New EmailLabs Panel
API DOCSEmail API & Cloud SMTPPricingBlog
EN
EN
  • 👋New EmailLabs Panel
  • 💡first steps
    • Completing Company Data
    • GDPR Agreement
      • Choosing the Right GDPR Agreement
      • Signing the GDPR Agreement
    • Security
      • Changing Your Login Password
      • Password Reset
      • IP Authorization
      • Two-Factor Authentication (2FA)
    • SMTP Server Password
    • Sender Authorization
    • SPF Record
      • If You Don’t Have an SPF Record
      • If You Have an SPF Record from Another Service
  • 💌Email
    • Introduction
      • How the Email Channel Works with Omnichannel
      • How to Use Email Campaigns vs API Sends
    • Email API
      • Dashboard
        • Elements on the Dashboard
          • Date Selection
          • SMTP Account Selection
          • Message Statuses and Line Chart
        • Server Information
      • Emails Report
        • Navigation and Tab Selection
          • Structure of the Email Reports Tab
            • Search Tool
            • Email List
              • Detailed Message Logs
      • Tag Report
        • Compare Statuses
          • Search Tool
          • Tags Report Search Results
        • Compare Tags
          • Search Tool
          • Tags Report Search Results
      • Domain Report
        • Search Tool
        • Search Results
      • Blacklist Report
        • Emails Blacklist
          • Search Tool
          • Adding and Exporting Email Addresses
            • Importing Addresses to the Blacklist
            • Exporting Email Addresses from the Blacklist
            • Adding a New Address
        • Domains Blacklist
          • Tool Search
          • Adding a New Domain
        • Import List
          • Search Tool
        • Export List
          • Search Tool
      • Whitelist Report
        • Email Addresses Whitelist
          • Search Tool
          • Add New Address
        • Domain Addresses
          • Search Tool
          • Add New Domain
      • Settings
        • SMTP Accounts
          • General Settings
          • IP Authorization
          • SPF
          • S/MIME
          • Block Disposable Temporary Addresses
          • Tags
            • Configuring a New Rule
          • Headers
            • Configuring Headers
          • Footer
            • Configuring the Footer
          • Link Tracking
            • Link Tracking Configuration
          • Open Tracking
            • Open Tracking Configuration
          • Deep Links
          • Google Analytics
            • Google Analytics Configuration
          • Unsubscribe
            • Unsubscribe Configuration
              • Unsubscribe Page
              • Redirect to Your Unsubscribe Page
            • List-Unsubscribe Header (One-Click Unsubscribe)
        • Blacklist
          • Types of Blacklist
          • Validity of Entries on the Blacklist
          • Bounce Number Before Address Blocking
        • Messages Templaets
          • Email Template Configuration
          • Sending Emails with a Template
    • Email Campaigns
      • Dashboard
        • Elements on the Dashboard
      • Campaigns
        • Campaign List
          • Overview of the Campaign List
          • Campaign Search
          • Campaign List
        • Campaign Export
          • How to Export Campaign List
          • Data Included in the Export File
      • Creating a New Email Campaign
        • Email Template
        • Basic Information
        • Recipients
        • Summary
          • Campaign Preview and Summary
          • Action Button
          • Booster Configuration
          • Campaign Execution
        • Booster Configuration in E-mail Campaign
        • A/B Campaign Email Builder
        • Designing Emails Using the Drag-and-Drop Editor
          • Features of the Editor
            • Content Blocks
            • Rows
            • Settings
          • Creating an Email Design in the Editor
            • Adding Rows
            • Adding Content Elements
            • Personalization and Modification
            • Testing and Optimization
            • Saving and Launching the Campaign
      • Outgoing
        • How to Access Outgoing Emails?
        • Outgoing Emails List
        • Email Details
      • Campaign Reports
        • Summary
        • Opens
        • Clicks
        • Domain Report
        • Heatmap
        • Geo/Tech
        • Tools
        • Data Availability
      • Settings
        • Unsubscribe Pages
          • Adding a New Unsubscribe Page
          • Creating the Unsubscribe Confirmation Page
          • Saving and Completing the Process
          • Available Actions for Created Templates
  • Common Settings
    • Sender Domain Authorization
      • Login and Domain Selection
      • Advanced Settings
      • Generating and Adding DNS Records
        • Domain Authorization in Cloudflare
        • Domain Authorization in GoDaddy
        • Domain Authorization in cyber_Folks
        • Domain Authorization in home.pl
        • Domain Authorization in nazwa.pl
        • Domain Authorization in OVHcloud
        • Domain Authorization in Zenbox
      • Verification and Process Completion
      • Restricting Authorization to Specific SMTPs
      • Technical Support
  • 📱SMS
    • Overview
    • SMS Campaings
      • Dashboard
        • Dashboard Elements
      • Campaigns
        • Campaign List
          • Campaign List Overview
          • Campaign Search
          • Campaign List
        • Campaign Export
          • Data Included in the Export File
        • Creating a New SMS Campaign
          • Sender
          • Recipients
          • Content
            • Message Content
            • Personalization
            • Character Count and Message Billing
            • Message Billing Rules
            • Billing Table
            • Additional Options
              • Campaign Name
              • Campaign Description
              • Progress Notifications (email)
              • Capacity [SMS/h]
              • Unsubscribe Page Template
              • Insert Tracking List
              • Debug Message Content
          • Summary
          • Test Send
          • Booster Configuration
          • Save and Send Campaign
        • Booster Configuration in SMS Campaign
        • Send Test to Multiple
        • Delivery Report
          • Summary
          • Clicks
          • Tools
      • Incoming Messages
        • Incoming Messages
        • Incoming Messages List
        • Exporting Incoming Messages
      • Outgoing Messages
        • Access to Outgoing Messages
        • Outgoing Messages List
        • Exporting Outgoing Messages
      • Settings
        • Links with Suffixes
          • Creating a New Link with a Suffix
          • Managing Links with Suffixes
          • Exporting Link Click Data
          • Best Practises
        • Unsubscribes Pages
          • Configuration Options
          • Unsubscribe Page Functionality
          • Best Practises
    • SMS API
      • Dashboard
      • Incoming Messages
        • Access to Incoming Messages
        • Incoming Messages List
        • Exporting Incoming Messages
      • Outgoing Messages
        • Access to Messages Sent via the API
        • Outgoing Messages List
        • Exporting Outgoing Messages
    • Common Settings
      • SMS Headers
        • Adding a New Sender ID
        • Managing Headers
        • Searching for Headers
        • Security and Best Practises
  • SMS Billing
  • 📲PUSH
    • Push Notifications – How Does It Work?
      • Push Notification Specifications
    • PUSH Campaigns
      • PUSH Dashboard
      • Campaigns
        • Creating a New PUSH Campaign
          • Content
          • Applications and Recipients
          • Summary
        • Booster Configuration in PUSH Campaign
        • Send Test to Multiple
        • Delivery Report
      • Outgoing
    • PUSH API
      • PUSH API Dashboard
      • Outgoing
    • Common Settings
      • Applications
      • Test Contacts
  • ⚙️Integrations
    • SMTP
      • SMTP Relay
      • Atomstore
      • BaseLinker
      • eFitness
      • IdoSell
      • Joomla!
      • Microsoft Outlook
      • Mozilla Thunderbird
      • PrestaShop
      • SALESmanago
      • Selly
      • Shoper
      • SOTE
      • User.com
      • WordPress
    • API
    • SMS
      • SALESmanago
  • 👥Account
    • Users
      • Adding a User
      • Assigning Permissions
      • 2FA Settings
        • Resetting 2FA Settings
      • User Account Activation
      • Editing and Deleting a User
    • Settlements
      • Company Data
      • Invoices
    • Settings
      • Security
        • IP Authorization
        • Two-Factor Authentication (2FA)
      • API
        • Generating API Keys
        • Assigning Permissions
        • Limiting Access to Specific IP Addresses
        • Managing API Keys
        • Integration and Technical Requirements
      • Webhooks
        • Supported Channels and Events
        • Webhook Configuration
        • Data Transmission
    • Notifications
      • Notification Icon
      • Accessing the Full Notification List
        • Full Notification List View
    • Operations List
      • Operation Search
    • File Manager
    • GDPR
  • 🤝CONTACTS
    • Contacts Dashboard
    • Contacts List
      • Adding Individual Contacts
      • Editing Contacts
    • Groups List
      • Adding a New Group
      • Assigning Contacts to a Group
      • Static Group Segmentation
    • Dynamic Segments
      • List of Dynamic Segments
      • Creating a New Dynamic Segment
    • Import
      • Importing Contacts from a File
    • Archive
      • List of Archived Contacts
      • Managing Archived Contacts
    • Additional Fields
      • Adding a New Additional Field
  • 🔐SECURITY CENTER
    • User Account Security
      • Managing Login Password
      • Two-Factor Authentication (2FA)
      • IP Address Access Authorization (Panel, API, SMTP)
      • Managing Users and Roles in the Account
    • Email Sending Security and Authorization
      • Introduction to Sender Authorization
      • SPF (Sender Policy Framework)
      • DKIM (DomainKeys Identified Mail)
      • DMARC (Domain-based Message Authentication, Reporting & Conformance)
      • BIMI (Brand Indicators for Message Identification)
      • Transmission Encryption (TLS)
    • Data Security and EmailLabs Infrastructure
      • EmailLabs' General Commitment to Security
      • Data Center Security
      • Technical and Organizational Measures Applied by EmailLabs
      • Service Protection and Connection Security (Cloudflare WAF)
    • Personal Data Protection and GDPR Compliance
      • Personal Data Processing in EmailLabs
      • EmailLabs Privacy Policy
      • Document Templates for Clients
    • Standards, Certifications, and Audits
      • ISO Certifications
      • Compliance with DORA & NIS2
      • Security and Penetration Tests
    • Protection against Threats and Abuse
      • How EmailLabs Protects Against Phishing and Abuse
      • How to Recognize and Analyze Suspicious Emails (User Tips)
      • Reporting Abuse (Anti-Abuse Policy)
    • Security – Frequently Asked Questions (FAQ)
Powered by GitBook
On this page
  • A Legal Framework for Data Protection and Electronic Marketing – Key Regulations and Obligations
  • Key Legal Regulations
  • 1. GDPR (General Data Protection Regulation) – EU / (RODO - Poland)
  • 2. Act on Combating Abuse in Electronic Communication (Poland)
  • 3. Regulation on Privacy and Electronic Communications ("Cookie Law") – EU & UK
  • 4. Global E-mail Marketing Regulations (Overview)
  • Company Responsibilities for Regulatory Compliance
  • Managing Consents and Recipient Rights
  • Monitoring Regulatory Compliance
  1. SECURITY CENTER

Personal Data Protection and GDPR Compliance

A Legal Framework for Data Protection and Electronic Marketing – Key Regulations and Obligations

Data protection and compliance with regulations are the foundation of secure and transparent communication in the digital world. Our cross-channel platform, enabling interaction with customers in many countries, requires special attention to adherence to applicable legal regulations.

This section will present key aspects of GDPR and other regulations concerning data protection and electronic marketing that directly impact the use of our service. Compliance with these rules not only ensures legal conformity but also supports building trust and security in relationships with recipients in different parts of the world.

Key Legal Regulations

1. GDPR (General Data Protection Regulation) – EU / (RODO - Poland)

The General Data Protection Regulation (GDPR) is an EU regulation that establishes a global standard for data privacy protection. It requires explicit consent for data processing, ensures the right to be forgotten, imposes an obligation for timely data breach notification, and establishes basic personal data safeguards. In Poland, GDPR provisions are supplemented by national regulations that specify and implement EU laws.

  • Key aspects of GDPR:

    • Explicit consent for data processing.

    • The right to be forgotten (permanent data deletion).

    • Obligation to report data breaches.

    • Safeguarding of personal data.

2. Act on Combating Abuse in Electronic Communication (Poland)

Effective from September 25, 2023, the Act on Combating Abuse in Electronic Communication introduces significant regulations concerning communication security. According to Art. 14, public entities may only commission the sending of short text messages (SMS) to an SMS service integrator listed in the register maintained by the President of the Office of Electronic Communications (UKE). Our company, Vercom S.A., is on this list.

To counter threats such as spoofing and smishing, public entities are obliged to use email secured with SPF, DKIM, and DMARC mechanisms:

  • SPF (Sender Policy Framework) – an email sender authentication mechanism that prevents sender domain spoofing.

  • DMARC (Domain-based Message Authentication, Reporting and Conformance) – a protocol enabling domain owners to protect against email spoofing.

  • DKIM (Domain Keys Identified Mail) – a method of cryptographically signing emails, securing their content against alteration during delivery.

Additionally, email service providers serving public entities must offer the possibility of using multi-factor authentication (MFA), which further strengthens user account protection. In the My settings -> 2FA settings section, you can check if two-factor authentication is enabled for your account. More information: 2FA Settings

3. Regulation on Privacy and Electronic Communications ("Cookie Law") – EU & UK

The ePrivacy Regulation, also known as the "Cookie Law," governs the use of cookies and other tracking technologies in the European Union and the United Kingdom. It requires user consent for placing cookies on their device, except for cookies essential for the website's operation.

  • Key aspects of ePrivacy:

    • Consent for the use of cookies.

    • Exceptions for essential cookies.

    • Transparency in informing about used tracking technologies.

4. Global E-mail Marketing Regulations (Overview)

Different countries have varying laws regulating e-mail marketing. Below are key regulations in selected regions.

  • 🇺🇸 United States – CAN-SPAM Act & TCPA

    • CAN-SPAM Act: Defines rules for sending commercial emails. It gives recipients the right to opt-out of receiving messages and imposes strict penalties for violations.

    • TCPA (Telephone Consumer Protection Act): Regulates text messages and telephone calls.

  • 🇨🇦 Canada – CASL (Canada’s Anti-Spam Legislation) One of the world's strictest anti-spam laws. It requires explicit consent for sending commercial electronic messages.

  • 🇦🇺 Australia – Spam Act (2003) Requires recipient consent and an option to unsubscribe. Violations can result in penalties of up to AUD 2.1 million.

  • Other selected regulations:

    • 🇬🇧 PECR (Privacy and Electronic Communications Regulations) – UK: Supplements the UK GDPR, regulating, among other things, the use of cookies and electronic marketing.

    • 🇸🇬 PDPA (Personal Data Protection Act) – Singapore: Defines rules for the collection, use, and disclosure of personal data.

    • 🇧🇷 LGPD (Lei Geral de Proteção de Dados) – Brazil: Introduces comprehensive personal data protection rules, modeled on GDPR.

    • 🇿🇦 POPIA (Protection of Personal Information Act) – South Africa: Regulates the processing of personal data in South Africa.

    • 🇮🇳 DPDPA (Digital Personal Data Protection Act) – India: Modern personal data protection laws in India.

    • 🇯🇵 APPI (Act on the Protection of Personal Information) – Japan: Data protection regulations in Japan.

    • 🇨🇳 PIPL (Personal Information Protection Law) – China: Imposes strict limitations on personal data processing.

Company Responsibilities for Regulatory Compliance

Companies using our omnichannel platform and processing personal data have a number of obligations arising from data protection laws, such as GDPR. Ensuring compliance with regulations not only minimizes legal risk but also builds customer trust. Below are key requirements that must be met.

  • Transparency Companies must clearly inform users about the purposes of data processing, its recipients, and their rights. The privacy policy should be written in an accessible way so that users can easily understand how their data is used.

  • Data Security Appropriate technical and organizational measures must be implemented to protect data against unauthorized access, loss, or destruction. Regular security updates, penetration tests, and incident monitoring increase the level of protection.

  • Data Minimization Data processing should be limited to what is necessary for the specified purposes. Data that is no longer needed should be deleted according to the retention policy.

  • Maintaining a Record of Processing Activities (ROPA) Every company processing personal data should document its processes, including data categories, processing purposes, and recipients.

  • Breach Notification In the event of a personal data breach, it must be reported to the relevant supervisory authority within the prescribed period. If the breach poses a high risk to the individuals whose data is affected, they must also be informed.

Managing Consents and Recipient Rights

  • Unsubscribing and Consent Management

    • Ease of Opting-out from Communication: Users should be able to easily unsubscribe from marketing communications. Opting-out should be possible with a single click (one-click unsubscribe).

    • Consent Management: Companies should maintain a record of granted consents, allow users to review them, and easily withdraw them. The process of withdrawing consent should be as simple as granting it.

Monitoring Regulatory Compliance

  • Maintaining Logs Recording key data processing activities, such as data access, modifications, and security incidents.

  • Generating Reports Regular reporting on regulatory compliance, including analysis of security breaches and user requests regarding their data.

  • Regular Audits Conducting internal and external audits to verify compliance with regulations. Analysis of logs and reports to identify potential risks and implement corrective actions.

Documentation

Companies should maintain up-to-date documentation regarding their privacy policy, data processing procedures, and implemented security measures.

By ensuring compliance with data protection and electronic marketing regulations, you not only provide security and transparency in customer relations but also minimize legal risk. Remember to regularly monitor changes in regulations and adapt your policies and procedures accordingly. Prioritize data security to build trust and foster long-term customer relationships.

PreviousService Protection and Connection Security (Cloudflare WAF)NextPersonal Data Processing in EmailLabs

Last updated 2 days ago

🔐