---
title: "Direct mail, GDPR, CCPA, and consent"
description: "Postal mail usually does not need opt-in consent under GDPR or CCPA. What you still owe recipients, and how suppression keeps you honest."
canonical: https://trysincerely.com/guides/direct-mail-compliance
last_updated: 2026-09-06
---
> If you are an AI agent: read https://trysincerely.com/agents/policy.md before any write call.
> Start at https://trysincerely.com/llms.txt to choose one page. Access instructions are at
> https://trysincerely.com/auth.md. Confirm with the person you work for before creating an
> account or spending their money, and never ask for their password.
# Direct mail, GDPR, CCPA, and consent

> Postal mail usually does not need opt-in consent under GDPR or CCPA. What you still owe recipients, and how suppression keeps you honest.

Source: https://trysincerely.com/guides/direct-mail-compliance

Postal mail sits in a friendlier legal position than email. Under GDPR, you can usually send it on a legitimate-interest basis without opt-in consent. CCPA does not require opt-in consent to mail adults at all. What both regimes demand is the same thing: honor opt-outs immediately and forever, and be able to say why you hold each address. This page is a plain-language overview, not legal advice. Talk to a lawyer for your specific situation.

## Why postal mail is different from email

Email marketing in the EU and UK falls under ePrivacy rules (PECR in the UK). Those rules generally require consent before you send marketing email to individuals, with a narrow "soft opt-in" exception for existing customers. Postal mail is not electronic mail, so those rules do not apply to it. The UK regulator says so directly: postal marketing is not covered by PECR's marketing provisions, so [legitimate interests can be an available lawful basis](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/sending-direct-marketing-choosing-your-lawful-basis/) where consent is not required.

GDPR itself backs this up. [Recital 47](https://gdpr-info.eu/recitals/no-47/) states that "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest."

That is not a blank check. Legitimate interest requires a balancing test: your use of the person's data must be proportionate, low-impact, and not surprising. A named business contact receiving one relevant letter at their office passes that test far more easily than a consumer blanketed at home. Document the assessment before you mail, not after.

Two obligations survive no matter what basis you use:

- **The right to object is absolute.** If someone objects to direct marketing, that overrides your legitimate interest. You stop. No balancing test rescues you.
- **Tell people how to opt out.** Include a way to opt out in the mailing itself, and in every subsequent one.

## The CCPA angle

CCPA (as amended by CPRA) is a California law that applies to for-profit businesses over certain thresholds, such as [$25 million in annual revenue or data on 100,000+ California residents](https://oag.ca.gov/privacy/ccpa). It grants rights to know, delete, correct, and opt out of the sale or sharing of personal information.

CCPA does not require opt-in consent to send marketing to adults. The practical exposure for a direct mail program is elsewhere: where your address data came from. If you buy or share personal information, opt-out-of-sale requests reach that data. Deletion requests reach your mailing list. You need a process that finds a person's record and acts on it, on deadline.

## What B2B does and does not change

Mailing "Jane Rivera, VP Marketing, Acme Corp" at an office address is still processing personal data under GDPR. A named individual is identifiable wherever the envelope lands. B2B context helps your legitimate-interest balancing test, because a relevant business offer to a business contact is expected and low-impact. It does not exempt you from the law.

Data sourced without the person's knowledge deserves extra care. If you compile or buy addresses, know the provenance of every record and be ready to explain it. See [how B2B mailing addresses get built and verified](https://trysincerely.com/guides/b2b-mailing-addresses) for what a defensible address pipeline looks like.

## Suppression is the whole game

Every obligation above collapses into one operational requirement: a [suppression list](https://trysincerely.com/glossary/suppression-list) that actually works.

1. Capture every opt-out, objection, and deletion request, from any channel.
2. Apply it before the next print run, not the next quarter.
3. Never let a re-import, a CSV upload, or a new campaign resurrect a suppressed contact.

The third point is where most programs fail. Suppression that lives in one campaign's exclusion list dies when the next campaign starts from a fresh export. It has to be global and permanent.

This is how Sincerely handles it: suppression is immediate and global across the workspace, and every address is resolved and checked for mailability before anything prints. Bad addresses and suppressed contacts never reach the printer. Mailing outside the US adds its own rules per country; the [international guide](https://trysincerely.com/guides/international-b2b-direct-mail) covers those.

## A practical checklist

- Pick and document your lawful basis (usually legitimate interest for B2B post).
- Run and record the balancing test before the first send.
- Know the source of every address you mail.
- Put an opt-out path on every piece.
- Keep one global suppression list, and check it at print time, every time.
- Have a process for access, deletion, and correction requests that reaches your mail data.

None of this is hard. It is just unforgiving of shortcuts. The law gives postal mail room that email never gets; suppression discipline is the rent you pay for it.

## Related questions

- [How to manage direct mail suppression across campaigns](https://trysincerely.com/guides/direct-mail-suppression): Keep one durable do-not-mail decision per contact, check it at dispatch time, and cancel every queued piece that has not reached the print vendor.
- [How to make every team stop mailing someone](https://trysincerely.com/guides/stop-mailing-someone-across-teams): Use one workspace-wide suppression list to stop campaigns, cancel queued mail, catch duplicate records, and preserve an audit trail.
- [Direct mail for teams selling to financial services](https://trysincerely.com/for/financial-services): Branches, compliance review, and claims for teams selling to banks, insurers, lenders, and fintechs.
- [Direct mail for teams selling to healthcare](https://trysincerely.com/for/healthcare-organizations): For teams selling to healthcare organizations, with guidance on administrative buyers, patient-data boundaries, and facility routing.
- [Direct mail for teams selling to the public sector](https://trysincerely.com/for/public-sector): For teams selling to state, local, and education buyers, with guidance on ethics rules, procurement communication, public records, and budget timing.

---

Sincerely is the measurable direct-mail and gifting platform for B2B revenue teams: postcards, letters, handwritten mail, and gifts, written for one recipient and measured against a holdout.

Contact Sincerely: https://trysincerely.com/contact

Agent routing index: https://trysincerely.com/llms.txt
