Compliance

GDPR email signature — what to include, what's a myth

This is a plain-language summary, not legal advice. But most GDPR "signature requirements" you see quoted online aren't in the regulation at all — they're a mix of company-law disclosures, industry conventions and legacy paranoia. Here's what's actually required, and three templates that satisfy it in one line.

Not legal advice. Confirm anything material with your DPO or counsel.

The short answer

GDPR requires a lawful basis for processing personal data and transparency about how data is handled — usually satisfied by linking to your privacy policy. It does not require any specific signature text, confidentiality notice, or GDPR banner. Add whatever your industry or company law requires, then stop.

What's actually required (usually)

  • A link to your privacy policy. One line satisfies transparency for most B2B email.
  • Company registration details in commercial email — required by UK Companies Act 2006 (s. 82), Germany's TMG, and equivalents across the EU. Not GDPR, but often bundled with it.
  • Industry-specific disclosures — regulated finance, healthcare, and legal roles have their own requirements. Check with your regulator, not a signature generator.

What's not required

  • A three-paragraph confidentiality notice.
  • A "this email may contain personal data" disclaimer.
  • A separate "GDPR" heading in the signature.
  • Consent language on outgoing email — you don't need consent from a recipient to send them a legitimate business email.

Three compliant templates

UK Ltd — minimal
Anna Weber
Head of Growth · Northlight Ltd
northlight.co.uk  ·  privacy policy
Registered in England no. 12345678, 5 Curtain Rd, London EC2A 3AH
Germany GmbH — minimal
Marta Klein
Customer Success · Northlight GmbH
northlight.de  ·  Datenschutz
Geschäftsführer: A. Weber · HRB 12345, Amtsgericht Berlin
EU startup — one-liner
Jules Park
Product · Northlight
northlight.eu · privacy · unsubscribe from marketing

Common questions

Does GDPR require a specific email signature disclaimer?

No. GDPR does not mandate any signature text. What it does require is a lawful basis for processing personal data and a way for the recipient to find your privacy policy. Most compliant teams satisfy this with a single line linking to the privacy policy — not a wall of legal text.

Do I need to include my company registration number in the signature?

This isn't GDPR — it's local company law. In the UK, limited companies must state the registered name, number, place of registration and registered office in business emails. Germany's TMG requires similar for GmbHs. Both are one-line requirements, not paragraphs.

Is a confidentiality disclaimer required?

No. It's a habit, not a law. Confidentiality notices have no binding effect on someone who receives an email in error — sender-imposed obligations aren't enforceable. Include one only if your industry regulator (law, finance, healthcare) specifically requires it.

Do banner-marketing images in signatures count as marketing under GDPR?

If the banner promotes a product or offer to someone who hasn't given marketing consent, yes — treat it like any other marketing communication. Business-to-business communication generally falls under legitimate interest, but sending promotional banners to consumer addresses without consent is risky. Keep marketing banners for opted-in audiences or genuine B2B correspondence.

More resources