Guide
GDPR and email courses: consent, records, and erasure
Last reviewed 18 September 2026
Under the GDPR, consent to receive marketing email must be freely given, specific, informed and unambiguous, given by a statement or a clear affirmative action (Art. 4(11)). Article 7(1) puts the burden of proof on you: you must be able to demonstrate that the person consented, which in practice means recording what they were shown, what they agreed to, when, and from where. None of this is legal advice; it is what the text says, with the articles named so you can read them.
The GDPR does not contain the phrase "double opt-in", does not set a retention period for a mailing list, and does not name a mechanism for anything. What it does is define consent, put the burden of proving it on whoever relies on it, and give people a set of rights that a list has to be built to honour. Everything below is a description of the text and of the regulators’ published guidance on it, with article numbers so you can check. It is not legal advice, and a sender with real exposure should get some.
What consent has to be, in the words of the text
Article 4(11) defines consent as "any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her". Four adjectives and one mechanism, and each of the four rules something out.
Freely given rules out consent as the price of something unrelated. Article 7(4) says that in assessing whether consent was freely given, account must be taken of whether the performance of a contract was made conditional on consent to processing that is not necessary for it. Specific rules out one tick covering a course, a newsletter and a partner’s offers. Informed means they knew who you are and what you would do. Unambiguous, with the "clear affirmative action" in the definition, rules out a pre-ticked box, silence and inactivity, which Recital 32 names directly.
Article 7(2) adds that where consent is given in a written declaration covering other matters, the request for consent must be presented in a manner clearly distinguishable from those other matters, in intelligible and plain language. Article 7(3) says consent can be withdrawn at any time, that withdrawal must be as easy as giving it, and that people must be told this before they consent. An unsubscribe that takes more effort than the sign-up did is the everyday version of failing that requirement.
The burden of proof is yours, so record the consent
Article 7(1): "Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data." That single sentence is what turns consent from a state of mind into a record, and it is the practical reason confirmed opt-in exists. A form submission demonstrates that a browser sent you a string. A confirmation click demonstrates that whoever reads that mailbox acted.
What a record has to contain is not enumerated in the regulation, but it follows from the definition: to demonstrate that consent was specific and informed you need to be able to reproduce what was said at the time, not what your form says today. Wording changes. A record that points at a live page is a record of your current copy.
| What to record | What it demonstrates | Example |
|---|---|---|
| The address itself | That the consent attaches to an identifiable person | [email protected] |
| When the form was submitted, to the second, with time zone | That a request was made, and when the clock started | 2026-09-18T09:14:07Z |
| When the confirmation link was clicked, and the IP it came from | Unambiguous agreement by a clear affirmative action, Art. 4(11) | 2026-09-18T09:15:41Z from 203.0.113.9 |
| The exact consent sentence displayed beside the form, stored as text | That consent was informed, and reproducible after the page changes | "Send me [the course title]. Five emails, one a day. Unsubscribe any time." |
| What they were agreeing to receive, named | That consent was specific rather than a blanket permission | The course [the course title], not "all marketing" |
| Where it happened: the page URL, and the source if it was not your own page | The context, which is what makes "freely given" checkable later | https://example.com/courses/[slug] |
The soft opt-in, and why it is not in the GDPR
Electronic marketing is governed by two instruments, and the one that decides whether you may send unsolicited mail is not the GDPR. It is the ePrivacy Directive, 2002/58/EC as amended, implemented in national law in each member state, and in the United Kingdom as the Privacy and Electronic Communications Regulations. That is where the rule about unsolicited commercial email lives, and the GDPR supplies the definition of the consent it refers to.
Those rules contain a narrow exception, usually called the soft opt-in. Where a person’s details were obtained in the course of a sale or negotiations for a sale, the seller may market their own similar products and services to them, provided the person was given a clear opportunity to object when the details were collected and is given one in every message. The ICO’s direct marketing guidance sets out how narrowly each of those conditions is read: your own products, similar ones, a real sale or negotiation, and an opt-out offered at collection.
Two things follow for a course sender. A list of people who bought something from you is not automatically a list you may send a course to, and it is certainly not a list you may sell access to. And the exception is national law rather than the GDPR, so it differs between member states and it is the one place where being in one country rather than another genuinely changes the answer.
Erasure, and how a suppression list survives it
Article 17 gives a right to erasure, including where consent has been withdrawn and there is no other legal ground for the processing. Article 21(2) gives an absolute right to object to processing for direct marketing purposes, and Article 21(3) says that once someone objects, the personal data shall no longer be processed for those purposes. There is no balancing test for marketing. They say stop, you stop.
That creates an obvious tension with a suppression list, which exists precisely so that you never mail the address again and which is therefore a record of a person who asked you to delete their data. The way it is usually resolved is to keep the minimum necessary to honour the request rather than the record itself: a one-way hash of the normalised address, with no name, no history and no profile attached, checked before every send. What is retained is then not a subscriber but a prohibition.
Article 17(3) lists the grounds on which erasure does not apply, including processing necessary for compliance with a legal obligation. The ICO’s guidance is explicit that keeping a suppression record is the right way to honour an objection to marketing rather than a breach of it, and the same logic runs through the EDPB’s material on the interaction between the two. Say what you keep and why in the privacy notice, keep nothing beyond the hash, and never let a suppression entry be the seed of a re-import.
What the privacy notice has to say
Article 13 sets out what must be told to a person at the point their data is collected from them, and it is a list rather than a sentiment. Who you are and how to contact you. The purposes of the processing and the legal basis for each. Any recipients of the data. Whether it is transferred outside the EU and on what safeguard. How long it is kept, or the criteria used to decide. The rights to access, rectification, erasure, restriction, objection and portability. The right to withdraw consent at any time. The right to lodge a complaint with a supervisory authority.
For a small sender this is one page, written in plain language, linked from beside the sign-up form rather than only from the footer, because Article 13 requires the information at the time the data is obtained. The most commonly missing items are the specific ones: the actual retention period, the actual named processors, and the right to complain to a supervisory authority.
Processors, sub-processors and transfers
If you run a list, you are the controller. Your sending provider, your database host and your analytics are processors, and Article 28 requires a written contract with each of them containing a specific set of terms, which providers publish as a data processing agreement. Article 28(2) says a processor may not engage a sub-processor without your authorisation, which is why providers publish sub-processor lists and notify changes. Reading that list is how you find out which countries your subscribers’ addresses are actually stored in.
Transfers outside the EU are governed by Chapter V. A transfer to a country covered by an adequacy decision under Article 45 needs no further instrument; otherwise the usual route is the Commission’s standard contractual clauses under Article 46, with a transfer impact assessment on top. In practice this is a matter of choosing providers and then naming them, honestly, in the privacy notice, rather than of drafting anything yourself.
Common questions
Does the GDPR require double opt-in?
No. The regulation names no mechanism. It defines consent as freely given, specific, informed and unambiguous, given by a statement or clear affirmative action (Art. 4(11)), and requires you to be able to demonstrate it (Art. 7(1)). A confirmation click is the cheapest way to hold that evidence, which is why it is so common, not because it is prescribed.
What has to be in a consent record?
Enough to reproduce what happened: the address, when the form was submitted, when the confirmation link was clicked, the exact consent wording shown at the time, what the person was agreeing to receive, and where it happened. Article 7(1) puts the burden of proof on the controller, so a record that points at a live page rather than stored text is a record of your current copy.
Can I email people who bought from me without asking again?
Possibly, under the soft opt-in in national ePrivacy law rather than under the GDPR. It applies where the details were obtained in the course of a sale or negotiations for one, covers only your own similar products, and requires that an opportunity to object was given at collection and in every message. The ICO reads each of those conditions narrowly, and the detail differs between countries.
If someone asks to be deleted, can I keep them on a suppression list?
That is the usual way to honour an objection to marketing rather than a breach of it, provided you keep only what is needed to avoid mailing them again: a one-way hash of the address, no name, no history, no profile. Article 21(3) requires you to stop marketing to them, and a suppression check is how you comply. Say what you keep, and why, in the privacy notice.
The short version for an email course: ask for consent in a sentence that names what you will send, take a confirmation click, store the six things in the table with the timestamps, honour a withdrawal faster than the rules require, keep a hashed suppression list and say so in the notice, and name your processors. That is most of the compliance work and nearly all of the trust. The articles are linked below so you can read the text rather than a summary of it.
Sources
Read next
This page is part of Email deliverability for small senders: authentication and reputation, which is the complete guide to the subject.
- Email deliverability for small senders: authentication and reputation
What deliverability is, how SPF, DKIM and DMARC fit together, and what the Google and Yahoo bulk sender rules require of a small sender.
- Confirmed opt-in (double opt-in): what it costs, and what it buys
What double opt-in (confirmed opt-in) is, what it costs you in list size, and why the mailbox providers have settled the argument.
- Confirmation email template for double opt-in
Three confirmation emails written out in full: plain, warm, and re-permission for an imported list, with the reasoning for every line.
- How to set up SPF, DKIM and DMARC for a sending domain
The order to do it in: a dedicated sending subdomain, SPF, DKIM, DMARC at p=none, two weeks of reports, then quarantine and reject.
- CAN-SPAM for course senders: the footer checklist
The seven CAN-SPAM requirements from the FTC compliance guide, what they mean for an email course, and how the law differs from GDPR and CASL.
- Unsubscribe requirements: one-click, List-Unsubscribe and two days
What one-click unsubscribe requires under RFC 8058, the two-day honouring window in the Google and Yahoo rules, and what the endpoint must return.
These guides are about the format rather than about any particular tool. What this site itself does is on the home page, and the rest of the set is on the guides index .
Elsewhere on this site
The rest of this site comes at the same subject from other directions: guides on the format itself, a tool for one job each, a page for each kind of work, and what to check when choosing software.
Free tool
DMARC, SPF and DKIM checkerBy the work you do
Email courses for therapists and wellbeing practitionersBy the work you do
Email courses for nonprofits and charities
Thinking of writing one of these?
5dayemail hosts a five-to-ten day email course: you write it once, and everyone who joins your list gets one email a day, in order, starting from the day they confirm.
Accounts are opened a few at a time rather than by signing up. Leave your address and you will be written to when the next ones open.
One message, when there is room. No course emails, no newsletter, and the address is not passed on. Ask and it is deleted; what is kept, and for how long, is in the privacy policy.