YourTrend
Email API & SMTP Campaigns Automations SMS Web push Messengers Unified inbox Secure mail Analytics
ENUKRU
Sign in Start free
Security & privacy

GDPR and Email Marketing: Consent Done Right

Short answer

How to collect email consent lawfully under GDPR: legal bases, double opt-in, consent records, unsubscribe and retention periods.

GDPR and email marketing: what the law requires

Under GDPR you may send marketing emails to EU residents if you have a lawful basis — most often explicit consent. Consent must be freely given, specific, informed and unambiguous, and you must document that it happened. Below is the practice: bases, double opt-in, records, unsubscribe and retention.

Lawful bases

For email marketing, two Article 6 bases are common:

  • Consent. The default path for cold lists and B2C. It requires an active user action.
  • Legitimate interest. Sometimes valid for existing customers (a "soft opt-in"), but it requires a balancing test and always an easy unsubscribe.

Pre-ticked boxes and "consent by default" are not allowed: consent is an affirmative action.

Double opt-in: how it works

Double opt-in confirms a subscription via a link in an email. It is the best way to prove consent and, at the same time, clean your list of mistyped or third-party addresses.

  1. The user submits an email in a form (first step, opt-in).
  2. You send an email with a confirmation link.
  3. Clicking the link records consent: time, IP, form text.

You can wire the confirmation flow through YourTrend's API and webhooks so the subscriber status updates automatically.

What to store as proof of consent

FieldExample
Date and time2026-08-04T10:22:31Z
Sourceform on /en/landing, footer
Consent text"I agree to receive news and offers"
Policy versionprivacy v3.1
Confirmationdouble opt-in, IP 203.0.113.7

You should be able to pull this record for any address — in case a user or a regulator asks.

Unsubscribe

Unsubscribe must be simple and work in one click, without logging in. Technically, add the header for mailbox providers:

List-Unsubscribe: <https://example.com/u/abc123>, <mailto:unsub@example.com>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

Since 2024 Gmail and Yahoo require one-click unsubscribe for bulk senders and expect the request honoured within two days. Process opt-outs within that window and never send a "please come back" email without fresh consent.

Data processing and retention

  • Minimisation. Collect only the fields you need. Extra data is extra risk.
  • Processor agreement (DPA). Your ESP acts as a processor — you need a data-processing agreement.
  • Retention. Do not keep addresses forever: remove inactive and unsubscribed contacts by policy (for example, move opt-outs straight to a suppression list, not the main base).
  • Data-subject rights. Provide access, correction and erasure on request.

For sensitive scenarios, zero-access secure mail helps: the operator cannot read the message contents.

Profiling and segmentation

Behavioural segmentation (opens, clicks, purchases) is lawful, but automated profiling with significant effects on a person calls for extra care and transparency. State plainly in your privacy policy what data you collect and how you use it for personalisation. The clearer the wording, the lower the risk of complaints and claims.

Cross-border data transfers

If EU residents' data is processed outside the EEA, you need a lawful transfer mechanism — for example Standard Contractual Clauses (SCC) or an adequacy decision. Ask your ESP where data is physically stored and what safeguards it provides. That is part of due diligence when choosing an email service.

Common violations

  • bought lists and cold sends with no basis;
  • pre-ticked consent boxes;
  • a missing or obstructed unsubscribe;
  • keeping data "forever" with no retention limit;
  • bundling purposes: consent to a service is not consent to marketing.

GDPR fines reach up to EUR 20 million or 4% of annual turnover, but in practice systematic data hygiene matters more — and it also improves deliverability, since a clean list yields fewer complaints and opt-outs.

Quick FAQ

Does the law require double opt-in? GDPR does not mandate it directly, but it is the most reliable way to prove consent, so it is recommended.

Can I email existing customers? Sometimes — on a legitimate-interest basis (soft opt-in) for similar products, always with an easy unsubscribe and a balancing test.

How long should I keep consent? While the subscription is active plus a reasonable period after opt-out as evidence — but not indefinitely.

How to start implementation

Begin with an audit of current forms and collection points: where exactly a person gives consent and what they see at that moment. Then document processing purposes and retention periods for each data type. Update the privacy policy in plain language and set up double opt-in with evidence logging. Finally, test unsubscribe end to end — from the click to actual removal from the mailing. This order covers the core requirements before you send the first email.

Checklist

  1. Active, specific consent with no pre-ticked boxes.
  2. Double opt-in and stored evidence.
  3. One-click unsubscribe and the List-Unsubscribe header.
  4. A DPA with your ESP and sensible retention periods.
  5. Readiness to handle data-subject requests.

This is not legal advice — involve a lawyer for your specifics. But meeting these points covers most common GDPR risks. Start with the form and confirmation setup on the features page.

Terms explained in the glossary: Double opt-in · List-Unsubscribe
On this page ← All articles
Was this useful?

One click. It tells us what to write next.

No ratings yet — yours would be the first.

Comments

Comments are read before they appear.
  1. No comments yet. Start the conversation.
Put it into practice

Start sending in minutes