All posts
15 min read

Getting opt-in: consent people actually complete

What UK law needs before you message your own customers, how it differs by channel, and why most tricks for lifting opt-in rates make consent invalid.

A person filling in a short form on a smartphone.
On this page

Two different questions get asked as one. What am I allowed to send, and how do I get more people to say yes.

They are connected in an awkward way. Most of the published techniques for raising opt-in rates work by making the choice less clear, and a choice that is less clear is not valid consent. The honest set of levers is smaller than the internet suggests.

The good news is that the small set works, and it is mostly about asking for less at a better moment.

Key takeaways

  • Two layers apply. PECR decides whether you may send marketing at all. UK GDPR decides whether you had a lawful basis for holding the details.
  • Consent has to be a clear affirmative action. Pre-ticked boxes, silence and “by joining you agree” all fail, and the ICO says so explicitly.
  • The soft opt-in can cover email and SMS without a tick, but only on three conditions, and a counter sign-up with no purchase probably does not meet the first one.
  • Whether a wallet pass push counts as marketing is genuinely unsettled. The useful distinction is administrative versus promotional, not the channel.
  • The design changes that lift consent rates in published experiments are the same ones a regulator would call invalid. Ask for less instead.

This is a working guide, not legal advice. Several points below are genuinely unsettled, and they are flagged where they arise.

The two layers

Almost all the confusion on this topic comes from treating one question as two separate rulebooks, or two questions as one.

PECR, the Privacy and Electronic Communications (EC Directive) Regulations 2003, governs whether you may send a marketing message by electronic means. This is the layer that decides if you can hit send.

UK GDPR governs whether you may hold and use the personal data at all. This is the layer that decides your lawful basis.

You need both. If you take the consent route, your lawful basis is consent. If you rely on the soft opt-in described below, the ICO’s position is that your lawful basis is likely to be legitimate interests, which needs its own assessment written down.

UK GDPR defines it, and the definition is doing real work:

any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her

Four adjectives and one action. The ICO’s guidance turns them into rules that are blunt enough to check your own form against.

On pre-ticked boxes: “Silence, pre-ticked boxes or inactivity should not therefore constitute consent.”

On opting out: “There is no such thing as ‘opt-out consent’. Failure to opt out is not consent.”

On bundling: “Consent should not be bundled up as a condition of service unless it is necessary for that service.”

That last one is the common failure in a loyalty sign-up. Making marketing consent a condition of joining the card fails, because you do not need marketing permission in order to operate a stamp card. The card works without it. The ICO also expects you to name yourself in the request, so “we may share your details with selected partners” is not a thing a small shop should be writing at all.

The soft opt-in, and whether it covers you

There is a route that does not need a tick, and it is the one most shops are quietly relying on without knowing its name.

Regulation 22(3) sets three conditions, all of which must hold:

(a) that person has obtained the contact details of the recipient of that electronic mail in the course of the sale or negotiations for the sale of a product or service to that recipient; (b) the direct marketing is in respect of that person’s similar products and services only; and (c) the recipient has been given a simple means of refusing … at the time that the details were initially collected, and, where he did not initially refuse the use of the details, at the time of each subsequent communication.

Three things follow that matter at a counter.

It covers electronic mail. The ICO reads that to include email, SMS, picture and video messages, voicemail, in-app messages and social media direct messages. It does not cover live phone calls.

“In the course of the sale” is broader than a completed sale, but not unlimited. The ICO says a person “doesn’t need to actually buy anything from you. It’s enough if ‘negotiations for the sale’ took place”, while also requiring that they “actively express an interest in buying your products or services”.

So a customer who buys a coffee and joins your card at the till is on much firmer ground than somebody who scanned a QR code in the window and joined without ever buying anything. The safest ground is a join that sits alongside a purchase or a genuine enquiry about buying. With neither, the soft opt-in is hard to justify. Whether a given counter sign-up clears that bar is a real question for a lawyer, not something to settle from a blog post.

Condition (c) is the one that gets people fined. The refusal has to be offered at collection and in every message afterwards. Not one or the other.

A decision flow for whether you may send marketing by email or SMS: a clear separate yes gives you consent; otherwise the soft opt-in route requires details collected during a sale, similar products only, and a refusal offered at collection and in every message.May you send this person marketing by email or SMS?Did they give a clear yes to marketing,separate from joining the card itself?YesConsent. Send, with a wayto opt out in every message.NoWere the details collected during a sale,or a genuine negotiation for one?NoNo route. Do not sendmarketing to them.YesYour own similar goods only, with a refusaloffered then and in every message since?NoNo route. Fix the gapbefore sending anything.YesSoft opt-in may apply. Write down why.
The consent route is simpler and safer. The soft opt-in has three conditions and all of them have to hold.

Where push notifications sit

If your loyalty card lives in Apple Wallet or Google Wallet, the customer added the pass themselves, and the pass can send notifications. Does PECR apply?

This is genuinely unsettled, and anybody who tells you otherwise is guessing. The ICO’s guidance on electronic mail names in-app messages, and we could not find push notifications named anywhere in it. The underlying definition in PECR is broad enough to capture them on a plain reading: “any text, voice, sound or image message sent over a public electronic communications network which can be stored in the network or in the recipient’s terminal equipment until it is collected by the recipient.”

Rather than betting on the channel question, use the distinction that is actually documented. The ICO’s position is that service messages “do not count as direct marketing if they only provide administrative information and do not promote anything. However, if you add advertising or marketing material the message becomes direct marketing.”

That draws a clear line through the messages a loyalty card sends:

Message Reads as Why
“Your card is full. Your next coffee is free.” Administrative It reports the state of their account and promotes nothing
“You are one stamp from a free coffee.” Administrative Same. It is a fact about their card
“Your card is full, and Fridays are 20% off.” Marketing The second clause is a promotion
“New winter menu from Monday.” Marketing Nothing to do with their account

The conservative approach, which is the one worth taking: collect consent anyway, put an opt-out in anything promotional, and keep purely administrative notifications clearly separate from offers. That way the unsettled question never has to be answered.

What the ICO actually fines people for

Worth a look, because the pattern is more useful than the amounts.

On 20 January 2026 the ICO issued £225,000 in fines across two companies. Allay Claims Ltd was fined £120,000 for 4,046,947 marketing texts sent over a year. Its soft opt-in defense failed because it “failed to offer a simple way for customers to refuse marketing” when the details were collected. That is condition (c), and it was the only thing that went wrong.

ZMLUK Ltd was fined £105,000 for 67,772,285 emails. Its consent was invalid because it was bundled across 361 “partner” companies with no granular choice.

Neither is a corner shop, and the volumes are not comparable to anything a café does. The instructive part is why each one failed. One forgot the refusal at collection. The other bundled the permission. Both mistakes are available to a business with fifty customers.

One change worth knowing about: since the Data (Use and Access) Act 2025 commenced on 5 February 2026, the maximum PECR penalty rose from £500,000 to £17.5 million or 4% of global turnover, whichever is higher. The ceiling has moved a long way. The cases the ICO actually publishes remain large-volume senders rather than small shops.

Designing the ask so people finish it

Now the second question, and the reason it is harder than it looks.

The most useful evidence comes from Midas Nouwens and colleagues, who scraped 680 cookie consent interfaces and ran a field experiment with about 40 participants. Their findings are worth reading as a warning rather than a playbook.

Removing the opt-out from the first screen raised consent by 22 to 23 percentage points. Putting genuine granular controls on the first page lowered it by 8 to 20 points. Whether the thing was a banner or a full barrier made no difference at all.

That is website cookie banners on a small sample, not a counter sign-up, so do not read the numbers across. Read the direction across, because it is the part that generalizes.

In other words, the changes that most improve opt-in rates are precisely the ones a regulator would call invalid. If you go looking for tricks, those are the tricks, and they are not available to you.

What is left is genuine and still effective: ask for less, and ask at a better moment.

The UK Government Digital Service manual gives the rule in one line: only ask for information “if you know that you need the information to deliver the service.” Every field beyond that is a place to abandon the form.

For scale, Baymard Institute’s checkout research found the average checkout ran 11.3 fields in 2024, down from 12.7 in 2019, and concludes that most sites need only about 8. Checkout is not a loyalty join form, and a join form should be far shorter, but the direction is the point: the number of fields has been coming down because shorter works.

Which fields a join form should actually contain is covered in what to put next to the till, which makes the case for a name plus one contact field and treats everything else as optional. What this page owns is the box underneath it.

That box has three jobs:

  • Stand on its own. Separate from joining the card, so the customer can have one without the other.
  • Name you. “From [shop name]”, not “from us and selected partners”. This is the failure that cost ZMLUK £105,000.
  • Start unticked. An empty box the customer chooses to fill is the clear affirmative action the definition asks for.

The wording that has to do the work:

Email me offers and news from [shop name].
You can unsubscribe at any time.

Unticked, separate from the join, specific about who is sending. That is the whole thing.

A counter-top sign beside a display case in a small shop.

Photo by Thoriq Shobih on Unsplash.

There is no published research on the wording of consent checkboxes specifically, or on where a QR code should sit on a counter. Anybody quoting you a number on either is making it up. What to put next to the till covers the placement question from experience rather than from data, and says so.

Frequently asked questions

Do I need a tick box if someone gives me their email to join a loyalty card? For the card itself, no. Running the card is the service they asked for. For marketing that is not about their own account, you need either a separate unticked consent box or a soft opt-in you can actually justify. The safe answer for most shops is the box, because it removes the argument entirely.

Can I message customers I collected before I had a proper consent box? This is the question most worth paying a professional for. It turns on how the details were collected and what people were told at the time, and the answer is often that some of the list is usable and some is not. Do not assume a blanket yes, and do not assume a blanket no either.

Does an unsubscribe link have to be in every message? Under the soft opt-in, yes, that is condition (c) and it is explicit. Under consent, you must let people withdraw as easily as they gave it. In practice put a working opt-out in everything promotional and stop worrying about which route you are on.

What about SMS specifically? Same rules as email. PECR treats both as electronic mail, so the soft opt-in can apply to texts as well. The practical difference is that people are far less tolerant of an unexpected text, so a technically defensible SMS can still cost you a customer. Push, email or SMS covers what each channel is for.

Is “by joining you agree to receive our offers” enough? No. That bundles marketing consent into the service, which the ICO says should not happen unless the consent is necessary to deliver the service. A stamp card works perfectly well without marketing permission, so it is not necessary.

Do I need to keep a record of consent? Yes, and it is the part most shops skip. You want to be able to say who consented, when, and to what wording. If your loyalty system stores that automatically, check that it does. If you are collecting on paper, keep the paper.

Where to go next

Getting the opt-in is the first half. Deciding what to do with it is loyalty segmentation, and how often anyone should hear from you is how often should you message your customers.

The counter moment where the ask actually happens is what to put next to the till. What to send once somebody has said yes is automated loyalty campaigns and writing a message people do not delete.

A join form that keeps the marketing consent separate from the card, records what was agreed and when, and puts an opt-out in every message, is what Passumo does by default. The channels page covers what goes out on which.


This article is general information about UK rules, not legal advice. Four points above need a professional rather than a blog:

  • whether a particular counter sign-up counts as “negotiations for the sale”
  • whether a wallet pass push notification is electronic mail under PECR
  • what counts as “similar products and services” for a business that does more than one thing
  • any reuse of contact details collected before your current wording was in place

Sources: PECR regulation 22 and regulation 2, legislation.gov.uk; UK GDPR Article 4. ICO guidance on valid consent and key concepts for direct marketing using electronic mail. Enforcement figures from the ICO’s January 2026 announcement and its statement on the commencement of the Data (Use and Access) Act. Consent interface findings from Midas Nouwens, Ilaria Liccardi, Michael Veale, David Karger and Lalana Kagal, “Dark Patterns after the GDPR”, CHI 2020. Form length figures from Baymard Institute and the GDS Service Manual.