Newsletter sign-ups: double opt-in and what proof you need

What European rules require before you email someone marketing, why double opt-in is the practical standard, and what records you must be able to produce.

4 minread 822words last updated

The short answer

Sending marketing email to individuals in Europe generally requires their prior consent, obtained before the first message and provable afterwards. National rules implementing the European e-privacy regime add a narrow exception for existing customers, letting you contact them about your own similar products or services provided they were given the opportunity to object when their details were collected and are given it in every message; the Dutch regulator’s page below sets out how that works here. Everything else, cards collected at events, addresses found online, contacts imported from a CRM for a purpose they never agreed to, and bought lists, falls outside it. Consent must be freely given, specific, informed and unambiguous, which means an unticked box with clear wording about what they will receive, never bundled with other terms and never a condition of submitting a contact form. Double opt-in, where the subscriber confirms through a link, is not spelled out in the regulation but is the practical way to demonstrate consent and to prove that the person who owns the address gave it. Every message must carry an easy, working unsubscribe that is honoured promptly.

What valid sign-up looks like

ElementRequirement
The boxUnticked, separate from other agreements, never required to access something else
The wordingWhat they will receive, how often, from whom, in plain language
The basisConsent for marketing; the customer exception only where it genuinely applies
ConfirmationA confirmation email with a single-purpose link; subscription only on confirmation
The recordTimestamp, wording shown, method, source page, confirmation event, stored and exportable
Every messageSender identity, a working unsubscribe, and a way to see or change preferences
UnsubscribesHonoured promptly and permanently, including across list imports
SharingNever to third parties unless specifically consented
ChildrenExtra care; age thresholds apply for information society services

Building a list you can defend

  1. Use an unticked, separate box with wording describing what the subscriber gets.
  2. Turn on double opt-in in your email platform, and check that the confirmation email is clear and single-purpose.
  3. Verify the records your platform keeps, and that they survive an export or a platform migration.
  4. Never import cards, scraped addresses, bought lists or CRM contacts collected for other purposes.
  5. Segment existing customers separately if you rely on the customer exception, and document why it applies.
  6. Include unsubscribe and preferences in every message, and process them promptly.
  7. Clean the list of never-engaged and long-dormant addresses, which is good for deliverability as well as compliance.
  8. Review annually, including the wording, which tends to drift from what you actually send.

Why this is also good marketing

A list built on explicit confirmation is smaller and performs better: higher open rates, fewer spam complaints, better deliverability for the whole domain, and recipients who actually want the messages. The practices that make a list lawful, clear wording, confirmation, easy unsubscribe, regular cleaning, are the same ones that keep it out of spam folders. Businesses that buy or scrape lists get worse results as well as legal exposure.

What this means for you

Get explicit consent before marketing email, use double opt-in so you can prove it, keep records of the wording, time and confirmation for every subscriber, and put a working unsubscribe in every message. Rely on the existing-customer exception only where it genuinely applies, never import lists collected for other purposes, and carry consent records through any platform migration. The result is a list that is both defensible and more effective. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Is double opt-in legally required?

The regulation requires consent that is freely given, specific, informed and unambiguous, and it requires you to be able to demonstrate it. Double opt-in, where the subscriber confirms via a link in an email, is the most straightforward way to satisfy the demonstration requirement and to prove the address belonged to the person who consented. Single opt-in can be lawful with strong records, but double opt-in is what we recommend because it is defensible and it produces a better list.

Can we email people who gave us their business card?

Exchanging a card is not consent to marketing email. There is a limited exception allowing you to email existing customers about your own similar products or services, provided they were given the chance to object when their details were collected and in every message. A card at an event, a contact found on a website, or a name from a bought list are not covered. The safe route is an explicit opt-in.

What records do we have to keep?

Enough to demonstrate valid consent for each subscriber: the date and time, the wording they saw, the method, the source page or form, and the confirmation event if double opt-in. Email platforms record this if configured to; check that yours does and that the records survive list imports and platform changes. Without them, a complaint becomes your word against the subscriber's.

Sources

  1. EUR-Lex: Regulation (EU) 2016/679, Article 7 (accessed 2026-09-14)
  2. ACM: Spam voorkomen in uw reclame (accessed 2026-09-12)