Skip to content

Home Topics Email Compliance Consent and opt-in

Email Compliance · Consent and opt-in

Email consent management examples: what good and bad look like

Short answer

A good email consent management implementation follows these steps: Use an unchecked checkbox or a dedicated signup form; never pre-tick; Record timestamp, IP, source, and the exact wording shown at consent. A bad one typically bundling marketing consent into terms of service acceptance.

Consent is the documented permission a recipient gives to receive marketing email. Laws differ on whether it must be express (opt-in) or may be implied (existing relationship), and on how long it lasts.

What good looks like#

  • Done: Use an unchecked checkbox or a dedicated signup form; never pre-tick.
  • Done: Record timestamp, IP, source, and the exact wording shown at consent.
  • Done: Use double opt-in for marketing lists where feasible.
  • Done: Separate consent for different purposes (newsletter vs partner offers).
  • Done: Refresh consent for contacts older than two years with no engagement.

What bad looks like#

  • Seen in audits: Bundling marketing consent into terms of service acceptance.
  • Seen in audits: Losing consent records during a CRM migration.

How to move from bad to good#

Work through the good list in order and re-verify after each change. Most teams find one or two items from the bad list already present; fixing those usually produces the largest improvement.

Frequently asked questions#

Is double opt-in required by law?

Not explicitly in most jurisdictions, but it is the easiest way to prove consent under GDPR and CASL and it improves list quality.

Keep reading on Consent and opt-in