Definition
Age of consent for email marketing refers to the minimum age at which an individual can give valid legal consent to receive marketing communications. The age varies by jurisdiction: under the General Data Protection Regulation (GDPR) the default age is 16, though member states may lower it to 13; the Children's Online Privacy Protection Act (COPPA) in the United States sets the age at 13; Canada's Anti-Spam Legislation (CASL) does not specify a single age, but the Personal Information Protection and Electronic Documents Act (PIPEDA) considers minors under 13 as incapable of providing meaningful consent, with 13–18 depending on provincial laws. These regulations apply to the collection of personal data, including email addresses, for marketing purposes.
The implications for email senders are significant. Collecting an email address from someone below the age of consent without verifiable parental consent is a violation of data protection law, carrying potential fines of up to 4% of global annual turnover under GDPR or US$43,280 per violation under COPPA. The risk is not hypothetical; children routinely falsify their age online, and email signup forms that do not implement age gating can easily collect addresses from underage users without the sender's knowledge.
Age verification methods in email signup forms range from simple self-declaration (a date-of-birth field or age checkbox) to more robust methods such as credit card verification or third-party identity services. Self-declaration is the most common approach and, while not foolproof, demonstrates due diligence when documented properly. The legal standard is not perfect verification but reasonable steps considering the risk level. For organisations that market products likely to appeal to children (toys, games, educational services), stronger verification measures are expected.
Best Practices
Implement age gating on all email signup forms with a date-of-birth or age confirmation field. Design the field so that users cannot easily bypass it (disable default pre-fill for the year field).
Set the age gate to 16 for European audiences and 13 for US audiences by default. If you cannot determine the user's location, use the highest applicable age threshold (16).
Collect and store the age verification response alongside the consent record. In a compliance audit, having a record that the user declared themselves as over the threshold age is evidence of due diligence.
Do not send marketing emails to addresses collected without age verification if there is any indication the subscriber may be underage. When in doubt, suppress and require parental consent.
Provide a clear mechanism for parents to request deletion of their child's data under COPPA and GDPR. Publish a privacy notice that explains how parents can exercise this right.
Review the consent age in each jurisdiction where you collect email addresses. GDPR allows member state variation from 13 to 16, and you must comply with the age of the subscriber's country of residence.
Related Glossary Terms
Email Compliance Automation
Email compliance automation uses automated processes to manage unsubscribe processing, consent record-keeping, data retention enforcement, and regulatory monitoring within required legal timeframes.
Email Consent Record
Email consent record-keeping captures proof of opt-in including timestamp, IP address, method, and exact wording shown. GDPR requires controllers to demonstrate consent upon request.
Email Consent Renewal
Consent renewal campaigns restore permission to email subscribers whose consent has expired under GDPR regulations, typically achieving 10-30% renewal rates.
Email Data Portability
Data portability under GDPR Article 20 gives subscribers the right to receive their email marketing data in a machine-readable format and transfer it to another provider. Common export formats are CSV and JSON.
Email Data Retention
Email data retention policies govern how long subscriber data, activity logs, consent records, and campaign data are kept. GDPR requires data not be kept longer than necessary for the processing purpose.
Email Forwarding Consent
Forward-to-a-friend email mechanisms create consent implications around subscriber data processing, privacy expectations, and regulatory liability under GDPR and CAN-SPAM.
Frequently Asked Questions
You must delete the personal data promptly upon discovery and cease all marketing communications. Under COPPA, you must also notify the parent and obtain verifiable parental consent before continuing to process the data. Document the deletion as part of your compliance records.
Self-declaration is generally considered sufficient due diligence for most email marketing contexts, provided the form makes clear that the user must be above the applicable age of consent. However, regulators expect stronger measures for services directed at children, such as interactive games or educational platforms.
COPPA applies to operators of websites and online services directed at children in the United States, regardless of where the operator is based. If your email programme targets US children or collects data from US residents, you must comply with COPPA even if you are based outside the US.
CASL does not prescribe specific age verification methods. The requirement is that consent must be obtained from the individual, and individuals under the age of majority in their province (18 or 19 depending on the province) may not have the legal capacity to give consent. A parent or guardian must provide consent for minors.
Yes, but you must ensure that any underage subscribers provide consent through a parent or guardian. In practice, this means age-gating the signup process and requiring parental consent for users who indicate they are below the age threshold. The age gate should apply to the signup itself, not just the marketing content targeting.