What does consent have to be?
GDPR is long, but the part that governs your email list is short and human. To email someone marketing, you need their consent, and consent has a specific meaning: a clear, informed yes that the person chose to give. Four plain qualities make it real.
- Freely given. She could have said no just as easily, and nothing she wanted was held hostage to her yes.
- Specific. She agreed to marketing email, not to 'anything you feel like doing with my address.'
- Informed. She knew who she was hearing from and roughly what she would get before she agreed.
- Unambiguous. She did something active to say yes rather than simply failing to object: ticked an empty box, tapped a button.
Notice what this rules out. A yes that was assumed, buried, pre-filled, or taken in exchange for something she needed is not consent under GDPR, however many addresses it collects. The law is not asking you to be a lawyer. It is asking you to make sure a yes is really a yes.
Where do stores get it wrong?
Most consent mistakes are not villainy. They are old habits copied from other stores. These are the common ones, and every one of them collects addresses you are not actually allowed to email:
- The pre-ticked box. A checkbox already ticked when the page loads is the classic mistake. Silence is not a yes, and a box she never touched is silence.
- Consent bundled with the purchase. 'Enter your email to complete your order' collects an address to send a receipt, not permission to send marketing. One does not imply the other.
- The buried agreement. Consent hidden in a wall of terms she had to accept is not freely given or specific. She agreed to check out, not to hear from you weekly.
- The forced trade. 'Agree to marketing to get your discount' makes the yes the price of something she wanted, which is the opposite of freely given.
Capture it right, at the form
Doing it right is not harder than doing it wrong. It is mostly a matter of asking plainly at the moment you collect the address. Wherever an email address enters your world, the consent question should be right there beside it.
- At the signup form or popup, offer a clear, unticked choice to receive marketing, in words a person understands, not legalese.
- At the checkout, keep the receipt and the marketing opt-in separate. Let her buy without subscribing, and let her subscribe with a deliberate tick.
- Say what she is signing up for in a short line so the yes is informed: what kind of email, and roughly how often.
- Make the yes an action she takes, never a default she has to notice and undo.
This costs you a few addresses from people who would not have wanted your mail anyway, and those are precisely the addresses that hurt your email deliverability and invite complaints. A consent-first list is smaller and worth more, because everyone on it actually chose to be there.
How do you prove consent was given?
Here is the word most stores miss: compliant. It is not enough to get consent. You have to be able to prove you got it. If someone ever asks, or a regulator does, 'they seemed fine with it' is not an answer. A record is.
So every time someone opts in, keep the quiet facts that show it was real: that this person said yes, to what exactly, and when. You do not build this by hand. The tool that captures the address should capture the proof alongside it, automatically, and hold it for as long as you are mailing that person. Consent you cannot evidence is, for practical purposes, consent you do not have.
Honor every no, for good
Consent is not a one-time capture; it is a standing relationship, and the person can end it whenever she likes. Honoring that quickly and completely is as much a part of compliance as the opt-in was.
- Make leaving easy. A clear, one-click unsubscribe in every marketing email is required, and it is also just decent.
- Treat an unsubscribe as final. Once she leaves, she stays left: no quiet re-adding her the next time she buys something.
- Honor erasure. If she asks to be forgotten, remove her, and be sure your tool can actually do it, cleanly and for good.
None of this weakens your marketing. The people who leave were never going to buy from your emails; letting them go in peace protects the inbox reputation that carries your mail to everyone who stayed. A no, honored well, is not a loss. It is the system working.
The owner's checklist
Everything above, as the list you can check your store against this week:
- Ask for marketing consent as a clear, unticked, freely-given yes, separate from the purchase and the receipt.
- Say in a short line what she is signing up for and roughly how often, so the yes is informed.
- Never pre-tick, never bundle consent into terms, never make it the price of a discount.
- Keep a record of every opt-in, captured automatically, not by hand: who, to what, and when.
- Put a one-click unsubscribe in every marketing email and treat every unsubscribe as permanent.
- Be able to honor an erasure request completely, and confirm your tool actually can.
Where Overvio fits
Consent is a discipline, and the checklist above holds whatever you use to capture email. Overvio's job is to make the compliant path the default one. Its signup forms and popups ask for marketing consent as a clear, unticked, separate choice. When someone opts in, the proof of that yes is recorded alongside the address, automatically, without you keeping a spreadsheet.
Unsubscribes are honored on their own and stay honored; erasure requests remove a person cleanly and for good. If you want the fuller picture of how Overvio treats consent, deletion, and EU data, our approach to GDPR and privacy lays it out plainly. Capturing email the right way should be the easy way. That is the whole idea.

