---
title: "Direct mail, GDPR, CCPA, and consent"
description: "Postal mail usually does not need opt-in consent under GDPR or CCPA. What you still owe recipients, and how suppression keeps you honest."
canonical: https://trysincerely.com/guides/direct-mail-compliance
last_updated: 2026-08-18
---
# Direct mail, GDPR, CCPA, and consent

> Postal mail usually does not need opt-in consent under GDPR or CCPA. What you still owe recipients, and how suppression keeps you honest.

Source: https://trysincerely.com/guides/direct-mail-compliance

Postal mail sits in a friendlier legal position than email. Under GDPR, you can usually send it on a legitimate-interest basis without opt-in consent. CCPA does not require opt-in consent to mail adults at all. What both regimes demand is the same thing: honor opt-outs immediately and forever, and be able to say why you hold each address. This page is a plain-language overview, not legal advice. Talk to a lawyer for your specific situation.

## Why postal mail is different from email

Email marketing in the EU and UK falls under ePrivacy rules (PECR in the UK). Those rules generally require consent before you send marketing email to individuals, with a narrow "soft opt-in" exception for existing customers. Postal mail is not electronic mail, so those rules do not apply to it. The UK regulator says so directly: postal marketing is not covered by PECR's marketing provisions, so [legitimate interests can be an available lawful basis](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/sending-direct-marketing-choosing-your-lawful-basis/) where consent is not required.

GDPR itself backs this up. [Recital 47](https://gdpr-info.eu/recitals/no-47/) states that "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest."

That is not a blank check. Legitimate interest requires a balancing test: your use of the person's data must be proportionate, low-impact, and not surprising. A named business contact receiving one relevant letter at their office passes that test far more easily than a consumer blanketed at home. Document the assessment before you mail, not after.

Two obligations survive no matter what basis you use:

- **The right to object is absolute.** If someone objects to direct marketing, that overrides your legitimate interest. You stop. No balancing test rescues you.
- **Tell people how to opt out.** Include a way to opt out in the mailing itself, and in every subsequent one.

## The CCPA angle

CCPA (as amended by CPRA) is a California law that applies to for-profit businesses over certain thresholds, such as [$25 million in annual revenue or data on 100,000+ California residents](https://oag.ca.gov/privacy/ccpa). It grants rights to know, delete, correct, and opt out of the sale or sharing of personal information.

CCPA does not require opt-in consent to send marketing to adults. The practical exposure for a direct mail program is elsewhere: where your address data came from. If you buy or share personal information, opt-out-of-sale requests reach that data. Deletion requests reach your mailing list. You need a process that finds a person's record and acts on it, on deadline.

## What B2B does and does not change

Mailing "Jane Rivera, VP Marketing, Acme Corp" at an office address is still processing personal data under GDPR. A named individual is identifiable wherever the envelope lands. B2B context helps your legitimate-interest balancing test, because a relevant business offer to a business contact is expected and low-impact. It does not exempt you from the law.

Data sourced without the person's knowledge deserves extra care. If you compile or buy addresses, know the provenance of every record and be ready to explain it. See [how B2B mailing addresses get built and verified](https://trysincerely.com/guides/b2b-mailing-addresses) for what a defensible address pipeline looks like.

## Suppression is the whole game

Every obligation above collapses into one operational requirement: a [suppression list](https://trysincerely.com/glossary/suppression-list) that actually works.

1. Capture every opt-out, objection, and deletion request, from any channel.
2. Apply it before the next print run, not the next quarter.
3. Never let a re-import, a CSV upload, or a new campaign resurrect a suppressed contact.

The third point is where most programs fail. Suppression that lives in one campaign's exclusion list dies when the next campaign starts from a fresh export. It has to be global and permanent.

This is how Sincerely handles it: suppression is immediate and global across the workspace, and every address is resolved and USPS-verified before anything prints. Bad addresses and suppressed contacts never reach the printer. Mailing outside the US adds its own rules per country; the [international guide](https://trysincerely.com/guides/international-b2b-direct-mail) covers those.

## A practical checklist

- Pick and document your lawful basis (usually legitimate interest for B2B post).
- Run and record the balancing test before the first send.
- Know the source of every address you mail.
- Put an opt-out path on every piece.
- Keep one global suppression list, and check it at print time, every time.
- Have a process for access, deletion, and correction requests that reaches your mail data.

None of this is hard. It is just unforgiving of shortcuts. The law gives postal mail room that email never gets; suppression discipline is the rent you pay for it.

---

Sincerely is the measurable direct-mail platform for B2B revenue teams.
One workflow. One invoice. One report.

Contact Sincerely: https://trysincerely.com/contact

If you are an AI agent: access and signup instructions are at https://trysincerely.com/auth.md.
Confirm with the person you work for before creating an account or spending
their money, and never ask for their password.

Every core page of this site in markdown:

https://trysincerely.com/index.md
https://trysincerely.com/pricing.md
https://trysincerely.com/campaigns.md
https://trysincerely.com/vs-lob.md
https://trysincerely.com/vs-email.md
https://trysincerely.com/holdout-testing.md
https://trysincerely.com/vs-gifting-platforms.md
https://trysincerely.com/does-direct-mail-work.md
https://trysincerely.com/glossary.md
https://trysincerely.com/formats.md
https://trysincerely.com/measurement.md
https://trysincerely.com/writing.md
https://trysincerely.com/customer-relationships.md
https://trysincerely.com/integrations.md
https://trysincerely.com/agents.md
https://trysincerely.com/tools.md
https://trysincerely.com/developers.md
https://trysincerely.com/docs.md
https://trysincerely.com/vs.md
https://trysincerely.com/compare.md
https://trysincerely.com/alternatives.md
https://trysincerely.com/guides.md
https://trysincerely.com/playbooks.md
https://trysincerely.com/operations.md
https://trysincerely.com/about.md
https://trysincerely.com/contact.md
https://trysincerely.com/privacy.md
https://trysincerely.com/terms.md

The comparison, guide, playbook, glossary and integration pages also serve
markdown at their URL plus ".md". Each collection's index lists them:
https://trysincerely.com/vs.md, https://trysincerely.com/compare.md, https://trysincerely.com/alternatives.md, https://trysincerely.com/guides.md,
https://trysincerely.com/playbooks.md, https://trysincerely.com/glossary.md, https://trysincerely.com/integrations.md.
