Is an email address personal data under GDPR?
By the YelMail team7 min read

Usually, yes. Under the GDPR, an email address is personal data whenever it relates to a person who can be identified, either directly or by combining it with other information. An address with your name in it clearly qualifies. A shared inbox like info@ usually doesn't. A random-looking address attached to an account still counts for the company holding it, because the account ties it to one person.
What counts as personal data under GDPR?
Personal data is any information relating to an identified or identifiable living person. The information doesn't have to name you; it only has to be possible to connect it to you, on its own or combined with other data.
The European Commission's plain-language explainer gives examples on both sides. Personal data includes a name, a home address, an email address, an IP address, a cookie ID and your phone's advertising identifier. Its examples of data that isn't personal include a company registration number, an address like [email protected], and data that has been anonymised irreversibly.
This post is general information, not legal advice.
Which email addresses count as personal data?
Any address that points to one person does. Addresses shared by a team, or tied to a company rather than a person, usually don't.
| Address | Personal data? | Why |
|---|---|---|
| Personal address with your name in it | Yes | It identifies you directly |
Work address like first.last@company |
Yes | It identifies an employee, even in a professional role |
Nickname address like skater92@ |
Yes, in practice | Your provider, and everyone you email, can tie it to you |
| Random address attached to an account | Yes, for the company holding the account | The account, IP address and orders single out one person |
| Hashed email in an ad platform | Usually yes | It's pseudonymised, and anyone with the address can match it |
Role inbox like info@ or sales@ |
Usually no | It points to an organization, not a person |
info@ of a one-person business |
It can be | If it effectively identifies one individual |
The less obvious rows get their own sections below.
Is a work email address personal data?
Yes, if it identifies an employee, and most do. Using an address in a professional role doesn't take it outside the GDPR.
The UK regulator's guidance on what personal data is puts it bluntly: a name and a corporate email address clearly relate to a particular individual. So a B2B mailing list full of first.last@ addresses is a list of personal data, with all the duties that come with it.
Some countries' marketing rules treat business addresses differently from personal ones on the question of consent. That's a question about who you may email and how, not about whether the address is personal data.
Are generic addresses like info@ personal data?
Usually not. A shared inbox such as [email protected] points to an organization rather than a person, which is why the European Commission uses it as an example of data that isn't personal.
There are two catches. The messages sent to that inbox are often full of personal data: the sender's name, their order number, their complaint, their phone number. And a one-person business changes the picture. If a freelance photographer's info@ address only ever reaches her, it identifies her as surely as her name would. UK guidance covers sole traders when the information relates to them as an individual.
Is a random or disposable email address personal data?
For the company that holds it, usually yes. An address like k7x2q9@ doesn't name anyone, but once it's attached to an account, an IP address and a purchase history, it singles out one person, and that's enough.
The distinction that matters here is pseudonymous versus anonymous. A random address is pseudonymous: it hides the name, but the link to a person still exists somewhere. The Commission is clear that pseudonymised data which can be used to re-identify someone remains personal data. Only data that has been anonymised irreversibly falls outside the rules.
There's one wrinkle. The EU's Court of Justice, in a case known as EDPS v SRB, accepted that the same pseudonymised data can be personal data for the organization holding the key and not for a recipient with no realistic means of identifying anyone. It rarely helps a website that holds your account, because that site has the account, the logs and the orders.
A disposable email address doesn't take your data outside the GDPR; the rules still apply to whatever the site keeps. What it changes is how much of it leads back to your real identity: no shared address linking your accounts, no hashed copy of your main email to match in ad platforms, and a leaked address that leads nowhere when that site is breached. Using one is legal in most places, as our post on whether temp mail is legal explains.
The honest trade-off: exercising your rights later usually means proving you own the account, and companies check that through the email address. Once a free temp inbox has expired, that proof is gone. If you think you'll want a copy of your data or a clean deletion later, give that site an address you'll keep.
On YelMail, each inbox is private to the browser or account that created it, messages are deleted automatically when they expire, and email content is never used for ads, profiling or AI training.
What does this mean if you run a website?
Treat every email address you collect as personal data, including the random ones. That means having a reason to collect it, telling people what you'll do with it, and not keeping it longer than you need.
A short checklist:
- Know why you're collecting it. An account can't work without an email; a newsletter usually needs the person's consent.
- Say what you do with it in a privacy notice people can actually find.
- Set a retention period for inactive accounts and old leads, and stick to it.
- Remember that hashing isn't anonymising. Uploading hashed customer emails to an ad platform is still processing personal data. Why websites want your email looks at the same practice from the user's side.
- Use BCC or a mailing tool for group emails. Exposing a list of personal addresses to every recipient is a disclosure.
- Handle access and deletion requests properly, including from people who signed up with a throwaway address.
Blocking disposable addresses doesn't get you out of any of this. If you're weighing it anyway, see what you'd lose in whether to block disposable emails.
What does it mean for you?
Because your email address is personal data, you have rights over it: you can ask a company what it holds about you, ask it to delete that data, and tell it to stop sending you marketing.
Objecting to marketing is the strongest of these. EU guidance on data protection and online privacy says you can object at any time and the company has to stop using your data for it immediately. Deletion has more exceptions, and our guide to removing your email from websites walks through them, with a request template.
These rights also apply to companies outside the EU when they offer goods or services to people in the EU. If a company ignores a request, you can complain to your national data protection authority.
Frequently asked questions
Is an IP address personal data under GDPR?
Yes, in most cases. The European Commission lists IP addresses alongside cookie IDs and phone advertising identifiers as examples of personal data, because they can be linked to a device and the person using it. That's why a website's server logs and analytics can fall under the GDPR even when the site never asks for a name.
Is sending an email with everyone in CC a GDPR breach?
It can be. When an organization emails a group of customers with every personal address visible, it has disclosed their personal data to strangers, and regulators can treat that as a personal data breach. It's worse when the list itself reveals something sensitive, such as the members of a support group or the patients of a clinic. BCC or a proper mailing tool avoids the problem entirely.
Is a hashed email address anonymous?
No. Hashing turns an address into a fixed string of characters, but anyone who has the same address can hash it the same way and get a match. Ad platforms rely on exactly that to match customer lists. Under the GDPR it counts as pseudonymised data, and pseudonymised data that can be linked back to a person is still personal data.
Does GDPR apply to the email addresses saved in my phone?
Not if you keep them for purely personal reasons. The GDPR doesn't cover data an individual handles for personal or household activities, so your contacts, family chats and party invitations are outside it. That changes once the addresses are used for business or professional activity, even a small side business run from your kitchen table.
Where this leaves you
If you're in the EU or UK and a company has your email address, the GDPR almost certainly gives you a say in what it does with it. The easier move is to hand fewer companies your real one: a free temp mail inbox covers the sign-ups you won't keep.
Keep reading

How to remove your email from websites and get your data deleted
Unsubscribing only stops the emails. How to actually get your address deleted, with a request template and what GDPR and CCPA do and don't require.

My email was in a data breach: what to do in the first hour
A breach alert sounds worse than it usually is. What to check, what to change in the first hour, and the habit that makes the next breach a non-event.

Why do companies want your email address? What they use it for
Your email address is the most stable identifier you hand out online. What companies do with it, from newsletters to hashed-email ad matching, and what changes when you give a throwaway.