Is an Email Address Personal Data?

A definitional question with real, usable consequences.


Under the GDPR, yes — an email address is personal data whenever it can identify a living person, which covers essentially all individual addresses. That's not a technicality: it's what gives you the right to ask what an organisation holds, to object to marketing, and to demand erasure. Role addresses like info@company.com are the grey area, and aliases are personal data too, because they identify you just as well.

The test

Personal data is information relating to an identified or identifiable living person. An address like firstname.lastname@example.com identifies someone directly. Even one that doesn't contain a name — x7fq2k@example.com — is still personal data if the holder can link it to a person, which they generally can, because they have the account it belongs to.

So in practice: if it's an individual's address, treat it as personal data. That's the working assumption regulators apply.

Why it matters practically

Because the classification is what unlocks the rights. If your address is personal data, then any organisation holding it in scope of the GDPR owes you:

  • The right to be informed — what they hold, why, and who they share it with.
  • The right of access — a copy, free, within one month.
  • The right to object to direct marketing — absolute, with no balancing test. They must stop.
  • The right to erasure, subject to exceptions. How to make a request
  • The right to rectification if what they hold is wrong.

This is what makes a request to a data broker something they must answer rather than a polite enquiry. Broker opt-outs

Role addresses: the grey area

Is info@company.com personal data? Usually not, if it's a genuine shared function not attributable to an individual. But alex@company.com plainly is, even though it's a work address — being at work doesn't remove the protection.

The distinction matters for B2B marketing: senders sometimes assume business addresses are fair game, and for named individuals that assumption is wrong.

What about aliases?

An alias is personal data on the same test. ikea@yourdomain.com identifies you to Ikea as reliably as your real address would, and it's linkable to you by anyone holding the domain records.

This is worth understanding because it cuts against a comfortable assumption: using an alias doesn't put you outside the data-protection framework, and it doesn't make you anonymous to the company. It changes which address they hold, not whether the law applies. The boundary

The upside is that your rights travel with the alias. You can make an erasure request about an alias exactly as you would about your real address.

Outside the EU and UK

The answer varies. California's CCPA treats email addresses as personal information and gives residents rights to know, delete and opt out of sale — a comparable framework with different mechanics. What Californians can do

Many jurisdictions have weaker or no equivalent, which is why the practical protections available to you depend heavily on where you live — and why prevention matters more where the law does less. Removal vs prevention

More: data brokers explained · broker vs processor vs controller

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading