Engage+
Compliance

GDPR-compliant email marketing for venues: a practical checklist

This practical checklist guides venue marketers through the essentials of GDPR-compliant email marketing. It covers conscious-choice opt-ins, data storage, automated opt-outs, and how Purple Engage builds a compliant first-party data list directly from guest WiFi logins.

5 min read1,233 words

Why this matters for your venue

Most venues are sitting on a goldmine of customer footfall but are doing almost nothing with it. Guests arrive, spend money, and leave. You have no follow-up. There is no reason for them to return. No relationship.

Email marketing solves this problem. A well-timed email to a guest who visited three weeks ago can bring them back through your doors. A birthday offer sent to a diner who provided their details at login can generate a booking that would otherwise never have happened. Venues using Purple Engage see open rates of over 40% on first-party data lists, compared to an industry average of around 21% for purchased or scraped lists. The reason for this difference is consent. When someone actively chooses to hear from you, they read the emails you send.

But here is the catch. Under GDPR, you cannot simply collect email addresses and start sending. You need clear, informed, and freely given consent. And you must be able to prove it. Getting this wrong can cost you fines of up to €20 million or 4% of global annual turnover, whichever is higher.

The good news is that if you collect consent correctly during Guest WiFi login, you are already more than halfway there. Purple Engage is built to do exactly this.

The method

Let's go through the five pillars of GDPR-compliant email marketing for venues.

GDPR requires consent to be freely given, specific, informed, and unambiguous. In simple terms, this means your guest must actively tick a box - not a pre-ticked box, and not a clause hidden in your terms and conditions - to say yes, I want to receive marketing emails from you.

When a guest connects to your venue's WiFi via Purple Engage, they see a Captive Portal - a splash page that loads before they go online. On that page is a clearly labelled opt-in checkbox. The language is important. It should be something like: "I would like to receive offers and news from The Crown Hotel. You can unsubscribe at any time." Short, clear, honest. No complex legalese.

The checkbox must be unticked by default. Ticking it is the guest's active choice. This is what makes it a conscious-choice opt-in - and this is the phrase we use at Purple because it captures exactly what GDPR demands.

Gdpr consent flow

Collecting consent is not enough. You must be able to prove it. Under GDPR Article 7, if you are challenged by a guest or investigated by a regulatory body, you must prove that consent was given. This means recording the timestamp of when consent was given, the source - in this case, the WiFi login portal - the exact wording the guest agreed to, and which version of your privacy policy was active at the time.

Purple Engage records all of this automatically. Every opt-in is timestamped, tagged to the venue, and stored in the guest profile. If the ICO ever investigates, you can pull up the consent record in seconds.

Pillar 3: Data storage and security

Under GDPR, personal data - including email addresses - must be stored securely and, for UK and EU organisations, within the UK or EU, or in a country that has an adequacy agreement with the UK or EU. Purple's infrastructure is ISO 27001 certified and GDPR-compliant. Data is stored in EU-based data centres. You do not have to worry about cross-border data transfer issues when you use Purple Engage.

You also need to ensure that only authorised staff can access your guest data. Purple Engage uses role-based access control, so your marketing manager can run campaigns without exporting the entire database.

Pillar 4: Opt-out mechanics

Every marketing email you send must contain a clear, working unsubscribe link. Under GDPR, an opt-out request must be actioned quickly - within a reasonable timeframe according to ICO guidelines, with best practice being within 10 working days. In reality, Purple Engage processes unsubscribes automatically. When a guest clicks unsubscribe, they are immediately added to your suppression list. They will not receive another email from you. You do not have to manage this manually.

The suppression list is crucial. Simply deleting someone from your active list is not enough. You must keep a record that they have opted out, so that if their email address is added again later - say, via a data import - the system knows not to email them. Purple Engage maintains this suppression list automatically.

Pillar 5: Data retention and hygiene

GDPR's storage limitation principle states that you should not keep personal data for longer than you need it. For email marketing, this means you need a data retention policy. A sensible approach for most venues is to review consent every 24 months. If a guest has not interacted with any of your emails and has not visited your venue in two years, their consent may no longer be meaningful. Send a re-consent email. If they do not respond, remove them from your active list.

This is not just a compliance exercise. It is also good marketing. A clean, active list will always outperform a large but disengaged one. Deliverability improves. Open rates go up. Revenue per email increases.

How to do this with your Guest WiFi

Venues that get this right are building something that Mailchimp, Klaviyo, and HubSpot cannot give them: a list that builds itself from real guests who have made a conscious choice to hear from you. This is first-party data. And in a world where third-party cookies are disappearing and paid media costs are rising, first-party data is the most valuable marketing asset you own.

Purple Engage captures conscious-choice opt-ins during WiFi login, timestamps every consent record, and handles unsubscribes automatically. GDPR compliance is built-in - not bolted on.

To learn more about how to segment this data, read our Email segmentation for venues: a practical guide.

What to send and when to send it

Once you have a consented list, you need to send emails that drive revenue.

Welcome emails Send this within 24 hours of opt-in. This is your best-performing email. Welcome emails have an average open rate of 50% or higher. Include a clear offer to encourage a repeat visit.

Birthday offers If you collect date of birth at login, set up an automated birthday email 14 days before the date. This drives high-value group bookings.

Re-engagement campaigns Send an offer to guests who have not visited in 90 days. This turns one-time visitors into loyal regulars.

Measuring what works

Do not just measure opens and clicks. Measure repeat visits and revenue.

Because Purple Engage tracks WiFi logins, you can see when a guest returns to your venue after receiving an email. This is true closed-loop attribution. You will know exactly how much revenue your email marketing is generating.

Where to start

Your next steps are simple.

  1. Audit your current consent capture process. Is your opt-in checkbox unticked by default? Is the wording specific to marketing emails?
  2. Check your data storage. Where is your guest data being held, and is it GDPR-compliant?
  3. Test your unsubscribe flow. Click the unsubscribe link in one of your own emails and check that it works and that the opt-out is processed within 10 days.

Gdpr compliance checklist

Listen to our 10-minute briefing on this topic below.