A marketer argues that GDPR legitimate interests alone justify unsolicited promotional emails to cold EU consumer addresses, ignoring ePrivacy consent overlays. What is the better CIPP/E-aligned view?
Select an answer to reveal the explanation.
Short Explanation
GDPR and ePrivacy are a tag team, not a choose-your-own adventure. Even if someone waves 'legitimate interests,' electronic marketing to people often still needs consent or a soft-opt-in under the ePrivacy layer. LI is not a skeleton key for cold spam.
Full Explanation
The GDPR provides lawful bases for processing personal data, but electronic communications marketing remains heavily shaped by the ePrivacy Directive and national implementations that commonly require prior consent for unsolicited B2C email, subject to limited soft-opt-in exceptions. Controllers cannot rely on Art. 6(1)(f) legitimate interests alone to bypass those sectoral rules. CIPP/E candidates should treat ePrivacy overlays as controlling for many electronic direct-marketing channels.