EU marketing email needs prior consent, with one narrow customer exception
Article 13 of the ePrivacy Directive requires prior consent for marketing email. The one exception, usually called soft opt-in, lets you email existing customers about your own similar products, but only if you obtained the address in the context of a sale and you offer an opt-out both at collection and in every message.
Who this applies to
Anyone sending marketing email into the EU. Because ePrivacy is a Directive rather than a Regulation, the detail lives in national law and genuinely differs between member states.
What to do
- Record where and when each address was collected, and whether a purchase actually happened.
- Keep soft opt-in to your own similar products. A different brand in the same group does not qualify.
- Put an opt-out in every single message, not just the first.
- For B2B in France, note that legitimate interest can cover profession-related contact, and generic addresses such as info@ fall outside because they identify a legal entity.
What happens if you do not
Actively enforced, and usually about consent quality rather than the absence of consent. Recent examples include a 400,000 euro Garante fine in November 2025 for continuing to message people who had objected and for bundling marketing consent into quote requests, and a 1.8 million euro Norwegian fine in June 2026 over invalid customer-club consent.
Sources
Related
History of this page
- Added CNIL's B2B and generic-address guidance.
- Added.