The School of Net Marketing

M8.L2 · Email & Lifecycle

Consent and the law: GDPR and ePrivacy, done properly

13 min

What you'll be able to doApply GDPR and ePrivacy rules to design a lawful email programme: the right lawful basis per audience, valid consent capture, the soft opt-in and its limits, unsubscribe handling, and a retention rule.

Learn

Why this is the growth lesson in disguise

Here is the practical case for doing this properly, before the legal one: addresses collected without permission cannot be lawfully used, so every hour spent gathering them is wasted twice — once collecting, once deleting. Complaints to data protection authorities are free to file and fines are real. And permission-based lists get delivered and get read, because the people on them asked to be there; Lesson 8.4 will show you that mailbox providers now enforce this economically, whatever the law says. In Europe, lawful and effective are the same list.

Two laws, one programme

Two separate sets of rules apply to marketing email, and you must satisfy both:

  • GDPR governs processing personal data. An email address is personal data — usually obviously so (t.herzog@… identifies a person; even info@ addresses often do). Storing, tagging and emailing addresses is processing, and processing needs a lawful basis.
  • The ePrivacy rules govern sending electronic direct marketing — email, SMS, and similar. These come from the ePrivacy Directive, which each EU member state has implemented in its own national law. The core rule everywhere: marketing email to individuals requires prior consent, with one carefully bounded exception described below. The details — especially for B2B — genuinely vary by country.

A common and expensive confusion: "we have a lawful basis under GDPR" does not by itself authorise sending marketing email. GDPR's recitals acknowledge that direct marketing may be a legitimate interest — but the ePrivacy rules still demand consent or the soft opt-in for the sending. Legitimate interest is not a loophole around the inbox. Where it genuinely features is narrow: some member states permit opt-out-based email to corporate addresses in B2B contexts. If you plan to rely on that, check your country's specific rule first — this is one of the places national law differs most.

What valid consent looks like

GDPR defines consent tightly: freely given, specific, informed, and unambiguous, by a clear affirmative action. In practice:

  • No pre-ticked boxes. The EU's top court has ruled explicitly that a pre-ticked box is not consent. The person must act.
  • Unbundled. Consent to marketing cannot be smuggled into a "Download" button or buried in terms. If the button says "Get the guide", the marketing signup needs its own clear wording or its own box.
  • Specific and informed. Say what they'll get and roughly how often: "Recovery advice and clinic news, about once a month." Link the privacy notice.
  • As easy to withdraw as to give. Which is most of why unsubscribe links exist.
  • Recorded. Keep who, when, what wording, and how. Your ESP does this if you let it — a reason it appears in Lesson 8.4's selection criteria.

The soft opt-in — and its real limits

The ePrivacy rules contain one exception worth knowing precisely, because it is both genuinely useful and routinely abused. You may email existing customers without fresh consent, if all of these hold:

  1. You obtained the address in the context of a sale of your product or service (some countries extend this to sale negotiations; some don't — national variation again).
  2. You are marketing your own similar products or services — not a partner's, not an unrelated line.
  3. You told them at collection their address would be used this way, and offered an opt-out at that moment.
  4. You offer an opt-out in every message.

What the soft opt-in is not: a basis for emailing people who downloaded a PDF (that's consent territory — the magnet in Lesson 8.3 needs a real signup), a way to use a list someone else collected, or a cure for addresses found, bought or scraped. It covers customers, narrowly, and the "told them at collection" condition means it can't be applied retroactively to a list gathered in silence.

Double opt-in

Double opt-in (DOI) means the signup only counts after the person clicks a confirmation link. GDPR does not use the words "double opt-in" anywhere. So why does this school teach it as the default?

Because consent you can't prove is consent you don't have, and the confirmation click — timestamped, logged by the ESP — is the cleanest proof there is. German case law has effectively made confirmed opt-in the standard of proof there, and if you mail into Germany or Austria you should treat DOI as non-negotiable. Everywhere else it is the difference between asserting your list is clean and demonstrating it — and it filters out typos and fake addresses before they poison your deliverability.

The honest cost: some share of signups never click the confirmation, and they are lost. Accept it. A smaller list you can prove beats a larger one you must hope about.

Unsubscribe, retention, minimisation

Unsubscribe: present in every marketing email, working, free, and requiring no login. Honour it promptly — in practice, immediately; the major mailbox providers now also require one-click unsubscribe for bulk senders and expect opt-outs processed within days. And suppress, don't delete: keeping the address on a do-not-contact list is how you prove you stopped. Deleting it entirely means you could re-import the same address next year and start the whole violation fresh.

Retention: GDPR's storage-limitation principle says keep personal data no longer than needed — it sets no number; you must, and must be able to defend it. A workable rule: contacts inactive for 24 months who never became customers are suppressed and anonymised. Lesson 8.6's sunset policy is this principle wearing work clothes.

Minimisation: collect what the purpose needs. A newsletter needs an email address, perhaps a first name. Birthdays "for later" are a liability collecting dust.

Lena audits the 900

Storkflow's 900-subscriber newsletter list has been sitting untouched since Module 1. Before Lena can market to it, she has to answer a question nobody at Storkflow ever asked: where did these addresses come from? The audit finds three populations:

  • 380 customer contacts, collected at purchase, with product updates mentioned and an opt-out offered at signup. Soft opt-in conditions met, for messages about Storkflow's own services. She documents the basis and moves on.
  • 340 past trial signups, told at signup their address would be used for onboarding tips and product news, opt-out offered. A trial is the negotiation of a service — soft opt-in territory in the Netherlands, and she notes the national-law caveat in her records. To use them beyond product messages, she sends one value-led re-permission email — "Want the client-intake guides?" — and upgrades the 96 who say yes to full newsletter consent. The rest stay soft-opt-in, product messages only.
  • 180 addresses imported in 2022 from a trade-show attendee list the organiser shared. Nobody consented, nobody was told, no sale ever happened. No lawful basis exists, and none can be conjured. She deletes them.

Deleting 180 addresses feels like burning money. It is disposing of a liability — those contacts could never lawfully be mailed, and any accidental send to them was a complaint waiting to be filed. The list drops from 900 to 720, and for the first time every address on it has a documented basis.

Tomas, for contrast, has nothing to triage — the pack's brutal fact from Lesson 8.1 — but his front-desk card was designed right from day one: "Recovery advice and clinic news, about once a month. Tick here if you'd like it. Unsubscribe any time." Affirmative action, specific, informed, opt-out stated. Starting correctly is cheaper than auditing.

Now write your own policy.


Do

Exercise 8.2.1 — Your consent & retention policy

Write the consent and retention policy for your list: your lawful basis per audience, the exact signup wording you'll deploy, your double opt-in decision, and your retention rule. You will implement all of it, live, in Lessons 8.4 and 8.5 — so write what you'll actually do.

Write these down — in your plan document, or on the worksheet at the end of this lesson.

What to write Guidance
Your audiences, 1–3 rows Each: the audience (e.g. "newsletter prospects", "past customers"), its lawful basis — consent · soft opt-in: existing customers, own similar products · legitimate interest: B2B, documented, national rules checked — and 20–60 words justifying it. If you claim legitimate interest, the national-rule note is not optional
Your signup wording 15–60 words; must say what they'll receive and roughly how often. No pre-ticked language, no consent bundled into a download button
Double opt-in Yes (the taught default) or no, with your reason in writing — and if no, reread the proof-of-consent and Germany passages first
Your retention rule Must contain a number and a unit of time, e.g. "suppress and anonymise after 24 months of inactivity"
Existing list audit 30–100 words: what addresses do you already hold, where did each population come from, and what is its basis? "None yet" is accepted and honest

One pairing is always wrong: a scraped, purchased or found list carries no lawful basis, whatever you write next to it. If your audit surfaces one, its row reads "delete".

Where this goes: section 8.2 — Compliance — of your Marketing Plan. You'll reuse the signup wording in Lesson 8.4's form and the retention rule in Lesson 8.6's sunset policy.


Check

Rubric

Mark your own work against these criteria.

Criterion 8–10 5–7 1–4
Basis matched to audience Every audience carries the correct basis with a real justification; national caveats noted where relevant Bases broadly right, one justification thin A basis misapplied — e.g. soft opt-in for downloaders, or legitimate interest as a consent bypass
Signup wording Specific, unbundled, states content and frequency, affirmative Lawful but vague ("occasional updates") Bundled, pre-ticked, or silent on what they're agreeing to
Retention rule Concrete number, defensible, suppress-not-delete understood A number, weak reasoning No rule, or "keep forever"
Existing-list honesty Every held address accounted for, uncomfortable findings included Audit present, provenance partly guessed Audit flattering or absent

Pass: 5+ on every criterion. Any unlawful pairing is a fail regardless of other scores.

Quiz — 4 questions

1. A pre-ticked "send me the newsletter" box at checkout produces…

  • a) Valid consent — they could have unticked it
  • b) Invalid consent — consent requires a clear affirmative action, and the EU's top court has ruled pre-ticked boxes are exactly not that
  • c) Valid consent if the privacy policy is linked
  • d) Soft opt-in

Why: silence and inaction are not agreement. The person must do something. A linked policy informs; it doesn't consent on their behalf.

2. Storkflow may email its 340 past trial users about a new Storkflow feature without fresh consent because…

  • a) B2B contacts have no GDPR rights
  • b) Trials aren't purchases, so no rules apply
  • c) The soft opt-in can apply: addresses collected in the context of a sale or its negotiation, messages about Storkflow's own similar services, opt-out offered at collection and in every message — subject to national implementation
  • d) Ten years haven't passed yet

Why: all four conditions must hold, and the "told at collection" one is the usual killer. Storkflow's trial signup happened to state the use and offer the opt-out — which is why Lena documented it rather than assumed it.

3. The 180 addresses imported from a trade-show attendee list: what can Lena lawfully do with them?

  • a) Email them once to ask for consent
  • b) Move them to the soft opt-in basis — they're B2B
  • c) Delete them — no consent, no notice at collection, no sale: there is no basis to email them, and even a "may we email you?" email is itself marketing email
  • d) Wait 24 months, then email them

Why: the permission-request email is the trap — it is an unsolicited electronic message to people who never agreed to receive one. A list collected without permission cannot be repaired by contacting it.

4. A subscriber unsubscribes on Tuesday. The correct handling is…

  • a) Delete every trace of them immediately, for GDPR reasons
  • b) Remove them from sends within 30 days
  • c) Stop marketing to them promptly — in practice at once — and keep the address suppressed, so you can prove non-contact and never accidentally re-import them
  • d) Move them to a "win-back" sequence

Why: suppression is the mechanism that makes "we stopped" provable. Full deletion sounds virtuous and quietly destroys the evidence — and the safeguard. And an unsubscribe is the opposite of an invitation to a win-back flow.


Advance

You now have something most working marketers can't produce: a written answer to "who are you allowed to email, and why?" Everything you build in the next four lessons stands on it — which is the point of building it first.

Next: M8.L3 — Lead magnets people actually want. Consent is the legal half of the exchange. Now the commercial half: what you offer that makes your ICP's email address feel like a fair trade.


Mark your own work

Good Not yet
Every audience has a basis Consent, soft opt-in or (checked) B2B rule — each justified in writing "It's fine, they know us"
Wording is honest Says what and how often, needs an affirmative act A pre-ticked box, or consent hidden in a button
Soft opt-in respected Applied only to customers, told at collection, opt-out everywhere Applied to downloaders, event lists, or old silent data
Retention exists A number, a unit, and suppress-not-delete "We keep everything, forever, just in case"
Audit is uncomfortable You wrote down the provenance you're not proud of The awkward addresses went unmentioned

Worksheet

THE SCHOOL OF NET MARKETING
Lesson 8.2 — Consent and the law
(Education, not legal advice. National rules vary.)

MY AUDIENCES AND BASES
  Audience              Basis                    Why it holds
  1. _________________  ☐ consent                ______________
                        ☐ soft opt-in (customers)
                        ☐ legit. interest (B2B — national rule checked)
  2. _________________  ☐ / ☐ / ☐               ______________
  3. _________________  ☐ / ☐ / ☐               ______________

SOFT OPT-IN — all four or none:
  ☐ Address collected in the context of a sale
  ☐ Marketing my own similar products/services only
  ☐ Told them at collection + opt-out offered then
  ☐ Opt-out in every message

MY SIGNUP WORDING (15–60 words — what + how often)
  ____________________________________________________
  ____________________________________________________
  ☐ Affirmative action  ☐ Unbundled  ☐ Privacy notice linked

DOUBLE OPT-IN:  ☐ Yes (default)   ☐ No, because ________
  (Mailing into Germany/Austria? Treat DOI as required.)

RETENTION RULE (number + unit + suppress, not delete)
  ____________________________________________________

EXISTING LIST AUDIT — every address I hold today
  Population            From where?         Basis or DELETE
  ____________________  __________________  ______________
  ____________________  __________________  ______________

SELF-CHECK
  ☐ No scraped, bought or found addresses survive this page
  ☐ Consent I claim, I can prove (who/when/wording/how)
  ☐ Unsubscribe: every email, free, no login, prompt
  ☐ My retention rule exists and I could defend it

Next: Lesson 8.3 — Lead magnets people actually want.
theschoolofnetmarketing.com/learn/lead-magnets