Definition
Email consent is the legally valid permission an organisation obtains from an individual before sending commercial or marketing email communications. Consent types vary by jurisdiction and regulatory framework. Explicit consent (also called opt-in or affirmative consent) requires the subscriber to take a positive action — checking a box, clicking a confirmation link, or submitting a sign-up form — to indicate they wish to receive emails. This is the standard under the GDPR for electronic direct marketing in most EU member states and under Canada's Anti-Spam Legislation (CASL). Implied consent (also called soft opt-in) arises from an existing business relationship — a customer who made a purchase can receive marketing about similar products without explicit opt-in, subject to providing an opt-out mechanism. This is recognised under the UK's Privacy and Electronic Communications Regulations (PECR) and the CAN-SPAM Act in the United States.
Consent rates vary significantly by collection method and audience. Industry benchmarks for explicit opt-in (when the subscriber fills out a form and clicks submit) range from 40-70% depending on the lead magnet quality, form design, and audience targeting. Homepage pop-up opt-in forms convert at 1-5% on average. Targeted lead magnets convert at 15-40%. Content upgrades on relevant blog posts achieve 20-60%. According to the DMA's 2024 Consumer Email Tracker, 78% of consumers say they are more likely to subscribe to a brand's emails if the sign-up process is clear about what they will receive and how often — underscoring the importance of transparency in the consent process.
Best Practices
-
Implement confirmed opt-in for all EU and UK subscriber acquisition: Confirmed opt-in (double opt-in) requires the subscriber to click a link in a confirmation email before being added to the marketing list. This creates an auditable consent record (timestamps for initial submission, confirmation email send, and confirmation click) that satisfies GDPR Article 7 requirements for demonstrable consent. While COI reduces sign-up completion by 20-35%, it produces subscribers with 50-70% higher long-term engagement.
-
Maintain a centralised consent repository with full audit trail: Store consent records separately from the active subscriber database — including the consent timestamp, consent type (explicit or implied), the exact wording of the consent statement the subscriber agreed to, the method of collection (form, API, in-person), and the URL or location of collection. GDPR Article 7 requires the ability to demonstrate that consent was obtained, and a centralised repository makes this demonstrable during a regulatory audit.
-
Implement consent withdrawal mechanisms that are as easy as consent grant: Under GDPR Article 7(3), withdrawing consent must be as easy as giving it. If a subscriber could opt-in through a single-click form, they should be able to opt-out through a single-click mechanism — not through a multi-step process requiring login and navigation. Preference centres that allow subscribers to adjust consent for different communication types (newsletter, promotional, transactional) respect subscriber autonomy and reduce full unsubscribes by 20-30%.
-
Document the legal basis for every email send and review annually: Each commercial email should have a documented legal basis — explicit consent, implied consent (soft opt-in), or legitimate interest (for B2B cold email under GDPR). Review these bases annually as regulatory interpretations evolve. A consent basis that was valid under 2023 guidance may require updating based on 2025 regulatory rulings.
-
Segment consent types and never send marketing to non-consented contacts: Maintain separate lists or tags for contacts with explicit consent, implied consent, legitimate interest basis, and no consent. Marketing campaigns should only send to explicit and implied-consent contacts. Transactional and operational emails can be sent based on the contractual necessity basis (GDPR Article 6(1)(b)) without marketing consent.
-
Respect consent age requirements by jurisdiction: Under GDPR, the minimum age for valid consent to data processing varies by member state — typically 13-16 years old with parental consent required below that threshold. Under COPPA in the United States, it is 13. Verify and enforce age gates on subscription forms if your audience includes minors, and never knowingly collect consent from underage subscribers.
Related Glossary Terms
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Double Opt-In
Double opt-in (also called confirmed opt-in) is an email signup process that requires a new subscriber to confirm their email address by clicking a verification link in a confirmation email before they are added to your mailing list.
Email Archive
The systematic storage and retention of sent email records for regulatory compliance, legal discovery, and business reference purposes.
Email Classification
The systematic categorisation of sent emails into transactional, marketing, operational, and relational types based on content, purpose, and regulatory implications.
Email Compliance Audit
A systematic review of an organisation's email practices against regulatory requirements, brand standards, and industry best practices to identify and remediate risks.
Email Governance
The policies, standards, approval workflows, and compliance controls that ensure email communications align with brand, legal, and regulatory requirements.
Frequently Asked Questions
Explicit consent requires the subscriber to take a positive action indicating they want to receive emails — ticking a box, clicking submit, confirming through a double opt-in link. Implied consent arises from an existing relationship — a customer who bought a product can receive marketing about similar products without explicit opt-in. Explicit consent is required under GDPR for most marketing. Implied consent is recognised under CAN-SPAM and PECR soft opt-in provisions.
GDPR does not specify a consent expiry period, but regulatory guidance recommends refreshing consent every 2-3 years or if there is a significant change in how the data will be used. Many organisations send a re-consent or re-permission campaign every 24-36 months to confirm subscriber intent. Re-consent campaigns typically achieve a 20-40% re-confirmation rate, meaning 60-80% of the list is suppressed.
Under UK PECR soft opt-in provisions and US CAN-SPAM, yes — if the customer provided their email address in the course of a sale or negotiation for a sale, and the marketing is for similar products or services. However, you must offer a clear opt-out at the point of collection and in every subsequent email. Under GDPR in most EU member states, soft opt-in is not recognised and explicit consent is required for electronic direct marketing.
Consent rate is the percentage of people who complete an opt-in action divided by the total number of people who were presented with the opt-in opportunity. For a landing page, it is form submissions divided by unique page visitors. For a pop-up, it is submissions divided by pop-up impressions. Industry benchmarks range from 1-5% for generic homepage pop-ups to 20-60% for targeted content upgrades on relevant content.
For GDPR-regulated sends, yes — you must be able to demonstrate that consent was obtained for each recipient. This means maintaining timestamps, consent records, and audit trails. For CAN-SPAM regulated sends, no affirmative consent is required, but you must provide a clear opt-out in every email and honour opt-out requests promptly. The burden of proof differs significantly by jurisdiction.