The question of whether to pre-check email marketing opt-in boxes at Shopify checkouts, considering GDPR, CASL, and deliverability, elicits a largely negative consensus. While Shopify allows pre-selection, experts and marketers overwhelmingly advise against it. The core issue is consent. GDPR, CASL, and other data privacy regulations mandate explicit, active consent. Pre-checked boxes assume consent, which is non-compliant and can lead to legal ramifications. Furthermore, assuming consent can increase spam complaints, lower engagement, and damage sender reputation, negatively impacting deliverability. Though some sources suggest that recent interaction might yield good metrics regardless, the prevailing recommendation is to prioritize legal compliance, ethical data collection, and respecting user choice by implementing unchecked opt-in boxes and clear, unambiguous language.
11 marketer opinions
The question revolves around whether Shopify checkout opt-in boxes for email marketing should be pre-checked, considering GDPR, CASL, and email deliverability implications. The answers present a mixed perspective. Some argue that pre-checked boxes can increase sign-ups, leading to potentially good metrics due to recent customer interaction. However, the consensus leans towards avoiding pre-checked boxes for legal (GDPR, CASL) and deliverability reasons. GDPR and CASL require explicit consent, which pre-checked boxes do not provide. This lack of explicit consent can lead to increased spam complaints, lower engagement rates, and ultimately, damage sender reputation and brand trust. While a Shopify representative suggested that it is ok as long as an easy unsubscribe link is included, the strong majority of marketers disagree.
Marketer view
Email marketer from Marketing Forum says the same issues related to GDPR also exist in CASL (Canadian Anti-Spam Legislation) - you must obtain express consent, so prechecked boxes should not be used when trying to comply with these laws.
17 Nov 2021 - Marketing Forum
Marketer view
Email marketer from Deliverability Blog notes that the same issues related to purchased email lists can impact deliverability for those using pre-checked boxes - assuming consent where it has not been given will increase bounces, spam reports and negatively impact sender reputation.
19 Jan 2023 - Deliverability Blog
5 expert opinions
Experts uniformly advise against pre-checking opt-in boxes for email marketing, particularly in the context of Shopify checkouts, GDPR, and deliverability. A central theme is that pre-checked boxes assume permission, which is not equivalent to obtaining explicit consent. This assumption can lead to legal issues, negative impacts on deliverability (spam complaints, bounces), and damaged brand reputation. The consensus emphasizes the need for active, unambiguous consent from subscribers. The decision to use pre-checked boxes ultimately depends on a company's risk tolerance, but experts advise against it.
Expert view
Expert from Email Geeks highlights that the decision regarding pre-checked boxes is an internal company decision based on their risk assessment. Some companies prioritize acquiring more addresses and are prepared to handle any resulting delivery or legal issues.
6 Aug 2022 - Email Geeks
Expert view
Expert from Spam Resource covers permission and consent where the post states that permission is NOT consent. Permission can be assumed or inferred but is not enough to meet current requirements. Consent is when someone actively says YES I want to receive messages. This is needed to remain compliant.
25 Feb 2023 - Spam Resource
4 technical articles
The provided documentation from Shopify, GDPR.EU, the ICO, and the Canadian Government uniformly indicates that pre-checked opt-in boxes for email marketing at Shopify checkouts are problematic from a legal compliance standpoint. Shopify allows merchants to set the marketing option as preselected, however, GDPR, ICO and CASL documentation states consent must be freely given, specific, informed, and unambiguous, requiring a positive opt-in, and pre-checked boxes are explicitly non-compliant. These regulations require express consent that cannot be assumed.
Technical article
Documentation from the ICO (UK's data protection authority) specifies that consent requires a positive opt-in. A pre-ticked box is not indicative of a freely given specific and informed indication of the data subject's wishes. The ICO enforces GDPR.
25 Feb 2025 - ICO
Technical article
Documentation from GDPR.EU clearly states that consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes are explicitly mentioned as not meeting the requirement for unambiguous consent, making them non-compliant with GDPR.
12 Jul 2021 - GDPR.EU
Are cold outreach 'best practices' actually illegal spam tactics?
Do email marketing opt-outs ever expire?
How are Gmail and Yahoo enforcing unsubscribe requests, and what factors do they consider for compliance?
How can I prevent fake email addresses from being added at checkout and causing hard bounces?
How can I reduce spam rates and improve consent for welcome footer flows in email marketing?