Suped

Summary

While a client may suspect that double opt-in (DOI) is a strict General Data Protection Regulation (GDPR) requirement for subscribers in the UK and EMEA, the reality is more nuanced. GDPR does not explicitly mandate DOI. Instead, it focuses on the ability to prove consent for every recipient.

What email marketers say

Email marketers generally agree that while double opt-in (DOI) isn't a hard legal requirement under GDPR, it's a highly recommended practice for building high-quality lists and mitigating compliance risks. Many adopt it even for non-EU/UK audiences due to its benefits.

Marketer view

Marketer from Email Geeks indicates that double opt-in is not a direct requirement under GDPR. However, they emphasize that the fundamental requirement is to be able to explicitly prove consent for every subscriber. Double opt-in simplifies this proof.

28 Apr 2021 - Email Geeks

Marketer view

Marketer from Email Geeks explains that their client, a retailer, uses double opt-in for subscribers in the EU and UK. This practice was adopted because the client believed DOI to be a mandatory requirement under GDPR, even though it serves customers mostly in North America.

28 Apr 2021 - Email Geeks

What the experts say

Industry experts concur that while GDPR does not explicitly mandate double opt-in, it remains the most reliable and safest method for demonstrating unequivocal consent. They emphasize that the focus should be on proving consent, and DOI provides the strongest audit trail.

Expert view

Expert from Email Geeks explains that double opt-in is not a hard requirement under GDPR. However, they strongly advise that businesses must be able to prove consent for every recipient. They conclude that confirmed opt-in (DOI) is always a safe choice.

28 Apr 2021 - Email Geeks

Expert view

Expert from Email Geeks highlights that Germany has established case law supporting double opt-in as a valid method to prove consent. Additionally, German data protection authorities recommend using DOI for email subscriptions to ensure compliance.

28 Apr 2021 - Email Geeks

What the documentation says

Official GDPR documentation and related privacy guidance consistently emphasize the requirement for clear, affirmative consent for processing personal data, including for email marketing. While double opt-in is not named specifically, it's widely recognized as a robust mechanism to achieve this level of consent.

Technical article

Documentation from iubenda.com states that GDPR does not include a requirement for a double opt-in process. Nevertheless, it is widely considered a best practice in many countries, particularly within Germany and across the European Union, for ensuring robust consent.

1 Apr 2025 - iubenda.com

Technical article

Documentation from Securiti.ai clarifies that GDPR does not explicitly require double opt-in for consent compliance. It emphasizes, however, that GDPR demands consent to be unambiguous and affirmative, making strong consent mechanisms essential.

10 Mar 2025 - Securiti.ai

15 resources

Start improving your email deliverability today

Get started