Definition
Permission and consent are two related but distinct concepts describing how a sender is authorised to email someone. Consent is a specific, high-standard basis: it must be freely given, informed, specific and unambiguous, typically captured through an explicit opt-in. Permission is a broader term that can include softer grounds, such as soft opt-in or a legitimate-interest judgement.
While "permission" and "consent" are sometimes used interchangeably, regulators treat them differently. Fulfilling clear consent is the strongest and safest basis for UK and EU marketing email under PECR and the GDPR.
Consent vs Permission Compared
| Factor | Consent | Permission |
|---|---|---|
| Standard | High and strict | Broader, can be softer |
| Basis | Explicit opt-in | May include inferred grounds |
| Documentation | Rigorous records expected | Varies |
| Regulatory recognition | The clear safe standard | Depends on the specific basis |
A sender may claim "permission" through several routes, but only genuine consent satisfies the strictest rules.
The Routes to "Permission"
- Explicit opt-in: The subscriber actively consents through a clearly worded action.
- Soft opt-in: An existing customer with relevant contact can receive messages about similar products, without a separate opt-in.
- Legitimate interest: A balanced judgement that emailing is justified, mainly used for functional or business-to-business messages.
- Contract necessity: Email required to provide a requested service.
How to Choose Between Consent and Other Permission
- Prefer consent for marketing: For marketing email to consumers, clear opt-in consent is the safest route.
- Document the basis: Record whether consent or another ground justifies each mailing list.
- Respect opt-outs: Withdrawal of consent overrides any softer permission ground.
- Review marketing lists: Re-capture consent where the original basis is weak or outdated.
Related Glossary Terms
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Cold Email
A cold email is an unsolicited message sent to a recipient who has not previously opted in, commonly used for B2B outreach, sales prospecting and networking.
Consent Banner
A consent banner is an on-site notice that informs visitors about data collection and allows them to agree to or manage email marketing preferences.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Frequently Asked Questions
Consent is a strict, high-standard basis requiring an informed, specific, unambiguous opt-in. Permission is a broader term covering softer grounds like soft opt-in or legitimate interest. Consent is the safest basis for UK and EU marketing email.
No. Consent is a specific, high-standard form of permission. You can have some form of permission through softer grounds, but only genuine, explicit, documented consent satisfies the strictest email marketing compliance requirements.
Under rules like the UK PECR, a soft opt-in can apply to existing customers who have not opted out, for similar products you sold them. Business-to-business and functional email may also rest on legitimate interest. These are weaker than consent and must be weighed case by case.
For marketing email to consumers, explicit consent is the safest and cleanest basis. It provides strong, documented justification and greatly reduces compliance risk compared with relying on softer permission grounds.