Under the GDPR, consent to receive marketing email must be freely given, specific, informed and unambiguous, and given by a clear affirmative action. In practice that means a person actively ticked a box or filled in a form that said what they were signing up for, and you can show when and how they did it. A pre-ticked box is not consent. Silence is not consent. Burying it in your terms of service is not consent.
That is the whole rule. Everything else is detail about how to satisfy it without making your signup form miserable.
The four words that decide everything
Freely given means consent cannot be a condition of getting something unrelated. Requiring a newsletter subscription in order to download a whitepaper is the classic failure — the paper and the newsletter are separate things, so bundling them makes the consent conditional. Offering the paper and also offering the newsletter, as a separate unticked box, is fine. This is the rule that catches most gated content strategies.
Specific means consent covers a defined purpose. "Marketing communications" is arguably specific enough; "we may contact you" is not. If you intend to send both a weekly newsletter and occasional partner offers, those are two purposes and need two boxes.
Informed means the person knew who they were giving consent to and what they would receive. Your organisation's name has to appear. If you share the list with a group company, name it.
Unambiguous is where pre-ticked boxes die. The affirmative action has to be positive and deliberate. Continuing to browse the site is not an action. Ticking a box, clicking a clearly labelled button, or replying to a confirmation email all are.
What you have to be able to prove
Article 7 puts the burden on you: you must be able to demonstrate that the person consented. In practice, a defensible consent record has four fields.
| Field | What to store |
|---|---|
| Who | The email address, and any identifier you hold |
| When | Timestamp of the opt-in, in UTC |
| How | Source — form URL, offline event, import, API |
| What | The exact consent wording shown at the time |
That last row is the one people skip and the one that matters most, because your form copy changes over time and a regulator asking about a 2024 signup wants the 2024 wording. Store a version reference, not a live link. We go deeper on the mechanics in how to keep email consent records.
Double opt-in is not required by the GDPR. It is, however, the cheapest way to produce evidence that consent was real, because the confirmation click is logged, timestamped and hard to argue with. It also removes typo addresses and spam traps before they ever reach your list, which is why it helps deliverability independently of compliance. The trade-off is a smaller list, and we lay both sides out in double opt-in vs single opt-in.
When legitimate interest actually applies
This is the most-abused phrase in email marketing. Legitimate interest is a real lawful basis under the GDPR, and direct marketing is explicitly named in the recitals as a possible legitimate interest. But two things narrow it sharply.
First, the ePrivacy Directive — not the GDPR — governs unsolicited electronic marketing in the EU, and it requires prior consent with one exception: the "soft opt-in", where you may email existing customers about your own similar products, provided they were given a chance to refuse at the point of sale and in every message since. That is a customer-only exception. It does not cover people who downloaded a PDF.
Second, legitimate interest requires a balancing test that you document. If you cannot write down why your commercial interest outweighs the recipient's expectation of not being emailed, you do not have it.
For B2B in some member states the position is looser, but "we found their address on their company website" has never been a lawful basis on its own. If your growth plan involves purchased lists, the GDPR is the least of the reasons it will not work.
What every marketing email must carry
- The identity of the sender, unambiguously.
- A working, no-login-required unsubscribe link.
- A List-Unsubscribe header with one-click support — required by Google and Yahoo for bulk senders regardless of jurisdiction, and good practice everywhere.
- Nothing that makes withdrawal harder than giving consent was. If signing up took one click, unsubscribing must take one click.
Withdrawal has to be honoured promptly. The GDPR does not put a number on it; treat it as immediate, because the Google and Yahoo requirements put a two-day ceiling on unsubscribe processing and that is the standard mailbox providers now hold you to.
The pragmatic version
If you do these five things you are in good shape and your list will be healthier for it:
- Unticked, separate consent boxes with your organisation named in the wording.
- Double opt-in for anything that came from a form.
- Consent records with timestamp, source and the wording version.
- One-click unsubscribe in the body and in the header.
- A quarterly purge of anyone who has not engaged in twelve months — which also fixes list churn and your sender reputation.
This is general information rather than legal advice; if you process significant volumes of EU personal data, have a data protection specialist review your specific setup. Our EU-specific guidance covers data residency and processing agreements.
Frequently asked questions
Is double opt-in required by GDPR?
No. The GDPR requires that consent be demonstrable, not that it be confirmed twice. Double opt-in is the easiest way to demonstrate it, which is why most compliance guidance recommends it, but a single opt-in with a proper audit record is also lawful.
Can I email people who gave me a business card?
Only if the exchange made it clear you would send marketing email, and you can show that. A card handed over at a trade show where your stand said "sign up for our newsletter" is arguably consent. A card collected in a fishbowl draw is not, because the stated purpose was the draw.
How long does GDPR consent last?
The regulation sets no expiry. Regulators generally expect you to refresh consent when it goes stale, and a common working standard is two years of no engagement. Practically, someone who has not opened anything in two years is costing you deliverability anyway, so the compliance answer and the commercial answer agree.
Does GDPR apply if my business is not in the EU?
It applies based on whose data you process, not where you are. If you market to people in the EU, you are in scope. The same logic applies to the UK GDPR for UK residents.

