GDPR and your email signature

A name, direct phone number, and photo are typically personal data - a compliance footer sentence at the bottom does not, by itself, make the processing lawful.

Under the GDPR and UK GDPR, an employee's name, job title, direct phone number, and photo in an email signature are typically personal data, and a company processes that data every time it sets a signature template. GDPR does not prescribe exact signature content; it regulates how that data is collected, used, and minimized, with a lawful basis behind it.

Who this applies to

The GDPR (Regulation (EU) 2016/679) and the UK GDPR apply to any processing of personal data about an identified or identifiable natural person, carried out by an organization established in, or offering goods and services to, the EU or UK. An employee's business contact details in a signature are personal data about that employee; the GDPR applies to the company setting the template just as it applies to any other processing of staff data.

What it actually requires

A lawful basis for processing
A company needs a lawful basis (commonly legitimate interests, for ordinary business contact details) to set an employee's name, title, and contact details in a company-wide signature. The EDPB and the UK ICO's guidance on legitimate interests describe the balancing test this involves - the employer's interest in professional identification, weighed against the individual's expectations and any risk to them.
Data minimization
Only the personal data genuinely needed for the stated purpose belongs in the signature. A direct-dial number, a personal mobile number, or a photo carries more personal data than a name and job title, and each addition should be weighable against why it is there.
Transparency to the employee
Employees whose details appear in a company signature are typically entitled to know that this processing happens and to see it reflected in the employer's privacy information for staff (commonly an internal privacy notice), alongside their access, correction, and erasure rights over their own data generally.
A basis for any marketing content added to the signature
A banner, tracking pixel, or link to a mailing-list sign-up added to a company-wide signature is marketing content layered onto personal data, and it raises its own question under GDPR and, in the UK, under PECR (see the companion page on marketing email) - the signature question and the marketing-consent question are related but not identical.

Myths we hear often

The myth

Adding a GDPR-compliance sentence to the footer makes the signature GDPR-compliant.

What the source actually says

GDPR does not work through a footer disclaimer. It requires a lawful basis for the processing and adherence to principles like minimization and transparency; a sentence stating compliance is not itself a lawful basis and does not create one.

The myth

GDPR only cares about customer data, not what goes in an employee signature.

What the source actually says

GDPR applies to personal data about any identified or identifiable natural person, which includes an employee's own name and contact details in a company-set signature template - it is not limited to customer or prospect data.

The myth

A company can put any contact detail it wants in everyone's signature, since it owns the template.

What the source actually says

Setting the template is itself an act of processing personal data, and minimization applies to it: the question is what the signature needs for its stated business purpose, not what the company is technically able to include.

A worked example

A fictional example: Marrow & Finch Consulting
Marrow & Finch Consulting, a fictional advisory firm, standardizes its email signature to name, job title, direct-dial number, and the firm's main switchboard number - it leaves out home or mobile numbers and drops the employee photo it had briefly trialed, after asking whether the photo served the signature's business purpose or added personal data without a clear reason. It documents the legitimate-interest basis for the standard fields in its internal data-processing record and tells new hires, in onboarding, what goes into their signature and why.

Questions people ask

Is a name and job title in an email signature personal data under GDPR?

Generally, yes - a name combined with an employer and job title can identify a natural person, which is what GDPR's definition of personal data turns on. That does not mean it is unlawful to use; it means the processing needs a lawful basis, most commonly legitimate interests for ordinary business contact information.

Do I need consent from each employee to put their details in the company signature?

Not necessarily consent specifically - legitimate interests is the basis most commonly relied on for ordinary business contact details in a work signature, since consent from an employee to an employer carries its own validity questions under GDPR given the power imbalance. Which basis actually fits is a fact-specific question a company's own data protection advice should answer.

Does adding a company logo or photo to signatures change the GDPR analysis?

A photo is personal data too, and typically more sensitive to get wrong than a name and phone number, so it deserves its own look at whether it is minimized to a real purpose and whether employees know it is used this way - the same principles apply, with a slightly higher bar given how identifying a photo is.

Put your own details on every signature you send

Signatoro puts your name, title and contact details on every signature, free for one person. From the Up to 15 plan, a company adds one compliance footnote to everyone's signature.

Other pages in this series

Sources