Skip to content

GDPR and email marketing: a plain-language guide to consent

Who can you email, what counts as permission, and what every marketing email needs under EU rules. A practical guide for small businesses, without the legalese.

Published 18 June 20266 min readBy Smart Marketing

The short version

  • In the EU, marketing email generally needs clear, recorded permission from each person.
  • Pre-ticked boxes and “by signing up you agree” small print don't count as consent, and bought lists almost never include valid consent for you.
  • Confirming a sign-up by email proves the address is real and that its owner asked to hear from you.
  • Every email needs a visible, easy way to unsubscribe, and you must stop once someone uses it.
  • Good consent isn't only about staying legal. It gives you a list that actually wants your mail.

If you run a business in the EU, you've probably heard that the GDPR makes email marketing complicated. It doesn't have to be. The permission rule itself comes from EU rules on electronic marketing, and the GDPR defines what counts as valid permission. Together, they come down to one idea that also happens to be good marketing: only email people who asked to hear from you, and make it easy for them to stop.

This guide walks through what that means in practice. It's written for business owners, not lawyers, so it's a practical overview rather than legal advice.

It's tempting to treat consent as paperwork. But permission is also the single biggest factor in whether your emails get read.

People who chose to join your list open, click and buy. People who never asked mark you as spam, and every complaint tells mailbox providers your mail isn't wanted. That pushes your future campaigns out of the inbox, for everyone on your list. We covered this in more depth in why emails end up in spam.

So even if the rules didn't exist, a permission-based list would still be the right way to build one.

What counts as real permission

Under EU rules, consent for marketing email has to be:

  • Freely given. Nobody should have to agree to marketing email to buy something or use your service.
  • Specific. They agreed to receive marketing emails from you, not a vague "we may contact you."
  • Informed. It's clear who they're signing up with, what they'll receive, and that they can unsubscribe at any time.
  • A clear action. They ticked an empty box or filled in a form that is clearly a newsletter sign-up. Silence, a pre-ticked box, or an address typed in at checkout isn't consent.

What doesn't count:

  1. Pre-ticked boxes. If the box was already ticked, the person didn't choose anything.
  2. Bought or rented lists. Consent only counts if your business was named when people signed up, which is almost never the case with purchased lists.
  3. Small print. "By buying, you agree to receive our newsletter" hidden in the terms isn't a free choice.
  4. Scraped addresses. An address published on a website isn't an invitation to market to it.

If you'd feel awkward explaining to a customer how their address got on your list, it probably shouldn't be there.

The existing customer exception

EU rules allow a limited exception, sometimes called "soft opt-in," for people who already bought from you. You may email them about your own similar products or services without separate consent, as long as:

  • you got their address when they bought something from you,
  • you told them clearly, at that moment, that they could say no for free, and they didn't,
  • every email you send gives them an easy, free way to opt out, and
  • in Austria, they are not on the national opt-out list for marketing email (the ECG list).

The details vary a little by country, and the exception is narrow. It doesn't cover people who only asked a question, and it doesn't let you promote unrelated things. If you plan to rely on it, check how it works where you operate.

Confirm every sign-up

The strongest way to show that someone really asked to hear from you is to have them confirm. After they sign up, they get a short email with a link. Only once they click is their address added to your list.

This is often called double opt-in, and it does three useful things:

  1. It proves the person asked. You have a clear record of when and how they signed up.
  2. It keeps typos and fake addresses out. An address that can't click a link never joins your list.
  3. It protects your reputation. Mistyped or malicious sign-ups can include addresses that exist only to catch careless senders. Confirmation filters them out.

A small share of people never click, and your list grows a little more slowly. What you get in return is a clean list of people who genuinely want your email. We explain the whole process, and why we use it for every client, in double opt-in explained.

What every marketing email needs

Once someone is on your list, each email should include:

  • Who you are. Your business name and a way to contact you. In Austria and Germany, that includes your imprint details.
  • A visible unsubscribe link. Not hidden in tiny grey text, and not behind a login.
  • Easy unsubscribing. The law says leaving must be as easy as signing up. In practice that means one click: no forms, no login, no asking for a reason first. Big mailbox providers like Gmail and Yahoo now expect one-click unsubscribing from larger senders anyway.
  • Honest subject lines. The subject should reflect what's inside.

When someone unsubscribes, stop as soon as possible, ideally the same day. Large mailbox providers expect it within two days, and mailing someone after they asked you to stop is one of the fastest ways to earn complaints and trouble.

Keep a simple record

You don't need an elaborate system, but you should be able to answer, for any address on your list:

  • When did they sign up?
  • Where did they sign up (which form or page)?
  • What did they agree to receive?
  • Did they confirm, and when?
  • Have they unsubscribed?

If someone asks, or a regulator does, you can show exactly why they're on your list.

A short checklist

  • Sign-up forms use an empty checkbox or a clear sign-up button, never a pre-ticked box.
  • Every new address confirms before it's added.
  • Existing customers are only emailed without consent if you meet every condition of the exception, including giving them a chance to say no when you took their address.
  • No bought, rented or scraped addresses. Ever.
  • Every email has a visible, easy unsubscribe link, and requests are handled right away.
  • You can show when and how each person signed up.

How we handle it

Consent is built into how we work rather than bolted on. We set up sign-up confirmation, keep a record of how each subscriber joined, clean out addresses that shouldn't be there before we send, and handle unsubscribes and complaints for you after every campaign. We operate from Austria, so EU data handling is the default, not an extra.

If you're not sure whether your current list is in good shape, that's a good thing to look at on a free call.

Frequently asked questions

Do I need consent to send marketing emails to my customers?

In most cases, yes. EU rules generally require clear permission for marketing email. There is a narrow exception across the EU for existing customers: you may email them about similar products if they could say no when they gave you their address and can opt out in every email. The exact conditions differ a little from country to country, so check how it applies in yours.

Can I email people who gave me their business card?

Handing over a business card isn't clear permission to receive marketing email. A personal note that simply continues your conversation is usually fine, but sending offers or adding them to your newsletter needs their agreement first. In Austria and Germany this applies to business contacts too.

What is double opt-in?

It means that after someone signs up, they get an email asking them to confirm by clicking a link. Only confirmed addresses are added to your list. It proves the address is real and that its owner really asked to hear from you.

How long do I need to keep records of consent?

For as long as you email that person, and for a reasonable period afterwards in case questions come up. The record should show when and how they signed up and what they agreed to receive.

Is this legal advice?

No. This article is a practical overview for small businesses. For decisions about your specific situation, speak to a lawyer or your local data protection authority.

Let's get your emails into the inbox.

Book a free 30-minute call. We'll look at where your email stands today and exactly what we'd do to turn your list into revenue.

Free, no pressure, no obligation.