Email signature generator › GDPR
GDPR and what belongs in an email footer
A great many European signatures acquired a GDPR paragraph in 2018 and have carried it since. Most of them are addressing a requirement that does not apply to a signature at all.
Your details
Layout
Logo or photo — optional
Drop an image here or click to choose
PNG or JPG, under 2 MB
or use a hosted image
Preview
Nothing is uploaded and nothing is stored. The image you drop stays in this browser.
The confusion at the root of it
The regulation requires that people be informed about how their personal data is processed, at the time it is collected. A signature on a message you send is not a collection point: you are not gathering anything from the recipient by signing your name.
The obligation attaches to the form, the sign-up, the contract, the CCTV notice — the moment where data comes in. Restating it at the bottom of every outgoing message satisfies nothing and informs nobody, because a paragraph nobody reads is not information.
Where it genuinely touches a footer
Marketing email is different. Where a message is commercial communication sent under a lawful basis, an unsubscribe mechanism and an identification of the sender are required, and the footer is where they conventionally live. That is a real requirement, and it applies to campaigns rather than to individual correspondence.
The second case is a link to a privacy notice. If your organisation's privacy notice is the document that explains how you handle correspondence, a one-line link to it in the footer is a reasonable way to make it findable. A link, not a paragraph.
The signature itself contains personal data
Your own name and contact details are personal data, and they are being processed every time you send a message. This is lawful and unremarkable — it is necessary for the correspondence — and it does not require any notice. People occasionally reason from "the signature contains personal data" to "the signature needs a GDPR paragraph", which does not follow.
Tracking pixels are the real issue
The part of a signature that can raise a genuine question is a tracking pixel — a one-pixel image whose retrieval tells the sender that the message was opened, and roughly where from. That is monitoring of a recipient who did not ask for it, in a context where consent has not been obtained.
Some signature management products insert these by default. If yours does, it is worth knowing, because the analysis is quite different from the analysis of your name and phone number, and the answer may be that it should be switched off.
What a proportionate footer looks like
For ordinary business correspondence: your details, and if you want it, one link reading "Privacy notice". Nothing else. For marketing email: sender identification and a working unsubscribe, which is a different document from your personal signature and should be treated as one.
The caveat that matters
This is a description of how the regulation is generally understood, not advice about your situation. Sector rules, national implementations and the nature of your correspondence can all change the answer, and the person to ask is whoever advises your organisation. What this page is for is to stop you adding a paragraph that addresses nothing.
What a link to the privacy notice should look like
One line, at the same 11 or 12 pixels as any other small print, reading Privacy notice and pointing at the document. Not a paragraph summarising it, not a statement that you comply, and not a claim about lawful bases — those belong in the document itself, which is where a reader who cares will go.
How to tell whether your signature has a tracking pixel
Send yourself a message and view the source. Look for an
<img> tag with a width and height of 1, or a URL containing
words like open, track or pixel with a long
identifier attached. A one-pixel image is never decorative; if it is there, it
is reporting something.
Signature management products
Centrally managed signature tools often add analytics by default — click tracking on links and an open pixel — because measuring engagement is a selling point. Whether that is appropriate for ordinary correspondence, as opposed to marketing, is a decision someone should make deliberately rather than inherit from a default setting.
Frequently asked questions
Does GDPR require a notice in my email signature?
Not for ordinary correspondence. The obligation to inform attaches where data is collected, and a signature is not a collection point.
What about marketing email?
That is different. Commercial communication requires sender identification and a working unsubscribe, and the footer is where those conventionally live.
Is a tracking pixel in a signature a problem?
It raises a genuine question, because it monitors a recipient who did not ask for it. Some signature products insert one by default, which is worth checking.
Should I link to a privacy notice?
A one-line link is reasonable and makes the document findable. A paragraph restating its contents is not.