GDPR - email opt-ins

  • Thread starter Thread starter shadrach
  • Start date Start date
S

shadrach

Hello,

Another small business here struggling to work out how we need to change our marketing practices in light of the recent GDPR laws. My main area of confusion is around email opt-ins.

We send out our newsletters via mailchimp. Currently, clients opt-in to our mailing list when they enquire via our website - through the usual "Do you want to subscribe to our mailing list?" + tick box (the tick box is unchecked by default). The opt-ins then appear on our internal customer database, from where we export them to mailchimp periodically.

However, my understanding is that we now need customers to sign-up via a specific GDPR form i.e., they can't just tick a simple check box on our contact form page, but need to go through to a separate page with lots of small print. We created one such form on mailchimp using their default template and sent it out to our existing mailing list early last month (which unfortunately saw our mailing list reduced to about 1/3 of its previous number when we counted those who chose to re-opt in), but I don't know how we approach new subscribers.

My question is, do we need to find a way to integrate the new mailchimp form into our website, or can we continue as we are, having clients tick the box and then manually adding them to mailchimp? We're reluctant to add the mailchimp form to our website, as it basically means redirecting browsers to a new page after they fill in the contact form on our website (the form is long-winded and there's no way to integrate it into an existing page that we can see). It also requires them to re-enter details like their name, email address and so on which they anyway enter when they fill in their details on our contact form. It just seems like an overly clumsy system.

The other complication is that we get a lot of enquiries via phone rather than via our website and we'll often ask the clients at the end of the call if they're happy to be added to our mailing list. We now make a note on their customer file after doing so that they opted in verbally on such and such a date, but I don't know if this is still considered acceptable following the new GDPR laws? Or do we now have to send them a link to the GDPR-compliant form after getting verbal consent via the phone, and ask them to fill it in? Again, it just seems convoluted and creates an extra headache for the client, nevermind us.

I hope I'm misinterpreting things and the form we've created on mailchimp only needed to be sent to existing subscribers to re-confirm their subscription, but my understanding is that everyone who is added to our mailing list now at some stage needs to see this form and fill in their details on it. Is this correct?

Edit: Yikes. Sorry, didn't mean for that to be so long.

tl;dr: Is it acceptable post-GDPR to get email opt-ins via a simple tick-box on a customer enquiry form? And is it acceptable to ask clients to opt-in to our mailing list over the phone, or do they need to fill in a GDPR-compliant form?
 
If your earlier opt-in met GDPR standards (opt-in by ticking a box, not become signed up because you didn't UN-tick a box) then you can continue to use that mailing list without getting them to opt in again. This would also apply to people who said on the phone that they wanted to join the list rather than didn't say that they didn't want to join. It's all about positive consent.

Now the GDPR is in force, you need to have a privacy policy that explains everything but you don't have to get people to opt in at the bottom of it. If your opt-in box has a clear message saying something like "Can we send you emails about ......" and there's an available link to the privacy policy, you're fine. Similarly on the phone you need to make sure that what you're asking is clear and covers everything you're going to use their email address for.

Going forward, you need to record not only that consent was given but also when and how. Our list now has a field for "web/phone/email/face to face" and a date field.

When you have your privacy policy completed, you can send a link to it to your current mailing list (as many MANY people are doing now) but you don't need people to re-confirm membership. So long as the email you send contains a way to opt out, you're good.

Standard disclaimer: I'm not a lawyer and this doesn't constitute legal advice. It's my understanding of it though.
 
  • Like
Reactions: shadrach
Upvote 0
Hi Frank. That's really helpful. Thanks.

So a simple text box is fine, provided it's unticked by default, and we have a link to our privacy policy? I had the notion that if we're going to continue using mailchimp going forward we would need to have people sign up via one of their GDPR-compliant form templates, but I think I may have been getting in a muddle. If we adapt our existing contact page to include a clear privacy policy, there shouldn't be anything wrong with continuing to export user details into mailchimp, as we have been doing? My only concern here is that the mailchimp form includes a link to their privacy policy, and I'm not sure if we need to include this on our contact page.

From what you're saying it seems that we perhaps didn't actually need to send out an email asking our existing subcribers to re-opt it. We've always been pretty careful in how we acquire sign-ups - no automatic opt-ins or anything like that. In any case, nothing to be done now. We've sent the email and I don't see that we can exactly continue emailing those who didn't open it or did open it and chose not to re-opt in. We could try sending another email but I'd rather not contribute further to the mass of GDPR emails stuffing up the world's inboxes.
 
Upvote 0
Agreed, don't send another email. If you believe you can argue that your prior opt-in was GDPR compliant (and from what you've said, I'd say that it was) then the only thing you need to do with your existing list is remove anyone who opted out and record the date and method of the third who opted in again. the remaining roughly two thirds minus opt-outs you can keep on your list. Just ensure that your mail-outs include an opt-out link and record internally your reason for keeping the old ones on the list in case of a future audit. Most of all, don't panic :)
 
  • Like
Reactions: shadrach
Upvote 0

Latest Articles