Definition
GDPR consent is the legal basis most email marketers rely on to process personal data under the General Data Protection Regulation (GDPR), which applies to anyone marketing to EU residents. For consent to be valid under GDPR, it must be freely given, specific, informed, unambiguous, and revocable.
GDPR raised the standard for email marketing consent significantly. Pre-checked boxes, implied consent from purchasing a product, and consent bundled with terms and conditions do not meet GDPR requirements. Active, affirmative opt-in is required.
Requirements for Valid GDPR Consent
| Requirement | Description | Email Marketing Application |
|---|---|---|
| Freely Given | No pressure, no bundled consent | Separate checkbox for marketing, not tied to purchase |
| Specific | Separate consent for different purposes | Distinct options for newsletter, offers, third-party |
| Informed | Clear what subscriber is agreeing to | Explain what emails they will receive and how often |
| Unambiguous | Clear affirmative action required | Active checkbox tick, not pre-checked |
| Withdrawable | Easy to unsubscribe or change preferences | One-click unsubscribe, preference centre |
| Documented | Proof of consent must be stored | Record consent timestamp, IP, and exact wording |
Consent vs Legitimate Interest
GDPR provides two main bases for email marketing:
- Consent: The subscriber actively agreed. Required for most B2C marketing emails and any sensitive data processing.
- Legitimate Interest: Processing is necessary for a legitimate business purpose. May apply to existing customer communications about related products or services.
Legitimate interest cannot be assumed and must be balanced against the subscriber's privacy rights. It is a narrower basis than many marketers assume.
How to Collect GDPR-Compliant Consent
- Use active opt-in: Empty checkbox that the subscriber ticks to agree
- Provide granular choices: Separate checkboxes for different email types
- Link to privacy policy: Include a link to your privacy policy at the point of consent
- Record consent details: Store the exact consent text, timestamp, IP address, and method
- Send confirmation email: Send a welcome email confirming what the subscriber signed up for
- Make withdrawal easy: Unsubscribe link in every email, preference centre accessible at any time
Consequences of Non-Compliance
GDPR fines for non-compliance can reach 4% of global annual turnover or €20 million, whichever is greater. Beyond fines, regulators can issue bans on data processing, forcing you to stop email marketing to affected subscribers entirely.
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
AIDA Model for Email
The AIDA model (Attention, Interest, Desire, Action) is a classic copywriting framework used to structure email campaigns that guide subscribers from awareness to conversion.
AMP for Email
AMP for Email is a Google-developed framework that allows email messages to include interactive elements like forms, carousels, accordions, and live content. It turns static emails into dynamic, interactive experiences directly inside the inbox.
Anchoring Effect in Email Marketing
The anchoring effect is a cognitive bias where the first piece of information presented (the anchor) influences subsequent decisions, used in email to frame pricing and value perception.
Announcement Email
An announcement email is a dedicated campaign that communicates a specific update, milestone, or change to subscribers, from product launches and feature releases to company news and events.
Frequently Asked Questions
GDPR applies if you market to any EU residents, regardless of where your business is based. If EU subscribers are on your email list, you must comply with GDPR requirements for those subscribers.
Soft opt-in (sending marketing to existing customers without explicit consent) is available under UK GDPR and PECR but only for your own similar products or services, and only if the subscriber had a clear opportunity to opt out at data collection and in every subsequent message.
GDPR does not specify a fixed period for consent renewal. However, consent may degrade over time, and the ICO recommends refreshing consent every two years or when you change how you use data. Demonstrably engaged subscribers may not need re-consent, but inactive subscribers' consent should be refreshed before re-engagement.