GDPR Email List Management: Compliance Best Practices
What consent has to look like, what you must be able to prove, and the retention question most senders have never answered.
On this page
The short version
- The obligation is to demonstrate consent, not merely to have obtained it. A list with no record of how permission was given cannot be demonstrated, however it was actually collected.
- Four fields recorded at capture cover most of it: what was shown, when, from where, and what the person did.
- Retention is the question almost nobody has answered, and the answer that satisfies a regulator is usually the same one that helps deliverability.
This is a plain-language description of what these obligations ask of an email sender. It is not legal advice — the detail varies by jurisdiction and by circumstance, and anything consequential is worth a lawyer's time.
The useful framing for a marketer is that a consent regime asks two separate things. Did you obtain permission, and can you show that you did. Most senders are fine on the first and unprepared for the second.
What consent has to look like
Freely given, specific, informed and unambiguous, indicated by an affirmative action. In practice that rules out several common arrangements.
A pre-ticked box is not an affirmative action. Consent bundled into acceptance of terms and conditions is not specific. A checkbox covering "our partners" without naming them is not informed. Making a subscription a condition of entering a competition is not freely given, because the person had no real choice.
The version that clears all four is an unticked box, or a separate button, with wording that says who is sending and what they will send.
The four fields to record at capture
| Field | Example | Why |
|---|---|---|
| The wording shown | A stored copy or a version ID | Proves what they agreed to |
| Timestamp | The moment of submission | Proves when |
| Source | The form, page or event | Proves the context |
| The action taken | Box ticked, button pressed, link confirmed | Proves it was affirmative |
Storing a version ID for the wording rather than the wording itself is the practical approach — keep a dated record of each version of the consent text, and store which version each subscriber saw.
Soft opt-in, and how narrow it is
Some regimes allow contacting existing customers about similar products without fresh consent, provided the address was obtained during a sale, an opt-out was offered at that point, and every message since has carried one.
It is a genuine and useful exception, and it is narrower than it is usually treated as being. It covers similar products, not the whole catalogue. It applies to customers, not to anyone who once filled in a form. And the opt-out must have been offered at collection, not merely available later.
Treating it as general permission to mail anyone who transacted is the most common way senders end up outside it.
Retention, which almost nobody has decided
How long do you keep an address belonging to someone who has never engaged? Most senders have no answer, and regimes generally expect one — data should not be kept indefinitely without a reason.
The convenient part is that the answer you would defend to a regulator is usually close to the sunset threshold you should be applying for deliverability anyway. A policy of removing subscribers after a defined period of no engagement satisfies both, which makes it an unusually easy piece of compliance work to justify internally.
Write it down, apply it, and record that you did. An undocumented practice is not a policy.
Access and deletion requests
Someone can ask what you hold about them and can ask you to delete it. Both need a process that works, and the process is usually the thing that does not exist rather than the capability.
Two practical points. Deletion has to reach every system — the email platform, the analytics tool, the backup, the spreadsheet someone exported. And a suppression list is a legitimate exception worth understanding: keeping a record specifically so you never mail them again generally serves the person's own interest, but the reasoning belongs written down rather than assumed.
Compliance check
- No pre-ticked boxes anywhere
- Consent is unbundled from terms and from any other action
- The wording, timestamp, source and action are recorded
- Consent text is versioned and dated
- Any inherited list has a documented decision attached to it
- A retention period is written down and applied
- Access and deletion have a process that has been tested
- Deletion reaches every system, not just the email platform
Frequently asked questions
Does this apply if we are not in the EU or UK?
It can, because the regulation follows the individual rather than the sender. If you knowingly market to people there, it is in scope — which is why applying the strictest standard across the board is usually simpler than segmenting by geography.
Is double opt-in required?
No regime named here requires it. It is a strong way to evidence consent, which is a different thing — single opt-in with a proper record satisfies the requirement in most cases.
How long should consent records be kept?
For as long as you rely on the consent, plus enough time to answer a challenge afterwards. This is a question to put to a lawyer rather than to settle from an article.