WorkflowEU

EU ePrivacy Directive soft opt-in marketing review workflow

Use this workflow before sending electronic-mail direct marketing without prior consent under the Article 13 soft opt-in.

The review focuses on proof of an existing customer relationship, own similar products or services, collection-time and message-level opt-out, sender identity, suppression records, approval gates, and national transposition caveats.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

Do not use the unless every condition passes for the specific sender, contact source, product, channel, and country. starts from prior consent for electronic-mail direct marketing. Its customer exception permits the same natural or legal person that obtained electronic contact details in the context of a sale to market its own similar products or services, provided the customer received a clear, free, easy opportunity to object when the details were collected and with every later message. If any condition fails, suppress the contact unless another route under the applicable national law is documented, such as valid prior consent. The Commission withdrew its proposed replacement ePrivacy Regulation on 6 October 2025, so this workflow applies Directive 2002/58/EC as amended and the relevant national implementing law.

Section 1

Gate 1: confirm the customer relationship and collection context

Trace the contact detail to its collection event before reviewing the campaign. The is tied to electronic contact details obtained lawfully from customers in the context of a product or service sale. For this workflow, is broader than email: the Directive's definition covers stored text, voice, sound, or image messages sent over a public communications network, which includes SMS. Confirm the national rule for the channel being used.

Approve this gate only when the CRM record can show the product or service sale in whose context the address was collected, which legal entity collected it, the privacy notice or checkout screen shown at collection, and whether the customer objected at that moment. A quote, negotiation, trial, or abandoned transaction is not enough under the Directive's EU baseline unless the applicable national implementation supplies a separately sourced route.

  • Evidence to collect: completed order, paid subscription, renewal, or other product-or-service sale record; the address or number collected in that sale context; collection timestamp; country or regional store; collecting legal entity; and a screenshot or versioned copy of the direct-marketing opt-out language shown at collection.
  • Reject or escalate: quotes, negotiations, free trials, abandoned transactions, purchased lists, scraped addresses, event badge scans, contacts imported from another group company, or addresses collected by a partner that is not the sending entity, unless a separately sourced national rule supports the proposed route.
  • Approval gate: CRM owner certifies the source record, privacy/legal confirms the basis is available for the contact source, and marketing operations locks the approved segment before creative review.
  • Record format: one campaign-level decision plus a sampled contact-evidence pack, with a link to the suppression query used to exclude objectors.
Section 2

Gate 2: test own similar products or services

The campaign must market the same sender's own similar products or services. The same brand, corporate group, shared CRM, or common marketing team does not by itself make two companies the same natural or legal person. Record the entity that obtained the contact detail and the entity on whose behalf the message will be sent.

The Directive does not define a universal similarity test. Use a short matrix before audience upload, then apply the relevant national law and regulator guidance. Compare the original purchase category and use with the advertised offer, its function, likely customer expectation, and whether it is supplied by the same legal person. Price, delivery channel, or shared branding may inform the review but cannot replace the own-similar-products condition.

  • Possible candidates for approval, subject to the national test: replenishment, renewal, compatible add-ons, upgrades, service extensions, or closely related replacements from the same sender when every other gate also passes.
  • Escalate: unrelated product lines, third-party offers, affiliate campaigns, cross-sell by a different legal entity, or campaigns where similarity depends only on broad customer-interest profiling.
  • Document: product owner rationale, legal/entity check, campaign objective, audience source, creative summary, and the reason each borderline product category is included or excluded.
  • Control: block campaign cloning into new countries, brands, or entities until the similarity and national-law checks are repeated.
Section 3

Gate 3: verify opt-out, sender identity, and suppression controls

The opt-out must exist twice: at collection and on each marketing message if the customer did not initially refuse. The send must also avoid disguised or concealed sender identity and provide a valid address to which the recipient may send a request to stop further communications.

Marketing operations should test the unsubscribe path before approval, then prove suppression after the test. The record should show that an objection entered through the campaign link, valid stop-contact address, preference center, or supported manual channel reaches the suppression store used by every platform sending marketing on behalf of that legal person. Keep service messages outside the marketing suppression rule only where their non-marketing purpose is documented.

  • Collection-time check: clear and distinct objection wording, no charge for refusal, easy action, and stored evidence of whether the customer refused.
  • Message-level check: visible marketing identity, sender identity on whose behalf the message is sent, valid stop-contact address or link, and no creative or routing pattern that hides the sender.
  • Suppression check: sender-wide and campaign-level marketing suppressions applied before send, unsubscribe test completed, manual opt-out channels mapped, and objectors excluded from marketing retargeting uploads that reuse the same contact details.
  • Closeout check: export campaign audience count, suppression count, test unsubscribe evidence, final creative, approval log, and the query or segment version used for the live send.
Section 4

Gate 4: national-law caveat and final approval

Do not convert this EU-level workflow into a country-rule database. is implemented through national provisions, and the ePrivacy/GDPR relationship can affect enforcement and documentation. Before launch, the regional owner should confirm whether the target country implementation changes the practical result for the channel, audience type, timing, or objection mechanism.

Passing addresses the electronic-mail channel rule; it does not supply or replace the GDPR basis, transparency information, data minimisation, retention, or rights analysis for personal data used to select and contact the audience. In particular, Article 21 GDPR gives a person the right to object at any time to processing for direct marketing, after which the personal data may no longer be processed for that purpose.

If a national-law answer is missing, record the issue as blocked for that country instead of guessing. The campaign can proceed only for countries whose legal, product-similarity, opt-out, sender-identity, suppression, and GDPR gates are approved.

  • Country caveat checklist: target country or countries, natural-person or legal-person audience classification if relevant to the local implementation, channel type, opt-out wording language, timing since sale if the local review requires it, and whether a local reviewer approved or blocked the send.
  • GDPR record: controller, purpose, lawful basis, source of the contact data, notice version, selection or profiling criteria, retention rule, and evidence that every direct-marketing objection is enforced.
  • Approval order: CRM source owner, product owner, privacy/legal owner, marketing operations owner, regional owner, then final campaign approver.
  • Reopen triggers: new product category, new sending entity, imported audience, changed unsubscribe flow, preference-center migration, expansion to another country, complaint spike, or a material change to national transposition guidance.
  • Blocked outcome: obtain valid prior consent before sending, if that route is available under the applicable law, or suppress the audience until the missing customer-relationship, similarity, opt-out, sender-identity, suppression, GDPR, or national-law evidence is complete.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Supports this page's analysis of national-law caveat because Member States lay down rules and penalties for national provisions adopted under the Directive.
"Member States shall lay down the rules on penalties"
eur-lex.europa.eu
Referenced sections
  • Supports the collection-time and each-message opportunity to object, plus the prohibition on concealed sender identity or missing stop-contact address.
"on the occasion of each message"
eur-lex.europa.eu
Referenced sections
  • Provides the electronic-mail definition, the prior-consent rule, and the limited customer-relationship exception in Article 13(2).
"obtains from its customers their electronic contact details"
eur-lex.europa.eu
Referenced sections
  • Binding EU-level source for the electronic-mail definition, prior-consent rule, customer exception, similar-products condition, each-message objection opportunity, sender-identity prohibition, and Member State enforcement provisions.
"direct marketing of its own similar products or services"
edpb.europa.eu
Referenced sections
  • Used for the consent fallback: if soft opt-in fails and consent is used instead, the consent mechanism must be free, specific, informed, unambiguous, and withdrawable.
"freely given, specific, informed and unambiguous"
eur-lex.europa.eu
Referenced sections
  • Supports the separate GDPR analysis for audience data and the right to object at any time to processing for direct marketing, after which the data may no longer be processed for that purpose.
Related guides

Explore more topics

Are cookie walls allowed under the EU ePrivacy Directive?
FAQ answer on cookie walls under the EU ePrivacy Directive, covering freely given consent, refusal and withdrawal paths, banner evidence, and national-law caveats.
Do Analytics Cookies Require Consent under the EU ePrivacy Directive?
FAQ answer on analytics cookies under Article 5(3) ePrivacy, limited analytics exemptions, configuration evidence, consent logs, and national-law caveats.
ePrivacy cookie consent vs DSA advertising rules
Compare ePrivacy rules for device storage and access with DSA ad labels, advertiser disclosures, targeting information, profiling limits, and VLOP/VLOSE ad repositories.
ePrivacy Directive vs GDPR: cookies, communications, consent, and evidence
Compare the EU ePrivacy Directive and GDPR across subject matter, lex specialis overlap, terminal equipment, communications confidentiality, marketing, consent, enforcement, and evidence.
EU cookie banner requirements under the ePrivacy Directive
EU ePrivacy cookie banner requirements for non-exempt cookies and trackers: prior consent, reject choices, no pre-ticked boxes, withdrawal, analytics limits, cookie walls, and evidence logs.
EU ePrivacy analytics cookies: consent, exemption, and evidence guide
Source-backed guide to analytics cookies under EU ePrivacy: Article 5(3) scope, when consent is usually needed, limited analytics exemptions, consent records, and evidence gaps.
EU ePrivacy Applicability Test for Cookies, SDKs, Pixels, Communications, and Marketing
A concrete EU ePrivacy Directive applicability test for electronic communications services, terminal-equipment storage or access, cookies, SDKs, pixels, local storage, direct marketing, GDPR overlap, and evidence.
EU ePrivacy Article 5(3) terminal equipment test
A cited Article 5(3) test for cookies, pixels, local identifiers, device APIs, strictly necessary exceptions, and consent evidence.
EU ePrivacy Confidentiality of Communications: Article 5 controls
Article 5 confidentiality guide for EU ePrivacy communications, traffic data, metadata, terminal-equipment access, consent limits, and GDPR interplay.
EU ePrivacy consent-log evidence workflow for cookies and trackers
Build evidence that links each cookie or tracker decision to the banner shown, the user's signal, the live technical behavior, withdrawal, and later changes.
EU ePrivacy cookie banner UX test cases
Source-backed cookie banner UX tests for Article 5(3) ePrivacy consent: reject all, pre-ticked boxes, withdrawal, cookie walls, analytics toggles, and consent evidence.
EU ePrivacy Cookie Scope Classifier Workflow
Decide whether cookies, pixels, SDKs, local storage, identifiers, and analytics fall within Article 5(3), then document consent, an exemption, or escalation.
EU ePrivacy direct-marketing consent checklist
Checklist for ePrivacy Directive direct-marketing messages: consent, soft opt-in, sender identity, opt-out handling, proof records, suppression, and national-law caveats.
EU ePrivacy Directive compliance calendar for cookies, consent, and marketing
Source-backed ePrivacy calendar covering Directive milestones, Article 5(3) cookie reviews, consent evidence, direct marketing checks, and national-law follow-up.
EU ePrivacy Directive Compliance Checklist
A concrete ePrivacy checklist for terminal equipment access, cookie consent, exemptions, banner UX, direct marketing, confidentiality, GDPR interplay, and evidence records.
EU ePrivacy Directive Compliance Guide for Cookies, Marketing, and Communications
Practical ePrivacy Directive compliance checks for terminal equipment, communications confidentiality, cookie consent, exemptions, direct marketing, evidence, and national-law caveats.
EU ePrivacy Directive Cookies and Consent: Article 5(3), exemptions, and banner evidence
Cookie consent guide for the EU ePrivacy Directive: Article 5(3) scope, strictly necessary and transmission exemptions, consent UX, withdrawal, logs, analytics caveats, and GDPR interplay.
EU ePrivacy Directive direct marketing rules for electronic mail
Source-backed guide to Article 13 ePrivacy Directive rules for electronic mail marketing, prior consent, customer soft opt-in, opt-out handling, sender identity, and Member State caveats.
EU ePrivacy Directive Enforcement and Fines
Source-backed guide to ePrivacy Directive enforcement, national penalties, competent authorities, GDPR interplay, cookie-banner risk, and evidence limits.
EU ePrivacy Directive FAQ: cookies, consent, marketing, GDPR interplay
Answers to recurring EU ePrivacy Directive questions on Article 5(3), terminal-equipment access, cookie consent, exemptions, analytics, direct marketing, GDPR interplay, national enforcement, and evidence.
EU ePrivacy Directive Member State Cookie Rules
How to evidence EU ePrivacy cookie compliance when Article 5(3) is implemented through Member State law and national authority practice.
EU ePrivacy Directive Metadata and Location Data Guide
Source-backed guide to EU ePrivacy Directive rules for traffic data, location data, anonymisation, consent, value-added services, Article 5(3) overlap, and national-law limits.
EU ePrivacy Directive penalties and fines: national enforcement caveats
Source-backed guide to ePrivacy Directive penalty exposure, national transposition caveats, cookie enforcement evidence, consent defects, and GDPR overlap limits.
EU ePrivacy Directive Requirements: cookies, communications and marketing
Source-backed map of EU ePrivacy Directive requirements for communications confidentiality, terminal-equipment access, consent, traffic and location data, and direct marketing.
EU ePrivacy Directive vs GDPR: cookies, communications, marketing, and evidence
Compare the EU ePrivacy Directive and GDPR by trigger, consent standard, lex specialis overlap, enforcement caveats, and evidence outputs for cookies, device access, communications, and marketing.
EU ePrivacy Directive vs UK PECR: cookies and direct marketing
Compare the EU ePrivacy Directive with current UK PECR rules for device storage and access, statutory exceptions, consent, electronic-mail marketing, soft opt-ins, and enforcement.
EU ePrivacy soft opt-in FAQ for email marketing
When Article 13(2) soft opt-in can support EU customer email marketing, including existing-customer, similar-offer, opt-out, sender-identity, suppression-list, and national-law checks.
EU ePrivacy soft opt-in marketing checklist
Source-backed checklist for using the EU ePrivacy Directive soft opt-in exception for customer email marketing, opt-outs, sender identity, suppression records, and national-law caveats.
EU ePrivacy Strictly Necessary Cookie Exemptions
Source-backed guide to the Article 5(3) ePrivacy exemptions for transmission cookies, requested-service cookies, analytics caveats, evidence, and national-law checks.
Is a reject-all button required for EU ePrivacy cookie consent?
Standalone FAQ answer on EU ePrivacy reject-all and refuse options for cookie banners, including equal prominence, deceptive UX, consent evidence, withdrawal, and national-law caveats.
Strictly Necessary Cookies under the EU ePrivacy Directive
FAQ answer on when EU ePrivacy Article 5(3) allows cookies without consent, with cited examples, analytics caveats, evidence records, and national-law cautions.
What should CMP consent logs retain under the EU ePrivacy Directive?
FAQ answer on CMP consent logs for EU ePrivacy cookie consent: retained fields, consent validity signals, banner versioning, refusal and withdrawal events, proof limits, and national-law caveats.