Product
July 12, 2024

Email signature in compliance with GDPR

By
Guillaume De la Sablonnière
Content Factory Manager

Is your email signature compliant with the General Data Protection Regulation (GDPR) standards?

Not sure? Don't worry, we're here to help!

Here is our practical guide to learn more about the compliance of your email signature—and more broadly, your emails—with GDPR.

Understanding GDPR and Email Signatures

The General Data Protection Regulation (GDPR) is an EU regulation that has been in effect since May 2018 and governs the collection, storage, and use of personal data. Similar to the "cookie law," this regulation applies to all entities, without exception, and aims to protect individuals' privacy. All businesses that process personal data (most of them) are therefore heavily impacted.

What is Personal Data?

Personal data has been defined by the National Commission on Informatics and Liberty (CNIL) as "any information relating to an identified or identifiable natural person." In this sense, a simple name, photo, postal address, phone number, or a variety of other information can be considered personal data.

Note that according to CNIL's definition, personal data can be both direct and indirect:

  • Direct personal data: which allows the identification of a person directly from the disclosed information;
  • Indirect personal data: which allows the identification of a person indirectly from the disclosed information. In this case, even if the information doesn't immediately identify the person, it can later be used to identify them through cross-referencing other information (e.g., phone number, license plate, email address, voice, etc.).

In both cases, the management of this personal data must comply with the applicable regulations.

Is an Email Signature Personal Data?

Yes! Since an email signature can contain personal information such as name, surname, phone number, email address, or even a photo, it is indeed considered personal data.

As a company, you must ensure that the processing of your employees' personal data through their email signatures complies with the obligations of the GDPR (as described by CNIL).

Respecting these obligations is crucial, as non-compliance could lead to a fine of up to 4% of the company's annual global revenue.

How to Create a GDPR-Compliant Email Signature?

The "signature object" itself is not directly subject to GDPR, but its content is. If you've chosen to include personal data of your employees (name, phone number, etc.) in corporate signatures, you indeed have certain obligations.

To comply with the regulation, the employer must inform employees that their personal data will be used for the creation of their email signature. Employees should also be made aware of their rights (access, correction, deletion, etc.) regarding this personal data.

Small tip: If you find yourself in a situation where an employee refuses to display their personal data in a signature, you can create generic signature templates that do not disclose personal information (e.g., a template that only shows the company logo).

Using a Tool to Manage Your Email Signatures?

If you're using a tool to manage your email signatures, be aware that the personal data that passes through your email signature tool must also comply with GDPR.

For example, at Letsignit, we follow the highest protection standards for information security. Our solution is certified under ISO 27001 and ISO 27018, ensuring our clients the confidentiality of their data, with encryption and full traceability of our actions.

Be careful! Not all solutions will protect your data this way! We encourage you to reach out to the data processing officer of the solution you choose to learn more.

Legal Obligations for Sending Emails

What about email campaigns? How do you ensure you're complying with legal obligations when sending emails?

The recommended approach will vary depending on your recipients.

For a B2C Email Campaign (Business to Consumer)

You must obtain prior consent from individuals on your mailing list. This is also known as "opt-in," a mechanism that prevents people from receiving communications without having agreed to them in advance:

  1. Consent: Before collecting any data, the consent of the individuals must be obtained. This consent must be freely given, specific, informed, and unambiguous.
  2. Information and Transparency: Individuals must be clearly and transparently informed about how their data will be used, and this data must be up to date and accurate. This means defining the identity of the data controller, specifying the purpose of the data processing, the data retention period, etc.; and not forgetting to explain the rights the individual has over their data (access, correction, deletion, opposition, etc.).
  3. Data Security: The collected data must be protected from unauthorized access, disclosure, modification, or destruction without prior consent. This can involve technical measures (encryption, firewalls, etc.) or organizational measures (access control, password policies, etc.).
  4. Limitation of Processing: The data should only be collected and processed for specific, legitimate, and defined purposes. It should not be processed in a way incompatible with those purposes.

Even after agreeing to "opt-in," any person has the right to change their mind and choose to stop receiving commercial communications. This is known as "opt-out." You must ensure that, through your data processing officer, such a mechanism is in place.

The only exception to the "opt-in" process is when personal data (email address) is collected during a commercial transaction, and it allows the company to send advertisements for similar products. In this case, prior consent is not necessary, but the consumer must still have the option to unsubscribe and stop receiving such communications.

Best practice: It is strongly recommended to implement a "double opt-in" system. This means sending a confirmation email to the person who subscribed to your mailing list, asking them to confirm (via a link) their consent a second time.

For a B2B Email Campaign (Business to Business)

Email marketing to businesses, unlike emails to consumers, does not require an "opt-in" process. However, that doesn't mean businesses don't have rights—communicating with a business in this way gives the company the right to opt-out. The company can therefore choose to exit the mailing chain via an "opt-out," which must legally be respected.

Best practice: For B2B cases, it is recommended to include the unsubscribe link directly in each communication. This makes the "opt-out" process easier for the recipient company, and your brand avoids being perceived as "too pushy" from a commercial standpoint.

For more information, please refer to the GDPR Guide from the Ministry of the Economy and Finance.

Adding a GDPR Notice to Your Email Signature

Currently, in France, it is not required to state how you process personal data in each of your emails. However, some companies still choose to include certain legal disclaimers in the form of a disclaimer.

Including such a notice in your email signature can enhance transparency and trust with your correspondents while emphasizing your commitment to data protection. This practice also promotes compliance and educates your contacts about your privacy policies, which can be a valuable asset in your professional communications.

For example, you might include "This email complies with GDPR" in your email signature to reassure recipients:

Message modèle RGPD signature mail

If you work in a field where confidentiality is important (e.g., healthcare, legal, consulting), the signature can also serve to remind others that the information shared is confidential:

Exemple disclaimer signature mail

The Importance of the Format and Size of the Email Signature

If you use the email signature to highlight your compliance with GDPR or commitment to data confidentiality, you'll need to ensure that it adheres to a certain format.

Why is the format of your email signature important?

Because if it doesn't display well on different devices, is difficult to read, or appears pixelated, your message may not be properly conveyed. And if it can't be read correctly, what's the point of including it in the first place?

For optimal reading, we recommend:

• Sur PC/MAC : une signature de 400 pixels par 150 pixels ;

• Sur smartphone et tablette : une signature de 300 pixels par 150 pixels.

Also, ensure that in terms of design (presence of iconographic elements, color choices, etc.), the signature is not too cluttered and, therefore, hard to read.

Letsignit: The Email Signature Tool for Sending GDPR-Compliant Emails

At Letsignit, we work hard to provide a tool that respects GDPR. Thanks to this commitment, many clients can create professional email signatures without compromising their personal data.

And in the same spirit, we pledge never to use our clients' personal data for anything other than creating email signatures.

Ready to try the simplest and most secure email signature solution on the market?

CTA tester solution de signatures mail RGPD

About the author
Guillaume is the Content Factory Manager at Letsignit! Using words, he creates various types of content (text, videos, and in the most extreme cases, telepathic) to increase Letsignit's visibility on the web. Legend has it that at the age of 3, Guillaume built his first multichannel web marketing strategy using a dictionary, a bottle, and a bit of Chinese ink. Whether this is true or not, well, that's what they say...
About Letsignit
Letsignit is an email signature management solution that enables organizations to transform their employees' email signatures into a powerful 1-1 engagement medium for their brands and campaigns.

Questions
Fréquentes

1

Is it possible to track the number of clicks on email signatures?

Yes, with the 'Campaigns' offer, it is possible to track the number of clicks on the email signatures of all your employees in the 'Statistics' area of the platform.

You can then access a detailed or global view of the number of clicks on the email signatures of each employee. You can use the search option to target a specific signature or a given period. Finally, you have the possibility to export all statistics to an Excel document.

If you launch campaigns with banners inserted in your email signatures, you can also access their performance via this same space.

2

Can we add links to social networks, our website, and appointment-setting applications such as Calendly?

With Letsignit, you can easily add social network icons in your collaborators' email signatures and link to your company pages. Also, our "attributes" feature allows you to manage personalized URLs for each of your collaborators such as their individual LinkedIn profile.

And that's not all: you can add links to an appointment-setting application, allow your customers to leave reviews easily, and integrate our 'Chat on Teams' widget to let anyone start a discussion via Microsoft Teams chat.

3

Can employees update their signature information themselves (number, function, etc.)?

It’s up to you! As an administrator of the Letsignit platform, you choose whether or not to grant modification rights to your employees. These permissions are managed on an attribute-by-attribute basis, which means that you can decide to allow the employee to change their phone number, but not the address of your premises, for example.

This feature applies to all attributes in your directory, including custom attributes created on Letsignit. When your employees change one or more attributes, your directory is obviously not affected.

4

Why it is important to standardize our email signatures on a large scale to ensure our identity and brand image?

It often happens that employees make their email signature their own: custom format, bad fonts, colors inconsistent with the brand standards... all of this has an impact on your brand!

A consistent visual identity is considered authentic and outperforms a perceived weak one by 20%. And, your customers are 2.4 times more likely to buy your products.

With Letsignit, take back control over your brand identity by standardizing all your email signatures. Our tool has many features that allow you to customize your signatures by department, by audience or by subsidiary. Not to mention the possibility of carrying out campaigns within your email signatures thanks to our Campaign offer.

5

What is the user experience like for our employees?

What is the user experience like for our employees?

  • If you opt for the Letsignit Add-in for Outlook, they will have a dedicated space in their Outlook account where they will be able to view the signatures and campaigns assigned to them.
  • If you opt for the Letsignit Desktop APP, they will be able to preview all their signatures and campaigns in this space. If they want to change their default signature to another one when sending an email, this will be done in their signature library in Outlook.

In both cases:

  • They preview their signature before sending an email and choose from signatures assigned to them.
  • Based on the permissions granted, they will also be able to modify their personal information such as their name, position, or address in these spaces.

In short, they have autonomy in their email signature, but you keep control on the field, signatures, and banners they can edit or use.

6

Can my employees have multiple signatures available to them?

With our "multi-signature" feature, your employees can benefit from multiple email signatures. No technical manipulation is required. Thanks to our Add-in for Outlook or the desktop app, they can change their email signatures as they wish with just a few clicks.

Regarding the creation of email signatures, you can make several variations such as:

Everything has been thought of to go further in the personalization process based on the recipient of your emails.

7

Regarding “Green IT,” have you implemented measures to limit the digital footprint of email signatures?

If sending emails has an impact, non-optimized email signatures also have an impact. An unsuitable format or an image that is too heavy considerably increases the size of your signatures... and therefore, your emails.

As a responsible economic actor, we contribute to reducing our CO2 emissions and those of our customers in several ways:

  • Optimization of the weight of signatures and campaigns in emails.
  • Green features: lightening of signatures during response/transfer emails, possibility of not embedding images, implementation of lighter signatures for internal exchanges.
  • Integration of a 'Switch to Teams' widget to encourage your employees to continue their exchanges via chat, rather than email.

As we are increasingly involved in sustainability initiatives, our priority in 2023 is to develop even more green IT functionality.

8

Regarding “Green IT,” have you implemented measures to limit the digital footprint of email signatures?

If sending emails has an impact, non-optimized email signatures also have an impact. An unsuitable format or an image that is too heavy considerably increases the size of your signatures... and therefore, your emails.

As a responsible economic actor, we contribute to reducing our CO2 emissions and those of our customers in several ways:

  • Optimization of the weight of signatures and campaigns in emails.
  • Green features: lightening of signatures during response/transfer emails, possibility of not embedding images, implementation of lighter signatures for internal exchanges.
  • Integration of a 'Switch to Teams' widget to encourage your employees to continue their exchanges via chat, rather than email.

As we are increasingly involved in sustainability initiatives, our priority in 2023 is to develop even more green IT functionality.

Questions
Fréquentes

1

2

3

4

5

6

7
8

Looking for a tool to manage your email signatures?

Letsignit allows you to create, manage, and deploy email signatures for all your employees in just a few clicks.
Discover Letsignit

You may also like

Dive deeper. Unlock the full potential of your email signatures.