The soft opt in rules UK ecommerce brands have to follow
What PECR lets you send to past customers, where the line sits, and the record that decides which side of it you are on.
The soft opt-in is why you can email somebody who bought from you without a tick box. It's narrower than most brands assume, the conditions have to be met every time, not once, and it falls apart the moment you can't show where an address came from.

What the soft opt in actually says
Look, it isn't a right. It lives in PECR, the Privacy and Electronic Communications Regulations, and it's an exception. The Information Commissioner's Office publishes the plain reading in its direct marketing guidance, which is short enough to read in a lunch break.
- You got the contact details in the course of a sale, or of negotiations for a sale, with that person
- What you're sending is marketing for your own similar products or services
- They were given a simple way to refuse when you collected the address
- They're given a simple way to refuse in every message you send after that
All four, every time. Miss the last one and the first three stop helping you, which is why an unsubscribe link is a condition of the exception, not a courtesy.
The phrase that settles most of the arguments
Similar means similar to what they bought or were about to buy, from you. Not from a sister brand, and not from the partner you share a warehouse with. A candle buyer hearing about candles is clearly fine. The same address hearing about your new insurance product clearly isn't.
Most catalogues sit somewhere between those two. The honest test is whether the customer would recognise the message as coming from the shop they bought from. Having to explain the connection in the first line of the email? You've answered your own question.
What an opt in looks like when it is done properly
Where the soft opt-in doesn't apply, you need consent, and consent has a shape. An unticked box, wording that says who's sending and what they're sending, and a way out stated in the same breath.

That one's a text message sign-up, not an email one, and text is the stricter of the two, but the anatomy is the point. The box isn't pre-ticked, the sender is named, and how to stop is written where somebody might read it.
If you cannot show where an address came from, you do not have consent
Here's the hard truth: the thing that fails an audit is never the law. It's the paperwork. A regulator, or a buyer doing diligence on your business, asks the same question every time: where this person came from, and what they were told at the time.
- The source of every profile, stamped at the moment it arrived and never reconstructed later
- The wording that was on screen when they gave you the address, kept with the date it changed
- Which addresses came in from an older platform, and what anybody can actually prove about them
- Suppressions carried across every migration, so a refusal outlives the tool you were using at the time
- A separate record for text messages, because that consent isn't the same consent
Setting it up so the answer lives in the account
Stamp the source on the profile as it arrives, and keep buyers who never opted in to marketing apart from subscribers who did. One is a soft opt-in audience with a narrow licence. The other is a consented list. They aren't the same people even when the names overlap. The glossary has the vocabulary if the difference between suppressed, unsubscribed and never subscribed isn't yet second nature.
Then let the flows respect that. The post purchase flow is the natural home for soft opt-in sending, because it's aimed at somebody who bought a thing and is hearing about that thing. The wider calendar is where brands drift.
None of this is legal advice, and if the answer matters to your board, ask a solicitor, not an agency. What we can tell you is what an account looks like once the question has been taken seriously. Sources, dates and honest segments.
Where brands cross it without noticing
| Where the address came from | Covered | Why |
|---|---|---|
| They bought from you | Yes, if the four conditions were met | This is the situation the exception was written for |
| They abandoned a checkout | Usually, on our reading | The guidance covers details taken during negotiations for a sale, and a checkout is a negotiation |
| They browsed and left | No | Nothing was negotiated, so you are back to needing consent |
| They entered a competition | No | A prize draw is not a sale, whatever the entry form implied |
| A list you bought or inherited | No | Consent does not transfer with a spreadsheet, and neither does the soft opt-in |
| A business contact | Different rules | Corporate subscribers sit outside this test, though sole traders and partnerships do not |
The pattern is easy to spot once you look for it. Every crossing starts with somebody treating the soft opt-in as a licence to email anybody in the database, instead of a narrow permission attached to one customer and one sort of product.

Theo Tziapouras
Founder and strategy at Engage Commerce, the ecommerce agency for 7 and 8 figure DTC brands.
FAQs

Does the soft opt-in cover abandoned basket emails?
On our reading, usually yes. The exception covers details obtained during negotiations for a sale, and somebody who reached your checkout and stopped has negotiated. Somebody who looked at a product page hasn't. Keep the content close to what they were buying, and give them the same easy way out you give everybody else.
Can I email customers who bought years ago?
The rule sets no expiry, but a regulator will look at whether the person would still expect to hear from you, and a mailbox provider will look at whether anybody engages. Both go the same way with an old list. Send to it deliberately, watch complaints, and let people go instead of keeping them for the count.
Do I still need an unsubscribe link if they bought from me?
Yes, in every message. A simple means of refusing at the point of collection and in each message afterwards is one of the conditions of the exception, not an optional extra. Drop it and you've lost the ground you were standing on.
Is a pre-ticked box valid consent in the UK?
No. Consent has to be a positive action, so the box starts empty and the person ticks it. Bundling marketing consent into the terms and conditions fails for the same reason, and so does making it a condition of buying something.
Treat it as a standard, not a loophole
The brands that get this right aren't the ones with the longest privacy policy. They're the ones who can tell you, in a minute, where any address in the account came from and what it was told. That habit costs almost nothing to start and is close to impossible to backfill, which is why we set it up first instead of tidying it later. Picking an agency? Ask how they handle it before you ask about revenue: the buyer's guide has the rest of the questions.
Deliverability and UK consent
Getting into the inbox, and staying inside UK GDPR and PECR while you do it.

Email sending domain warm up: changing domains without wrecking the list
Reputation is attached to the domain, not to you. Move it and you start again, so the first question is whether you have to.
Read it
Your email open rate dropped suddenly: what to check, and in what order
Opens are a soft number now. A collapse still means something, and it is almost never the subject line.
Read it
The WhatsApp 24 hour window is the real reason your broadcasts keep failing
Free-form messages live inside a window the customer opens. Everything outside it is a template Meta has already judged, and keeps judging.
Read itWould you rather this was just handled?
Bring your Klaviyo account and the thing annoying you most. We will tell you what we would fix first, on the call, before you spend anything.


Book a call with our founder.
We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊



