
Email marketing runs on more rules than almost any other function inside a growing company. Every campaign has to clear a spam filter, respect an unsubscribe request, and stay inside the boundaries of laws like CAN-SPAM in the United States or the UK’s e-privacy regulations. A marketer who ignores these rules does not just annoy a subscriber. They put the company’s sender reputation, and sometimes its legal standing, at risk.
Because of this, companies have gotten fairly disciplined about the compliance side of the campaigns themselves. What gets far less attention is a second compliance question sitting one layer beneath it: who actually employs the person running those campaigns, and does that arrangement hold up under the law of the country where they live.
This question matters more than it used to, because the person sending the campaigns is increasingly not a full-time employee at company headquarters. Growth marketers, lifecycle specialists, and email deliverability consultants now work from wherever the talent happens to be, brought on as remote contractors rather than hired into a local office. It is a sensible way to build a marketing function. It also creates a legal question that most companies never get around to answering properly.
The rules everyone already thinks about
Start with what companies already do well. Anyone running email campaigns knows the basic guardrails by now: get consent before sending, make unsubscribing genuinely easy, avoid the kind of subject-line tricks that get flagged as deceptive, and keep the sending list clean.
That last point matters more than it looks. A list full of dead addresses or, worse, disposable inboxes that no longer exist, drives up the bounce rate on a campaign. A high bounce rate signals a spam operation to internet service providers, and once an ISP starts routing a domain’s mail to the spam folder, it tends to apply that judgment to every message from that sender going forward, including the ones real customers actually want. This is exactly why marketing teams invest in list hygiene tools, verified sending domains, and platforms built to manage deliverability at scale. It is a well-understood problem with well-understood solutions.
Data privacy sits alongside deliverability as the other rule nobody skips anymore. A campaign sent to European Union residents has to account for GDPR, which requires a clear lawful basis for holding someone’s email address and an easy way for them to withdraw consent at any point. A campaign sent to UK residents falls under the UK GDPR and the Privacy and Electronic Communications Regulations, which go further and require specific, informed consent before most marketing emails can be sent at all. Getting either of these wrong does not just risk a spam complaint. It can bring a regulatory investigation and a fine calculated as a percentage of company revenue, not a flat penalty. None of this is optional, and most marketing teams, or the platforms they use, have built it into their workflow by now.
All of this is the compliance layer companies already know to plan for. The one they routinely miss sits underneath it.
Why the role goes remote in the first place
It helps to understand why email marketing specifically tends to get outsourced this way, rather than filled with a local hire. Deliverability and lifecycle marketing are narrow, technical skills. A specialist who has spent years tuning sender reputation, building segmentation logic, and reading engagement data is genuinely hard to find, and companies that need this expertise for twenty hours a week rarely want to commit to a full local salary and benefits package to get it.
There is also a scheduling argument that does not apply to most other roles. A company running campaigns across multiple regions benefits from having someone who can send, monitor, and adjust a campaign while the home office is asleep. A marketer based several time zones away is not a workaround in this case. It is often the better setup.
Both of these are legitimate business reasons to hire remotely and internationally. Neither of them has anything to do with how the person should be legally employed once the arrangement becomes a regular, ongoing part of the team rather than a one-off project. That is a separate question, and it is the one that gets skipped.
The rule almost nobody thinks about
Once a company decides to bring on a marketing specialist who lives in another country, a second and entirely separate legal question appears: what is the actual employment relationship with that person, and does it match what local law expects.
The default answer, in most cases, is a contractor agreement. It is the fastest option, requires no new registration in the specialist’s home country, and can be signed the same week the role is filled. For a single short-term project, this rarely causes a problem. The trouble starts when the arrangement stops looking like a project and starts looking like a job.
Tax and labor authorities in most countries do not take a company’s word for how a working relationship should be labeled. They look at how it actually functions. A marketer who works agreed hours, logs into the company’s own email platform and analytics tools, reports weekly to the same manager, and has no other clients bears very little resemblance to an independent contractor, regardless of what the signed agreement says. In the United Kingdom specifically, this question falls under what is generally known as IR35, and HMRC provides its own Check Employment Status for Tax tool to help businesses and workers determine, before the engagement even starts, whether a role should be treated as employment for tax purposes.
Getting this wrong is not a minor administrative slip. Reclassification can mean back taxes, unpaid National Insurance contributions, and penalties applied retroactively, sometimes for years of work that has already been completed and paid for. The cost scales with how long the arrangement has been running and how many people the company has brought on the same informal way.
Three ways to actually structure the hire
Once a company recognizes that an ongoing marketing role needs a real structure rather than an improvised one, the options generally come down to three.
Setting up a local entity gives a company full control over how it employs someone in a given country, but it also means registration paperwork, ongoing statutory filings, and a genuine long-term commitment to that market. For a single marketing hire, this is rarely worth the overhead unless the company already has other plans to operate there.
Continuing to engage the person as a contractor remains appropriate only if the relationship stays genuinely independent: defined project scope, the marketer’s own tools and schedule, and other clients on the books. The moment weekly reporting, fixed hours, and exclusivity enter the picture, the contractor label stops matching reality.
The third option is working with an employer of record, which becomes the legal employer of the marketer in their own country while the hiring company continues to direct their day-to-day work. The employer of record handles the local employment contract, statutory benefits, payroll, and tax withholding, which removes the guesswork around classification entirely because the relationship is structured correctly from the start. A growth marketer based in London, for instance, could be brought on through a UK employer of record, rather than a contractor agreement that may not survive an IR35 review, giving the company a properly employed team member without opening a UK entity of its own.
For a company still testing whether a market, or a specific hire, is going to work out long term, this route tends to offer the fastest way to a compliant employment relationship, without the multi-month timeline that comes with registering a new entity.
Where the two questions collide
There is a point where the campaign rules and the employment structure stop being separate concerns, and it catches companies out precisely because they have been treated as separate.
An outsourced email marketer holds the most sensitive dataset the company owns. The entire subscriber list, engagement history, and whatever segmentation data sits behind it. GDPR expects the people handling that data to be trained on how to handle it, and the accountability principle expects the company to be able to demonstrate that the training happened. Not to assert it. To evidence it.
In practice, this is exactly the training nobody assigns. The marketer is not in the HR system, does not appear on an onboarding list, and arrives through a contractor invoice rather than a start date. So the data protection module every internal employee completes never gets sent to the one person with full access to the subscriber database.
Then the classification problem doubles back on itself. Compelling someone to complete your training, on your schedule, with consequences for not doing it, is an exercise of control, and control is one of the main things a tax authority weighs when deciding whether a contractor is really a contractor. So a company that reacts by mandating its internal curriculum for an offshore contractor has closed one gap and widened another.
The clean version depends on which structure you actually chose. If the person is properly employed, through an entity or an employer of record, they belong in the normal training program, and the only thing to settle is which party holds the completion records. If they are a genuine contractor, ask what certifications they already hold and make those a condition of the engagement, rather than pushing your own courses at them.
Both routes land in the same operational place. Someone has to assign the right material to the right person, and someone has to keep a record of what was completed and when. Teams that handle this well tend to stop treating it as an HR errand and run it the way they run the rest of the function, through an LMS learning platform that assigns modules by role, logs completions, and stores the certificates a contractor already holds alongside the ones the company issues. It also lifts the training question out of any one manager’s inbox, which matters once the person who onboarded the marketer has moved on.
The evidence problem then largely solves itself. Due diligence eventually asks who legally employs your contractors, and it asks a parallel question about who was trained to handle personal data. A dated record naming the person, the material, and the date is simple to produce when it was captured as the work happened, and close to impossible to reconstruct two years after an engagement has ended.
Two compliance layers, one team
It is worth stepping back to see the full picture. A marketing team that outsources its email function is already operating inside a fairly dense compliance framework: consent rules, deliverability standards, data protection law, and increasingly strict spam filtering on the receiving end. None of that gets skipped, because the consequences of getting it wrong show up immediately in the form of a tanking sender reputation or a regulatory complaint.
The employment question deserves the same level of attention, even though its consequences take longer to surface. A misclassified contractor does not usually cause a problem in the first month, or even the first year. The exposure tends to show up later, often during a due diligence process ahead of a funding round or an acquisition, or when the relationship ends and the terminated marketer, or a labor authority in their home country, starts asking questions the company never prepared answers for.
Companies that treat both compliance layers with equal seriousness from the start, the campaign rules and the employment structure underneath the person running them, generally spend far less time firefighting as the marketing function grows. The alternative is discovering the gap at the worst possible moment, after the relationship has already run for years and the exposure has grown along with it.
