3 August 2026 · Last reviewed 3 August 2026

Consent vs Legitimate Interest for Email Marketing: Which Should You Use?

When UK businesses set up email marketing, one of the first questions is which GDPR lawful basis to use: consent or legitimate interest. Both are valid under Article 6 of the UK GDPR — but they apply in different circumstances, carry different documentation requirements, and have different practical implications for your list.

The choice is also not purely a GDPR question. PECR adds an additional layer that shapes which basis is even available to you for email marketing.

The PECR constraint that shapes the choice

Before choosing between consent and legitimate interest as your GDPR basis, you need to understand that PECR Regulation 22 governs whether you can send a marketing email at all — and PECR only gives you two options for marketing to individual subscribers (consumers, sole traders, small partnerships):

  1. Explicit prior consent (PECR consent)
  2. The soft opt-in under Regulation 22(3)

GDPR legitimate interest is not a PECR option. You cannot satisfy PECR by relying on legitimate interest alone.

This means the choice between GDPR consent and GDPR legitimate interest is most meaningful for:

  • B2B email to corporate subscribers (limited companies, LLPs) — where PECR's consent requirement doesn't apply to the company
  • Postal direct marketing — which PECR doesn't regulate at all
  • Other marketing processing (building suppression lists, profiling for segmentation) — where you need a GDPR basis for the processing activity, separate from the PECR send permission

For consumer email lists, if you have PECR consent, you typically also have GDPR consent — and the two align cleanly. For B2B email to companies, you have PECR flexibility but still need a GDPR basis for the individual's data.

Our PECR vs GDPR overview explains the two-layer structure in more detail.

When to use GDPR consent

GDPR consent is the right basis when:

  • You are building a consumer email list from scratch and want a clean, robust foundation
  • Your audience includes sole traders or individuals (PECR will likely require consent anyway)
  • The processing is sensitive or your audience would not expect to receive marketing from you
  • You want the clearest possible basis with the lowest enforcement risk

What GDPR consent requires:

  • Freely given, specific, informed, and unambiguous
  • Clear affirmative action (unticked checkbox, not pre-ticked or bundled)
  • Separate from terms of service or other consents
  • Easy to withdraw — as easy as it was to give
  • Documented — you must be able to show when consent was given, what the person was told, and through what mechanism

Key trade-off: Consent is strong but it decays. People forget they consented, lapse into disengagement, and either unsubscribe or simply stop opening. Lists built on consent require active consent management to remain usable. The consent records retention guide covers what records you need and for how long.

When to use legitimate interest

Legitimate interest is the right basis when:

  • You are doing B2B email marketing to business organisations (corporate subscribers) where there is a genuine commercial relationship
  • You are doing postal direct marketing to individuals where PECR doesn't apply
  • You are processing data for marketing purposes that aren't the email send itself (building suppression lists, lead scoring, segmentation)
  • You have an existing customer relationship and are marketing genuinely related products or services

What legitimate interest requires:

  • A documented Legitimate Interests Assessment (LIA) covering the three-part test: purpose, necessity, and balancing
  • A genuine interest that passes the balancing test against the individual's reasonable expectations
  • An easy-to-exercise opt-out mechanism in every marketing communication
  • An absolute right to object to direct marketing, which must be honoured immediately

Key trade-off: Legitimate interest is more flexible than consent — you don't need to collect anything at the point of first contact, and it doesn't decay in the same way. But it requires genuine analysis, ongoing documentation, and an unconditional right to object. See our legitimate interest assessment template for a worked example of the LIA.

The DUAA 2025 change: what it means in practice

The Data (Use and Access) Act 2025 inserted direct marketing as an example of a legitimate interest under Article 6(1)(f) of the UK GDPR. This is a strengthening of the legal position for legitimate interest — it removes the ambiguity that existed before about whether marketing could be a legitimate interest at all.

But the DUAA did not:

  • Remove the balancing test for direct marketing
  • Add direct marketing to the "recognised legitimate interests" category (which would remove the balancing test)
  • Change PECR's requirements for electronic marketing

In practice, legitimate interest remains the right basis for B2B email and postal marketing, but it still requires the full LIA. Our guide to the DUAA 2025 PECR changes covers the full picture.

A practical decision framework

You are building a consumer email newsletter list: Use consent. You will likely need PECR consent anyway. Align your GDPR basis with your PECR basis for the cleanest compliance position.

You are emailing existing customers about similar products: Consider the soft opt-in (PECR) + consent or legitimate interest (GDPR). If you gathered consent at purchase, use it. If not, evaluate whether the soft opt-in conditions are met for PECR, and whether legitimate interest works for GDPR given the existing relationship.

You are doing B2B email outreach to company addresses: You don't need PECR consent for the company. Use legitimate interest as your GDPR basis for processing the named individual's work email. Complete the LIA. Provide opt-out in every message.

You are doing postal direct marketing: PECR doesn't apply. Use legitimate interest if there is a genuine commercial interest and the balancing test is passed. Consent is also valid but less commonly used for post.

You are managing a suppression list: You are processing personal data to prevent marketing — legitimate interest typically applies here, even for contacts who originally came in via consent.

What to document either way

Whether you choose consent or legitimate interest, the documentation requirements are substantial:

For consent: Date consent was given, what the person was told (the exact wording of the consent mechanism), how they consented (checkbox, written form, verbal), who holds the evidence, and when (if ever) consent was withdrawn.

For legitimate interest: The completed LIA (purpose, necessity, and balancing tests), the date it was completed, who completed it, when it was last reviewed, and what the opt-out mechanism is for each marketing activity.

The PECR compliance checklist sets out the evidence requirements across both bases.


This article is for informational purposes only and does not constitute legal advice. For guidance specific to your situation, consult a qualified legal professional or data protection officer.