A rule has been circulating for twenty years: the GDPR supposedly requires double opt-in, that confirmation message sent after a signup, which you must click to be truly subscribed.
We looked for the text. It does not exist.
Not in the GDPR, not in the ePrivacy directive, not in the published guidance of the French data protection authority, not in the European guidelines. The term itself appears nowhere.
What the GDPR requires, and nothing more
Consent is defined in Article 4(11):
“‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”
A clear affirmative action. Once.
Recital 32 gives the examples the legislator had in mind, and all of them are single-step:
“This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject’s acceptance of the proposed processing.”
And the sentence that draws the prohibition, which never mentions confirmation:
“Silence, pre-ticked boxes or inactivity should not therefore constitute consent.”
As for Article 7, it imposes only one obligation, and it concerns proof: “the controller shall be able to demonstrate that the data subject has consented”.
Demonstrate. Not confirm.
What the French authority actually recommends
The CNIL reference page on electronic prospecting, updated on 10 June 2026, contains one recommendation about form, and only one:
“La CNIL recommande que le consentement préalable (pour le B to C) ou le droit d’opposition (pour le B to B) soit recueilli par le biais d’une case à cocher. L’utilisation d’une case pré-cochée est interdite en matière de recueil du consentement.”
A tick box. Not a second message.
On proof, the CNIL names a different mechanism: “Les responsables du traitement peuvent notamment tenir un registre des consentements, qui peut s’insérer dans la documentation plus générale de l’organisme.”
A consent register. Not an email confirmation.
Note finally that the CNIL’s explanatory page on the subject knows only two concepts, opt-in and opt-out. There is no third category in its published guidance.
What the European authority says
The European Data Protection Board guidelines on consent, adopted in May 2020, settle the question at paragraph 107:
“It is up to the controller to prove that valid consent was obtained from the data subject. The GDPR does not prescribe exactly how this must be done. However, the controller must be able to prove that a data subject in a given case has consented.”
The GDPR does not prescribe how. It is an obligation of result on proof, with the means left open.
Paragraph 108 gives the example the Board settles on, and it is no more a confirmation message: “the controller may keep a record of consent statements received, so he can show how consent was obtained, when consent was obtained and the information provided to the data subject at the time”.
The phrase “double opt-in” appears not once in those guidelines. Not in English, not in French.
Across the Channel, the ICO writes the same: “There are several ways you can obtain consent for your electronic mail marketing. For example, you could use opt-in tick boxes or take the consent verbally.”
Consent may be verbal. That is a long way from a requirement for double written confirmation.
So why does everyone recommend it?
Because it is a good practice. Just not a legal one.
Double opt-in solves three technical problems, and it solves them well.
It eliminates typos, which are the leading source of invalid addresses in a self-declared list.
It neutralises malicious signups. An address entered by a third party never confirms, so never enters. That is the most effective defence against form hijacking, the very thing Spamhaus recommends protecting your forms against.
And it mechanically removes spam traps, which never click on anything.
Three deliverability benefits. Zero legal obligation. Confusing the two registers is precisely the mistake commercial guides make, and it has a consequence: it makes people believe a double opt-in list is legally protected, which is false.
What is actually sanctioned
Look at what the French authority holds against companies in its recent decisions, and you will see that double opt-in never appears.
What gets sanctioned is the inability to produce proof, the deceptive appearance of collection forms, transmission to partners without a valid legal basis, and retention beyond the permitted periods.
A company practising double opt-in but keeping no timestamped record of the original signup has demonstrated nothing. A company keeping a complete register without double opt-in has satisfied Article 7.
The question is not how many clicks. The question is: what can you produce, three years later, for an address picked at random from your list?
What to do tomorrow morning
Take ten addresses at random from your database and try to reconstruct, for each, the collection date, the form used, the text displayed at the time and the purpose accepted.
If you manage it for all ten, your proof arrangement holds, with or without double opt-in.
If you manage it for none, adding a confirmation step tomorrow fixes nothing: you will have proof for future subscribers and still none for the existing list.
Keep the text of the forms, not just the ticked boxes. The authority judges the appearance of the form, which requires being able to show what it looked like on the day.
And keep double opt-in if you practise it. It does not protect you legally, but it protects your domain, which is reason enough.
Sources
- European Union (27 April 2016). Regulation (EU) 2016/679 (GDPR), Articles 4(11) and 7, Recital 32
- CNIL (updated 10 June 2026). La prospection commerciale par courrier électronique, SMS-MMS et automate d’appel
- CNIL. Conformité RGPD : comment recueillir le consentement des personnes ?
- EDPB (version 1.1, May 2020). Guidelines 05/2020 on consent under Regulation 2016/679, paragraphs 106 to 108
- ICO. How do we comply with the PECR electronic mail marketing rules?
LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.
