Building an e-mail list legally: consent, sign-up forms and unsubscribing

A good e-mail list is built with people who asked to be on it, knowing what they were signing up for. It is the rule that protects your domain, your reputation and, depending on where the subscribers live, the law. This article deals with the list side: the form, consent and the exit. Sending and authenticating the domain are in e-mail marketing without burning your domain.

The sign-up form

1 Say what the person receives and how often, next to the button. “One e-mail a month with news and offers” is honest and filters out those who do not want it.
2 Ask only for what you need. The e-mail is enough. Every extra field is a reason to give up and one more piece of data to protect. See personal data protection.
3 The consent box stays unticked. Never pre-ticked, and separate from the send button. Whoever does not tick it does not sign up.
4 Link to the privacy policy in the form, saying what you collect, what for and for how long.
5 Confirm the address with an e-mail containing a link (two-step sign-up). It filters typing errors and sign-ups made by others, and it is the best proof that it really was the person.
6 Keep the proof: when, where and how they signed up, and the text they saw. If anyone ever disputes it, that is what protects you.

What counts as consent

Situation Allowed or not
The person filled in the form and ticked the box Allowed. It is the ideal case.
Gave a card or an e-mail in a purchase and never signed up Depends on the rules where they live. The safe way is to ask. When in doubt, talk to a lawyer.
You bought or inherited a list No. Nobody consented to you, and the result is complaints and a burned reputation.
You copied e-mails from a website or a business card No, for a mass campaign. A personal contact is something else.
You have customers and want to tell them something about what they bought It is a service message, not marketing, and a different category.

Letting people leave, without friction

1 An unsubscribe link in every message, clearly visible, that works with one click.
2 Honour the request at once. Remove the person before the next send, and do not add them back by mistake in an import.
3 Clean the list. Remove those who have not opened for a long time and the addresses that bounce. A smaller, living list delivers better than a big, dead one.
The rules vary from country to country. The European regulation (GDPR) applies to people who sign up in the European Union, wherever your business is. Other countries have their own laws. This is practical guidance, not legal advice: for a decision with consequences, talk to a lawyer. The situation by place is summarised in personal data protection.
If the form uses an outside sending service, the data leaves your site: say so in the privacy policy. And if you measure sign-ups with Analytics or pixels, see the cookie notice.

Does the sign-up form not reach your mailbox, or do the confirmation messages land in spam? Tell us the address and an example.

Open a support ticket

SEE ALSO

E-mail marketing without burning your domain

Personal data protection

SPF, DKIM and DMARC: why your e-mail lands in spam

Professional e-mail

RECOMMENDED PRODUCT

Professional e-mail on your domain

Mailboxes in your company name, no adverts, with spam filtering. from £5.28/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?