Email is one of the few channels a business genuinely owns: no platform in between, no reach that gets recalculated overnight, no price per click. That is precisely why the route into the inbox is tightly regulated in Germany and across the EU. Advertising by electronic mail without prior express consent is unlawful, and if a dispute arises it is not the recipient who has to show that consent was missing, but the business that has to show it existed. This guide walks through the full sequence of a signup that holds up: from the form to the confirmation mail and the log entry, through to the unsubscribe link and the deletion of inactive addresses. It also sets out what the much-quoted existing-customer exception really allows, and why bought address lists and discounts in exchange for a subscription regularly cause trouble. It does not replace legal advice on an individual case.
Why consent is the real core of it
The technical side of a newsletter signup is built in a morning: one input field, one button, one list. The real effort sits somewhere else, in the record. Around 89 percent (Federal Statistical Office of Germany) of companies with internet access run their own website, and 97 percent (Federal Statistical Office of Germany) of people in Germany aged 16 to 74 are online. A mailing list is therefore within reach of practically every business. Whether it holds up is decided not by its size, but by whether each individual address comes with a record of when it was entered, which wording the person agreed to, and how the subscription was confirmed. A list of 300 properly logged addresses is worth more, in a dispute, than one of 3,000 whose origin nobody can reconstruct.
Two bodies of law interlock here. Competition law decides whether a marketing email may be sent at all: an unreasonable nuisance exists where advertising uses electronic mail without the prior express consent of the addressee (German Act against Unfair Competition, Section 7(2) no. 2). Data protection law decides on what basis the address may be processed and who has to prove what: the controller must be able to demonstrate that the data subject has consented to the processing (General Data Protection Regulation, Article 7(1)). The burden of proof therefore sits with the sender, not the recipient, and it can hardly be produced after the fact. Anyone who starts looking only once the first complaint letter arrives usually finds nothing usable.
A newsletter signup differs from an enquiry form more sharply than the visual similarity suggests. Someone who submits a specific enquiry through a contact form expects an answer to that particular request; that processing rests on entering into or performing a contract and needs no separate consent. A newsletter signup, by contrast, creates a standing permission for future advertising, and that permission has to be evidenced. So the two paths belong apart: separate fields, separate wording, separate storage. A tick box labelled „I would like to receive the newsletter“ underneath a quotation request mixes two purposes that have to be documented separately, and it weakens both records.
This article does not replace legal advice
What Section 7 UWG requires for email advertising
The statutory wording is short and leaves little room: an unreasonable nuisance exists in the case of advertising using an automated calling machine, a fax machine or electronic mail without the prior express consent of the addressee (German Act against Unfair Competition, Section 7(2) no. 2). Three words carry the whole weight. Prior means: before the first marketing email, not after it and not by means of it. Express means: an active statement, not silence, not a preset, and not an inference drawn from an order. Consent means: freely given, specific and informed (General Data Protection Regulation, Article 4 no. 11).
What is routinely underestimated is how far the notion of advertising reaches. It covers not only offers and discounts, but any statement intended to promote sales. In practice that catches considerably more mailings than many businesses assume:
- Newsletters with product news, dates or campaigns, even where no price is mentioned.
- Invitations to open days, consultation hours, webinars or trade fair stands.
- Satisfaction surveys and requests for a review once a job is finished.
- Automated reminders about an abandoned basket or an offer about to expire.
- Birthday and anniversary mails carrying a voucher code or campaign note.
- Forwarded offers from cooperation partners sent under your own sender name.
The third and fourth lines cause the most surprises. Asking for a review looks harmless, but it serves to promote sales and is therefore treated as advertising; anyone planning to collect customer reviews actively should settle the occasion and the legal basis beforehand. Pure contract communication remains permissible: an order confirmation, an appointment reminder, an invoice, a dispatch notice. The decisive point is that those messages carry no promotional additions, because an appended campaign block turns a system message into a marketing email.
Sending without consent primarily risks civil consequences: an injunction claim, a cease-and-desist letter with cost reimbursement, and a formal undertaking backed by a contractual penalty that falls due on each further breach. Fines come on top and, within competition law, mainly target telephone advertising: marketing calls without consent carry up to 300,000 euros (German Act against Unfair Competition, Section 20), documentation breaches up to 50,000 euros (German Act against Unfair Competition, Section 20). That this is more than a theoretical ceiling is shown by the practice of the competent authority: 1,435,000 euros (Verbraucherzentrale) in fines for unlawful telephone advertising and calling line identification withholding in 2023 alone. On the data protection side there is a separate ceiling, reaching up to 20 million euros or 4 percent of worldwide annual turnover for breaches of the consent requirements (General Data Protection Regulation, Article 83(5)).
The signup form: ask sparingly, word it clearly
Sending a newsletter requires exactly one piece of data: the email address. Everything else is convenience and has to be recognisable as optional, because personal data must be limited to what is necessary for the purpose (General Data Protection Regulation, Article 5(1)(c)). Every additional mandatory field costs subscriptions and creates explanatory work at the same time: anyone demanding date of birth, phone number and company address has to be able to justify what those details are needed for when sending a newsletter. In practice an optional first-name field is enough for a personal salutation, visibly marked as voluntary and with no effect on whether the form can be submitted.
One mandatory field
The email address is the only field genuinely needed for sending. A second input field to check the spelling is fine, but it does not replace confirmation by click.
Optional details
Salutation, first name or areas of interest may be collected, but they have to be visibly marked as voluntary and must not block submission of the form.
Active agreement
The checkbox stays empty until the person ticks it themselves. A pre-ticked box, or agreement inferred from scrolling on, does not carry as consent.
That agreement has to be active is settled in case law: a pre-ticked checkbox does not constitute valid consent (Court of Justice of the European Union, case C-673/17). Nor does a construction that buries consent in the general terms and conditions; the request for consent must be presented in an intelligible and easily accessible form, using clear and plain language, and clearly distinguishable from other matters (General Data Protection Regulation, Article 7(2)). In practice that means: a dedicated checkbox, the full consent wording directly next to or beneath it, and no second purpose hidden in the same tick.
Usability is part of validity, because a statement someone makes by accident is not an informed statement. The label has to be tied to the input field, error messages have to say in plain words what is missing, and the whole signup has to work with a keyboard. Those are the same requirements that apply to accessible copy and forms. The signup also needs a fixed home: its own linkable page carrying the full wording, supplemented by a compact block in the footer area. That page belongs in the structure of a business website from the outset, not in an overlay added later.
The consent wording: what belongs in it
Being informed is not a soft criterion but a testable one. The supervisory authorities state that being informed presupposes that the type of advertising intended, the products or services to be advertised, and the advertising company are named (German Data Protection Conference, guidance on direct marketing). A sentence such as „Yes, I would like to receive information“ does not meet that: it names neither the sender, nor the content, nor the channel. The wording has to be concrete enough that, years later, it still shows what exactly permission was given for.
- Who is advertising: the full name of the business, not just a brand name or an abbreviation.
- What is being advertised: the topics, services or product areas the newsletter will cover.
- By which channel: dispatch by email, named expressly and not extended to further channels.
- Roughly how often: an honest indication of frequency instead of a vague formula such as „occasionally“.
- How to withdraw: the note that consent can be withdrawn at any time with effect for the future (General Data Protection Regulation, Article 7(3)).
- Where the detail sits: a reference to the privacy policy, without outsourcing the consent statement itself into it.
The data subject has to be informed of the right to withdraw and its scope before giving consent, and in direct connection with obtaining it (General Data Protection Regulation, Article 7(3) sentence 3; German Data Protection Conference, guidance on direct marketing). A note that appears only in the privacy policy does not reliably meet that requirement. A second note is worth adding and is frequently missing: the record of consent is kept even after a withdrawal, and that continued retention has to be pointed out already when the data is collected (German Data Protection Conference, guidance on direct marketing).
Linguistically, the consent wording follows the same rules as every other page: short sentences, familiar words, no nested constructions. Anyone who avoids jargon when writing website copy customers actually read should not abandon that discipline at the very point where a legally binding statement is made. A workable test: have someone who does not know the business read the wording, then ask what they now expect to receive. If the answer and the intention diverge, the wording is too vague.
The confirmation mail: one link, no advertising
After the form is submitted, nothing happens except a single message: an email to the address entered, asking the recipient to confirm the signup with a click. Only that click activates the address. The purpose of the procedure is quickly explained: it rules out that someone enters an address belonging to another person, and it evidences that the person who controls the inbox actually wanted the subscription. For consent declared electronically, the supervisory authorities therefore consider the double opt-in procedure to be called for (German Data Protection Conference, guidance on direct marketing).
The confirmation mail is not advertising space
It adds to the evidential value if the confirmation demonstrably originates from the address given. The supervisory authorities point out that digital signatures such as DKIM can establish the authenticity of an email and therefore of the consent (German Data Protection Conference, guidance on direct marketing). That presupposes your own, correctly configured sender domain. If that groundwork is missing, the basics are covered under your own domain and business email address: a newsletter sent from a free mail account lands in the spam folder more often and is harder to attribute in a dispute.
If the confirmation does not arrive, the address is not a quiet gain but a liability. A short window of a few days makes sense, after which the unconfirmed entry is deleted. A single, factual reminder without promotional content is defensible; a second or third reminder carrying an offer is not. And the point that matters most in practice: unconfirmed addresses belong in no mailing, not even in one presented as purely informational.
Logging: timestamp, wording, confirmation
The evidence is not created by the procedure alone, but by what gets written down along the way. When logging, the evidence requirements set by the Federal Court of Justice under competition law have to be taken into account (German Data Protection Conference, guidance on direct marketing; Federal Court of Justice, judgment of 10 February 2011, I ZR 164/09). Consent must be fully demonstrable, including as to its wording; for statements transmitted electronically that requires storing them and being able to print them out at any time (German Data Protection Conference, guidance on direct marketing). A flag in a database column does not achieve that, because it does not reveal the text that was agreed to.
Merely storing an IP address and asserting that consent was given from that IP address is not sufficient, including under the case law of the Federal Court of Justice on the Act against Unfair Competition.
In practice that means a small but complete record per signup. It does not have to be sophisticated; it has to survive a change of system, a change of service provider, and the gap of several years between signup and complaint.
| Logged item | Evidential value | Why it counts in a dispute |
|---|---|---|
| Timestamp of the signup | high | Shows that consent existed before the first mailing and was not obtained after the fact. |
| Wording of the consent text | high | The scope of the permission follows from the text agreed to, not from today's version of the page. |
| Time of confirmation from the check mail | high | Ties the statement to the mailbox that is later sent to. |
| Origin: page, form, language version | medium | Assigns the signup to a concrete source and explains differences in the consent wording. |
| The IP address on its own | low | Without a confirmed click and without the wording, no consent can be derived from it. |
The record is kept for as long as claims can be brought. The supervisory authorities take their bearings from the standard limitation period of three years under administrative fine and civil law (German Data Protection Conference, guidance on direct marketing). Even after a withdrawal and after the address has been removed from the list, the business has to be able to evidence the earlier consent, which is why the record belongs in storage separate from the active list (German Data Protection Conference, guidance on direct marketing). For consent to telephone advertising there is a separate, longer documentation duty of five years (German Act against Unfair Competition, Section 7a) — a good reason to collect and store telephone and email consent separately.
Unsubscribe link and mandatory details in every mailing
Consent does not end at dispatch; it accompanies every single mailing. Data subjects have the right to object at any time to processing of their data for direct marketing purposes; after that the data may no longer be processed for those purposes (General Data Protection Regulation, Article 21(2) and (3)). This right has to be brought to their attention explicitly and separately from any other information, at the latest at the time of the first communication (General Data Protection Regulation, Article 21(4)). And withdrawing consent has to be as easy as giving it (General Data Protection Regulation, Article 7(3) sentence 4).
Unsubscribing from email advertising should be possible with a single click wherever feasible, without additional hurdles or obstacles. In particular, questions about the reason for unsubscribing must not be mandatory.
- An unsubscribe link that works without logging into a customer account and without re-entering the address.
- No compulsory question about the reason for leaving and no interstitial page with a retention offer.
- The notice about the right to object clearly set apart, not as the last line of the small print.
- Sender details and provider identification, as they apply to the legal pages of the website too.
- A sender address that can be replied to; with a pure no-reply address, at least a reply-to address set.
- A subject line that matches the content, so nobody mistakes the message for a system notification.
The unsubscribe link also has to be hittable on the move. Roughly nine in ten (Bitkom) people in Germany use a smartphone, and a large share of mailings is opened on exactly those devices. A link in eight-point type squeezed between two other footer lines is a hurdle in practice, even where it formally exists. What works is a line of its own with enough spacing, a target of at least 44 by 44 pixels, and wording that names the function instead of something like „manage settings“.
On the sender address the guidance is clear: anyone using no-reply addresses cuts off an obvious route for objecting and has to offer a simple, quick alternative in return; setting a reply-to address is expressly recommended (German Data Protection Conference, guidance on direct marketing). A spam filter is no excuse either: emails that land in the spam folder still count as received, and the business has to ensure organisationally that messages concerning data subject rights are noticed regardless (German Data Protection Conference, guidance on direct marketing).
An objection has to be implemented without undue delay. Where it is made through a link in a marketing email or a setting in a customer account, there is no reason for purely electronic advertising to depart from the wording of the law, under which the objection takes effect immediately (German Data Protection Conference, guidance on direct marketing). Anyone who only documents the objection but deletes the address without a marker risks that same address reappearing on the list at the next import. Where the marketing use rests on a balancing of interests, a suppression list is an option, and the data subject has to be informed of its purpose (German Data Protection Conference, guidance on direct marketing).
The narrow existing-customer exception
There is exactly one statutory route to advertising by email without express consent. It is quoted often and stretched just as often. The exception applies only where all four conditions are met at the same time (German Act against Unfair Competition, Section 7(3)):
- The trader obtained the email address from the customer in connection with the sale of goods or services.
- The address is used for direct advertising of the trader's own similar goods or services.
- The customer has not objected to that use.
- When the address is collected and on each use, the customer is clearly and unambiguously told that they may object at any time, at no cost other than transmission costs at basic rates.
Similar means genuinely similar
Two points are often overlooked in practice. First, the business has to be able to demonstrate that the address used for advertising belongs to an existing customer at all (German Data Protection Conference, guidance on direct marketing; General Data Protection Regulation, Article 5(2)). That poses the same documentation question as consent does, only with a different reference point. Second, the supervisory authorities recommend pointing out clearly and comprehensibly, already during the ordering process, that advertising for similar services is possible independently of a newsletter subscription, and enabling the right to object to be exercised right there, for instance through a checkbox or a link (German Data Protection Conference, guidance on direct marketing). That is exactly what prevents the irritation that arises when advertising turns up after an order although nobody signed up for a newsletter.
Bought lists, prize draws and discounts for signing up
Purchased or swapped address lists are the fastest route to a mailing list and the least safe. Consent is given to a specific company for a specific purpose; it is not a tradable good. Even where the seller asserts that consent exists, the sending business has to be able to evidence it, specifically with regard to the means of communication used for the advertising and including the wording (German Data Protection Conference, guidance on direct marketing). A blanket assurance from the seller does not do that as a rule. There is a practical effect on top: addresses with no relationship to the business generate complaints and spam markings, which degrades deliverability for all the other recipients.
Tying is similarly delicate. Where a discount, a download, a prize draw or an appointment slot is made conditional on a newsletter subscription although the subscription is not necessary for it, the element of free choice is regularly missing and the consent is invalid (General Data Protection Regulation, Article 7(4); German Data Protection Conference, guidance on direct marketing). The difference lies in free choice, not in the incentive: a discount code that is also available without subscribing stays permissible; a discount code available only in exchange for the subscription is the classic case of tying. If you communicate price advantages openly anyway, the groundwork is covered under showing prices on your website.
Deleting inactive addresses, refreshing consent
Consent does not, in principle, expire through the mere passage of time; the Federal Court of Justice clarified this for the equivalent earlier legal position (Federal Court of Justice, judgment of 1 February 2018, III ZR 196/17). It does not follow, though, that a mailing list should run on indefinitely. The principles of transparency and storage limitation can mean that controllers may no longer rely on consent where they have left it unused for a long period and data subjects no longer have to expect processing (German Data Protection Conference, guidance on direct marketing; General Data Protection Regulation, Article 5(1)(e)). Concretely, the supervisory authorities recommend renewing the information, or indeed the consent itself, where consent has gone unused for more than two years (German Data Protection Conference, guidance on direct marketing).
- Addresses without confirmation: delete after a short window, with no further mailing.
- Addresses with an objection: remove from the list, keep the record of the earlier consent separately.
- Addresses with no opens or clicks over a long period: approach them deliberately and drop them if no reaction follows.
- Consent unused for around two years: renew the information or obtain fresh consent.
- Lists during a change of system: migrate the logs as well, otherwise the evidence is lost in the move.
The effort stays small once it becomes routine. One fixed appointment per quarter is enough: look at the numbers, sort out inactive addresses, check the consent wording against current practice. If you already run website maintenance as a fixed routine, simply add the mailing list to the same checklist. The side effect is commercial: smaller, active lists achieve better delivery rates, because mailbox providers evaluate recipient behaviour. A list without reactions harms deliverability for the entire sender domain.
Taking signups without third-party scripts
Many signup forms are embedded as a ready-made component: a script from an external provider, a form inside a frame, a window from an outside source. With that, the signup technically leaves your own page. The consequences are familiar from dealing with embedded maps, videos and fonts: loading the page opens connections to third parties, transmits IP addresses and, depending on the setup, stores information on the device. For a page that is delivered statically and otherwise manages without third-party content, that is an avoidable break.
The leaner route works with static delivery too: the form is part of the delivered page, submission goes to an endpoint on the same domain, and processing happens there. No external script is loaded, no connection to a third-party provider is opened, and no cookie is set beyond what is technically necessary. As a side effect the page stays fast, because no additional JavaScript has to load before it renders.
Your own domain
Form and endpoint sit under the same domain. Merely loading the page creates no connections to third parties.
Logs kept in house
Timestamp, consent wording, confirmation and origin are stored where the other enquiries sit, and remain exportable.
Without extra scripts
No embedded external form, no additional tracking. What the spam protection needs runs server-side and without profiling.
One frequent misunderstanding concerns consent in the cookie banner. A signup form that stores or reads no information on the device and loads no third-party content needs no separate consent there; consent to the newsletter is a different thing from consent to accessing storage on the device. How the two fit together is set out under GDPR and consent on the website. As soon as a service provider processes the addresses on your behalf, a data processing agreement comes into play; the requirements are summarised under data processing agreements with website vendors.
Signup, evidence and legal pages with XICflow
In XICflow the signup form is a building block of the page rather than an embedded foreign element. Submission runs through an endpoint on the website's own domain, and delivery stays static and therefore fast. The consent wording is more than a label here: it is stored together with the signup, so it remains traceable later which text was agreed to and when that happened.
- Signup form with one mandatory field, optional extra fields and an empty checkbox that has to be ticked actively.
- Storage of consent wording, timestamp, source page and confirmation, exportable in case anyone asks.
- Confirmation mail without promotional content, sent through the website's own domain.
- Automatic links to the privacy policy and the imprint, in every language version of the site.
- An unsubscribe route via a link that works without a customer account and without re-entering the address.
- Static delivery without embedded external forms, so the page manages without extra scripts.
What that looks like in a finished state can be seen in the example websites: signup block, legal pages and contact routes all come from the same data basis, so they do not drift apart. Which building blocks sit behind it, and how forms, legal pages and delivery relate to each other, is described in the product overview. Existing lists can be migrated as soon as there is evidence for the addresses they contain; for everything else, a fresh and logged signup is the more honest route.
Sources and studies