Skip to content

Home Topics Email Compliance Consent and opt-in

Email Compliance · Consent and opt-in

Email consent management and UK GDPR and PECR compliance in the United Kingdom

Short answer

PECR governs electronic marketing; the soft opt-in applies only to existing customers for similar products. Email consent management supports compliance by making sender identity verifiable and recipient choices enforceable.

What UK GDPR and PECR requires#

PECR governs electronic marketing; the soft opt-in applies only to existing customers for similar products.

Consent is the documented permission a recipient gives to receive marketing email. Laws differ on whether it must be express (opt-in) or may be implied (existing relationship), and on how long it lasts.

Why it matters#

Consent is the legal basis for marketing mail in most jurisdictions and the practical basis for good deliverability: people who asked for mail rarely complain.

Regulators and recipients need to identify who sent a message and trust that opt-out mechanisms work. Email consent management contributes by consent is the legal basis for marketing mail in most jurisdictions and the practical basis for good deliverability: people who asked for mail rarely complain.

Implementation steps#

  1. Use an unchecked checkbox or a dedicated signup form; never pre-tick.
  2. Record timestamp, IP, source, and the exact wording shown at consent.
  3. Use double opt-in for marketing lists where feasible.
  4. Separate consent for different purposes (newsletter vs partner offers).
  5. Refresh consent for contacts older than two years with no engagement.

Frequently asked questions#

Is double opt-in required by law?

Not explicitly in most jurisdictions, but it is the easiest way to prove consent under GDPR and CASL and it improves list quality.

Keep reading on Consent and opt-in