UK GDPR email marketing consent: what a lawful sign-up looks like
What the ICO expects from an ecommerce sign-up form, written by people who configure them rather than people who argue about them afterwards.
Consent isn't a tick box you add at the end. It's the record of what somebody agreed to, when they agreed and what the form said at the time, and it either exists in your account or it doesn't. Most UK shops are one field and one screenshot away from being fine.

Two laws, one job, and only one of them is about email
Two laws, one job. UK GDPR sets the standard a consent has to meet. PECR is the rule saying you need one before you market by email or text. The Information Commissioner's Office enforces both, and its direct marketing guidance is worth reading in the original, not in somebody's summary of it.
- Freely given, so not the price of a discount you've already advertised
- Specific, so agreeing to email isn't agreeing to a text message
- Informed, so the person can see who's asking and what will arrive
- Unambiguous, meaning a positive action and never the absence of one
- Recorded, so you can show when it happened and what the form said that day
We're not lawyers and this isn't legal advice. It's what we configure on client accounts, checked against the regulator's own words, not against what everybody else's pop-up seems to get away with.
What a lawful sign-up form looks like in practice
The tick box is the easy part. The wording above it does the work. That sentence is where a person learns what they'll get, how often, and from which company.
The box is unticked, and the text messages are their own agreement, not a side effect of the email one. The small print names the brand, says how to stop, and links the privacy policy. Not a difficult shape to copy.
Why you can email a customer who never ticked anything
| Where the address came from | Can you market to it | What has to be true |
|---|---|---|
| They ticked the box on your form | Yes | The wording said email marketing, and you kept the record |
| They bought, and were offered an opt out | Within limits | Your own customer, similar products, an opt out in every message |
| They entered a competition | Only if it said so | The entry asked for marketing separately from the entry itself |
| A list you bought, rented or were handed | No | Consent does not transfer between companies |
| An old export from a previous platform | Only what it can prove | You need the original consent, not the import date |
That second row is why a shop can email past buyers who never ticked anything, and it's also where the trouble starts. A first order doesn't make somebody a subscriber to everything you'll ever launch, and the ICO sets out the conditions for electronic mail marketing in plain terms.
If you cannot show the record, you do not have consent
Nobody came into ecommerce to file paperwork. But consent is something you evidence, not something you remember. Klaviyo stores the method, the timestamp and the source against each profile, which is most of the job done as long as nobody imports over the top of it.

Keep a copy of the form wording every time you change it. When somebody asks in the autumn what they agreed to in March, the honest answer is a screenshot of what March's form said. Not the wording sitting on the site today.
The five ways UK shops end up with addresses they cannot use
None of these happen in bad faith. They happen when list growth is somebody's target and consent is nobody's.
- A competition entry treated afterwards as a newsletter sign-up
- An old platform export imported whole, with the consent unknown
- A checkout tick that was really about order updates, reused for marketing
- Two brands under one company mailing each other's customers as one audience
- Unsubscribes honoured in one system and quietly reimported by another
The fix for all five is the same, and it's unpopular. Suppress what you can't evidence, then rebuild from a form that says what it means. Deliverability improves at the same time, because the addresses you lose weren't opening anything.
The half hour that puts most shops right
- Read your own sign-up form out loud and check it says who is asking and what arrives
- Untick anything pre-ticked, and separate email consent from text message consent
- Screenshot the form and the privacy policy, and file them with today's date on them
- Look at what your last import did to consent records, especially after a platform move
- Make the unsubscribe obvious, then honour it everywhere including inside the flows
Then leave it alone. Consent isn't a project with an end date, but it's something you can be straight about in an afternoon, and the welcome flow is where the promise the form made has to be kept.

Theo Tziapouras
Founder and strategy at Engage Commerce, the ecommerce agency for 7 and 8 figure DTC brands.
FAQs

Do I need double opt-in in the UK?
No. Neither UK GDPR nor PECR asks for a confirmation email, and a single opt-in with clear wording is lawful. Double opt-in is a deliverability decision, not a legal one: it costs you subscribers and buys you a cleaner list. We turn it on for lists with a history of junk sign-ups.
Can I email people who bought but never subscribed?
Often yes, under the soft opt-in. It covers your own customers, for similar products, where you offered an opt out when you took the address and offer one in every message afterwards. It doesn't stretch to a sister brand they've never bought from, and it doesn't stretch forever.
How long does consent last?
There's no expiry date written into the law, but the regulator expects it to be current, and somebody who has ignored two years of email isn't meaningfully agreeing to anything. We suppress on engagement long before the legal question arrives, because the mailbox providers get there first.
What has to be inside the email itself?
Who's sending it, an easy way to stop receiving it, and a contactable address for the sender. The unsubscribe has to work first time and be honoured across every list and flow, not only the campaign the person happened to click it in.
Does a pre-ticked box count as consent?
No. Consent has to be a positive action, so a box somebody has to untick isn't consent under UK GDPR. Same goes for marketing consent bundled into terms and conditions, and for a form where the only route to the discount is agreeing to be marketed to.
Consent is an asset, not a chore
A list you can evidence is a list you can send to at volume without flinching, and that's the whole point of building one. The brands who end up audited by their own inbox placement are the ones who cut corners on the form. Addresses that were never really theirs are the addresses that never open.
Deliverability and UK consent
Getting into the inbox, and staying inside UK GDPR and PECR while you do it.

How to set up DMARC for Klaviyo, and what SPF and DKIM do first
Three DNS records, one order to publish them in, and the mistake that stops a Shopify brand's sends reaching anybody at all.
Read it
The soft opt in rules UK ecommerce brands have to follow
What PECR lets you send to past customers, where the line sits, and the record that decides which side of it you are on.
Read it
Email sending domain warm up: changing domains without wrecking the list
Reputation is attached to the domain, not to you. Move it and you start again, so the first question is whether you have to.
Read itWould you rather this was just handled?
Bring your Klaviyo account and the thing annoying you most. We will tell you what we would fix first, on the call, before you spend anything.


Book a call with our founder.
We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊



