Direct mail has made a serious comeback in the last few years.
It’s tangible, cuts through digital noise, and when it’s done well, it works.
But there’s a question many businesses still get wrong (or forget to ask): Is your direct mail GDPR compliant?
Because while print might feel less intrusive than email or SMS, it still relies on personal data – names, addresses, segmentation, and profiling. All of this means that it falls firmly within GDPR. But don’t worry – compliance isn’t about shutting down your campaigns. It’s just about doing them properly.
So, with over 30 years of experience under our belts, here’s a practical, no-nonsense 12-point checklist to help you get there. If you can answer yes to these questions, your direct mail campaign is good to go.
1. Do You Have a Lawful Basis for Sending Mail?
Under the General Data Protection Regulation (GDPR), you can’t use personal data unless you have a clearly defined lawful basis. This isn’t optional – it’s legally necessary, and is the foundation of compliant marketing.
For direct mail, there are typically two routes you can follow all the way to legality:
- Legitimate interest (the most common for postal campaigns)
- Consent (used in more specific or sensitive scenarios
In practice, most businesses rely on legitimate interest because physical mail is generally considered less intrusive than digital channels like email or SMS. But that doesn’t mean it’s a free pass.
You still need to be able to answer:
- Why are we contacting this person?
- Is this something they would reasonably expect?
- Is there a genuine business benefit?
So, for example, sending relevant offers to existing customers is usually justifiable. Sending unrelated promotions to people who have no prior relationship with you or your business is much harder to defend.
And importantly, this reasoning can’t live in someone’s head – it needs to be documented. If challenged, you should be able to show:
- What your lawful basis is
- Why you chose it
- How you assessed the impact on individuals
If you can’t show any evidence of it, it doesn’t count.
2. Have You Conducted a Legitimate Interests Assessment (LIA)?
If you’re relying on legitimate interest, you’re expected to carry out a Legitimate Interests Assessment (LIA).
This is where many organisations fall short. It’s often treated like paperwork, rather than what it actually is: a structured justification for your marketing activity.
An effective LIA looks at three key areas:
- Purpose Test: Why are you doing this? What’s the objective of your campaign? Is it a genuine business need, or just “we’d like more leads”?
- Necessity Test: Do you need personal data to achieve it? Could you achieve the same outcome in a less intrusive way? If yes, you need to justify why you’re not doing that instead.
- Balancing Test: Are you overriding someone’s privacy? You need to weigh your commercial interests against the individual’s rights, expectations, and potential discomfort.
3. Do People Know You Have Their Data?
To put it simply: people shouldn’t be surprised to hear from you.
If someone receives a piece of direct mail and their first reaction is “How did they get my details?” That’s a huge red flag that you’re treading dubious waters.
With UK GDPR laws, you’re expected to clearly communicate:
- Who you are (your business identity)
- What data you hold (e.g. name, address, segmentation data)
- Why you’re using it (your marketing purpose)
- How they can object or opt out
This information is typically set out in your privacy policy, but it can’t just hide somewhere on your website. It needs to be easy to find, written in plain, understandable language, and actively signposted in your communications (where appropriate, but don’t use this as a loophole).
If you’ve obtained data through a third party, transparency becomes even more important. You should make sure individuals were informed when their data was collected, not just when you use it.
Remember, transparency isn’t just about compliance – it’s about trust. When people understand why they’re being contacted and how their data is being used, they’re far more likely to engage positively.
When they don’t, the opposite happens. Complaints increase, opt-outs rise ever higher, and your brand perception takes a hit. Can it recover? Probably. Should it have to? No.
4. Is Your Data Accurate and Up to Date?
It’s easy to think of data accuracy as a marketing issue, but actually, it’s a legal one.
Personal data must be accurate and kept up to date where necessary, and it must be relevant to the purpose it’s being used for.
If it’s inaccurate, data doesn’t just lead to wasted print and postage. It creates situations that, going straight past awkward, are perceived as careless or intrusive, and therefore are real compliance risks.
Also, let’s be realistic about data lifespan. If a contact hasn’t engaged in years, you should question whether it’s still appropriate to use their data at all.
5. Are You Only Using Data You Actually Need?
You should only collect and use what’s genuinely necessary for your campaign (data minimisation). If all you need is a name and address, then storing additional details like date of birth and their job title isn’t just unnecessary – it increases your risk.
Less data means lower compliance exposure, simpler data management, and greater trust.
So: collect less. Use less. Protect more. If that’s your mindset, everything will continue along smoothly.
6. Can People Easily Opt Out?
This is non-negotiable.
Under GDPR, individuals have the right to say no to direct marketing, and when they do, you must stop immediately.
In practice, that means:
- Clear, visible opt-out instructions on every piece of mail
- Up-to-date suppression lists that are actually used
Honestly, that’s just two things. It’s a process that’s quick and simple – no hoops to jump through
If opting out feels difficult, it’s not compliant.
7. Do You Keep Suppression Lists?
When someone opts out, you can’t simply delete their data and move on.
You need to retain just enough information to ensure they’re not contacted again. This is known as a suppression list.
It’s a common blind spot. Delete too much, and you risk re-contacting people later. Keep too much, and you risk holding unnecessary data.
The balance, though, is actually simple: Keep only what you need to honour the opt-out. Nothing more, nothing less.
8. Are Your Third-Party Suppliers Compliant?
If you’re using a mailing house like bakergoodchild, they’ll be handling personal data on your behalf. Under GDPR, that makes them a data processor, while you remain the data controller.
That means you need:
- A Data Processing Agreement (DPA) in place
- Confidence that they handle data securely and responsibly
- Assurance that they follow GDPR principles in practice
Outsourcing the work doesn’t outsource the responsibility.
9. Is Your Data Secure?
GDPR isn’t just about why you use data, but also about how well you can protect it. You should have secure storage systems with controlled access (only the right people, at the right time). Use encryption where appropriate, and always have clear internal policies so your team knows what’s expected.
10. Do You Know What Data You Hold (and Where)?
If you don’t know what data you have, you can’t manage it properly.
A solid data audit should give you a clear picture of:
- What data you hold
- Where it came from
- Who has access to it
- How long it’s been kept
These are foundational. Without it, everything else (compliance, security, retention) becomes a guessing game.
11. Do You Have a Data Retention Policy?
As we mentioned before, personal data shouldn’t be kept indefinitely.
GDPR expects you to:
- Define how long data is retained
- Be able to justify that timeframe
- Delete or anonymise it when it’s no longer needed
Holding onto old mailing lists “just in case” might feel safe, but it actually increases both risk and liability.
12. Are You Prepared for Data Subject Requests?
Under GDPR, individuals have clear rights over their data. People can request access to the data you hold, ask for corrections, request deletion, and object to processing.
In most cases, you’ll have one month to respond.
That means having processes in place, not scrambling when a request comes in. If you can’t respond quickly and accurately, you’re not just non-compliant – you’re exposed.
Getting It Right
Here’s the reality: when direct mail falls foul of GDPR, it’s rarely because of the channel itself. It’s what’s happening behind the scenes. Poor-quality data, unclear lawful basis, ignored opt-outs, and loose processes with third-party suppliers – those are the serious culprits.
In other words, the problem isn’t print – it’s how it’s handled.
That’s why the partner you work with matters more than most businesses realise.
With the right setup, compliance stops being an irritating box-ticking exercise and becomes part of how your campaigns run day to day – from secure data handling to accurate suppression, making sure everything aligns with GDPR best practice without slowing you down.
Because ultimately, GDPR isn’t there to stop you from marketing.
It’s there to make sure you’re doing it fairly, transparently, and with respect for the people you’re trying to reach.
To find out more about how bakergoodchild can help you do just that, give us a call at 0800 612 1972. We’re always keen to help organisations make the most of their mail.




