What Is GDPR Email Consent? (Why a Compliant Footer Does Not Help You)
Most GDPR email advice is about footers and cookie banners. The thing that actually decides whether you are lawful happened before the first send: whether you can show, for each address, a lawful basis you recorded at the time.

Key Takeaways
- GDPR is opt-IN. Lawfulness is decided before the send, not by what is in the footer.
- Two laws apply together: GDPR governs the personal data, and PECR (or each country’s ePrivacy rule) governs the act of sending marketing. People quote GDPR and mean both.
- Consent must be freely given, specific, informed and unambiguous, by a clear affirmative action. A pre-ticked box is not consent. Neither is a condition of purchase.
- You must be able to demonstrate consent per person: what they saw, what they agreed to, and when. An unevidenced list is an unlawful list.
- Soft opt-in lets you email existing customers about similar products without prior consent, if you offered a refusal at collection and in every message.
- Fines reach 20 million euro or 4% of worldwide annual turnover, whichever is higher.
The Thing Most Articles Get Wrong
GDPR and CAN-SPAM are not stricter and laxer versions of the same law. They regulate different moments.
CAN-SPAM regulates the message: what it must contain and how an opt-out must work. You may email a stranger provided the message is right. GDPR regulates the processing: whether you were permitted to hold and use that person’s address at all, which was decided at collection.
This is why a flawless unsubscribe footer does nothing for you under GDPR. If the lawful basis was never there, every send was unlawful from the first one, and adding a footer changes nothing about the breach.
It Is Two Laws, Not One
GDPR covers personal data. An email address is personal data, so collecting, storing, segmenting and sending to it is processing that needs a lawful basis.
PECR in the UK, and the national ePrivacy implementations across the EU, cover the act of sending unsolicited electronic marketing. PECR is the rule that actually says you need consent to email an individual, and GDPR is what defines the standard that consent has to meet.
In practice people say “GDPR” and mean both. It matters when you are reading guidance, because the consent requirement and the soft opt-in exemption below come from the ePrivacy side.
What Counts as Consent
Freely given, specific, informed and unambiguous, indicated by a statement or a clear affirmative action. In practice:
An unticked box the person ticks. Pre-ticked boxes were expressly ruled out by the Court of Justice in Planet49. Silence, inactivity and scrolling are not consent.
Separate from everything else. Consent bundled into terms and conditions is not freely given. Marketing consent cannot be a condition of buying something that does not require it.
Specific about who and what.“Our partners” is not specific. If a third party will email them, that party has to be named.
As easy to withdraw as it was to give. One click to subscribe and an email to support to leave does not satisfy this.
You Have to Be Able to Prove It
Article 7 puts the burden on you to demonstrate that consent was given. Per person. That means keeping, for each address, what they were shown, what they agreed to, when, and through which form.
This is where most list practices fail. Addresses collected at a trade show, imported from a CRM after an acquisition, or scraped from a website have no record attached, and a list you cannot evidence is a list you cannot lawfully mail. Deleting the evidence while keeping the address is the worst of both.
It is also why a consent log is a feature and not an afterthought. Action BeeMail writes a consent event for every subscribe, confirm and unsubscribe, with the method and the actor, because that record is the difference between a defensible list and an undefendable one.
Soft Opt-In: The Exemption Worth Knowing
You may email an existing customer about your own similar products without prior consent, provided all of the following hold: you obtained the address in the course of a sale or negotiations for a sale, the marketing is for your own similar products or services, and you gave a simple way to refuse both when you collected the address and in every message since.
The limits are narrower than people assume. “Negotiations for a sale” means a genuine enquiry, not a downloaded whitepaper. “Similar” means similar, not anything else you sell. And it does not apply to a prospect who never bought or enquired.
Legitimate Interest, and Why It Rarely Rescues You
GDPR offers legitimate interest as a lawful basis, and B2B marketers reach for it constantly. Two things to understand.
First, legitimate interest can be a lawful basis under GDPR for the processing and still leave you in breach of PECR, which separately requires consent to send marketing to an individual subscriber. The two have to be satisfied together.
Second, relying on it requires a documented balancing test weighing your interest against the person’s rights and their reasonable expectations. Corporate subscribers (a limited company rather than a sole trader or a named individual) are treated more permissively under PECR, which is the real reason B2B email to info@company.example is lower risk than email to a named person.
The Rights You Have to Service
Access, rectification, erasure, restriction, portability and objection. For email marketing the ones that bite are erasure and objection, and objection to direct marketing is absolute: there is no balancing test and no grounds on which you may refuse.
One practical trap. When someone asks to be erased, you still need to remember not to email them again, which requires keeping the address on a suppression list. That is lawful and necessary: a suppression record exists to honour the objection, and deleting it would guarantee you mail them again the next time the address is imported.
Who It Applies To
Not where your company is. GDPR applies where the person is. A US business with one subscriber in Dublin is within scope for that subscriber. There is no volume threshold and no small business exemption.
Practical Summary
Collect consent with an unticked box, separate from your terms, naming anyone else who will email them. Record what they saw and when. Treat an unsubscribe as instant. Keep a suppression list rather than deleting people into a position where you will re-import them. And if you cannot show how an address got onto your list, do not mail it: the revenue from a list you cannot evidence is never worth 4% of turnover.
This is a description of the rules, not legal advice. If a decision turns on your specific circumstances, ask a lawyer.
Ready to Try Aicente?
Join 10,000+ businesses using aicente's 60+ AI tools to manage operations, win recognition, and grow. Platform Access starts at $19.99/month. Action Award entry is always free.
Related Articles
What Is CAN-SPAM Compliance?
The US opt-out regime, its five requirements and the per-message penalty.
What Is CASL Compliance?
Canada, where penalties reach $10 million and directors are personally liable.
What Is Newsletter Software?
Building an owned list, and what separates a newsletter from bulk email.