CIPP/E Study Guide
IAPP Training · Module 8 - BoK V.C

Module 8 · Direct marketing channel rules & the soft opt-in

Channel rules differ sharply. Postal marketing is outside ePrivacy and can often rely on legitimate interests. Person-to-person phone calls need no consent (but automated calling systems require consent). Email and SMS generally need prior consent, unless the soft opt-in applies. Fax requires consent. The soft opt-in lets a controller market its own similar products to a person whose details it got in the context of a sale, if they could opt out at collection and in every message.

Direct-marketing channel matrix
ChannelConsent basisKey conditions
PostOutside ePrivacy - GDPR + national law; often legitimate interestsBalance: existing customer? nature of products? prior opt-out?
Live (person-to-person) phoneNo consent required for live callsArticle 13(3): Member State picks opt-in or opt-out; free opt-out minimum; screen opt-out registers
Automated phone (calling systems)Consent requiredApplies to automated/recorded calling systems
Email & SMS/MMSGenerally prior consentOr the soft opt-in; give valid opt-out, clear sender identity, clear commercial indication
FaxConsent requiredUnder ePrivacy
Soft opt-in conditions

The soft opt-in needs ALL of: the controller's own similar products/services; details obtained in the context of a sale; the chance to opt out at collection; and an opt-out in every subsequent message.

Since 2009, ePrivacy telephone rules cover both B2C and B2B. Most digital marketing other than person-to-person telephone requires prior opt-in consent.

Key terms - quick answers

What is “Soft opt-in”?
ePrivacy exemption letting a controller email/SMS its own similar products/services to a person whose details it obtained during a sale, if the person could opt out at collection and in every subsequent message.
What is “Opt-out register”?
A list (e.g. a do-not-call register) that marketers must screen against before making live calls in jurisdictions that use them.
What is “Automated calling system”?
A system that places marketing calls without a live person; it always requires consent under ePrivacy.