An unsubscribe must stop marketing email from every tool you use, under EU and UK law

Kenneth Graupner photo Kenneth Graupner Published 1 Oct 2026 AI drafted 8 min read
An unsubscribe must stop marketing email from every tool you use, under EU and UK law

A trial user clicks "unsubscribe from all emails" at the bottom of a software company's newsletter. Two days later the company's CRM emails them about the annual plan, and the product email platform sends them a feature announcement. Under EU and UK law, both of those emails went to someone who had already refused marketing. Every marketing email has to offer a free and easy way out, the way out has to work in every tool the company sends from, and where one sign-up put a person on several lists, leaving all of them has to be as easy as that sign-up was.

Regulators act on this. In 2025 France's regulator fined a company partly because people could not leave its four mailing lists in one click. And on 24 September 2026, Retail Gazette reported that the UK's regulator, the Information Commissioner's Office (ICO), had received complaints about the "complexity of Debenhams' unsubscribe process". One shopper said they had to untick 94 boxes across 15 group brands, and that the emails kept coming anyway. No investigation has been announced, and Debenhams told City AM the ICO had not contacted it.

Debenhams is a retailer, but its setup is common in software: a company adds a product-updates list, a webinar list and a second newsletter over time, each with its own toggle, and nobody checks how many steps it now takes to leave all of them. Selling to businesses does not take a company out of this. A named person at a client company can always object to marketing sent to their work address 7.

When does one unsubscribe have to stop all of a company's marketing email?

When the person reasonably understood they were leaving all of it, or when one sign-up put them on all of it. The rules do not require a single link that ends every kind of marketing: the ICO says an opt-out usually covers a specific channel or activity, and its own example lets a person stop texts while still getting emails 8. But if one sign-up form added someone to the newsletter, the product-updates list and the webinar list, I read the rules as requiring one step to take them off all three, because otherwise leaving takes three steps where joining took one. And a link that says "unsubscribe from all" or carries the company's name has to do what it says, in every tool.

Four rules get there.

  1. The ePrivacy rule on marketing email. The EU's ePrivacy Directive requires consent before marketing email, with one exception, often called the soft opt-in, for a company emailing its own customers about similar products. Under that exception the customer must be able to object "free of charge and in an easy manner" in every message 1. Marketing to paying customers can rely on the soft opt-in, while emails to people who only joined a newsletter rely on consent.
  2. Withdrawing consent. The GDPR says "it shall be as easy to withdraw as to give consent" 2. The European Data Protection Board (EDPB), the body of all EU data protection regulators, says that when consent was given with one click, withdrawing it must be just as easy, and free 3.
  3. The right to object to marketing. Anyone can object to their data being used for direct marketing "at any time", and once they do, it "shall no longer be processed for such purposes" 2. There are no exceptions to this right.
  4. The UK version. The UK's Privacy and Electronic Communications Regulations (PECR) copy the EU rule, and the ICO's guidance says a company "should not ask people to create an account to unsubscribe or ask them to log into their existing account to change their preferences" 5.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.

Get started

Has a regulator fined a company for an unsubscribe that worked one list at a time?

Yes. In May 2025, France's data protection regulator, the CNIL, fined CALOGA 80,000 euros, and one of the breaches was exactly this 4. CALOGA bought contact details from other data brokers and sent marketing email on behalf of advertisers. The fine also covered other breaches, such as misleading sign-up forms, so the amount was not for the unsubscribe alone.

CALOGA ran its email marketing through four databases it presented as brands: CALOGA, ZEPLAN, BASYLO and VOZEKO. The CNIL found it "was not possible for prospects to unsubscribe with a single click from the various CALOGA' databases in which they were registered". To leave them all, a person had to email the company's data protection officer. The CNIL's conclusion: "It was therefore not as easy for prospects to withdraw their consent as it was to give it" 4.

The CNIL added a detail that applies to any company with several lists. One of the four databases was itself called CALOGA, so a person clicking the link "do not receive any further offers from CALOGA advertisers" could reasonably believe they had left all of them, when they had left one 4. An unsubscribe link labelled with the company's name that removes people from one newsletter has the same problem.

Why do marketing emails keep arriving after someone unsubscribes?

In software companies the usual reason is that marketing email goes out from more than one tool. A newsletter tool, a CRM sequence and a product email platform each keep their own list, and an unsubscribe recorded in one does not reach the others unless someone connected them. To the person who clicked unsubscribe, the next email is from you, whichever tool sent it.

The law does not allow for that gap. After an objection to marketing, the GDPR says the data "shall no longer be processed" for marketing 2. The GDPR's general one-month deadline for answering rights requests is about replying to the person, and I would not read it as permission to keep emailing them for a month. The ICO's guidance is that a company "must stop the direct marketing that the consent covers immediately or as soon as possible", and that it should keep people who opt out on a suppression list rather than simply deleting them 8.

Gmail has set its own bar since February 2024. Google's sender guidelines require anyone sending more than 5,000 messages a day to Gmail to support one-click unsubscribe in marketing email, and its FAQ on the requirement recommends processing unsubscribes within 48 hours. That is a deliverability rule rather than law, but it gives a concrete number for "as soon as possible".

Which product emails count as marketing?

Any email that promotes something, even when it comes from the product rather than the marketing team. The ICO uses two tests 6:

  • Service messages. Messages a customer needs about a current contract or past purchase, such as changes to terms, are not marketing. They become marketing if they include "significant promotional material aimed at getting customers to buy extra products or services".
  • Surveys and research. Genuine market research is not marketing. A survey that includes any promotional material, or collects details for future campaigns, is.

In my reading, a password reset, an invoice or a notice that your terms are changing are service messages. Onboarding tips that push an upgrade, a "you are close to your plan limit, upgrade now" email, and a feature announcement sent to free users are marketing, and they need the same unsubscribe as the newsletter. Many products send these from the product email platform with no unsubscribe link at all. Review requests, which Debenhams shoppers also complained about, fall under the stricter survey test: "how was your experience?" on its own is fine, and the same email with a discount code is marketing.

What should a software company check?

If you email people in the EU or the UK, every marketing email needs a free, easy way out that works in every tool you send from. Otherwise each email after an opt-out goes to someone who refused it.

  • Count the steps. Sign up for your own marketing email, then leave it. If joining took one tick and leaving takes a login or a page of toggles, add a link that leaves everything that tick signed them up for.
  • Read your unsubscribe links literally. A link that says "unsubscribe from all", or names the company, has to remove people from every list, not the one newsletter it sits in. That was CALOGA's mistake.
  • Follow one unsubscribe through every tool. Unsubscribe a test address, then check that your newsletter tool, your CRM and your product email platform would all stop emailing it. Do not leave work addresses out of the sync.
  • Sort product emails into service and marketing. Upgrade nudges, feature announcements to free users and onboarding emails that sell go through the unsubscribe.
  • Tell people they can object, in the first marketing email. The GDPR requires the right to object to be presented clearly and separately from other information, at the latest in your first communication 2. A line of its own in the welcome email does this better than footer boilerplate.

Adding a sending tool also means a new company receives your users' data, which your privacy policy has to cover. Lawcel, the compliance tool we build, reads each pull request against your legal documents and flags changes like that one. It does not check whether your unsubscribes sync; the test address above does.

FAQ

In the UK, the ICO's guidance says you should not: a login is not a simple way to opt out. In the EU, withdrawing must be as easy as consenting was, so a login only fits where consent was given inside the account.
Yes. But if one sign-up put someone on many lists, a page where they must untick each one makes leaving harder than joining, which the GDPR forbids for consent.
The ICO says immediately or as soon as possible. The GDPR sets no grace period for continuing to email. Gmail asks bulk senders to process unsubscribes within 48 hours.
Partly. Emailing companies falls under looser rules than emailing individuals or sole traders, and EU countries differ, but a named person at a company can always object to marketing.

References

  1. Directive 2009/136/EC, Article 2(7), replacing Article 13 of the ePrivacy Directive 2002/58/EC (unsolicited communications) - accessed 1 Oct 2026
  2. Regulation (EU) 2016/679 (GDPR), Articles 7(3), 21 and Recital 70 - accessed 1 Oct 2026
  3. EDPB Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1, section 5.2 (withdrawal of consent) - accessed 1 Oct 2026
  4. CNIL, Data brokers: CALOGA fined €80,000 (decision of 15 May 2025) - accessed 1 Oct 2026
  5. ICO, How do we comply with the PECR electronic mail marketing rules? - accessed 1 Oct 2026
  6. ICO, Guide to PECR: Electronic and telephone marketing - accessed 1 Oct 2026
  7. ICO, Business-to-business marketing - accessed 1 Oct 2026
  8. ICO, Direct marketing guidance: Respect people's preferences - accessed 1 Oct 2026

About the author

Kenneth Graupner

Kenneth Graupner

Co-founder, Chief Product Officer

Kenneth is Co-founder and CPO at Lawcel. He focuses on product strategy and on shaping workflows so legal, engineering, and GTM teams can ship continuously without treating compliance as a late-stage gate.

  • Product strategy
  • Compliance operations
  • SaaS delivery
GDPR

Email tracking pixels need consent in France, even if you are not based there

Open-tracking pixels need the recipient's consent in France, wherever the sender is based. Two uses are exempt, securing a sign-in and checking deliverability, and only in emails the recipient asked for and only if the pixel records little more than the last-open date. Standard provider tracking records more, so it needs consent or switching off.

GDPR

Every contact you publish for GDPR data requests must be easy to use on its own

Spain's regulator fined Securitas Direct 100,000 euros for a paid 902 phone line on its camera signs, even though its privacy policy listed a free email address. It judged each route for data requests on its own. For a software product, a deletion route behind a login can fail the same test, and a request sent to support@ counts from the day it arrives.

GDPR

Is legitimate interest enough for product analytics? Check what your tool stores on the device first.

Not on its own. Two rules apply to analytics, in order. Article 5(3) of the ePrivacy Directive, the rule behind cookie banners, governs storing or reading anything on the visitor's device and offers consent or one of two narrow exemptions, never legitimate interest. GDPR Article 6 governs the analysis you run afterwards, and there legitimate interest is available if you can pass the balancing test.

GDPR

Keep your cookie banner. The Digital Omnibus cookie reform is still a proposal.

The EU's Digital Omnibus proposes fewer cookie banners, but it is not law. In August 2026 Parliament had not voted and the member states had no agreed position, and no deal had been reported by 2 October. Once agreed, the new rules would apply six months to two years later, depending on which draft wins. Until then today's rules apply, so refusing cookies must be as easy as accepting them.