Permission-based email: what counts as consent, and how to keep a record of it
What opt-in consent means for email, how GDPR, PECR, CAN-SPAM and CASL differ, and what a usable consent record contains. Not legal advice.
By the OutreachPro team at DanixSoft8 min read
Permission-based email means sending only to people who asked to hear from you, or who have an existing relationship with you that makes your message expected. It is a legal requirement in many places, a condition of Google’s and Microsoft’s terms for bulk mail, and the single biggest factor in whether mail reaches the inbox: people rarely mark mail they asked for as spam.
What counts as an opt-in
Consent is an affirmative act by the recipient, recorded at the time. Typical examples:
- Subscribing through a form on your site that says what they will receive.
- Confirming that subscription by clicking a link in a confirmation email (double opt-in), which also proves the address is real and theirs.
- Buying from you, where the law allows you to follow up with existing customers about similar products.
- Registering for an event, webinar or download where the form said follow-up email would be sent.
- Agreeing to it in a signed contract.
What does not count: an address you bought, scraped from a website or a directory, copied from someone else’s list, or collected for one purpose and reused for another. Having the address is not the same as having permission to email it.
How the main laws differ
- EU and UK (GDPR, and in the UK also PECR): marketing email to individuals generally needs prior consent. The UK’s “soft opt-in” allows marketing to existing customers about similar products, provided they were given a chance to refuse when their details were collected and in every message since.
- United States (CAN-SPAM): prior consent is not required, but every commercial message must identify the sender accurately, avoid deceptive subject lines, include a physical postal address and a working opt-out, and honour opt-outs within 10 business days.
- Canada (CASL): consent is required, either express or implied. Implied consent covers, for example, an existing business relationship such as a purchase within the past two years or an inquiry within the past six months.
Because your recipients may be anywhere, the practical standard is the strictest one that plausibly applies: have a clear opt-in, keep a record of it, and make leaving easy.
What a useful consent record contains
If someone asks why they received your email, or a platform reviewer asks how your list was built, a record lets you answer precisely. It should capture:
- The source: which form, purchase, event or agreement the address came from.
- The wording: what the person was told they would receive, ideally with a link to the page they saw.
- The date the person opted in, which is not the date you uploaded the list.
- Who attested to it on your side, and when.
How OutreachPro records it
Every CSV import requires a consent attestation: one of six sources (a signup form, double opt-in, existing customer, contract, event registration, or a referral the person asked for), a description in your own words, and optionally the URL of the disclosure and the date consent was given. Every address from that import carries the record. Addresses without one can be stored, but the sending queue will not accept them. There is deliberately no option for a bought or scraped list.
The other half of permission is letting people leave. Every message carries one-click unsubscribe headers and a visible link, and an unsubscribe suppresses the address across your whole account; the bulk sender rules explain why that matters to Gmail and Yahoo.