Guide

GDPR for Email Marketing: Consent, Opt-Ins, and the PECR Overlap

Email marketing sits at the intersection of two different EU laws, GDPR and the ePrivacy Directive (PECR in the UK). Here's how they overlap and what that means for opt-ins in practice.

Published June 29, 2026·Last updated August 18, 2026

Email marketing compliance in the EU/UK is governed by two overlapping laws, not one, GDPR and the ePrivacy Directive (implemented in the UK as PECR, the Privacy and Electronic Communications Regulations). Most confusion about “do I need opt-in or is opt-out fine” comes from not realizing both apply at once, to different parts of the same email.

Two laws, two different jobs

GDPR governs the personal data itself, the email address, the name, any behavioral data used to personalize the message. It requires a lawful basis for processing that data (see our decision guide on consent vs. legitimate interest).

PECR/ePrivacy governs the act of sending the electronic communication itself, independent of GDPR. It’s the reason email marketing specifically has its own stricter opt-in rule that doesn’t apply the same way to, say, keeping a customer’s shipping address on file.

The core rule: opt-in, with one narrow exception

For marketing emails to individuals, PECR/ePrivacy generally requires prior opt-in consent, not opt-out. There’s one commonly used exception, often called the “soft opt-in”: if you obtained someone’s email in the context of a sale (or negotiations for a sale) of a similar product or service, you can email them about similar offers without a separate opt-in, provided you gave them a clear opportunity to opt out at collection and in every subsequent email.

Outside that narrow exception, a pre-ticked “sign me up for offers” checkbox, or automatically enrolling someone in marketing because they made a purchase, does not meet the opt-in bar.

What a compliant opt-in actually looks like

  • Unticked by default. The individual has to take an affirmative action to opt in, a pre-checked box doesn’t count, the same principle covered in our cookie consent requirements piece.
  • Specific to email marketing, not bundled into a general “I agree to the terms” checkbox that covers several unrelated things at once.
  • Clearly described, what kind of content, roughly how often, from whom.
  • Easy to withdraw, with an unsubscribe link in every marketing email (a requirement that applies regardless of which lawful basis or exception got you there in the first place).
Our recommendation

CookieYes

Email opt-in consent and website tracking consent are often handled as if they're the same thing, they're not, and conflating them is a common gap. CookieYes handles the cookie/tracker side cleanly, which frees you to give your email opt-in flow the specific, unbundled treatment it needs.

Try CookieYes

Buying something doesn’t automatically mean someone wants marketing emails, transactional emails (order confirmations, shipping updates) don’t require marketing opt-in because they’re not marketing, but adding that same customer to your promotional newsletter list does, unless the narrow soft opt-in exception applies and you’ve met its specific conditions.

Under the accountability principle, see our overview of GDPR’s seven core principles, you should be able to show when and how someone opted in if that consent is ever questioned. Most email platforms log this automatically; confirm yours does and that you’re not relying on an imported list with no consent trail at all.

The bottom line

If you’re only thinking about GDPR’s general lawful-basis framework for your email list, you’re missing half the picture, PECR/ePrivacy’s opt-in requirement for the send itself is stricter and more specific than GDPR’s general rules, and it’s the one most commonly overlooked.

This guide is educational and not legal advice. For your specific email marketing setup and list sources, consult a privacy attorney.