Skip to content

Compliance

Email signatures and GDPR: employee data, click tracking and processors

Photos, phone numbers, banner analytics, signature tools: what GDPR means for email signatures — for employees, for recipients and for your service provider.

The Soniako team Published 3 min read

An email signature looks harmless from a data protection point of view. Yet it involves three groups of people: employees whose details appear in it, recipients whose interactions you may measure, and the provider that manages it all. Here is what to watch for with each.

This article is general information, not legal advice. Involve your DPO or counsel in your decisions.

1. Employee data

A signature contains personal data: name, title, phone, sometimes a photo and a LinkedIn profile.

Business contact details

Name, title, work email and work phone are needed for the business to operate. Showing them in the signature usually rests on the employer’s legitimate interest or on the employment contract. Simply inform employees, for example in the HR privacy notice.

Mobile number

A work mobile provided by the company follows the same logic. A personal number should never be published without the person’s explicit agreement.

Profile photo

Photos are more sensitive. The prudent recommendation: make it optional. Employees should be able to refuse having their photo in their signature, with no consequence. If the photo comes from the directory (Google Workspace, Microsoft 365), check that its use in signatures is known and accepted.

Minimization

Show only what is useful. Every extra field (home address, date of birth, and so on) needs a justification — which is almost never there.

2. Recipient data

If your signatures carry measured banners (impressions, clicks), you are processing data about the recipients of your emails.

Clicks

Click measurement usually works through a redirect link. At an aggregated level (“240 clicks on the campaign”) the impact is limited. Individual tracking (“this recipient clicked”) is more intrusive and needs more justification.

Impressions

Counting image loads works much like tracking pixels. European data protection authorities, including France’s CNIL, are paying close attention to tracking in emails and to the question of consent. To limit risk:

  • favor aggregated statistics per campaign;
  • avoid individual profiling of recipients;
  • document the processing in your records;
  • be transparent, for example with a privacy policy link in the signature.

See also measuring signature ROI.

3. The signature management provider

A signature management tool accesses your directory and processes your employees’ data: it is a processor under GDPR. Check:

CheckpointWhy
Data processing agreement (DPA)Mandatory (GDPR article 28)
Hosting locationEU hosting simplifies compliance
Sub-processorsKnow who else can access the data
Scope of directory accessLimited to the attributes needed
Encryption and backupsSecurity of processing (article 32)
Retention periodsDeletion of leavers’ data

These points are part of choosing a tool: see how to choose email signature software.

4. Leavers

When someone leaves, their signature data should be deleted or deactivated within a reasonable time. Directory sync does it automatically: a deactivated account no longer gets a signature. See joiners and leavers.

GDPR checklist for your signatures

  • Employees informed about the data shown in their signature
  • No personal number without explicit agreement
  • Photo optional, with the right to refuse
  • Banner statistics aggregated, no individual profiling
  • Processing recorded in your records of processing
  • DPA signed with the provider
  • Hosting location and sub-processors known
  • Data deleted when employees leave

For the obligation to show company details, see email signature legal requirements.

← All articles