Kurato

Double opt-in and GDPR: what the law requires and what tools make of it

Most articles claim the GDPR mandates double opt-in. It does not, and the difference matters more in practice than it sounds.

Search for double opt-in and GDPR and most results will tell you the regulation demands it. It does not. The term appears in no article of the GDPR, and no provision describes a confirmation email.

That does not make the method pointless. It moves the reason. The GDPR requires you to prove consent. European rules on marketing email require consent before the first message goes out, with the detail written by each member state. Double opt-in is how both become something you can put in front of a lawyer, a regulator or an annoyed recipient.

Once you see that, you evaluate tools differently: the question becomes what ends up in the record and whether you can get it back out. What follows separates the legal text, the practice around it, and the places where tools promise a compliance they cannot deliver.

What the GDPR actually asks for

Three provisions matter for a newsletter signup.

  • Art. 6(1)(a): consent is one of the lawful bases you can rely on to process personal data.
  • Art. 7: conditions for consent. The sentence with the most consequences sits in paragraph 1: the controller must be able to demonstrate that the data subject consented.
  • Art. 5(2): accountability. Complying with the principles is not enough, you have to show that you comply.

That is all. No confirmation step, no second email, no deadline. The regulation describes an outcome: a freely given, informed, unambiguous act of consent that you can produce when asked. Getting there is your problem.

Why single opt-in rarely holds up

With a single opt-in you have an address and a timestamp. What you do not have is evidence that the person behind the address filled in the form. Anyone can type in someone else's address, by accident or on purpose. In a dispute your claim stands against theirs, and the burden of proof is yours. The confirmation click closes that gap: somebody with access to the mailbox agreed.

The rule that actually governs marketing email

Data protection law is only half the picture. Email marketing in Europe also falls under the ePrivacy Directive. Article 13 sets the principle: unsolicited direct marketing by electronic mail requires the recipient's prior consent. A directive has to be transposed, so every member state wrote its own law around it, including a narrow exception for addresses collected from your own customers. Check what applies where you send.

Germany is the example worth knowing, because it is strict and because enforcement is cheap for the other side. Under § 7(2) UWG, advertising by electronic mail without prior express consent counts as an unreasonable nuisance and is unlawful. That is competition law: competitors and trade associations enforce it with a cease-and-desist letter, no regulator involved. One email to the wrong recipient can be enough.

A note where it counts: this is a practical orientation, not legal advice. If you send across borders, or plan to reactivate an old list, that belongs with someone who knows your case and your jurisdictions.

Planet49 and the pre-ticked box

One judgment changed the consent debate for good. On 1 October 2019, in case C-673/17 (Planet49), the Court of Justice of the European Union held that a pre-ticked checkbox is not valid consent. Agreement requires an active step.

For your signup form the consequence is plain: nothing is ticked in advance, on the newsletter checkbox and on every other consent you collect in the same place.

What a consent record has to contain

Double opt-in without a record is a procedure without evidence. The confirmation click only helps two years later if you can produce it. These entries make a record usable.

Entry in the recordWhat it proves in a dispute
Time of signupWhen the form was submitted
Time of confirmationThat the second step happened, and how long it took
IP address usedTies the signup to an internet connection
Wording of the consent statement at the time of signupWhat the person agreed to back then, not what your form says today
The version of the formWhat stood next to the checkbox, and which fields were required
The confirmation email itselfWhat the recipient received, and what it did not contain

The fourth row is where most systems fall down. You will rewrite the text next to that checkbox over the years, and a record that only points at the current version proves the wrong wording for a signup from 2023. What you want is versioning that keeps the old text with the entry.

One test: take any address from your list and show, in under a minute, when it signed up, when it confirmed and which wording it agreed to. If you cannot, you have double opt-in configured and no evidence to go with it.

Three mistakes that make the record worthless

Advertising inside the confirmation email

The confirmation email has one job: to ask for confirmation. The moment it carries an offer or a product image, you have sent a marketing email to someone who has not consented yet.

Whether the confirmation email itself already counts as unlawful advertising is judged differently by different commentators. Prevailing practice treats it as acceptable while it does nothing but request confirmation, and some take a narrower view. The disagreement is not settled, and this article does not settle it. The working rule: the plainer the email, the smaller the target.

Tying consent to something else

The second mistake is bundling. The whitepaper is only available if you also sign up for the newsletter, or the order will not go through unless the box is ticked. Consent has to be freely given, and that is hard to argue when the download does not start without it.

Separate the two. The whitepaper follows the form, the newsletter checkbox sits next to it and stays optional. Whoever confirms afterwards is the better recipient anyway.

The record lives somewhere you cannot export from

The third mistake only shows up when you leave. Your evidence sits in a provider's database, which is fine while you are their customer. On the way out the export covers address, name and a few custom fields, and the record stays behind. You end up with a list you cannot prove anything about.

So ask before you decide: can the complete record be exported, with both timestamps, IP address and wording? The answer sorts tools faster than any feature list.

Why double opt-in pays off where nobody requires it

Outside Germany many teams treat double opt-in as optional. Three practical arguments still hold.

  • Deliverability: typos and addresses typed in by someone else never reach the list, so your bounce rate stays low. Mailbox providers watch that number when they decide where your mail lands.
  • Evidence: when a recipient complains, or you enter a market with stricter rules, the record already exists. It cannot be built retroactively.
  • List quality: a confirmation step costs you the subscribers who were never going to read anything, and leaves a smaller list with better numbers.

Where tools promise a safety they do not have

A GDPR-compliant badge on a product page is a statement about a tool, not about your website. No plugin can hand you compliance: that depends on what you write in your form and what you send. What a tool contributes is narrow:

  • a confirmation flow that activates no address without a click on the link
  • a record that captures the entries listed above and exports in full
  • one-click unsubscribe with List-Unsubscribe per RFC 8058, so mail clients show their own unsubscribe button
  • tools for access and deletion requests, answered without digging through the database

Anything beyond that is marketing copy.

Kurato ships those four in the free version: double opt-in, a consent record, one-click unsubscribe per RFC 8058, and the GDPR tools for access and deletion. The record lives in your own WordPress database and exports in full, so if you move on, the evidence moves with you. What is missing belongs here too: sequences, OR segments and calendar sync.

If the signup runs through a form on your site, Leadlotse also carries double opt-in, plus a honeypot, a time trap and a rate limit. Bots submit other people's addresses, and each one becomes a confirmation email to somebody who never asked. Protecting forms without locking people out with a puzzle is covered in captchas and accessibility. Both plugins stay free, and the paid tiers sit on the pricing page.

A newsletter whose proof stays in your own database

Kurato includes double opt-in, the consent record and one-click unsubscribe per RFC 8058 in the free version. Sending runs through a provider you pick.

Look at Kurato

Frequently asked questions

Does the GDPR require double opt-in?

No. The term does not appear in the regulation. Art. 7 requires the controller to demonstrate that consent was given, and Art. 5(2) adds accountability. Double opt-in is the method that makes that demonstration work.

Is single opt-in enough for a newsletter?

It is not expressly forbidden, but you lack evidence that the person behind the address agreed. National rules built on Article 13 of the ePrivacy Directive require prior consent for marketing email, and Germany goes further with § 7(2) UWG. The burden of proof is yours.

Can the confirmation email include an offer?

It should only request confirmation. Whether the confirmation email itself already counts as unlawful advertising is judged differently, and prevailing practice treats it as acceptable while it contains nothing else. Discount codes and product images do not belong in it.

How long do I have to keep the consent record?

For as long as you rely on that consent, you need the evidence. After someone unsubscribes, the relevant period is the one in which claims can still be brought. The GDPR sets no fixed retention period, so this is a question for advice on your case.

What happens to my evidence when I switch providers?

That depends on the export. Many services hand over addresses and custom fields but not the full record with timestamps, IP address and wording. Ask before you migrate. With Kurato the record sits in your own database and exports in full.

Back to blog A post by hafenstudios