Definition
GDPR consent is the legal basis most email marketers rely on to process personal data under the General Data Protection Regulation (GDPR), which applies to anyone marketing to EU residents. For consent to be valid under GDPR, it must be freely given, specific, informed, unambiguous, and revocable.
GDPR raised the standard for email marketing consent significantly. Pre-checked boxes, implied consent from purchasing a product, and consent bundled with terms and conditions do not meet GDPR requirements. Active, affirmative opt-in is required.
Requirements for Valid GDPR Consent
| Requirement | Description | Email Marketing Application |
|---|---|---|
| Freely Given | No pressure, no bundled consent | Separate checkbox for marketing, not tied to purchase |
| Specific | Separate consent for different purposes | Distinct options for newsletter, offers, third-party |
| Informed | Clear what subscriber is agreeing to | Explain what emails they will receive and how often |
| Unambiguous | Clear affirmative action required | Active checkbox tick, not pre-checked |
| Withdrawable | Easy to unsubscribe or change preferences | One-click unsubscribe, preference centre |
| Documented | Proof of consent must be stored | Record consent timestamp, IP, and exact wording |
Consent vs Legitimate Interest
GDPR provides two main bases for email marketing:
- Consent: The subscriber actively agreed. Required for most B2C marketing emails and any sensitive data processing.
- Legitimate Interest: Processing is necessary for a legitimate business purpose. May apply to existing customer communications about related products or services.
Legitimate interest cannot be assumed and must be balanced against the subscriber's privacy rights. It is a narrower basis than many marketers assume.
How to Collect GDPR-Compliant Consent
- Use active opt-in: Empty checkbox that the subscriber ticks to agree
- Provide granular choices: Separate checkboxes for different email types
- Link to privacy policy: Include a link to your privacy policy at the point of consent
- Record consent details: Store the exact consent text, timestamp, IP address, and method
- Send confirmation email: Send a welcome email confirming what the subscriber signed up for
- Make withdrawal easy: Unsubscribe link in every email, preference centre accessible at any time
Consequences of Non-Compliance
GDPR fines for non-compliance can reach 4% of global annual turnover or €20 million, whichever is greater. Beyond fines, regulators can issue bans on data processing, forcing you to stop email marketing to affected subscribers entirely.
Was this useful?
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
AI Email Summary
An AI email summary is a short, machine-generated overview of an email's key points, shown by Gmail, Outlook and Apple Mail before a recipient opens the message. It is reshaping how email marketers think about subject lines, preview text and open rates.
AI Inbox Summary
An AI inbox summary is an AI-generated digest that condenses unread email — often highlighting news, actions and senders — changing how clearly your marketing email reaches and engages subscribers.
AI Inbox
An AI inbox is an email client that uses artificial intelligence to summarise, sort, prioritise and sometimes answer emails before the human recipient reads them. It is transforming email marketing metrics and copywriting.
Frequently Asked Questions
GDPR applies if you market to any EU residents, regardless of where your business is based. If EU subscribers are on your email list, you must comply with GDPR requirements for those subscribers.
Soft opt-in (sending marketing to existing customers without explicit consent) is available under UK GDPR and PECR but only for your own similar products or services, and only if the subscriber had a clear opportunity to opt out at data collection and in every subsequent message.
GDPR does not specify a fixed period for consent renewal. However, consent may degrade over time, and the ICO recommends refreshing consent every two years or when you change how you use data. Demonstrably engaged subscribers may not need re-consent, but inactive subscribers' consent should be refreshed before re-engagement.