and lawful means of identification, the approach adopted by authorities and businesses has become increasingly cautious. Identification does not need to be likely. It is often considered sufficient that identification cannot be entirely ruled out. As a result, all GDPR obligations may become applicable unnecessarily broadly. This shifts attention away from situations involving a genuine risk to privacy.


This cautious approach has led many organisations to abandon potentially beneficial data projects. They have been reluctant, for example, to interpret the available legal bases for processing flexibly. According to the Research Institute of the Finnish Economy, Etla, strict data protection regulation has significantly reduced research and development investment by pharmaceutical and biotechnology companies. When businesses consider whether patient data, customer data or Internet of Things data can be used to develop new services and products, caution driven by the fear of sanctions often prevails. This is not solely the result of the wording of data protection legislation. It is largely a consequence of how the legislation has been interpreted by the authorities.


European policymakers have become increasingly aware that, while the EU has built the world’s strongest data protection regime, it has fallen behind the United States and China in data-driven business and artificial intelligence development. Mario Draghi’s report on European competitiveness has highlighted this issue. The Commission has therefore faced growing pressure to soften digital regulation.


Can the Omnibus bring us happiness?


The Digital Omnibus package published by the Commission on 19 November 2025 aims to simplify regulation, reduce costs and improve the EU’s competitiveness. In practice, this can be seen, for example, in proposed changes to cookie practices. The objective is to reduce the constant need to click consent banners. Users could set broader consent preferences at browser level or provide consent that remains valid for a longer period.


Another visible proposal is to postpone the application of the strictest obligations under the AI Act. This would give companies more time to bring high-risk AI systems into compliance.


Targeted amendments have also been proposed to the core of the GDPR, including changes that would narrow the definition of personal data. This would create more room for the use of personal data in training AI models, including on the basis of legitimate interests. The desire to clarify the rules and remove regulatory overlap is understandable. The current digital regulatory framework, comprising the GDPR, the Data Act, the Digital Services Act, the Digital Markets Act, the NIS2 Directive and the AI Act, has grown into a complex mosaic. Managing it is difficult even for large organisations, let alone smaller businesses.


The proposals have nevertheless attracted vocal criticism. Civil society organisations and data protection experts have described the proposed amendments as a strategy of “a thousand small cuts”. The reforms may not dismantle the GDPR as a whole, but they could weaken its effectiveness in critical areas, such as the legal bases for processing personal data used to train AI models. The key question is the extent to which the problem lies in the wording of the GDPR itself and the extent to which it lies in the culture surrounding its application.


Even before the Digital Omnibus initiative, the European Data Protection Board, or EDPB, had recognised the need for practical simplification. In the so-called Helsinki Statement, the EDPB stated that it aims to make it easier for small and medium-sized enterprises in particular to comply with the GDPR in practice. The objective is to increase dialogue with stakeholders and improve the consistency of regulation without weakening individuals’ fundamental rights. This indicates that the supervisory authorities also recognise that the application of the GDPR has become unnecessarily burdensome. Companies’ compliance work should be facilitated through measures such as practical tools and templates.


A more pragmatic approach to the definition of personal data had also begun to emerge before the Digital Omnibus proposal. In EDPS v SRB (C-413/23 P), it was confirmed that pseudonymised data generally remains personal data from the perspective of an organisation that can obtain additional information and identify the data subject using means reasonably likely to be used, in accordance with the criteria established in Breyer.


At the same time, the judgment opened the possibility that the same data may constitute personal data for one organisation but be anonymous for another organisation that has no realistic means of re-identifying the data subject. The Omnibus proposal consolidates this approach and expressly rejects the position taken by the European Data Protection Supervisor, or EDPS, in the SRB case referred to above. Pseudonymised data is not always personal data for every organisation.


Conclusion


It is clear that data protection regulation has reached a crossroads. Most of the current problems do not arise because the GDPR’s fundamental principles are inherently too strict. They arise because those principles are translated into absolute prohibitions in day-to-day practice instead of being applied through a risk-based approach. From this perspective, amendments to the GDPR’s fundamental concepts may not have been necessary. A stronger culture of interpretation based on risk would have been the more appropriate response.


It is nevertheless difficult to oppose objectives such as removing overlapping regulation, making cookie practices more sensible and reducing the administrative burden on small and medium-sized enterprises. The coming years will determine whether the EU can modernise its data protection framework in a way that preserves its normative strength while enabling innovation.


The central question is whether reform can be achieved without weakening privacy protection or deepening existing competitive imbalances. Such an imbalance could arise if negotiating power is shifted away from individuals and European small and medium-sized businesses towards global technology companies.


Considering the criticism directed at the Digital Omnibus proposal, the political process required to implement the reforms is likely to be challenging. At Folks, we will continue to monitor the progress of the legislative initiative closely.


Folksin osakas Anna Paimela hymyilee, kädet ristissä, valkoinen paita. Tausta harmaata kiviseinää. Ilmapiiri ystävällinen ja rento. Ei tekstiä.

Anna Paimela

Partner

+358 40 1648626








To receive our articles directly by email, subscribe to the Folks newsletter here.

bottom of page