Digital Marketing

Consent for Marketing Emails and Texts: How to Get It Right

Talha Aslan 15 min read 3 views

How do you get consent for marketing emails and texts?

Consent for marketing emails and texts means the recipient clearly agrees, before you send, to receive promotional messages from you. In the EU and UK that agreement must be freely given, specific and informed, and you must be able to prove it. In the US the rules center on opt-out instead.

This guide shows what the rules look like in each region and how to build a sign-up flow that holds up. We write it as a marketing team, not as lawyers.

Note: This article is general information, not legal advice. Talk to a qualified lawyer about your own situation.

Also, keep the goal in mind. You are not collecting checkmarks for a lawyer. You are building a list of people who want to hear from you, so they open, click and buy. Therefore every design decision should make the choice clear and fair for the reader.

Why does consent for marketing emails matter so much?

Consent protects three things at once: your legal position, your sender reputation and your customer relationship. A list built on clear permission performs better because people actually want your messages.

Moreover, mailbox providers watch complaints closely. If recipients mark you as spam, your later campaigns land in junk folders. We cover that side in our guide to email deliverability and inbox placement.

Consent also makes your data cleaner. People who opt in tend to read, click and buy. So a smaller, willing list often beats a large, cold one.

Finally, platforms and partners ask about it. Ad networks, CRMs and email tools expect you to confirm that your contacts agreed to hear from you.

For example, imagine two lists with 5,000 contacts each. One came from a clear opt-in form, and the other came from an old import. The first list will usually bring fewer complaints and steadier delivery. So the smaller, permission-based list often wins in the long run, because engaged readers send stronger signals to mailbox providers. This is an example scenario, not measured data.

What does GDPR require for consent for marketing emails?

Under the GDPR, valid consent must be freely given, specific, informed and unambiguous. It needs a clear affirmative action, so pre-ticked boxes do not count. The European Data Protection Board explains these conditions in its guidelines on consent.

Withdrawing consent must be as easy as giving it. If someone signed up with one click, they should be able to leave with one click.

Because the rules cover personal data, you also need a privacy notice that explains what you collect and why. Our GDPR compliant website guide walks through that part.

Remember that e-privacy rules for electronic marketing can add national requirements on top of the GDPR. Check them for each country you target.

In addition, the consent request must stand apart from other matters. If you bundle it with terms of service, the person cannot make a real choice. Instead, show a separate checkbox and a short explanation. Then keep a record of what the person saw, because you carry the burden of proof.

How does UK PECR change the rules?

The UK Privacy and Electronic Communications Regulations (PECR) sit alongside UK GDPR. According to the ICO guidance on electronic mail marketing, you must not send marketing emails to individuals unless they consented or are existing customers.

The existing customer route is often called the soft opt-in. It applies to similar products you offered earlier, and you must give a simple way to opt out when you collect the address and in every message.

PECR covers texts, social media direct messages and picture messages too, not only email. So the same discipline applies across channels.

Marketing to companies has fewer restrictions. Even so, keep an opt-out list and respect it.

However, the soft opt-in has limits. It covers your own similar products, not partner offers or unrelated services. Also, you must have collected the address during a sale or negotiation. If any of these points is unclear, ask for fresh consent instead of relying on the exception.

What does the US CAN-SPAM Act require?

The US approach differs. CAN-SPAM does not demand prior opt-in for commercial email. Instead it sets rules for how you send. The FTC's CAN-SPAM compliance guide lists the main duties.

  • Do not use false or misleading header information or subject lines.
  • Identify the message as an advertisement.
  • Include a valid physical postal address.
  • Explain clearly how to opt out.
  • Honor opt-out requests within 10 business days.

These rules apply to business-to-business email too. Check the FTC page for current penalty amounts rather than relying on figures you see elsewhere.

Texts to mobile numbers fall under separate US rules. Review the current guidance from the relevant regulator before you launch an SMS program.

Still, do not read the US model as permission to send freely. State laws and platform rules can add duties, and mailbox providers punish high complaint rates regardless of the law. So many US senders choose opt-in anyway, because it protects deliverability and trust.

How do the regions compare?

The table below summarizes the main differences. Treat it as a starting frame, then confirm details with official sources.

RegionBasic approachExisting customersOpt-out duty
EU (GDPR and e-privacy)Opt-in consent, provableNarrow exceptions under national lawWithdraw as easily as you gave consent
UK (PECR and UK GDPR)Opt-in consent for individualsSoft opt-in for similar productsSimple opt-out in every message
US (CAN-SPAM)Opt-out model for emailNo opt-in needed for emailHonor within 10 business days
Germany (UWG)Prior express consentStrict four-part exceptionFree opt-out at collection and every use

So if you sell across borders, build for the strictest rule you face. That way one sign-up flow works almost everywhere.

For instance, a store that sells in Germany, the UK and the US should not run three different forms. Instead, build one flow with an empty checkbox and double opt-in, and add region-specific text where needed. Then your team maintains only one process.

What counts as valid consent for marketing emails?

Valid opt-in consent comes from a clear action by the person, such as ticking an empty box or clicking a confirmation link. It names your brand, explains what you will send and does not hide inside other terms.

Here is a checklist we use when reviewing forms:

  1. The checkbox starts empty.

2. The text names your company and the channel (email or SMS).

3. You do not tie consent to a purchase when it is not needed.

4. The privacy notice sits in a separate link.

5. You store date, time, source and wording.

Consequently, a form that seems to "convert well" because it tricks people does not help you. Complaints and unsubscribes will cancel the gain.

Moreover, the wording matters as much as the box. Avoid vague phrases like "stay in touch". Instead, say exactly what you will send, for example "monthly product news and occasional offers". Specific wording is easier to defend and easier for readers to understand.

What is double opt-in and when should you use it?

Double opt-in means the person submits the form and then confirms through a link in a follow-up email. Only the confirmed address joins your list. It proves that the owner of the mailbox actually agreed.

The method is not a legal requirement in every country. However, it gives you strong evidence, and it blocks typos and fake sign-ups. Germany treats it as the practical standard, as we explain in our German article on double opt-in.

Use it when you collect addresses on open forms, run giveaways or serve European audiences. Skip it only if you have another reliable way to verify ownership. Also, remember that a confirmed address is a cleaner address, which helps your sending reputation.

Keep the confirmation email short. One button, one sentence and your brand name are enough.

In practice, the flow has four steps. First, the visitor submits the form. Second, your system sends a confirmation email. Third, the visitor clicks the link. Finally, you record the confirmation time and activate the subscription. Unconfirmed entries stay inactive and you can delete them after a set period.

How do you design a form for consent for marketing emails?

A compliant form is also a clear form. Place the checkbox directly under the email field and write one plain sentence next to it. For example: "Yes, send me product news and offers by email."

Offer separate choices for email and SMS. Tell people how often you will write. Link to your privacy policy and explain how they can leave.

On mobile, make checkboxes large enough to tap. Small boxes cause mistakes, and mistakes cause complaints.

You can test form copy with our A/B test calculator and measure results with the conversion rate calculator. Test the wording, not the transparency.

Also, tell people what happens next. A thank-you page that says "Check your inbox to confirm" reduces confusion. Then your welcome email can restate the choice and link to preferences. This is a small step, but it builds trust from the first message.

Which mistakes do we see most often?

After many reviews, the same errors come up again and again:

  • Pre-ticked boxes or "by signing up you agree to everything" lines.
  • One consent that covers email, SMS and phone calls together.
  • Buying or renting lists with no proof of permission.
  • Missing unsubscribe links, or links that fail.
  • Ignoring opt-outs from support chats or phone calls.
  • Importing business cards from a trade fair into the newsletter list.

Most of these errors come from process gaps, not bad intent. Different teams own forms, lists and sends, and nobody sees the whole picture. Name one owner for consent records.

Because these errors repeat, a short quarterly audit pays off. Open your newest form as a stranger would, sign up, and check what arrives. Then compare it with your records. In our experience, a ten-minute walkthrough finds more problems than a long policy document.

How do you handle old lists and existing contacts?

If you have a list from years ago without proof of consent, do not just start mailing it. Split contacts into three groups: documented consent, unclear consent and no consent.

For the unclear group, a re-permission campaign can help. However, the message itself may count as marketing, so check the rules in your market first. Count only people who actively say yes.

Silence is not consent. Do not treat non-responders as agreed.

Purchased lists carry extra risk. You cannot show where the permission came from, and recipients never heard of you. Grow your own list instead.

Meanwhile, think about trade fairs and offline sources. A business card is not a subscription request. If you collected contacts in person, send one direct, personal message that asks for permission to add them, or use a sign-up sheet with clear wording from the start.

How should you record and store consent?

Records are your proof. For each contact, save the following:

  • The email address or phone number and the channel.
  • Date and time of consent.
  • The form or page where it happened, plus the IP or other technical source if your policy allows.
  • The exact wording the person saw.
  • Any later withdrawal.

Store this data securely, limit who can see it and set a retention period with your legal adviser. Do not delete the old wording when you update the form; keep a version history so you can show what each person agreed to.

Our privacy policy shows how we describe such handling on our own site.

Also, test whether you can answer a complaint quickly. Pick a random contact and see if you can show date, source and wording in under a minute. If not, improve your system. Fast answers show good faith and save time during any dispute.

How do you make unsubscribing easy?

Every promotional message needs a clear exit. In email, put a visible unsubscribe link in the footer and make it work with one click. In SMS, give a short reply keyword or link.

Avoid forcing a login or a long survey. A single confirmation step is fine, but a maze is not.

Process requests quickly across all systems. If the CRM, the email tool and the sales team keep separate lists, someone will email a person who already left.

Also tell people what they will stop receiving. A preference center that lets them reduce frequency instead of leaving entirely often saves subscribers.

For example, when someone unsubscribes from promotions, you can still send necessary service messages such as order confirmations. However, do not hide offers inside them. Keep the two types separate so that neither the law nor the reader gets confused.

What about WhatsApp and other messaging apps?

Messaging apps add platform policies on top of the law. You usually need a clear opt-in before you send templated messages, and the platform can restrict accounts that generate complaints.

We cover templates, costs and ad formats in our WhatsApp marketing messages guide, so we will not repeat it here. The main point is the same: ask first, record the answer and honor opt-outs.

Do not move contacts from one channel to another without permission. Email consent does not automatically cover SMS or WhatsApp.

Also, keep volume and timing in check on chat apps. People read these messages on their phones, often in private time, so complaints come fast. Therefore, use shorter lists, relevant content and a clear stop option in every campaign.

How does consent connect to advertising audiences?

When you upload customer lists to ad platforms, you also confirm that you collected the data lawfully. Clean consent records therefore protect your ad accounts as well as your inbox rates.

See our guide on Google Ads Customer Match requirements and consent before you upload any list.

Never try to bypass platform checks by opening new accounts or hiding data sources. Platforms treat that as circumvention, and it makes problems worse. If you lose access to a business account, start with our guide to recovering a Meta business account and Page.

For instance, a retargeting list built from newsletter subscribers should only include people who agreed to that use. So make sure your sign-up text matches how you plan to use the data. Otherwise you risk rejected uploads and unhappy users.

How do you measure campaigns without cutting corners?

Once consent is in place, you can measure confidently. Tag every campaign link with UTM parameters so your analytics shows which emails drive visits and sales. Our UTM builder speeds this up.

Track health metrics, not only volume: unsubscribe rate, complaint rate and the share of confirmed sign-ups. A sudden jump signals a problem with content, frequency or list quality.

Example calculation: if 10,000 consenting contacts produce 500 clicks, your click rate is 5 percent. The number only shows the math and is not a benchmark.

Design matters too. Clean, mobile-friendly templates help both readers and filters. Our HTML email design guide covers the details, and the piece on AI in email marketing reminds you that automation never replaces permission.

Also, review your reports monthly. If complaint rates rise after a new offer, pause and examine the form that produced those contacts. Often the issue is an unclear checkbox rather than the email itself. Fix the root cause and the numbers recover.

Do business-to-business emails need consent too?

It depends on the country and on who the recipient is. In the UK, PECR gives corporate subscribers fewer protections than individuals, yet the ICO still advises keeping an opt-out list. In the US, CAN-SPAM covers business email as well.

However, a work address such as a personal name at a company can still count as personal data under the GDPR. So do not assume that a business context removes your duties. Also, many B2B buyers simply dislike cold mass mailing.

Consequently, we recommend the same basics for B2B: say who you are, explain why you write, offer an easy opt-out and keep records. That approach protects your reputation while you build relationships.

What should you do when someone complains?

First, stop sending to that person right away. Then record the complaint, the date and the action you took. Reply politely, confirm the removal and, if the person asks, explain where you got the address.

Also, look for the cause. Did the contact come from an old import, a partner list or an unclear form? Fix the source, because one complaint often points to many more silent ones.

If the complaint comes from a regulator, answer promptly and bring your records. Clear documentation, a working opt-out and a consistent process show good faith. Finally, ask a lawyer to review your reply before you send it.

What is a simple step-by-step plan?

You can work through this plan in about a week. Keep it light at first, then refine.

  1. List every channel and tool you use to send promotions.

2. Check the rules in each market you target, using official sources.

3. Rewrite forms with empty checkboxes and clear wording.

4. Add double opt-in where the risk of fake sign-ups is high.

5. Sort old contacts into three consent groups.

6. Add a working unsubscribe path to every message.

7. Store consent records and review them every quarter.

If you want help connecting sign-up forms, ad audiences and reporting, look at our Google Ads management service or get in touch. Talha Aslan and team will gladly help.

Finally, assign owners. One person maintains forms, one maintains the contact database and one reviews campaigns. When tasks have names next to them, the plan survives staff changes. Review the plan every quarter and whenever you add a new channel.

Frequently Asked Questions

Do I need consent to send marketing emails?
It depends on where your recipients live. In the EU and UK you generally need opt-in consent for individuals, with narrow exceptions such as the UK soft opt-in. In the US, CAN-SPAM works on an opt-out basis. Check official guidance for each market and ask a lawyer about your case.
Is double opt-in required by law?
Double opt-in is not a legal requirement everywhere, but it is the strongest way to prove that a mailbox owner agreed. Germany treats it as the practical standard, and it also reduces fake sign-ups and typos. If you target European audiences, we recommend using it.
Can I email people who bought from me before?
In the UK, the soft opt-in can allow marketing to existing customers for similar products if you gave a clear opt-out at collection and in every message. Other countries set stricter or different conditions. Review the rules for each market and keep the opt-out visible.
How quickly must I honor an unsubscribe?
Under CAN-SPAM, the FTC says you must honor opt-out requests within 10 business days. Under GDPR and PECR you should stop as soon as you reasonably can, and withdrawal must be as easy as consent. In practice, update every system within a day or two.
Do the same rules apply to text messages?
PECR covers texts, direct messages and picture messages, so UK marketing texts need consent too. In the US, texts to mobile numbers fall under separate rules that differ from email. Always check the current guidance from the relevant regulator before you start an SMS program.
What records should I keep as proof of consent?
Keep the contact detail, channel, date and time, the form or page, the exact wording the person saw and any later withdrawal. Store them securely, limit access and set a retention period with your adviser. Keep old wording versions as well, so you can show what each person agreed to.
  • email consent
  • double opt-in
  • GDPR
  • PECR
  • CAN-SPAM
  • email marketing
  • SMS marketing
  • opt-out
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.