Definition
Email permission is the authorisation a sender receives from a recipient to send commercial or promotional email messages. It is the foundation of legitimate email marketing and sits at the centre of anti-spam legislation worldwide, including CAN-SPAM in the United States, GDPR in Europe, and CASL in Canada. Permission transforms email from an intrusive channel into an anticipated one, improving engagement, deliverability, and long-term subscriber value.
Permission exists on a spectrum rather than as a binary condition. Explicit permission, also known as express opt-in, occurs when a subscriber actively and unambiguously agrees to receive marketing emails, typically by ticking a checkbox or submitting a signup form. Implied permission arises from an existing customer relationship, such as a purchase or a service agreement, where the recipient has a reasonable expectation of receiving commercial communication. Transactional permission is a subset of implied permission that applies to messages required to complete a transaction, such as order confirmations or password resets, and does not extend to marketing content.
Best Practices
Implement confirmed opt-in (double opt-in) as the default permission mechanism. Requiring new subscribers to confirm their email address via a verification message eliminates invalid addresses, prevents accidental signups, and provides clear evidence of consent for regulatory compliance. The marginal drop in signup volume is offset by significantly higher list quality.
Document the type of permission you hold for each subscriber, including the date, source, and explicit consent language used at the point of collection. Maintain this record as part of your subscriber database so you can demonstrate compliance during audits or regulatory inquiries.
Establish a permission renewal cycle for dormant subscribers. Review your list every six to twelve months and send a re-confirmation request to subscribers who have not engaged within that period. Remove or suppress those who do not re-confirm to keep your list clean and protect sender reputation.
Understand the distinction between permission and consent under GDPR. Consent must be freely given, specific, informed, and unambiguous, while permission is a broader marketing concept. GDPR consent cannot be inferred from silence or pre-ticked boxes and must be as easy to withdraw as it was to give.
Related Glossary Terms
Email B2B Consent
The legal requirements for B2B email marketing consent, covering GDPR legitimate interest, CASL implied consent, CAN-SPAM exemptions, and jurisdiction-specific best practices.
Email Compliance Automation
Email compliance automation uses automated processes to manage unsubscribe processing, consent record-keeping, data retention enforcement, and regulatory monitoring within required legal timeframes.
Email Consent Age
Age of consent for email marketing across GDPR (16), COPPA (13), CASL, and PIPEDA jurisdictions, with age verification and compliance practices.
Email Consent Framework
A structured framework for managing email marketing consent across jurisdictions, covering consent types, lifecycle stages, audit procedures, and technology implementation.
Email Consent Record
Email consent record-keeping captures proof of opt-in including timestamp, IP address, method, and exact wording shown. GDPR requires controllers to demonstrate consent upon request.
Email Consent Renewal
Consent renewal campaigns restore permission to email subscribers whose consent has expired under GDPR regulations, typically achieving 10-30% renewal rates.
Frequently Asked Questions
Single opt-in adds a subscriber to your list immediately after they submit a form, whereas double opt-in requires the subscriber to confirm their email address by clicking a link in a verification message. Double opt-in provides stronger evidence of consent and higher list quality.
In many jurisdictions, you may send marketing emails to existing customers based on implied permission, provided you offer a clear unsubscribe option and the products or services are similar to those the customer previously purchased. This varies by country; GDPR requires explicit consent.
Permission marketing, a concept popularised by Seth Godin, refers to marketing communications that are anticipated, personal, and relevant because the recipient has given explicit permission to receive them. It contrasts with interruption marketing, which forces messages on unwilling audiences.
Permission does not have a fixed legal expiry date, but best practice recommends renewing permission every twelve to eighteen months if the subscriber has not engaged with your emails. A subscriber who has not opened an email in over a year may no longer remember giving permission.
Purchased email lists almost never include valid permission. The individuals on those lists have not consented to receive emails from you, and sending to them violates anti-spam laws, damages sender reputation, and results in extremely low engagement.