Definition
Consent renewal, also known as re-permission marketing, is the process of asking existing email subscribers to reconfirm their consent to receive marketing communications. Under GDPR and other data protection regulations, consent can expire or become invalid if the original collection context no longer applies, if the subscriber has not engaged for an extended period, or if the purpose of processing has changed. Consent renewal campaigns serve both a legal requirement and a list hygiene function, removing contacts who no longer wish to receive emails while retaining those who actively reconfirm their interest.
The timing and design of consent renewal campaigns significantly affect their success. GDPR does not specify a fixed consent expiry period, but regulatory guidance from European data protection authorities suggests that consent should be refreshed every one to two years for inactive subscribers. Re-permission campaigns typically achieve renewal rates of 10-30% of the target segment, with higher rates for recently inactive subscribers and those who originally provided active opt-in consent. The campaign format varies from simple single-click confirmation links to multi-step re-engagement sequences that offer incentives for reconfirmation. Failed renewal attempts should result in subscriber removal from the active marketing list, with records retained to document the consent renewal attempt for compliance purposes.
Best Practices
-
Segment consent renewal targets by inactivity duration. Send renewal requests to subscribers with no engagement in 12-18 months for quarterly or higher-frequency programmes. For lower-frequency programmes, extend to 18-24 months. Prioritise segments based on their original consent quality (explicit opt-in vs soft opt-in vs inferred consent) and the business value of the potential loss.
-
Design a multi-touch renewal sequence rather than a single email. Send an initial notice explaining why consent renewal is required, a follow-up reminder after 7 days, and a final notice after 14 days. Include clear language about what will happen if consent is not renewed (suspension of marketing emails). Use the brand tone appropriate for the relationship but remain transparent about the legal basis.
-
Offer a clear value proposition for renewing consent. Explain what subscribers will continue to receive, how often, and what benefits they gain. Consider offering a small incentive for renewal — a discount code, exclusive content access, or entry into a prize draw — while ensuring the incentive does not coerce consent under GDPR guidelines. The renewal mechanism must be as simple as a single click.
-
Document every consent renewal attempt comprehensively for compliance records. Store the date of renewal request, method of request (email, preference centre, in-app), the exact wording used, the subscriber's response (or lack thereof), and the date of list removal for non-renewals. Retain these records for the duration of the data processing relationship plus any applicable statutory periods.
-
Plan for the revenue impact of consent renewal campaigns. A 10-30% renewal rate means losing 70-90% of the targeted segment. Prepare mitigating strategies including reactivation campaigns for non-renewing subscribers via other channels, budget reallocation from lost subscribers to acquisition, and stakeholder communication about the expected short-term revenue dip and long-term list health benefits.
Related Glossary Terms
Bounce Management
Bounce management is the process of handling emails that are rejected by mailbox providers, including classification, removal of bad addresses and protection of sender reputation.
Email Account Health Score
A composite metric that evaluates the overall health of an email sending programme based on deliverability, engagement, list quality, and compliance factors.
Email Anti-Spam Laws
Overview of global anti-spam regulations including CAN-SPAM, CASL, GDPR, the Australian Spam Act, and POPIA with compliance requirements for each jurisdiction.
Australia Spam Act
Australia's Spam Act 2003 regulates commercial electronic messages including email. It requires consent, functional unsubscribe mechanisms within 5 working days, and sender identification. Penalties reach AUD $2.22 million per day.
Email B2B Consent
The legal requirements for B2B email marketing consent, covering GDPR legitimate interest, CASL implied consent, CAN-SPAM exemptions, and jurisdiction-specific best practices.
Blocked Contacts
Blocked contacts are email addresses that have been prevented from receiving future communications due to hard bounces, spam complaints, or explicit opt-out requests, maintained in a suppression list for compliance and list hygiene.
Frequently Asked Questions
GDPR does not specify a fixed consent expiry period. Consent validity depends on the original collection context, subscriber expectations, and ongoing engagement. Most data protection authorities suggest reviewing consent after 12-24 months of inactivity, or sooner if the data processing purpose changes materially.
Re-permission campaigns typically achieve 10-30% renewal rates from the targeted segment. Renewal rates vary significantly based on inactivity duration (shorter inactivity yields higher renewal), original consent quality, brand relationship strength, and the incentive offered. Rates below 10% suggest the segment is largely unrecoverable.
A three-email sequence is standard: an initial notice, a 7-day follow-up reminder, and a 14-day final notice. Additional sends beyond three rarely improve renewal rates significantly and may increase complaint rates. Each email should clearly communicate the consequence of non-renewal.
Consent cannot be purchased. Each data controller must obtain consent directly from the data subject. Third-party vendors can provide technology platforms for managing the renewal process but cannot supply consent itself. Purchasing lists with pre-obtained consent raises significant compliance risks under GDPR and CASL.
Subscribers who do not renew consent should be removed from active marketing lists but their details and consent renewal records should be retained for compliance purposes. Future marketing emails must not be sent unless new consent is obtained through a fresh opt-in. Consider whether the data should be fully deleted or retained in a suppression list.