Marketing Consent: Wording, Examples & Templates
Getting marketing consent right is mostly about two things: the exact words next to the checkbox, and proving later that someone actually ticked it. Here's the wording that holds up, copy-ready examples, and the rules behind them — GDPR, CAN-SPAM, and CASL.
What this covers
What marketing consent is
Marketing consent is a person's permission to receive promotional communications from you — email, SMS, or push — and, separately, permission to process their data for that purpose. It's distinct from cookie consent (which governs tracking on your website) and from your terms of service (which governs the relationship). Bundling them together is one of the most common and costly mistakes: attaching a newsletter opt-in to "I agree to the Terms" invalidates the marketing consent under GDPR, because consent has to be specific and unbundled.
The practical center of gravity is the consent checkbox and the words beside it. That short sentence determines whether the consent is valid — and whether, months later, you can defend it. Consent-based marketing isn't a compliance tax; lists built on genuine opt-in consistently outperform bought or bundled lists on engagement, because the people on them actually chose to be there.
The three laws that govern marketing consent
Which rules apply depends on where your recipient is, not where you are. Segment your list and apply the strictest law per subscriber.
What makes consent wording valid
Under GDPR Article 4(11), valid consent must be freely given, specific, informed, and unambiguous — a clear affirmative action. Translated into the words next to your checkbox, that means:
- Unchecked box. The visitor ticks it themselves. A pre-ticked box is not consent — it's the single most common failure DPAs cite.
- Name yourself. The wording identifies your organization by name — who the person is agreeing to hear from.
- State the purpose. Say what they'll receive ("weekly product emails"), not a vague "updates."
- One purpose per box. Separate email from SMS; separate marketing from terms acceptance. No bundling.
- Mention withdrawal. Note that they can unsubscribe any time, as easily as they opted in.
- Link the privacy policy at the point of collection — not buried in a footer.
"We may use your data to improve our services" (vague — no specific purpose). "Sign up for updates" with a pre-ticked box (not affirmative, not unchecked). "By creating an account you agree to receive marketing" buried in a privacy policy (bundled with ToS, not specific). Each of these collapses under GDPR because it fails the freely-given, specific, or unambiguous test.
Marketing consent checkbox: wording that works
Here are checkbox lines you can adapt. Each is unchecked by default, names a purpose, and stands alone. Replace the bracketed parts.
☐ I'd like to receive [Company]'s weekly email with [product tips and offers]. I can unsubscribe any time. See our [Privacy Policy].
☐ Email me [Company] marketing emails (about [new features and promotions]).
☐ Text me [Company] SMS offers. Msg & data rates may apply. Reply STOP to opt out.
☐ I consent to receive marketing emails from [Company Ltd, address] about [privacy & compliance content]. Frequency: ~1/week. Withdraw any time via the unsubscribe link.
GDPR does not explicitly require double opt-in — a single unchecked box with clear wording is valid. But double opt-in (a confirmation email the subscriber must click before joining your active list) produces a stronger consent record, filters bots and typos, and tends to yield materially higher open rates. For CASL and high-risk lists, it's the safer default.
Your website consent needs the same rigor
Marketing consent covers your emails — but the trackers on your site need consent too, before they fire. See which fire before consent on your site in ~10 seconds.
Scan your site free →Email consent wording & message examples
Beyond the checkbox, you'll need consent message examples for the moments where you ask, confirm, or re-permission. A few consent text examples you can lift:
- At signup (confirmation line): "Thanks — please check your inbox and click 'Confirm' to start receiving [Company] emails."
- Double opt-in email body: "You're almost subscribed. Confirm you want [Company]'s [weekly] emails by clicking below. Didn't sign up? Ignore this — you won't be added."
- Preference update: "Choose what you hear about: ☐ Product news ☐ Offers ☐ Events. Change these any time."
- SMS opt-in reply: "Reply YES to receive [Company] offers by text. Msg & data rates may apply. Reply STOP to cancel."
A marketing consent form template
A reusable marketing consent form template — the structure that satisfies GDPR and reads cleanly:
Email address: [_____________]
☐ I'd like to receive [Company]'s [weekly] emails about [topics].
I understand I can unsubscribe any time via the link in every email.
[Optional, separate:] ☐ Text me offers ([rates apply, STOP to cancel]).
We'll only use your details to send what you asked for. See our [Privacy Policy].
[Subscribe button]
// Behind the form, record: email, timestamp, exact wording shown,
// source URL, IP, and consent version — your proof it happened.
How to send a consent (re-permission) email
If you have an old list whose consent you can't prove, the compliant move is a re-permission (re-consent) campaign — how to send a consent email that asks people to actively opt back in:
- Subject: make it plain — "Do you still want to hear from [Company]?"
- Body: explain you're confirming consent, state what they'll get, and make the opt-in a single clear action ("Yes, keep me subscribed").
- Only re-add those who click. Non-responders don't get moved to your active list — that's the whole point. Suppress them.
- Record the new consent — timestamp, wording, and action — as your fresh proof.
It shrinks the list, but what remains is provably consented and far more engaged — which is the entire premise of consent-based marketing.
Key takeaways
The words next to the checkbox are the compliance. Unchecked, named, specific, one purpose per box, withdrawal mentioned, privacy policy linked.
Which law applies depends on the recipient. GDPR/ePrivacy (opt-in) for EU/UK, CAN-SPAM (opt-out) for the US, CASL (express opt-in) for Canada — segment and apply the strictest per subscriber.
Never bundle. Separate marketing from terms acceptance, and email from SMS. Bundled consent is invalid consent.
Consent you can't prove isn't consent. Record who, when, the exact wording, and the source for every subscriber — and re-permission any list you can't defend.
Consent on your emails and your website — handled
ConsentPixel — Privacy · Verified blocks website trackers before consent and logs every decision, the same rigor your marketing consent needs. Scan your site free, then start a 14-day trial.
Start 14-day free trial → Scan a site freeNo credit card required · from $8.99/domain/mo
We build consent infrastructure for websites and the teams that market on them. This article is educational and is not legal advice — consult a qualified privacy professional or your email-compliance counsel for your specific situation.
Frequently asked questions
Does marketing consent have to be a separate checkbox?
Under GDPR, yes — marketing consent must be specific and unbundled, which in practice means its own unchecked checkbox, separate from terms-of-service acceptance and separate for each channel (email vs SMS). Attaching a newsletter opt-in to "I agree to the Terms," or using one box for email and text together, invalidates the consent because it fails the specific and freely-given tests. Give each purpose its own box, unticked, with plain-language wording.
What's the best marketing consent checkbox wording?
Effective wording names your organization, states exactly what the person will receive, notes they can unsubscribe any time, and links the privacy policy — for example: "I'd like to receive [Company]'s weekly email about [topic]. I can unsubscribe any time." The box must be unchecked by default. Avoid vague phrases like "sign up for updates" or "we may use your data to improve our services," which fail GDPR's specific and informed requirements.
Is double opt-in required for email marketing?
No — GDPR does not explicitly require double opt-in. A single unchecked checkbox with clear, specific wording constitutes valid consent in most jurisdictions. However, double opt-in — sending a confirmation email the subscriber must click before joining your active list — produces a stronger consent record, filters out bots and mistyped addresses, and typically yields higher engagement. For CASL (Canada) and any list where proof matters, double opt-in is the safer choice.
Can I email people without their consent under CAN-SPAM?
In the US, CAN-SPAM uses an opt-out model, so prior consent is not strictly required to send commercial email — but you must identify yourself accurately, avoid deceptive subject lines, include a valid physical postal address, and honor unsubscribe requests promptly. That said, if any of your recipients are in the EU, UK, or Canada, GDPR/ePrivacy or CASL apply to them and generally require opt-in consent. Segment your list by location and apply the correct law to each group.
How do I fix a list I can't prove consent for?
Run a re-permission (re-consent) campaign: email the list asking recipients to actively confirm they still want to hear from you, state clearly what they'll receive, and make opting back in a single clear action. Only move people who click to your active list — suppress everyone who doesn't respond. Record the new consent (timestamp, wording, action) as fresh proof. Your list will shrink, but what remains is provably consented and far more engaged.