Skip to content
day3
All guides
Compliance7 min read

Double opt-in and the GDPR: what you actually have to record

Double opt-in is not a GDPR requirement. Demonstrable consent is, and double opt-in is the most practical way to produce it. The distinction matters, because it tells you what you actually have to store.

The short version

  • The GDPR does not mention double opt-in anywhere. It requires that consent be freely given, specific, informed and unambiguous, and that you be able to demonstrate it (Articles 4(11) and 7(1)).
  • Double opt-in is evidence, not compliance. It is the cheapest way to produce the evidence Article 7(1) asks for.
  • What to record: what they agreed to, the exact wording shown, when, and from where.
  • Pre-ticked boxes are not consent. The CJEU settled that in Planet49 (C-673/17).
  • Withdrawing consent must be as easy as giving it (Article 7(3)), which is a direct argument for one-click unsubscribe.
  • This is a description of the rules, not legal advice. Get advice for your own situation.

What the regulation actually says

Search the GDPR text for "double opt-in" and you will find nothing, because the phrase is an industry practice rather than a legal term. What the regulation gives you is a definition and an obligation.

Article 4(11) defines consent as "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her". Article 7(1) then adds the part that shapes your database: "the controller shall be able to demonstrate that the data subject has consented".

So the requirement is not a particular signup flow. It is that you can show, later, that a specific person agreed to a specific thing at a specific time. Everything about double opt-in follows from trying to satisfy that cheaply.

Why single opt-in usually fails the evidence test

A single opt-in form adds whatever was typed into it. That means the record you hold is "someone, using this browser, typed this address into our form". Which is not quite the claim you need to make, because you cannot show that the person who typed it is the person who owns the address.

In practice single opt-in lists accumulate four kinds of entry that undermine both your compliance position and your deliverability: typos, other people's addresses entered maliciously or carelessly, bot submissions, and spam-trap addresses seeded specifically to catch senders who do not verify.

Double opt-in closes the gap with one step. The address receives a confirmation email and nothing is sent to it until someone clicks the link inside. Now your record says "the person who controls this mailbox took an affirmative action", which is much closer to what Article 4(11) describes.

The fields to store

If Article 7(1) is the requirement, then your consent record is the deliverable. At minimum it should capture:

FieldWhy it matters
Timestamp of consentEstablishes when, which matters for withdrawal, retention and any dispute
SourceWhich form, page, or import. Ties the consent to a context you can describe
The exact wording shown"Informed" means informed about something specific. If your wording changed in 2025, you need to know which version this person saw
Confirmation timestampFor double opt-in, the moment the link was clicked. This is the affirmative action itself
IP addressCorroborating detail. Not required by name, but it is what turns a claim into a record
Withdrawal timestampWhen they unsubscribed. Keeping this is how you prove you honoured it, and how you avoid re-mailing them after a future import

That last row is the one people delete, on the theory that removing someone means removing their data. It does not follow. Keeping a suppression record of an address that asked never to be contacted is generally the more defensible position than deleting it and mailing them again next year, and it is usually treated as compatible with the original purpose rather than a new one.

Three things that are not consent

  • A pre-ticked box. The Court of Justice settled this in Planet49 (C-673/17, 2019): consent requires an active choice, and a box the user has to untick is not one.
  • Consent bundled into terms acceptance. "Specific" means the marketing consent has to be separable from signing up for the service. If declining the newsletter means not being able to use the product, the consent was not freely given.
  • A purchased or scraped list. Whoever sold it to you cannot transfer consent that was given to them, if it was given at all. There is no version of this that produces a record you could show anyone.

Worth separating from all of this: consent is not the only lawful basis, and marketing to your own existing customers about similar products may be permissible on a different footing. That route comes from the ePrivacy Directive rather than the GDPR, it is implemented differently in each member state, and it is narrower than most people hope. Do not assume it covers you without checking.

Withdrawal has to be as easy as consent

Article 7(3): "It shall be as easy to withdraw as to give consent." If signing up took one click on a form, then leaving should take one click too, and a preferences centre that requires a login and four screens does not meet that standard.

This lines up neatly with the deliverability argument for one-click unsubscribe, which is the rare case where the compliance requirement and the self-interested move are the same thing. Friction on the way out converts unsubscribes into spam complaints, and spam complaints cost you far more.

How day3 handles it

Double opt-in is on by default on every signup form, and you can turn it off per form for the cases where it makes sense, such as a form behind a login where the address is already verified. Confirmed signups store the consent timestamp and the originating IP address.

Unsubscribes are honoured immediately, written to a per-sender suppression list that survives re-import, and one-click unsubscribe headers go on every campaign. day3 is a Danish company with EU-only hosting and sub-processors, offers a DPA, and lists every sub-processor publicly.

Questions

Does the GDPR require double opt-in?
No. The GDPR never mentions double opt-in. It requires that consent be freely given, specific, informed and unambiguous, and that you be able to demonstrate it. Double opt-in is the most practical way to produce that evidence, which is why it is treated as the standard, but it is not itself a legal requirement.
What do I need to record to prove email consent?
When they consented, what form or page it came from, the exact wording they were shown, the confirmation timestamp if you use double opt-in, and ideally the originating IP. Keep the withdrawal timestamp too, so you can show you honoured an unsubscribe.
Are pre-ticked consent boxes allowed?
No. The Court of Justice of the European Union settled this in Planet49 (C-673/17): consent requires a clear affirmative action, and a box the user must untick does not qualify.
Can I email customers without consent under legitimate interest?
Sometimes, for existing customers about similar products, but that route comes from the ePrivacy Directive rather than the GDPR, is implemented differently in each member state, and is narrower than most senders assume. Do not rely on it without advice specific to your situation.
Should I delete contacts who unsubscribe?
Usually not entirely. Keeping a suppression record of an address that asked not to be contacted is what stops a future import from mailing them again, and is generally more defensible than deleting the record and re-adding them by accident later.
Is buying an email list ever GDPR compliant?
In practice, no. Consent given to one company cannot be transferred to another, and you would have no record showing what any individual on the list agreed to. It is also the fastest way to collect spam-trap hits and destroy your sending reputation.

day3 handles all of this by default.

Authenticated domains, one-click unsubscribe, double opt-in, and automatic suppression. Billed by emails sent, from $1/month.