01

Start with the campaign data flow

Map who collected the data, who selects recipients, who decides the message and channel, which tools are used and who receives results. Roles follow real decision-making rather than labels in the contract.

02

Controller, processor or separate controllers

An agency following documented instructions may be a processor, but it may become a controller or joint controller for decisions it makes independently. The contract and privacy information should reflect the actual allocation.

03

Verify the source and permitted use

Ask how the database was obtained, what people were told, which permissions exist and whether the intended channel and sender fit that scope. A purchased or client-supplied list is not safe merely because another party supplied it.

04

Separate GDPR from channel-specific rules

A GDPR legal basis does not automatically satisfy rules governing electronic communications and direct marketing. Analyse email, telephone, messaging and online advertising under all applicable Polish and EU requirements.

05

Supplier and platform arrangements

Review mailing providers, CRM, ad platforms, lead tools and subcontractors, including processing agreements, security, subprocessors and international transfers.

06

Objections, suppression and evidence

Create a reliable route for opt-outs and objections across the client, agency and suppliers. Preserve consent or other permission evidence, campaign versions and suppression lists without reactivating blocked contacts.

PRACTICE

How the issue appears in practice

Example

Hypothetical example: a client list used for a new purpose

A client sends an old customer list for a partner promotion. No one checks what customers were originally told or whether the new sender and channel are covered, and complaints are directed only to the agency.

Working checklist

Matters to determine or verify before proceeding

  • Start with the campaign data flow
  • Controller, processor or separate controllers
  • Verify the source and permitted use
  • Separate GDPR from channel-specific rules
  • Supplier and platform arrangements
  • Objections, suppression and evidence
  • Scope and format of deliverables

Key issues at a glance

IssueKey information
Start with the campaign data flowMap who collected the data, who selects recipients, who decides the message and channel, which tools are used and who receives results.
Controller, processor or separate controllersAn agency following documented instructions may be a processor, but it may become a controller or joint controller for decisions it makes independently.
Verify the source and permitted useAsk how the database was obtained, what people were told, which permissions exist and whether the intended channel and sender fit that scope.
Separate GDPR from channel-specific rulesA GDPR legal basis does not automatically satisfy rules governing electronic communications and direct marketing.
Supplier and platform arrangementsReview mailing providers, CRM, ad platforms, lead tools and subcontractors, including processing agreements, security, subprocessors and international transfers.
LEGAL BASIS

Legal basis

  • Regulation (EU) 2016/679 (GDPR)
  • Polish Entrepreneurs' Law of 6 March 2018
  • Polish Act of 6 March 2018 on participation of foreign entrepreneurs and other foreign persons in economic activity in Poland
  • Polish Electronic Communications Law of 12 July 2024
Explore this areaCreative industries

This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.

Summary

A defensible campaign begins with the data source and allocation of decisions. Contracts, permissions, privacy information and suppression procedures should match the actual technical flow.