Home Blog Is a Work Email Address Personal Data?

GDPR

Is a Work Email Address Personal Data?

Posted by Kevin Yun|August 31, 2026

Yes, wherever the address identifies an individual. An address in the form firstname.lastname@company.com is personal data under the GDPR regardless of who pays for the mailbox, because the test is whether a natural person can be identified, not who owns the account. A genuinely generic address such as info@company.com usually is not, because the regulation protects natural persons and not companies.

This article covers where that line actually falls, why the employer paying for the account changes nothing, the separate marketing rules that cause most of the confusion, why your own staff's addresses are in scope too, and what it means for your systems.

The Test Is Identifiability, Not Ownership

Article 4(1) defines personal data as information relating to an identified or identifiable natural person. There is no carve-out for information created in a work context, none for information an employer pays for, and none for information a person shares in a professional capacity.

sam.smith@acme.com identifies Sam Smith. It probably also reveals where Sam works, and combined with a public staff directory it may reveal Sam's role and seniority. That it exists because Acme bought a mailbox is legally irrelevant. Acme is a legal person, and the GDPR is concerned with natural ones.

It is worth noting that the American vocabulary points the other way here. Classification guides written around personally identifiable information routinely file work email addresses as non-sensitive, which is a judgment about breach impact rather than about legal scope. Under the GDPR the two questions are separate: sensitivity affects your risk assessment, identifiability decides whether the regulation applies at all.

This is worth stating plainly because the opposite belief is widespread and often held confidently. A useful sanity check: if Sam left Acme tomorrow and asked what you held about them, "your work email address" is obviously part of the answer.

Where The Line Actually Falls

The distinction is between addresses that identify a person and addresses that identify only a function.

Clearly personal data: sam.smith@acme.com, s.smith@acme.com, sam@acme.com in a company of eleven people. Clearly not, in most circumstances: info@acme.com, support@acme.com, billing@acme.com, where the mailbox is a queue and no individual is identifiable from it.

The middle is where care is needed. sales@acme.com at a two-person company effectively names a person. An initials-based scheme identifies people just as well as a full name where the population is small enough. Recital 14 confirms the regulation does not cover the personal data of legal persons, but the shield only holds while the address genuinely refers to the organisation rather than a person within it.

Note also that generic today does not mean generic forever. An address that once fed a shared inbox and now routes to one named person has quietly changed category, and nothing in your systems will flag that.

Two Different Laws, Two Different Questions

Most of the confusion on this topic comes from a genuine rule that answers a different question.

In the UK, the PECR rules on direct marketing by electronic mail do not apply to corporate subscribers in the way they apply to individuals, so consent is not required in the same terms when marketing to a corporate body. That is a real distinction and it is why B2B marketing operates differently from B2C.

It is not a statement about personal data. The address is still personal data, the UK GDPR still applies to processing it, and you still need a lawful basis, a retention period and transparency. What changes is which consent rule applies under a separate piece of legislation, not whether the data is in scope.

The failure mode is a straight line from "we don't need consent for B2B email" to "so it isn't personal data," and everything downstream of that inference is wrong: the record of processing, the response to an access request, the deletion obligation. The marketing rules themselves are a separate topic with their own complexities and are not covered here.

Your Own Employees' Addresses Count Too

Teams that reason carefully about customer contacts often overlook their own staff.

Every employee address in your directory, your version control history, your ticketing system and your access logs is personal data about that person. Employment does not create an exception; it creates a processing relationship with its own transparency obligations, and staff have the same rights of access and rectification as anyone else.

This matters most at offboarding. A departing employee's address persists in commit messages, audit trails, shared documents and years of ticket history. Deleting the mailbox does not delete the personal data, and in many cases you have good reasons to retain some of it. What you need is a decided position rather than an accidental one.

What This Means For Your Systems

Three consequences follow, and none is exotic.

Access requests reach your CRM. If a business contact asks what you hold, the answer includes their work address and everything attached to it: notes, call logs, enrichment fields, lead scores, and any inferred data your tooling added. Enrichment is worth particular attention, because data you bought rather than collected triggers Article 14's separate information obligation.

Your Article 30 record needs a line for business contacts. It is a distinct category of data subject with its own purposes, lawful basis and retention.

And retention needs a decision. Most CRMs keep contacts indefinitely by default because that is the commercially convenient setting, not because anyone assessed it. A contact who has not responded in four years and never became a customer is difficult to justify holding on a legitimate interests basis. Vendor contracts already reflect this reality; Calendly's data processing addendum, checked 7 August 2026, lists invitee data including email addresses among the categories it processes, and the specifics of how that flows are set out in our look at whether Calendly is GDPR compliant.

The related question of whether an IP address in the same record is personal data has its own, more contested answer, which we cover in is an IP address personal data.

Common Mistakes With Work Email Addresses

Concluding that B2B means out of scope. The marketing consent rules differ for corporate subscribers. The definition of personal data does not, and conflating the two produces a compliance position that fails at the first access request.

Treating any address at a company domain as corporate. The domain is not the test. A named individual at a corporate domain is identifiable and therefore in scope.

Forgetting enrichment data has a separate obligation. Contacts sourced from a data vendor rather than collected directly fall under Article 14, which requires you to inform the person, generally within one month.

Excluding employees from data mapping. Staff addresses in ticketing systems, repositories and audit logs are personal data. Internal systems are routinely missed because the mapping exercise started with customer-facing products.

Assuming deleting the mailbox deletes the data. The address persists in commit history, ticket threads, shared documents and backups. Removing the account closes one copy and leaves the rest untouched.

FAQ

Is info@company.com personal data?

Generally no. A genuinely generic mailbox identifies a function rather than a person, and Recital 14 confirms the GDPR does not cover the data of legal persons. The exception is a small organisation where everyone knows the shared address reaches one particular individual.

Does GDPR apply to B2B contact data?

Yes, where the contact is an identifiable person. Business context does not remove data from scope. Separate marketing rules for corporate subscribers may change whether consent is required for a given message, but the underlying processing obligations still apply.

Can I keep a work email address after someone leaves the company?

Sometimes, but you need a reason and a limit. Retaining an address in historical records for contractual or audit purposes is often justifiable. Keeping it in an active marketing list once you know the person has moved on generally is not.

Do I need consent to store a work email address?

Usually not. Consent is one of six lawful bases and rarely the right one for business contacts. Legitimate interests commonly fits, provided you have carried out and documented the balancing test rather than assuming the outcome.

Closing Thought

The instinct behind this question is usually not really about definitions. It is a hope that business contact data sits in a lighter regime, because treating it the same as consumer data makes a pipeline built on scraped and enriched contacts look considerably less comfortable.

It does not sit in a lighter regime. The one genuine difference is a marketing consent rule in separate legislation, and it has been asked to carry far more weight than it can bear. If the practical problem is knowing what you hold and being able to show it, ComplyDog hosts a compliance portal on your own domain with self-serve data subject request handling, your subprocessor list and your security page. It does not clean up your CRM, which is the part that usually needs doing.