Definition
Consent renewal, also known as re-permission marketing, is the process of asking existing email subscribers to reconfirm their consent to receive marketing communications. Under GDPR and other data protection regulations, consent can expire or become invalid if the original collection context no longer applies, if the subscriber has not engaged for an extended period, or if the purpose of processing has changed. Consent renewal campaigns serve both a legal requirement and a list hygiene function, removing contacts who no longer wish to receive emails while retaining those who actively reconfirm their interest.
The timing and design of consent renewal campaigns significantly affect their success. GDPR does not specify a fixed consent expiry period, but regulatory guidance from European data protection authorities suggests that consent should be refreshed every one to two years for inactive subscribers. Re-permission campaigns typically achieve renewal rates of 10-30% of the target segment, with higher rates for recently inactive subscribers and those who originally provided active opt-in consent. The campaign format varies from simple single-click confirmation links to multi-step re-engagement sequences that offer incentives for reconfirmation. Failed renewal attempts should result in subscriber removal from the active marketing list, with records retained to document the consent renewal attempt for compliance purposes.
Best Practices
-
Segment consent renewal targets by inactivity duration. Send renewal requests to subscribers with no engagement in 12-18 months for quarterly or higher-frequency programmes. For lower-frequency programmes, extend to 18-24 months. Prioritise segments based on their original consent quality (explicit opt-in vs soft opt-in vs inferred consent) and the business value of the potential loss.
-
Design a multi-touch renewal sequence rather than a single email. Send an initial notice explaining why consent renewal is required, a follow-up reminder after 7 days, and a final notice after 14 days. Include clear language about what will happen if consent is not renewed (suspension of marketing emails). Use the brand tone appropriate for the relationship but remain transparent about the legal basis.
-
Offer a clear value proposition for renewing consent. Explain what subscribers will continue to receive, how often, and what benefits they gain. Consider offering a small incentive for renewal — a discount code, exclusive content access, or entry into a prize draw — while ensuring the incentive does not coerce consent under GDPR guidelines. The renewal mechanism must be as simple as a single click.
-
Document every consent renewal attempt comprehensively for compliance records. Store the date of renewal request, method of request (email, preference centre, in-app), the exact wording used, the subscriber's response (or lack thereof), and the date of list removal for non-renewals. Retain these records for the duration of the data processing relationship plus any applicable statutory periods.
-
Plan for the revenue impact of consent renewal campaigns. A 10-30% renewal rate means losing 70-90% of the targeted segment. Prepare mitigating strategies including reactivation campaigns for non-renewing subscribers via other channels, budget reallocation from lost subscribers to acquisition, and stakeholder communication about the expected short-term revenue dip and long-term list health benefits.
Related Glossary Terms
Australia Spam Act
Australia's Spam Act 2003 regulates commercial electronic messages including email. It requires consent, functional unsubscribe mechanisms within 5 working days, and sender identification. Penalties reach AUD $2.22 million per day.
Email B2B Consent
The legal requirements for B2B email marketing consent, covering GDPR legitimate interest, CASL implied consent, CAN-SPAM exemptions, and jurisdiction-specific best practices.
Email Bounce Handling Automation
Email bounce handling automation uses automated workflows to classify, score, and suppress bounced addresses, protecting sender reputation through progressive suppression rules and real-time monitoring.
Email CASL
Canada's Anti-Spam Legislation requirements for commercial electronic messages, including consent types, record-keeping, and penalties up to $10 million per violation.
Email CCPA
California Consumer Privacy Act requirements for email marketing, including consumer rights to access, delete, and opt out of data collection and sale.
Email Compliance Automation
Email compliance automation uses automated processes to manage unsubscribe processing, consent record-keeping, data retention enforcement, and regulatory monitoring within required legal timeframes.
Frequently Asked Questions
GDPR does not specify a fixed consent expiry period. Consent validity depends on the original collection context, subscriber expectations, and ongoing engagement. Most data protection authorities suggest reviewing consent after 12-24 months of inactivity, or sooner if the data processing purpose changes materially.
Re-permission campaigns typically achieve 10-30% renewal rates from the targeted segment. Renewal rates vary significantly based on inactivity duration (shorter inactivity yields higher renewal), original consent quality, brand relationship strength, and the incentive offered. Rates below 10% suggest the segment is largely unrecoverable.
A three-email sequence is standard: an initial notice, a 7-day follow-up reminder, and a 14-day final notice. Additional sends beyond three rarely improve renewal rates significantly and may increase complaint rates. Each email should clearly communicate the consequence of non-renewal.
Consent cannot be purchased. Each data controller must obtain consent directly from the data subject. Third-party vendors can provide technology platforms for managing the renewal process but cannot supply consent itself. Purchasing lists with pre-obtained consent raises significant compliance risks under GDPR and CASL.
Subscribers who do not renew consent should be removed from active marketing lists but their details and consent renewal records should be retained for compliance purposes. Future marketing emails must not be sent unless new consent is obtained through a fresh opt-in. Consider whether the data should be fully deleted or retained in a suppression list.