GDPR Email Marketing 2026: The Consent Checklist
Most articles on this topic either scare you or wave it away. Neither helps. The honest position is narrow and boring: the law asks for three things — a valid consent, evidence that it happened, and a provider you have a contract with. Get those right once and you can stop worrying about your list. Here is the checklist, with the actual provisions so you can look them up yourself.
The rules, in one table
These are the provisions that decide whether an email list is defensible in the EU. Everything else in this article is detail on how to satisfy them.
| What it demands | Where it is written | In practice |
|---|---|---|
| Prior consent for advertising email | § 7(2) no. 2 UWG (Germany), Art. 6(1)(a) GDPR | No consent, no send — including to addresses you bought or scraped |
| You must be able to prove consent | Art. 7(1) GDPR | Store the confirmation trail per subscriber, not just a checkbox state |
| Withdrawal as easy as consent was | Art. 7(3) GDPR | One-click unsubscribe in every email, no login, no reason required |
| Information at the moment of collection | Art. 13 GDPR | Who you are, what you send, retention, right to withdraw — linked at the form |
| Contract with your email provider | Art. 28 GDPR | A signed processing agreement (DPA) before the first import |
| Record of processing activities | Art. 30 GDPR | One entry describing the newsletter processing |
| Fine ceiling for consent breaches | Art. 83(5) GDPR | Up to €20 million or 4 % of worldwide annual turnover, whichever is higher |
In Germany the realistic risk for a small sender is not that ceiling. It is a cease-and-desist letter from a competitor or a consumer association under the UWG, with costs attached — cheaper than a fine, still expensive enough to ruin a month.
Do I really need double opt-in?
No law names it. What the law names is the proof requirement in Art. 7(1) GDPR: if the lawfulness of your sending is questioned, you have to show that this specific person consented. A single opt-in gives you a form submission — which anyone could have made with someone else's address. A double opt-in gives you a confirmation click from the mailbox itself, which is why it is the standard every reputable EU provider builds around.
Two details people get wrong. First, the confirmation email must stay plain: German courts have treated a confirmation message that also carries advertising as an unsolicited advert in its own right. Second, an unconfirmed address is not a subscriber — do not mail it a reminder series, and delete it after a short grace period.
What a valid consent looks like
Consent under Art. 4(11) and Art. 7 GDPR has to be freely given, specific, informed and unambiguous. Translated into a signup form:
- Unticked by default. A pre-checked box is not consent, and never was.
- Specific about what you will send. "Newsletter with tips and offers on X" — not a blanket "information".
- Separate from other agreements. Do not bundle the newsletter into your terms or a purchase confirmation.
- Not the price of something else. If a lead magnet is only available in exchange for a marketing consent, that consent is on shaky ground (Art. 7(4) GDPR). Safer: give the download to everyone who confirms the address, and ask for the marketing consent as a distinct, honest yes.
- Withdrawable at any time, and you must say so at the form (Art. 7(3), Art. 13 GDPR).
What you must be able to show years later
This is the part almost everyone under-builds. Keep, per subscriber, for as long as you mail them and a reasonable period after:
- Timestamp of the signup and of the confirmation click
- The IP address recorded at each of those two moments
- The exact wording of the consent text as it stood on that day
- The URL of the form and the confirmation link that was sent
Any serious provider logs this automatically. Before you commit to one, open a test subscriber record and check that you can actually export those fields — several tools show them in the interface but not in any export, which is worth knowing before you need them.
The existing-customer exception — and what the ECJ changed
Germany's § 7(3) UWG lets you email your own customers without a fresh consent, but only if all four conditions hold at once:
- You obtained the address in connection with the sale of goods or services
- You advertise only your own similar goods or services
- You told the customer clearly at collection that the address would be used this way
- Every message carries a free, simple way to object
On 13 November 2025 the Court of Justice of the EU decided case C-654/23 (Inteligo Media) and read the equivalent exception in Art. 13(2) of the ePrivacy Directive more broadly than many had assumed: registering for a free service can be enough to bring someone inside it — a purchase is not strictly required. It is a genuine relief for freemium models, but it changes only the first condition. The other three still have to hold, advertising to people who are not your customers still needs consent, and passing addresses to third parties for their advertising still needs an explicit yes.
Your provider is part of your compliance
You stay the controller; your email tool is a processor. That means a processing agreement under Art. 28 GDPR before the first contact is imported — every established provider offers one, usually as a click-through in the account. Then two questions decide the rest:
- Where does the data sit, and who are the sub-processors? Check the provider's current sub-processor list rather than a comparison article, this one included — the list is the only version that is up to date.
- If any of it touches the US, what is the transfer built on? The European Commission's adequacy decision for the EU–US Data Privacy Framework (10 July 2023) makes transfers to certified US companies lawful today. It is also under challenge at the CJEU, so a purely EU-hosted setup is the lower-maintenance choice if you have a free pick.
Among the tools we cover, KlickTipp* is the one built explicitly around the German market and is the usual answer when data residency is the deciding factor. MailerLite* (Lithuania) and GetResponse* (Poland) are both EU companies with DPAs available in-account. On a zero budget, Systeme.io* covers list and funnel in one. Whichever you pick, verify the current hosting and sub-processor details in the provider's own documents — that is the check, not the brand name. Our comparison of the five tools covers everything else about them.
The five mistakes that cause most trouble
- Importing a list you did not build. Consent does not transfer with a spreadsheet. Business cards from a trade fair are not consent either.
- Advertising inside the confirmation email. Keep it to one sentence and one button.
- Mailing unconfirmed addresses. They are prospects in your form log, not subscribers.
- Unsubscribe that demands a login or a reason. Art. 7(3) GDPR wants it as easy as saying yes was.
- Changing what you send without asking again. Consent for a weekly tips newsletter does not cover a daily promotional blast.
Conclusion
A compliant list is not a legal project, it is four settings and one contract. Fix the form wording, switch on double opt-in, confirm you can export the consent log, sign the DPA. Then spend your attention on the part that actually earns money — getting the mail delivered and read, which we cover in the deliverability guide. If you have not chosen a provider yet, our free tool quiz gives you a recommendation in under a minute.
Please note: this is general orientation, not legal advice. For your specific setup — especially B2B outreach or an international list — ask a lawyer.
Frequently asked questions
Is double opt-in legally required in the EU?
Not by name. What is required is proof of consent under Art. 7(1) GDPR, and double opt-in is the only method that reliably delivers it for a web signup, because the confirmation click comes from the mailbox itself. Every established EU provider therefore builds around it.
Can I email people who gave me a business card?
Handing over a card is not consent to marketing email. It may open a business conversation, but a newsletter needs either an explicit consent or all four conditions of the existing-customer exception in § 7(3) UWG.
How long do I have to keep the consent records?
For as long as you send to that address, plus a reasonable period afterwards, because the proof obligation only matters when someone objects. Once the person unsubscribes, keep the minimum needed to show the consent existed and to honour the objection — and nothing else.
Is a US email provider allowed under GDPR?
Yes, if the transfer rests on a valid basis — most commonly the EU–US Data Privacy Framework adequacy decision of 10 July 2023, or standard contractual clauses. That framework is currently under challenge at the CJEU, which is why an EU-hosted provider is the lower-maintenance option when you are free to choose.
What happens if I get it wrong?
Art. 83(5) GDPR allows fines up to €20 million or 4 % of worldwide annual turnover. For a small sender the realistic outcome is different and closer to home: a cease-and-desist letter from a competitor or a consumer association, with the costs and an injunction attached.
Keep reading
Email Funnel: What It Actually Is, and the Four Worth Building
The difference between a newsletter and a funnel is not the software. It is the trigger — and that single decision explains the most striking ratio in email marketing.
ReviewFunnelCockpit Review 2026: Is the German All-in-One Funnel Software Worth It?
An honest look at FunnelCockpit — what the German funnel software does, what it costs, and who should use it.