GDPR Email Consent Examples: 7 Opt-In Patterns That Hold Up in 2026
Most people searching for gdpr email consent examples are not looking for theory. They want wording they can put on a signup form, webinar page, or lead-gen flow today.
That is fair, but example copy only helps if the surrounding choice is valid. The ICO’s electronic mail marketing guidance, updated on April 28, 2026, still says unsolicited marketing emails to individuals need consent unless a narrow soft opt-in applies. Its consent guidance says the request should be prominent, specific, easy to understand, and kept separate from general terms. Across Europe, the same baseline holds: prior consent is the normal rule for direct marketing emails, with a limited existing-customer exception in some cases.
If you want the broader legal backdrop first, start with our guides to GDPR consent email, GDPR marketing consent, and GDPR consent form. This article stays practical: seven examples, when each one fits, and the small wording mistakes that still weaken consent records.

What every strong example has in common
Before you write copy, pressure-test the choice itself.
William Malcolm of the ICO recently said businesses need to “explain why they need it.” That is a good first filter for any consent line. If the person cannot tell why you want the address and what kind of email will follow, the wording is not ready.
The design standard matters too. Anu Talus of the EDPB says privacy options should be presented in an “objective and neutral way.” John Edwards has framed the same fairness point more bluntly: it should be “just as easy to reject” as it is to accept. Good gdpr email consent examples do not hide the no path, bundle multiple purposes, or turn marketing into a condition of getting the service.
They also say who is sending the emails, what type of emails will arrive, and how the person can stop them later. If affiliates, group companies, or partners want to rely on the same permission, name them clearly. Generic wording like “selected partners” is usually where clean-looking forms start to fall apart.
7 GDPR Email Consent Examples You Can Actually Use
1. Simple newsletter signup
Use this when the person is voluntarily requesting updates and the email is optional.
[ ] Yes, send me DataShyre’s privacy and consent newsletter by email. I can unsubscribe at any time.
Why it works: one sender, one channel, one clear purpose.
2. Content download with a separate marketing choice
Use this when someone wants the asset whether or not they want future marketing.
Send me the guide.
>
[ ] Yes, email me DataShyre updates about consent management, privacy compliance, and upcoming webinars.
Why it works: the download and the marketing choice are split. The guide is not locked behind the box.
3. Webinar registration with optional future updates
Use this when event reminders are necessary but ongoing marketing is optional.
We will email you your webinar access details and schedule updates.
>
[ ] Yes, send me future webinar invites and product updates from DataShyre.
Why it works: operational emails and marketing emails are separated instead of blended together.
4. Granular product-form choices
Use this when one form could lead to more than one category of email.
[ ] Product announcements
>
[ ] Privacy compliance tips
>
[ ] Event invitations
Why it works: granular options beat one fuzzy yes. They also make later proof easier because the selected purpose is obvious.
5. Group-company marketing, but only if named
Use this when more than one controller will rely on the consent.
[ ] Yes, I agree to receive email updates from DataShyre and Example Affiliate Ltd. about privacy software and compliance services.
Why it works: the organisations using the consent are identifiable. That is much stronger than asking for permission on behalf of unnamed companies.
6. Double opt-in confirmation
Use this after the first signup, not instead of it.
Please confirm that you want to receive DataShyre email updates by clicking the button below.
Why it works: it strengthens your proof trail. It does not rescue a weak first collection screen.
7. Existing-customer soft opt-in wording
Use this only if you actually qualify. This is not consent copy. It is the PECR exception path for certain existing-customer situations.
[ ] I do not want to receive email updates about similar DataShyre services.
Why it works: it can fit when the email address was collected directly, during a sale or negotiation, for your own similar products or services, and every later email includes an easy unsubscribe path. If those conditions are missing, do not treat this as a shortcut.

The examples that look fine but usually fail
Some patterns still show up all over SaaS forms and ecommerce flows even though they are hard to defend later.
- “By creating an account, you agree to receive offers and updates” usually fails because the marketing request is buried inside other terms.
- Pre-ticked marketing boxes fail because default settings and inactivity are not a clear affirmative action.
- “We and selected partners may contact you” fails because the person cannot tell who else will use the permission.
- One large bright accept button and a faint or hidden decline path fails the fairness test. As Andrew Laughlin put it, people need “meaningful control over how it’s used.”
What to record when someone opts in
The wording matters, but the evidence around it matters more. Keep a record of:
- the email address or user identifier tied to the opt-in;
- the exact consent text or form version shown at that moment;
- the categories or purposes selected;
- the date, time, and source page or workflow;
- any double opt-in confirmation event; and
- later withdrawals, unsubscribes, or preference changes.
That is what makes the examples above useful in real life. If your team cannot reconstruct what the person saw, what they selected, and how they could say no, the copy is doing more work than the process deserves.
Bottom line
The best gdpr email consent examples are plain, narrow, and easy to refuse. If you need consent, ask cleanly. If you are actually relying on a soft opt-in, handle it as a different legal route and do not dress it up as permission you never really collected.
That clarity usually produces better signup rates, better lists, and fewer cleanup projects later.
Sources
- Information Commissioner’s Office guidance on direct marketing using electronic mail
- Information Commissioner’s Office consent guidance
- Information Commissioner’s Office business-to-business marketing guidance
- European Data Protection Board consent summary
- European Data Protection Board annual report
- Your Europe data protection and online privacy guidance