An email address is personal data under the GDPR whenever it identifies a natural person, for example firstname.lastname@company.com. A generic address such as info@company.com usually is not, because it points to an organisation rather than one individual. Whether the GDPR applies to your email addresses therefore depends on how each address is built, and most address books turn out to hold personal data.
What is personal data under the GDPR?
Personal data (persoonsgegevens) is any information relating to an identified or identifiable natural person, according to Article 4(1) of the General Data Protection Regulation (GDPR, known in the Netherlands as the AVG). A person is identifiable, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data or an online identifier. An IP address or a device identifier can count as an online identifier in the same way an email address can. The definition covers only living individuals: information about a deceased person or about a company as such is not personal data, even though data about the individuals working for that company can be.
The GDPR has applied directly in every EU member state, including the Netherlands, since 25 May 2018, replacing the older national data protection acts such as the Dutch Wet bescherming persoonsgegevens. It does not require a separate implementation law to take effect, and it applies to any organisation that processes personal data of people in the EU, regardless of where that organisation is based.
When is an email address personal data?
There is no separate GDPR article that lists email addresses by name. Instead, you apply the general test for identifiability from Article 4(1) GDPR to the specific address in front of you: does it, on its own or combined with other information you hold, point to one identifiable person? That makes the assessment format-dependent rather than a single fixed rule, and it explains why two email addresses that look similar can be treated differently.
Dutch case law confirms that an email address can be personal data, but not automatically: it depends on whether the address identifies a natural person, directly or indirectly.
Many people structure their address so that it does identify them, for example firstname.lastname@gmail.com. That address shows the user’s first and last name, so the person is identifiable from the address alone.
A work address such as initials.lastname@company.com can identify someone too: it can show their initials, their last name and their employer, which together are usually enough to identify the individual.
An address such as puppy12@hotmail.com is different: on its own, it does not reveal information that identifies a natural person, even though it is technically linked to one particular user.
Generic addresses such as info@company.com are not personal data either. They are not linked to one individual but to the organisation as such, and several people may use the same inbox.
It does not matter whether you actually use the address to identify someone. If an email address can identify a natural person, it is personal data, whether or not you use it for that purpose or process it for any other reason.
Even a coincidental technical link between an address and a person is not automatically enough on its own. But if the address could realistically be used to identify someone, for instance to investigate suspected fraud or to answer a support request, it counts as personal data. The law looks at the possibility of identification, not your intention or your actual use.
Is an email address special category data?
No. An email address can be personal data, but it is not special category data. Article 9 GDPR reserves that label for data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, and for genetic data, biometric data, health data and data on a person’s sex life or sexual orientation. Processing special category data is subject to stricter rules than ordinary personal data. An email address does not, by itself, reveal any of this, and it generally discloses less than a home address does.
An email address is usually harder to find than a home address, and it is largely up to the user whether it becomes public at all. If it leaks, the consequences are typically milder too: an email address is easy to change, and exposure leads at most to unwanted digital contact rather than someone showing up at your door. That does not mean an email address deserves no protection, only that the GDPR treats it as ordinary personal data rather than as a special category.
When does the GDPR apply to your use of email addresses?
The GDPR applies once you process personal data, and “processing” is defined broadly. Under Article 4(2) GDPR, processing is any operation performed on personal data, automated or not, including collecting, recording, organising, structuring, storing, adapting, retrieving, using, disclosing or erasing it. As soon as you collect or store email addresses that qualify as personal data, you are processing personal data and the GDPR applies to that processing, including your obligation to have a valid legal basis for it under Article 6 GDPR, such as consent, a contract with the person concerned, or your legitimate interest.
What this means for your organisation
Most email addresses you hold will be personal data, because most people build their address around their own name or their workplace, whether that is a customer list, a newsletter database or an internal staff directory.
Because this depends on the format of each address, there is no clean line you can draw in advance for an entire list. In practice, if your organisation processes email addresses at any scale, you should assume that at least part of that list is personal data, and you should have a privacy policy in place that reflects that, together with a legal basis for each use you make of the addresses. It also means your data processing register, your retention schedule and your security measures should cover your email lists in the same way they cover any other personal data you hold, rather than treating a spreadsheet of addresses as an exception.
Frequently asked questions
Is a shared mailbox such as sales@company.com personal data? Generally not, because it is linked to a function or department rather than to one identifiable individual. The moment such an address is only ever used by one named person, the analysis can shift.
Can I still use email addresses for marketing? Yes, provided you have a valid legal basis and comply with the separate marketing rules that apply on top of the GDPR, including the requirement to offer an easy way to unsubscribe from every message.
Does it matter if the email address also appears in a public source, such as a company website? No. An email address does not lose its status as personal data just because it is publicly available; publication can affect which legal basis is appropriate, not whether the GDPR applies at all.
Summarised
- An email address is personal data if it identifies a natural person, directly or indirectly.
- Addresses built from a name (firstname.lastname@, initials.lastname@) will usually qualify; addresses such as puppy12@ or generic addresses such as info@ usually will not.
- An email address is not special category data under Article 9 GDPR.
- Collecting, storing or using email addresses that qualify as personal data is “processing” under Article 4(2) GDPR, which brings you within the GDPR’s scope and requires a legal basis under Article 6 GDPR.
- Because this depends on how each address is built, treat your email lists as personal data unless you can show otherwise, and back that up with a privacy policy.
[1] Gerechtshof Amsterdam 18 July 2002, ECLI:NL:GHAMS:2002:AE5514.
[2] Kamerstukken II 1997/98, 25 892, nr. 3 (memorie van toelichting).
[3] Gerechtshof Amsterdam 18 July 2002, ECLI:NL:GHAMS:2002:AE5514.
Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.
How Law & More can help you with this is explained on our IT lawyer page.

