Start with the campaign data flow
Map who collected the data, who selects recipients, who decides the message and channel, which tools are used and who receives results. Roles follow real decision-making rather than labels in the contract.
Controller, processor or separate controllers
An agency following documented instructions may be a processor, but it may become a controller or joint controller for decisions it makes independently. The contract and privacy information should reflect the actual allocation.
Verify the source and permitted use
Ask how the database was obtained, what people were told, which permissions exist and whether the intended channel and sender fit that scope. A purchased or client-supplied list is not safe merely because another party supplied it.
Separate GDPR from channel-specific rules
A GDPR legal basis does not automatically satisfy rules governing electronic communications and direct marketing. Analyse email, telephone, messaging and online advertising under all applicable Polish and EU requirements.
Supplier and platform arrangements
Review mailing providers, CRM, ad platforms, lead tools and subcontractors, including processing agreements, security, subprocessors and international transfers.
Objections, suppression and evidence
Create a reliable route for opt-outs and objections across the client, agency and suppliers. Preserve consent or other permission evidence, campaign versions and suppression lists without reactivating blocked contacts.
How the issue appears in practice
Hypothetical example: a client list used for a new purpose
A client sends an old customer list for a partner promotion. No one checks what customers were originally told or whether the new sender and channel are covered, and complaints are directed only to the agency.
Matters to determine or verify before proceeding
- Start with the campaign data flow
- Controller, processor or separate controllers
- Verify the source and permitted use
- Separate GDPR from channel-specific rules
- Supplier and platform arrangements
- Objections, suppression and evidence
- Scope and format of deliverables
Key issues at a glance
| Issue | Key information |
|---|---|
| Start with the campaign data flow | Map who collected the data, who selects recipients, who decides the message and channel, which tools are used and who receives results. |
| Controller, processor or separate controllers | An agency following documented instructions may be a processor, but it may become a controller or joint controller for decisions it makes independently. |
| Verify the source and permitted use | Ask how the database was obtained, what people were told, which permissions exist and whether the intended channel and sender fit that scope. |
| Separate GDPR from channel-specific rules | A GDPR legal basis does not automatically satisfy rules governing electronic communications and direct marketing. |
| Supplier and platform arrangements | Review mailing providers, CRM, ad platforms, lead tools and subcontractors, including processing agreements, security, subprocessors and international transfers. |
Legal basis
- Regulation (EU) 2016/679 (GDPR)
- Polish Entrepreneurs' Law of 6 March 2018
- Polish Act of 6 March 2018 on participation of foreign entrepreneurs and other foreign persons in economic activity in Poland
- Polish Electronic Communications Law of 12 July 2024
This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.
Summary
A defensible campaign begins with the data source and allocation of decisions. Contracts, permissions, privacy information and suppression procedures should match the actual technical flow.