GDPR and email consent: what the rules actually say
What the GDPR and the ePrivacy rules require before you may send marketing email to people in the EU — consent, the soft opt-in, and the records you must keep. A map, not legal advice.
Compliance · 6 min read · updated
Read this first
This page describes what the rules say, in plain language, so you can have an informed conversation about your own situation. It is not legal advice, the rules are implemented differently in each country, and decisions about your specific list belong with a qualified professional. What it will do is stop you being surprised by the shape of the law.
One orienting fact: the rules follow the recipient, not the sender. A company with no European presence that emails people in the EU is, in general, inside the scope of these rules. "We are not based there" is not the exemption most people assume it is.
Two laws, not one
Email marketing in Europe sits under two overlapping regimes, and most confusion comes from conflating them.
- The GDPR. Governs processing personal data — and an email address that identifies a person is personal data. It demands a lawful basis for holding and using the address, grants the person rights over it, and defines what valid consent means. The UK's version mirrors it closely.
- The ePrivacy rules. A separate directive, implemented country by country, that specifically covers electronic marketing messages. This is where the actual "may I send this email?" rule lives — and for individuals, its general answer is: only with consent, or under the customer exception below.
What consent means — the strict version
The GDPR's definition is deliberately demanding: consent must be freely given, specific, informed and unambiguous, expressed through an affirmative act. Each phrase kills a familiar practice:
- No pre-ticked boxes. Europe's top court has ruled a pre-ticked checkbox is not consent. Silence, inactivity and defaults do not count — the person has to do something.
- No bundling. "By creating an account you agree to receive our newsletter" fails the freely-given test. Marketing consent must be separate from the thing the person actually came for, and refusing it cannot cost them the service.
- Specific and informed. The person must be told who is sending, what kind of messages, at collection time. Consent gathered for one purpose does not stretch to another, and "partners" consent that never names the partners has been repeatedly rejected by regulators.
- As easy to withdraw as to give. Withdrawal must be possible at any time, without cost or interrogation. A working unsubscribe satisfies this; an unsubscribe that requires logging in does not.
The soft opt-in: the customer exception
The ePrivacy rules carve out one important exception. You may email marketing to an existing customer without fresh consent when all of these hold: you obtained the address in the course of a sale (in some countries, a genuine sale negotiation counts), you are marketing your own similar products or services, the person was given a clear chance to refuse at the moment of collection, and every message since offers the same chance.
Each clause is load-bearing. A newsletter signup is not a sale; someone else's products are not similar; and a refusal option that appeared only in the privacy policy was not a clear chance. Where the conditions genuinely hold, the soft opt-in is the lawful backbone of most customer marketing in Europe.
You must be able to prove it
The GDPR puts the burden of demonstrating consent on the sender. In practice that means keeping, per address: when consent was given, how, what the person was shown, and what they agreed to. A list without that record is a list whose consent exists only as your say-so.
This is why double opt-in, though not literally required by the text, is the de facto evidentiary standard — courts in some countries, Germany most prominently, have treated the confirmation click as what makes consent provable. And it is why a purchased list is unusable almost by definition: whatever consent was collected, it was neither specific to you nor provable by you.
The rights that touch your list
- Objection to direct marketing is absolute. When someone objects to marketing, you stop. There is no balancing test and no legitimate-interest override — this is the one right in the regulation with no exceptions.
- Erasure — with a suppression twist. People can ask to be deleted. But deleting an objector outright destroys your memory of the objection, and a later import could resurrect them. The accepted practice is a minimal suppression record kept precisely to honour the objection — remembering just enough to keep forgetting them.
- Access. People can ask what you hold on them — which, for a marketing list, includes the consent record and any profiling or segment data attached to them.
Traps senders actually fall into
- The re-permission email. Emailing a list of unproven consent to ask "may we keep emailing you?" is itself a marketing email sent without consent — companies have been fined for exactly this. If consent for an old list cannot be established, the lawful options narrow sharply; asking nicely by email is not one of them.
- Assuming B2B is exempt. The GDPR does not care that an address is professional — a named person at a company is still a person. The ePrivacy rules DO differ by country for corporate recipients (some allow opt-out-based B2B marketing), which makes B2B the area where per-country rules matter most and generalisations fail fastest.
- Consent that expires in practice. The regulation sets no fixed lifespan on consent, but regulators expect it to stay fresh — consent from 2016 for a list you never mailed since is hard to defend. Regular sending, honest records and sunsetting the long-silent keep the question from arising.
- Forgetting the fine print is now large. Headline GDPR penalties reach into the tens of millions of euros or a percentage of global turnover. Email-marketing enforcement in practice has mostly produced smaller, but entirely real, fines — issued for purchased lists, pre-ticked boxes and re-permission campaigns.
What good practice looks like, mechanically
Strip the law back and the operational shape is familiar — it is simply list hygiene with receipts: an unticked, unbundled marketing checkbox that says who and what; a confirmation click creating a timestamped record; the soft opt-in used only where its four conditions genuinely hold; one-click unsubscribe honoured immediately; objections kept as suppressions, not deletions; and no address on the list whose story you could not tell to a regulator.
Senders who follow the deliverability practices in the rest of these guides are, mostly, already compliant in substance. The remaining work is keeping the evidence.
Common questions
Does GDPR require double opt-in?
The text does not use the phrase. It requires that consent be demonstrable, and the confirmation click is the cleanest demonstration there is — which is why regulators and courts in some countries treat it as the expected standard, and why this guide's practical answer is: behave as if it were required.
I'm outside the EU. Does any of this apply to me?
If you deliberately market to people in the EU, in general yes — the scope follows the recipients. If EU addresses merely trickle onto a list that never targets Europe, the analysis is more nuanced, and is exactly the kind of question to put to a professional.
Can I email a purchased list if the broker says it's opted in?
The consent burden is yours, not the broker's, and consent that never specifically named you rarely survives scrutiny. Regulators have fined buyers, not just sellers. The deliverability answer and the legal answer agree completely here: no.
Do I need consent to send receipts and password resets?
Transactional mail is not marketing, and does not run on consent — it runs on the contract or service relationship itself. The boundary is content: add promotion to a receipt and you have sent a marketing email, with everything that implies.
Check your addresses now
The free InkPigeon checker runs syntax, DNS, disposable, typo and role-account analysis on any address — instantly, no signup.