legal@, privacy@ and dpo@: The Email Addresses Regulators Expect
Which legal@, privacy@ and dpo@ email addresses to create for GDPR and privacy laws, what to put in your privacy notice, and how to answer requests on time.
Privacy laws do not care how small you are: if you have a website with a sign-up form or a mailing list, someone can email you a data access request and the clock starts. Regulators, app-store reviewers and enterprise procurement teams all look for a privacy contact on your domain. This guide covers which addresses to create, what to write in your privacy notice, and how to answer the requests that arrive.
Quick answer
Create privacy@yourdomain.com and legal@yourdomain.com as real mailboxes today. Add dpo@ only if you have appointed a Data Protection Officer or a customer asks for one; do not publish dpo@ and then leave the role empty, because it implies a formal appointment. All three are free role addresses on OquMail, so the cost is ten minutes, not a per-seat fee.
What each address is for
- privacy@ — data subject requests (access, erasure, correction, objection), questions about your privacy notice, cookie complaints, and "unsubscribe me from everything" messages. Publish it in your privacy notice and app-store listings.
- legal@ — contracts, notices of claim, copyright and trademark complaints (including takedown notices), court and regulator correspondence, and supplier terms. Publish it in your terms of service and on your imprint or "legal" page.
- dpo@ — the contact for your Data Protection Officer, where one is required or appointed. The GDPR requires a DPO for public bodies and for organisations whose core activity involves large-scale, regular monitoring of people or large-scale processing of special category data. Most small businesses are not required to appoint one.
- compliance@ or security@ — optional. security@ is the address researchers expect for vulnerability reports and is referenced by the security.txt convention (RFC 9116); compliance@ is worth having once you sell to banks or public bodies.
What the law expects you to publish
The GDPR (Articles 13 and 14) requires your privacy notice to include the identity and contact details of the controller and, where one exists, the DPO. The UK GDPR mirrors this. Kenya's Data Protection Act 2019, South Africa's POPIA, Nigeria's NDPA 2023 and Brazil's LGPD all require a contact through which people can exercise their rights, and California's CCPA requires at least two methods of submitting requests, of which an email address is the simplest. The pattern across all of them is the same: a monitored address on your own domain, stated plainly in the notice. A Gmail address in a privacy notice is a red flag to any reviewer.
Set up the mailboxes in six steps
- Create privacy@ and legal@ as separate mailboxes so an access request and a supplier contract are never in the same thread.
- Give each a named owner. In a five-person company this is usually a founder for legal@ and the operations lead for privacy@. Add one backup login per mailbox.
- Set an auto-reply on privacy@ that acknowledges receipt, states your identity verification step, and quotes the statutory deadline (one month under the GDPR, extendable by two months for complex requests; 45 days under the CCPA; check your own regulator for the rest).
- Create folders "Access requests", "Erasure requests", "Complaints" and "Closed", and log each request in a simple spreadsheet with received date, deadline date and outcome.
- Update your privacy notice, terms of service, cookie banner and app-store listings to show the new addresses. Search your site for any old personal address and replace it.
- Put the addresses on IMAP for their owners so a request received on a Friday afternoon is seen before Monday week.
Acknowledgement template for privacy@
Subject: We have received your privacy request [Ref: PR-YYYY-NNN]
Hello [Name],
Thank you for your message. We received your request on [date] and have logged it under reference PR-[YYYY]-[NNN].
To protect your data we need to confirm your identity before we act. Please reply from the email address registered with us, or send [one acceptable form of verification].
Once verified, we will respond within [one month / 45 days] as required by [GDPR / CCPA / applicable law]. If your request is complex we may extend this period and will tell you why.
You can contact our privacy team at privacy@[yourdomain].com at any time about this request.
Kind regards,
[Name]
Privacy contact, [Company]Mistakes that turn into complaints
- Publishing privacy@ but forwarding it to an unmonitored inbox; a missed deadline is itself a breach.
- Answering an erasure request without checking backups, CRM exports and mailing-list tools, then getting a second complaint when a newsletter goes out.
- Naming a DPO on the website who is also the CEO or head of marketing; regulators expect independence, and it is safer to have no DPO than a conflicted one.
- Handling legal notices by WhatsApp screenshot. Keep them in legal@ so there is a dated, complete record.
- Replying to takedown notices with a fight instead of a fact check; most are resolved by a calm, documented answer within a week.
Common questions
Can privacy@ and legal@ be the same mailbox?
At one or two people, yes, with folders. Split them the moment a second person takes over either function, because the legal mailbox often contains confidential contract terms that the person handling access requests does not need to see.
Do I need an EU representative address?
If you are outside the EU but offer goods or services to people in it, Article 27 of the GDPR may require you to appoint a representative in the EU and publish their contact details. That is a legal question worth a short consultation; the email setup is the easy part.
What if I get a request I do not understand?
Acknowledge it anyway, log the date, and ask one clarifying question. The deadline runs from receipt, not from the day you understood it, so a fast acknowledgement buys you nothing except goodwill, but a slow one loses you the case.
Free business email on your own domain
OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.
Get started free