Insights · uk consent

The soft opt in rules UK ecommerce brands have to follow

What PECR lets you send to past customers, where the line sits, and the record that decides which side of it you are on.

Wooden map pieces mounted on a white wall, the United Kingdom and Ireland lifted clear of the engraved European mainland beside them
Theo Tziapouras, founder and strategy at Engage Commerce
Theo TziapourasFounder and strategy
11 August 2026 1,218 words6 minute read
In short · six parts

The soft opt-in is why you can email somebody who bought from you without a tick box. It's narrower than most brands assume, the conditions have to be met every time, not once, and it falls apart the moment you can't show where an address came from.

A hand holding a loyalty card in front of an open laptop showing a shopping site, the screen bright and the room dark behind it

What the soft opt in actually says

Look, it isn't a right. It lives in PECR, the Privacy and Electronic Communications Regulations, and it's an exception. The Information Commissioner's Office publishes the plain reading in its direct marketing guidance, which is short enough to read in a lunch break.

  • You got the contact details in the course of a sale, or of negotiations for a sale, with that person
  • What you're sending is marketing for your own similar products or services
  • They were given a simple way to refuse when you collected the address
  • They're given a simple way to refuse in every message you send after that

All four, every time. Miss the last one and the first three stop helping you, which is why an unsubscribe link is a condition of the exception, not a courtesy.

The phrase that settles most of the arguments

Similar means similar to what they bought or were about to buy, from you. Not from a sister brand, and not from the partner you share a warehouse with. A candle buyer hearing about candles is clearly fine. The same address hearing about your new insurance product clearly isn't.

Most catalogues sit somewhere between those two. The honest test is whether the customer would recognise the message as coming from the shop they bought from. Having to explain the connection in the first line of the email? You've answered your own question.

If you cannot show where an address came from, you do not have consent

Here's the hard truth: the thing that fails an audit is never the law. It's the paperwork. A regulator, or a buyer doing diligence on your business, asks the same question every time: where this person came from, and what they were told at the time.

  • The source of every profile, stamped at the moment it arrived and never reconstructed later
  • The wording that was on screen when they gave you the address, kept with the date it changed
  • Which addresses came in from an older platform, and what anybody can actually prove about them
  • Suppressions carried across every migration, so a refusal outlives the tool you were using at the time
  • A separate record for text messages, because that consent isn't the same consent

Setting it up so the answer lives in the account

Stamp the source on the profile as it arrives, and keep buyers who never opted in to marketing apart from subscribers who did. One is a soft opt-in audience with a narrow licence. The other is a consented list. They aren't the same people even when the names overlap. The glossary has the vocabulary if the difference between suppressed, unsubscribed and never subscribed isn't yet second nature.

Then let the flows respect that. The post purchase flow is the natural home for soft opt-in sending, because it's aimed at somebody who bought a thing and is hearing about that thing. The wider calendar is where brands drift.

None of this is legal advice, and if the answer matters to your board, ask a solicitor, not an agency. What we can tell you is what an account looks like once the question has been taken seriously. Sources, dates and honest segments.

Where brands cross it without noticing

Where the address came fromCoveredWhy
They bought from youYes, if the four conditions were metThis is the situation the exception was written for
They abandoned a checkoutUsually, on our readingThe guidance covers details taken during negotiations for a sale, and a checkout is a negotiation
They browsed and leftNoNothing was negotiated, so you are back to needing consent
They entered a competitionNoA prize draw is not a sale, whatever the entry form implied
A list you bought or inheritedNoConsent does not transfer with a spreadsheet, and neither does the soft opt-in
A business contactDifferent rulesCorporate subscribers sit outside this test, though sole traders and partnerships do not

The pattern is easy to spot once you look for it. Every crossing starts with somebody treating the soft opt-in as a licence to email anybody in the database, instead of a narrow permission attached to one customer and one sort of product.

Theo Tziapouras, founder and strategy at Engage Commerce

Theo Tziapouras

Founder and strategy at Engage Commerce, the ecommerce agency for 7 and 8 figure DTC brands.

Does the soft opt-in cover abandoned basket emails?

On our reading, usually yes. The exception covers details obtained during negotiations for a sale, and somebody who reached your checkout and stopped has negotiated. Somebody who looked at a product page hasn't. Keep the content close to what they were buying, and give them the same easy way out you give everybody else.

Can I email customers who bought years ago?

The rule sets no expiry, but a regulator will look at whether the person would still expect to hear from you, and a mailbox provider will look at whether anybody engages. Both go the same way with an old list. Send to it deliberately, watch complaints, and let people go instead of keeping them for the count.

Do I still need an unsubscribe link if they bought from me?

Yes, in every message. A simple means of refusing at the point of collection and in each message afterwards is one of the conditions of the exception, not an optional extra. Drop it and you've lost the ground you were standing on.

Is a pre-ticked box valid consent in the UK?

No. Consent has to be a positive action, so the box starts empty and the person ticks it. Bundling marketing consent into the terms and conditions fails for the same reason, and so does making it a condition of buying something.

Not got your answer?Chat to us
End matter

Treat it as a standard, not a loophole

The brands that get this right aren't the ones with the longest privacy policy. They're the ones who can tell you, in a minute, where any address in the account came from and what it was told. That habit costs almost nothing to start and is close to impossible to backfill, which is why we set it up first instead of tidying it later. Picking an agency? Ask how they handle it before you ask about revenue: the buyer's guide has the rest of the questions.

Theo TziapourasFounder and strategy · Engage Commerce

Would you rather this was just handled?

Bring your Klaviyo account and the thing annoying you most. We will tell you what we would fix first, on the call, before you spend anything.

Engage CommerceTheo Tziapouras, founder of Engage Commerce

Book a call with our founder.

We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊