Marketing consent
Marketing consent is a person's permission for a store to send them promotional messages, such as offers and newsletters by email or text message.
How it works
In the EU, the ePrivacy Directive allows marketing by email, including text messages (SMS), only to people who have given their consent in advance. The GDPR sets what counts as consent: freely given, specific, informed and unambiguous, shown by a statement or a clear affirmative action. Silence, pre-ticked boxes or inactivity are not consent. The store must be able to show that the person consented, and withdrawing consent must be as easy as giving it.
The directive has one exception, sometimes called the soft opt-in. A store that got a customer’s email address during a sale may use it to market its own similar products. The customer must get a free and easy way to object, both when the address is collected and in every message.
Double opt-in, where the person confirms by clicking a link in a first email, is not a GDPR term. It is one way to keep the proof the GDPR asks for.
Each EU country writes the ePrivacy Directive into its own law, so details differ. Our guide to choosing a messaging channel compares SMS and messenger apps.
Where you see it
- Sign-up form and checkout: an unticked box of its own, separate from accepting the terms of sale. When the store asks for consent in a declaration that also covers other matters, the GDPR requires the request to be clearly distinguishable from them.
Not to be confused with
- Consent Mode — passes a visitor’s cookie choice to Google tags. Accepting cookies on a banner is not permission to receive offers.
Right and wrong readings
- Wrong: “A customer who placed an order has agreed to our newsletter.” Right: without separate consent, only the soft opt-in applies: the store’s own similar products, with a free way to object at collection and in every message.
- Wrong: “Newsletter subscribers can be uploaded to Customer Match as they are.” Right: each upload records consent on two points: sending the data to Google for advertising (
ad_user_data) and using it for personalised ads (ad_personalization). If consent is missing for EEA users, Google treats them as not consented and does not process their data.
Sources
- Regulation (EU) 2016/679 (GDPR) — Article 4(11), Article 7, recital 32. Checked 2 October 2026.
- Directive 2002/58/EC — recital 40; Article 13 of the consolidated text. Checked 2 October 2026.
- Get started with Customer Match — Google Ads API: consent for EEA users. Checked 2 October 2026.