An opt-in is a clear, positive action someone takes to agree to receive your marketing, such as ticking an unticked box or entering their email address into a form that plainly says it is for your newsletter. It is how you collect consent to send marketing emails and texts.
How opt-in works
The person takes the action, and you record it. A typical email opt-in sits on a sign-up form, at checkout or in an account area. The wording says what they will receive, roughly how often and from whom, and any tick box starts empty.
There are two main variations. With single opt-in, the address joins your list as soon as the form is submitted. With double opt-in, the person must click a link in a confirmation email first, which proves the address belongs to them and keeps typos and malicious sign-ups off your list. UK law does not require double opt-in, but it gives you stronger evidence.
Whichever you use, keep a record: the date and time, the form or page used, the exact wording shown and the source. If someone later asks why they are on your list, or complains to the ICO, that record is your answer.
Why it matters
For UK businesses, marketing by email or text is governed by PECR, with UK GDPR setting the standard for consent. Consent has to be freely given, specific, informed and unambiguous. That rules out pre-ticked boxes, consent buried in terms and conditions, and making marketing sign-up a condition of buying something unrelated.
PECR treats sole traders and some partnerships as individuals, so they need to opt in too, even though they are businesses. Staff at limited companies and other corporate subscribers are treated differently: you can usually email them without prior consent, provided you say who you are and give them a simple way to opt out. The main exception to the consent rule for individuals is the soft opt-in, which lets you market similar products and services to existing customers who were given a clear chance to refuse when you collected their details, and in every message since.
Beyond compliance, opted-in lists simply work better. People who chose to hear from you click and buy more and complain less, which protects your sender reputation.
Common mistakes
- Pre-ticked boxes, or wording such as “untick if you do not want offers”.
- One box covering several things, such as accepting terms and joining the mailing list.
- Vague wording like “we may contact you” that does not say what, how or how often.
- No record of when or how consent was given, especially for lists brought over from an old system.
- Assuming any business address is fair game and emailing sole traders without consent.
- Collecting consent on behalf of “selected partners” without naming them.
How to act on it
Go through every place you collect email addresses: website forms, checkout, pop-ups, events and in person. Check that each uses an unticked box or an equally clear action, names your business, and explains what people will receive. Keep marketing consent separate from your terms.
Then check your records. Make sure your email platform stores the source and timestamp of each opt-in, and that imported contacts carry the same information. Where you cannot show how someone joined, treat the consent as doubtful. I review sign-up journeys and consent wording as part of my digital marketing strategy and consulting work; for anything legally complex, take specialist data protection advice.
