Insights · uk consent

UK GDPR email marketing consent: what a lawful sign-up looks like

What the ICO expects from an ecommerce sign-up form, written by people who configure them rather than people who argue about them afterwards.

A wooden wall map of Europe with the United Kingdom and Ireland pieces closest to the camera and Germany behind them
Theo Tziapouras, founder and strategy at Engage Commerce
Theo TziapourasFounder and strategy
11 August 2026 1,192 words6 minute read
In short · six parts

Consent isn't a tick box you add at the end. It's the record of what somebody agreed to, when they agreed and what the form said at the time, and it either exists in your account or it doesn't. Most UK shops are one field and one screenshot away from being fine.

A sign-up pop-up over a natural health shop with a phone number field, a country flag selector, an unticked box for marketing texts and consent wording under the sign up button

Two laws, one job, and only one of them is about email

Two laws, one job. UK GDPR sets the standard a consent has to meet. PECR is the rule saying you need one before you market by email or text. The Information Commissioner's Office enforces both, and its direct marketing guidance is worth reading in the original, not in somebody's summary of it.

  • Freely given, so not the price of a discount you've already advertised
  • Specific, so agreeing to email isn't agreeing to a text message
  • Informed, so the person can see who's asking and what will arrive
  • Unambiguous, meaning a positive action and never the absence of one
  • Recorded, so you can show when it happened and what the form said that day

We're not lawyers and this isn't legal advice. It's what we configure on client accounts, checked against the regulator's own words, not against what everybody else's pop-up seems to get away with.

What a lawful sign-up form looks like in practice

The tick box is the easy part. The wording above it does the work. That sentence is where a person learns what they'll get, how often, and from which company.

The box is unticked, and the text messages are their own agreement, not a side effect of the email one. The small print names the brand, says how to stop, and links the privacy policy. Not a difficult shape to copy.

Why you can email a customer who never ticked anything

Where the address came fromCan you market to itWhat has to be true
They ticked the box on your formYesThe wording said email marketing, and you kept the record
They bought, and were offered an opt outWithin limitsYour own customer, similar products, an opt out in every message
They entered a competitionOnly if it said soThe entry asked for marketing separately from the entry itself
A list you bought, rented or were handedNoConsent does not transfer between companies
An old export from a previous platformOnly what it can proveYou need the original consent, not the import date

That second row is why a shop can email past buyers who never ticked anything, and it's also where the trouble starts. A first order doesn't make somebody a subscriber to everything you'll ever launch, and the ICO sets out the conditions for electronic mail marketing in plain terms.

If you cannot show the record, you do not have consent

Nobody came into ecommerce to file paperwork. But consent is something you evidence, not something you remember. Klaviyo stores the method, the timestamp and the source against each profile, which is most of the job done as long as nobody imports over the top of it.

A man lying on a grey sofa in a flat, reading something on his phone with kitchen shelves behind him

Keep a copy of the form wording every time you change it. When somebody asks in the autumn what they agreed to in March, the honest answer is a screenshot of what March's form said. Not the wording sitting on the site today.

The five ways UK shops end up with addresses they cannot use

None of these happen in bad faith. They happen when list growth is somebody's target and consent is nobody's.

  • A competition entry treated afterwards as a newsletter sign-up
  • An old platform export imported whole, with the consent unknown
  • A checkout tick that was really about order updates, reused for marketing
  • Two brands under one company mailing each other's customers as one audience
  • Unsubscribes honoured in one system and quietly reimported by another

The fix for all five is the same, and it's unpopular. Suppress what you can't evidence, then rebuild from a form that says what it means. Deliverability improves at the same time, because the addresses you lose weren't opening anything.

The half hour that puts most shops right

  1. Read your own sign-up form out loud and check it says who is asking and what arrives
  2. Untick anything pre-ticked, and separate email consent from text message consent
  3. Screenshot the form and the privacy policy, and file them with today's date on them
  4. Look at what your last import did to consent records, especially after a platform move
  5. Make the unsubscribe obvious, then honour it everywhere including inside the flows

Then leave it alone. Consent isn't a project with an end date, but it's something you can be straight about in an afternoon, and the welcome flow is where the promise the form made has to be kept.

Theo Tziapouras, founder and strategy at Engage Commerce

Theo Tziapouras

Founder and strategy at Engage Commerce, the ecommerce agency for 7 and 8 figure DTC brands.

Do I need double opt-in in the UK?

No. Neither UK GDPR nor PECR asks for a confirmation email, and a single opt-in with clear wording is lawful. Double opt-in is a deliverability decision, not a legal one: it costs you subscribers and buys you a cleaner list. We turn it on for lists with a history of junk sign-ups.

Can I email people who bought but never subscribed?

Often yes, under the soft opt-in. It covers your own customers, for similar products, where you offered an opt out when you took the address and offer one in every message afterwards. It doesn't stretch to a sister brand they've never bought from, and it doesn't stretch forever.

How long does consent last?

There's no expiry date written into the law, but the regulator expects it to be current, and somebody who has ignored two years of email isn't meaningfully agreeing to anything. We suppress on engagement long before the legal question arrives, because the mailbox providers get there first.

What has to be inside the email itself?

Who's sending it, an easy way to stop receiving it, and a contactable address for the sender. The unsubscribe has to work first time and be honoured across every list and flow, not only the campaign the person happened to click it in.

Does a pre-ticked box count as consent?

No. Consent has to be a positive action, so a box somebody has to untick isn't consent under UK GDPR. Same goes for marketing consent bundled into terms and conditions, and for a form where the only route to the discount is agreeing to be marketed to.

Not got your answer?Chat to us
End matter

Consent is an asset, not a chore

A list you can evidence is a list you can send to at volume without flinching, and that's the whole point of building one. The brands who end up audited by their own inbox placement are the ones who cut corners on the form. Addresses that were never really theirs are the addresses that never open.

Theo TziapourasFounder and strategy · Engage Commerce

Would you rather this was just handled?

Bring your Klaviyo account and the thing annoying you most. We will tell you what we would fix first, on the call, before you spend anything.

Engage CommerceTheo Tziapouras, founder of Engage Commerce

Book a call with our founder.

We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊