GDPR consent for marketing messages: a practical guide
Consent isn't a checkbox — it's a record you must honour and prove. How to get it right across email, SMS and WhatsApp.
Under the GDPR and ePrivacy rules, marketing messages generally require freely-given, specific, informed and unambiguous consent — and you must be able to demonstrate it.
Capture consent properly
- Use double opt-in for email so the address and intent are verified.
- Make consent granular: separate channels and topics, not one blanket toggle.
- Log when, how and what the customer agreed to.
Honour it automatically
Consent is worthless if a campaign ignores it. Enforce checks before every send, and offer one-click unsubscribe everywhere.
Give customers control
A self-serve preference center reduces complaints and unsubscribes — people would rather dial down than opt out entirely.
WeZend stores granular consent on the profile and enforces it on every message, with a hosted preference center and full audit logging.
This is general information, not legal advice.