CIPP/E Study Guide
Ch 16.1 - Right to opt out

Right to opt out of direct marketing

Whatever the lawful basis, the GDPR gives individuals an absolute right to object to direct marketing. On consent, they withdraw consent; on legitimate interests, the opt-out is the right to object under Article 21, which can be exercised at any time and cannot be overridden by a balancing test. Marketers must inform people of this right at first contact, honour requests promptly and free of charge, and should suppress rather than delete contact details.

The right to opt out applies regardless of whether the lawful basis is consent or legitimate interests, and across all channels (post, phone, email, any other). It must be brought to the individual's attention at the first communication, clearly and separately from other information.

Suppress, don't delete

On opt-out, controllers should suppress (keep a do-not-contact record) rather than delete. Deleting risks re-acquiring the person's details later and marketing to them again, against their wishes. The marketer must also stop using any profiling data about them.

How the opt-out works by lawful basis
Lawful basisMechanismCan the controller refuse / balance?
Consent (Art 6(1)(a))Withdraw consentNo - withdrawal must be as easy as giving it
Legitimate interests (Art 6(1)(f))Right to object, Art 21(2)No - objection to direct marketing is absolute, exercisable 'at any time'
  • Opt-outs must be honoured promptly and free of charge (no premium-rate-text-to-opt-out).
  • Minor incidental costs (e.g. the individual's own ISP charging to send an email) don't make it 'not free'.
  • Cleanse marketing lists against internal opt-out records before each campaign - and don't invite opted-out people to opt back in.
  • Many member states run national opt-out registers ('Robinson Lists' / preference services). Failing to cleanse a Robinson List is usually a breach of specific national law, not of data protection law itself.
  • A valid opt-in consent overrides a person's listing on a Robinson List.

Key terms - quick answers

What is “Article 21”?
GDPR right to object. Art 21(2) gives an absolute right to object to direct marketing 'at any time'; once exercised, the data may no longer be processed for marketing.
What is “Suppression list”?
A retained record that an individual must not be marketed to (e.g. in marketing-automation software), used instead of deletion so they are not re-acquired and re-marketed.
What is “Compelling legitimate grounds”?
Art 21(1) ground a controller must demonstrate to keep processing despite a general objection. Note: this does NOT defeat an objection to direct marketing, which is absolute.
What is “Preference service”?
A national opt-out register (e.g. UK Mail Preference Service / Telephone Preference Service) for a given channel.