Under the GDPR, yes — an email address is personal data whenever it can identify a living person, which covers essentially all individual addresses. That's not a technicality: it's what gives you the right to ask what an organisation holds, to object to marketing, and to demand erasure. Role addresses like info@company.com are the grey area, and aliases are personal data too, because they identify you just as well.
The test
Personal data is information relating to an identified or identifiable living person. An address like firstname.lastname@example.com identifies someone directly. Even one that doesn't contain a name — x7fq2k@example.com — is still personal data if the holder can link it to a person, which they generally can, because they have the account it belongs to.
So in practice: if it's an individual's address, treat it as personal data. That's the working assumption regulators apply.
Why it matters practically
Because the classification is what unlocks the rights. If your address is personal data, then any organisation holding it in scope of the GDPR owes you:
- The right to be informed — what they hold, why, and who they share it with.
- The right of access — a copy, free, within one month.
- The right to object to direct marketing — absolute, with no balancing test. They must stop.
- The right to erasure, subject to exceptions. How to make a request
- The right to rectification if what they hold is wrong.
This is what makes a request to a data broker something they must answer rather than a polite enquiry. Broker opt-outs
Role addresses: the grey area
Is info@company.com personal data? Usually not, if it's a genuine shared function not attributable to an individual. But alex@company.com plainly is, even though it's a work address — being at work doesn't remove the protection.
The distinction matters for B2B marketing: senders sometimes assume business addresses are fair game, and for named individuals that assumption is wrong.
What about aliases?
An alias is personal data on the same test. ikea@yourdomain.com identifies you to Ikea as reliably as your real address would, and it's linkable to you by anyone holding the domain records.
This is worth understanding because it cuts against a comfortable assumption: using an alias doesn't put you outside the data-protection framework, and it doesn't make you anonymous to the company. It changes which address they hold, not whether the law applies. The boundary
The upside is that your rights travel with the alias. You can make an erasure request about an alias exactly as you would about your real address.
Outside the EU and UK
The answer varies. California's CCPA treats email addresses as personal information and gives residents rights to know, delete and opt out of sale — a comparable framework with different mechanics. What Californians can do
Many jurisdictions have weaker or no equivalent, which is why the practical protections available to you depend heavily on where you live — and why prevention matters more where the law does less. Removal vs prevention
More: data brokers explained · broker vs processor vs controller