• g2 badge
    ★ ★ ★ ★ ★ 4.9 rating
Get a demo and an audit of your site from a CRO expert.
Book a demo
arrow-neon
Popups

Email popups and GDPR: how to collect consent [2026]

card0034

Key takeaways

  1. Consent has to be freely given, specific, informed and unambiguous. In a popup that means a stated purpose, an act from the visitor, and nothing pre-checked or bundled.

  2. A form whose only purpose is a newsletter subscription can treat the submit as the consent act. A separate checkbox becomes necessary the moment the form does two things at once.

  3. Double opt-in is not required by the regulation. Its value is proof: a dated click at an address only that person controls.

  4. The right to withdraw has to be stated before the visitor agrees, and unsubscribing has to be as easy as subscribing.

  5. An address collected to deliver an ebook can deliver that ebook and nothing else. Naming the newsletter alongside the gift is what lets you use the address for both.

  6. Quiz answers can cross into special category data. A question about a health condition needs separate explicit consent, and asking about the product keeps the answer outside the category.

A signup popup collects personal data, so the GDPR applies to it from the moment a visitor types an email address in. What the regulation asks for has not changed since 2018: a clear purpose, a real act of agreement, and a record you can produce later.

The difficulty sits in the popup rather than the regulation. Whether the checkbox is needed at all, what the consent line has to name, and what you can produce if someone asks two years later.

This article covers the wording and the settings that satisfy those three:

See your segments

Grow an opted-in list from the traffic you already have

We review your traffic and show which behavioral segments you have, the campaigns that fit each one, and the revenue they could reach.

Wisepops traffic activation audit

Last reviewed August 2026. We are not a law firm and this is not legal advice.

The GDPR popup checklist

Six of the thirteen are visible to the visitor, and they fit on one popup:

×
A

NORTHFIELD

B

Join the newsletter for new arrivals and sale previews. Get 10% off.

C
Email address
D
E
Get my code
F

We handle your data as set out in our privacy policy

  • A

    Sender is identifiable The visitor knows who is about to email them.

  • B

    Purpose named before the incentive The newsletter comes first, the discount second.

  • C

    One field, because that is all you need Every extra box is data you have to justify.

  • D

    Empty box, ticked by the visitor The wording names the channel, the sender and the way out.

  • E

    Consent is its own act Separate from the button, so nothing is bundled into the click.

  • F

    Policy inside the popup Reachable at the moment you take the address, not only from the footer.

Thirteen checks in all, grouped by where you go to verify each one:

Popup copy

  • 1

    The popup says what the subscriber will receive.
    "Sign up for our newsletter and get new arrivals and sale previews" satisfies this. "Get 10% off" on its own does not, because it names the reward and leaves the purpose unstated.

  • 2

    Your brand is named inside the popup.
    So the visitor knows who will be emailing them.

  • 3

    Lead magnet and prize copy names the newsletter as well as the gift.
    "Subscribe to our newsletter and receive our ebook as a welcome gift" lets you use the address for both. "Enter your email to get the ebook" lets you send the ebook and nothing else.

The form

  • 4

    The visitor does something that means yes.
    Ticking an empty checkbox, or submitting a form that exists only to subscribe. Silence, a pre-ticked box, closing a banner and continued browsing never count.

  • 5

    Nothing is pre-checked.
    Marketing consent is not the price of something the marketing has no bearing on, such as entry to a prize draw.

  • 6

    Email and SMS have separate consent.
    One box each, because each channel is a separate purpose. One box covering both is not specific consent.

Links and notices

  • 7

    The privacy policy is linked inside the popup.
    Not only in the site footer, because the notice has to reach them at the moment you take the address.

  • 8

    The consent text says the visitor can withdraw.
    Unsubscribing takes one click. They have to be told before they agree, and leaving cannot be harder than joining.

What you collect

  • 9

    No quiz question collects a special category without its own explicit consent.
    Asking about acne or medication collects health data. A question about product preference instead stays outside the category.

  • 10

    Where your audience includes teenagers, the form establishes age before consent.
    The default is 16 and some countries go as low as 13, so the threshold moves by market.

Records and policy

  • 11

    Your consent record stores the wording shown, the timestamp, the campaign and a version number.
    The burden of proving consent is yours, and an email plus a date does not show what the person agreed to.

  • 12

    Your email platform's consent fields are switched on and populated.
    Adding an address to a list records no consent by itself, in Klaviyo, in Mailchimp or anywhere else.

  • 13

    Your privacy policy names your processors.
    The popup tool, the email platform and any SMS provider.

What the GDPR requires from a signup popup

A popup that collects an email address needs a lawful basis for the marketing that follows, and for a newsletter that basis is consent.

Article 4(11) of the GDPR defines consent as a freely given, specific, informed and unambiguous indication of the visitor's wishes, given by a statement or by a clear affirmative action.

That definition, plus the conditions in Article 7, comes to seven rules:

  • Say what they are getting. The popup names who is collecting the address, what will be sent, and where the privacy policy is.

  • One consent per purpose. Email marketing and SMS marketing are two purposes, so they need two agreements.

  • Ask for an action. Checking an empty box, or submitting a form that exists only to subscribe. Silence and pre-checked boxes count for nothing.

  • Consent cannot be a condition. Agreement stops being free when someone has to accept marketing to get something the marketing has nothing to do with. A prize entry gated behind a newsletter opt-in is the case this was written for.

  • Keep it separate. Where the consent sits inside wording that also covers other things, the consent part has to stand out, in plain language. One box covering terms of sale and marketing fails.

  • Make leaving as easy as joining. People can withdraw whenever they want, they have to be told so before they agree, and getting out cannot be harder than getting in. One click to subscribe and an email to support to leave does not qualify.

  • Keep proof. You have to be able to show that the person agreed. A signup with no record behind it is a signup you cannot defend.

The shortcuts are ruled out too. Silence, a pre-ticked box and plain inactivity are not consent.

The Court of Justice settled the pre-ticked box question in a 2019 ruling against Planet49, a German lottery operator that pre-ticked the box for entrants. Only an active step counts.

European regulators have gone further and held that scrolling or swiping down a page can never count, because nobody can tell that behavior apart from ordinary reading.

Who these rules apply to

Article 3 ties the GDPR to where the visitor is and what you are doing, and not to where your email platform is hosted. Storing your list in a US tool does not put the collection outside the regulation.

Three cases make the boundary clear:

  • A store in Texas selling hats and belts worldwide has to comply for its European customers, including anyone who subscribes through a popup from an EU country.

  • A SaaS company in Germany selling in Europe and the US complies for its European subscribers, because the company is established in the EU.

  • A Shopify store in Hong Kong selling only in Asia, with no offer aimed at people in the EU, falls outside the regulation.

B2B is not exempt. A named work address such as firstname.lastname@company.com identifies a person, so a B2B signup form is covered. Generic role addresses like info@company.com normally identify a company and sit outside the regulation.

Under-16s need a parent's consent

The age of digital consent is 16. Below it, a parent has to give or authorize the consent, and you have to make reasonable efforts to check that they did.

Countries can lower it to 13 but no further, so the number changes as you cross a border. Germany and the Netherlands kept 16, Austria and Italy chose 14, and Ireland, Spain, Sweden and the UK went to 13.

Two things narrow this in practice. The rule covers services offered directly to children, so a site that says it serves adults only, and whose content and marketing back that up, falls outside it.

The other is your lawful basis. The age rule bites when you are relying on consent, which is exactly what a newsletter popup does, so a brand with teenage customers is squarely inside it.

Where your audience skews young, an age field on the form is the usual answer. Asking whether the visitor is above or below the relevant age lets you route the under-age case to a parental authorization step instead of straight onto the list.

An age question sits naturally on the first screen of a multi-step popup, before the email field.

The consent checkbox, and what double opt-in adds

An unchecked consent checkbox is the most defensible way to get an affirmative action out of any popup type, because the visitor does something separate from clicking submit. That separation is what a supervisory authority looks for when purposes are combined.

There is an exception most guidance misses. Where the form exists only to subscribe someone to a newsletter and the popup says so, submitting the form is itself the affirmative action.

A second checkbox adds nothing in that case, and our own documentation takes the same position.

From our help center: GDPR guide for signup forms, which covers the field settings behind each of these rules.

When a separate checkbox is needed:
  • The form collects the address for one reason and you also want to send marketing, such as a contest entry, a stock alert, or a downloadable guide.

  • The form collects both an email address and a phone number, since SMS consent has to be given on its own.

  • The address will be shared with a partner brand or used for advertising audiences.

  • Your legal counsel wants a visible, auditable act on every signup, which is a common internal standard even where the law allows less.

GDPR marketing consent examples

Short, specific, and written as something the visitor agrees to.

Three versions that meet the conditions:

I agree to receive marketing emails about new arrivals and offers from [brand]. Unsubscribe any time.
Yes, send me the newsletter. I have read the privacy policy.
I agree to receive marketing emails.
I agree to receive marketing texts.

Two boxes, one per channel

Wording that only says "I accept the privacy policy" is weaker, because accepting a policy is not the same act as agreeing to be emailed. The emails have to be named in the sentence itself.

Where you want one line that names the channel, settles the conditionality point and covers withdrawal at once, this is the pattern:

By signing up, you agree to receive marketing emails from [brand] at the address provided, including promotions, discount codes and newsletter updates. Consent is not a condition of any purchase.

You can withdraw it at any time using the unsubscribe link in our emails. See our privacy policy and terms.

Double opt-in is not a GDPR requirement, and turning it on does not repair a consent request that was unclear in the first place. What it gives you is evidence: a dated click on a link the visitor received at an address only they control.

That evidence sits in your email platform, which is where you will look when someone asks you to prove consent.

The confirmation email needs three things to carry its weight:

  • The purpose of the collection, in the same words the popup used.

  • A link to your privacy policy.

  • A line telling the subscriber they can unsubscribe and request access to their data at any time.

Double opt-in is configured in your email platform rather than in the popup tool, and the same confirmation step clears typos and throwaway addresses out of the list you are building. Plenty of brands run it with no regulatory motive at all.

What a lead magnet, discount or prize has to say

The campaigns above were finished work. This is the wording problem that produces them, and it only appears once you offer something in exchange for the address.

Article 5(1)(b) limits you to the purposes the visitor agreed to. An address collected to deliver one ebook can be used to deliver that ebook, and nothing else, which is where most lead magnet campaigns come apart.

The fix is in the copy, and it costs nothing.

Compare the two versions:

  • "Enter your email to receive our free ebook." One purpose, one send, no newsletter.

  • "Enter your email to subscribe to our newsletter. As a welcome gift, you'll receive our exclusive ebook." Two things covered, and the gift no longer looks conditional on subscribing.

The second version also handles the freely given condition. Consent stops being free when a visitor has to accept marketing to get something the marketing has no bearing on, so frame the ebook as a welcome gift for subscribers instead of a reward for consent.

Discount, lead magnet and gamified popups

Every incentive campaign splits the same way, whether it is a discount popup or a gamified wheel. One purpose is the thing the visitor asked for, and anything beyond it needs its own agreement.

How that plays out by campaign type:

Campaign

Covered by what the visitor asked for

Needs its own consent

Extra copy the popup carries

Discount code by email

Sending the code

Adding the address to a campaign list

Offer terms and the expiry date

Lead magnet download

Delivering the file

Any send after the file

The newsletter named beside the gift

Spin-to-win or giveaway

Running the draw and sending the prize

Adding the address to a campaign list

Entry rules, prize delivery, terms link

Quiz or preference form

Returning the recommendation

Marketing based on the answers

A separate line for any special category

A gated entry is the pattern the freely-given rule was written for, so the campaign mechanic and the consent have to stay apart. The émoi émoi giveaway reviewed above is that structure done properly.

When quiz answers become special category data

Quiz answers become personal data the moment they are attached to an email address. A short list of them cannot be collected on ordinary consent at all.

Article 9 puts these categories off limits without explicit consent:

  • Health, including a condition, a symptom, a medication or a pregnancy.

  • Religious or philosophical belief, racial or ethnic origin, political opinion, trade union membership.

  • Genetic and biometric data.

The second group catches more than it looks. The wording covers data revealing a belief, so an answer never has to state one to be inside the category.

Four rules keep a quiz popup clear of it:

  1. Ask about the product, not the person. This solves it in most cases and costs nothing.

  2. Where the category is genuinely needed, take a separate explicit consent that names what you collect and why. Newsletter consent never covers it.

  3. Store only the answers you will act on, and drop the rest at submit.

  4. At volume, run a data protection impact assessment, since these categories in quantity are one of the triggers.

Rule one in practice, on a skincare quiz that would otherwise collect a diagnosis:

×

NORTHFIELD

A

Which routine are you shopping for?

B
Clearing
Calming
Hydrating
C

We handle your data as set out in our privacy policy

  • A

    The question asks about the product "Which routine" replaces "which condition", so the answer is a shopping preference and not a diagnosis.

  • B

    The options name routines, not diagnoses Acne, eczema and rosacea would each be health data. Clearing, calming and hydrating are not.

  • C

    The policy is reachable from the step The notice is due when the answer is taken, and the end of the quiz is too late.

Four signup campaigns reviewed against the rules

Reading the conditions is one thing and recognizing them in a live campaign is another. There are ecommerce popup examples and popup design examples to compare against.

All four below are campaigns we built, audited against every rule above, and each one solves a different part of the problem.

A newsletter popup with no checkbox at all

Emma Sleep runs a discount offer as a newsletter signup, and the whole consent argument sits in the copy rather than in a control the visitor has to tick.

Emma Sleep's Easter campaign, with the offer terms and the consent line under the button:

Emma Sleep newsletter signup popup offering up to 25 percent off, with the consent line and privacy policy link below the subscribe button
Emma Sleep newsletter signup popup offering up to 25 percent off, with the consent line and privacy policy link below the subscribe button

What this campaign gets right:

  • The headline names the newsletter before it names the discount, so the purpose is stated ahead of the incentive.

  • The consent sentence names who will send the emails, rather than leaving the sender implied.

  • The offer footnote carries the promotion window down to the second, so "up to 25% off" is a claim the visitor can check. Dated offers are standard in Black Friday campaigns.

  • The form does one thing, so the submit is the affirmative act and a separate checkbox would add nothing.

The one line to add:

  • "Unsubscribe at any time", in the same sentence. The consent line links the privacy policy but never says the visitor can withdraw, and that has to appear before they agree.

Email and phone captured on separate steps

Maison Lejaby splits the request across two steps, taking the email address first and the phone number second, which is the cleanest structural answer to the one-consent-per-purpose rule.

The second step, where the phone number and its own consent text sit:

Maison Lejaby popup second step capturing a phone number for WhatsApp offers, with its own consent text, a Not now option and links to terms
Maison Lejaby popup second step capturing a phone number for WhatsApp offers, with its own consent text, a Not now option and links to terms

What this campaign gets right:

  • The email address and the phone number are collected on separate steps, so each channel gets its own act of agreement.

  • The consent text names the channel specifically, WhatsApp, where a vague "communications" would fail the specificity condition.

  • "Not now" gives the visitor a visible decline of equal weight to the accept, the same principle regulators apply to consent interfaces generally.

  • The step states that the visitor can unsubscribe at any time, covering the notice the Emma Sleep campaign leaves out.

Messaging consent is never carried by an email opt-in, and splitting the steps makes that visible in the campaign rather than buried in a policy.

A US disclosure, and what an EU version would change

This grant campaign runs on a US university site, so the disclosure is written to the TCPA and the GDPR does not reach it. That makes it the useful contrast, because it shows how far the two regimes diverge on the same form.

The disclosure under the signup button, written to US rules:

University grant signup popup collecting first name, last name and email, with a TCPA-style disclosure about automated calls and text messages below the button
University grant signup popup collecting first name, last name and email, with a TCPA-style disclosure about automated calls and text messages below the button

What this campaign gets right:

  • The disclosure states that consent is not a condition of any service, which is the freely-given point said out loud.

  • The visitor is told they may opt out at any time.

  • Three fields and nothing else, which is data minimization in practice.

What an EU or UK version would change:

  • Agreement to automated calls and text messages "for any reason" is the opposite of specific, and a purpose that broad cannot be consented to at all.

  • Calls and texts are bundled into the same act as submitting a grant enquiry, and those have to be kept apart.

  • No unchecked box separates the marketing channels from the enquiry itself, so an EU version needs one.

  • Nothing establishes the visitor's age, and an audience for a tuition grant includes under-16s, which is where the age rules bite.

A giveaway with the marketing consent kept separate

émoi émoi runs a giveaway with several gifts and incentives, and puts the newsletter opt-in on its own control rather than folding it into the entry.

The giveaway campaign, with the consent checkbox under the email field:

Giveaway popup from emoi emoi collecting an email address for a prize entry, with a separate unchecked newsletter consent checkbox
Giveaway popup from emoi emoi collecting an email address for a prize entry, with a separate unchecked newsletter consent checkbox

The consent text reads: I agree to receive newsletters from émoi émoi by email. Our privacy policy is available here.

What this campaign gets right:

  • The box arrives unchecked, so ticking it is the affirmative act the rules ask for, and the pre-ticked pattern the Court ruled out is avoided.

  • The consent text names the channel and the sender in one sentence, which is the specificity condition met without legal wording.

  • The newsletter opt-in is a separate control from the giveaway entry, so agreeing to marketing is not the price of taking part. So the newsletter is not the admission price, which is the test that matters here.

  • The privacy policy is reachable from inside the popup, which is where the notice has to arrive.

The one line to add:

  • "You can unsubscribe at any time", added to the consent text. Same gap as Emma Sleep. Linking the words "our privacy policy" instead of "here" would also read more clearly.

Serving the stricter version only where it is required

Running a US site and an EU site off one popup campaign is how this gap usually appears. A single design can carry two consent treatments, selected by where the visitor is.

How to split a campaign by region:
  1. Duplicate the campaign, so you have an EU and UK variant and a rest-of-world variant.

  2. Add the unchecked consent checkbox and the withdrawal line to the first variant.

  3. Set location targeting on each variant, with the EU and UK countries on one and the remaining markets on the other.

  4. Check that the two variants cannot both qualify for one visitor, or a visitor sees two popups.

Our targeting options reach the country level and finer, so the split does not need separate campaigns per market.

How to add a terms and conditions checkbox in Wisepops

We put the consent checkbox on the form field itself, which keeps the text, the link and the field validation in one place. Ticking the box becomes a condition of submitting.

How to add the checkbox and the link:
  1. Open the campaign in the editor and click the signup form.

  2. Select the email field, then open the Terms section in the left panel.

  3. Turn the terms checkbox on and write your consent text in it.

  4. Select the words that should carry the link, and point them at your privacy policy or terms page.

  5. Leave the box unchecked by default, then save and publish.

Here is the Terms section on an email field, with a consent line and a linked privacy policy:

Adding a terms and conditions checkbox with a privacy policy link to an email field in the Wisepops editor
Adding a terms and conditions checkbox with a privacy policy link to an email field in the Wisepops editor

Add a phone field to the same form and it carries its own terms text, which is how you keep email consent and SMS consent apart.

The same field settings drive a welcome popup and embedded signup forms, so a popup and an inline form on the same site can share one consent line.

What your privacy policy needs to say about your popup tool

Article 13 is the provision that decides where the privacy policy link goes, because the information has to reach the visitor at the moment you take the address. A footer link arrives later than that.

What the visitor has to be able to find:

  • Who you are, and how to reach you.

  • What you are going to do with the address, and on what basis.

  • Who else sees it, which is where your processors sit.

  • Whether it leaves the EU, and what protects it if it does.

  • How long you keep it.

  • What they can do about it: see it, correct it, delete it, take it elsewhere, object, withdraw, or complain to a regulator.

Two qualifiers sit around that. Information the visitor already has can be left out, and a new purpose means telling them before you use the address for it, which is the rule a lead magnet list reused for a newsletter runs into.

We act as a data processor and handle your subscribers' data on your instructions, which makes you the controller. Naming your processors, or at least the categories of recipients, is the part of a privacy policy that popup tools affect.

Our data processing agreement gives you the details your policy and your records need:

  • The data processed: names, email addresses and phone numbers collected through your campaigns, plus browsing signals such as the last visit, campaign interactions and the visitor's IP address.

  • The sub-processors: Google Ireland Limited and Amazon Web Services EMEA for hosting, and Cloudflare for content delivery.

  • Retention: data is kept for the duration of your subscription unless you say otherwise.

  • Breach notification: we notify you within 72 hours of becoming aware of a personal data breach.

A signed copy of the agreement is downloadable from that page, and the technical and organizational measures are published alongside it. Both are what a security review or a DPIA will ask you for.

A section you can adapt for your policy:

Marketing communications and consent. We use third-party email and SMS providers, including [providers], to manage and send marketing campaigns.

When you subscribe through a signup form or popup on our site, we collect your email address, your name where you provide it, your IP address and the time of submission.

The legal basis for this processing is your consent under Article 6(1)(a) of the GDPR, and we use the data only for the communications you asked for.

You can opt out at any time through the unsubscribe link in any message or by contacting us at [address]. Your data is processed by our providers under data processing agreements.

The provider list covers every tool that touches a subscriber record, including the popup tool, the email platform and any SMS provider. A policy naming two of the three is the version that fails a review.

Consent records, and lists you cannot prove consent for

The burden of proof sits with you. Storing an address and a signup date is thinner than it looks, because the question a regulator asks is what the person actually saw when they agreed.

Four fields answer that question, and a record holding only the first is a record you cannot defend:

Consent record

AAddressanna.k@example.com
BGiven at2026-03-14 09:41 UTC
CSourcewelcome-popup-eu
DWordingv2 · "I agree to receive marketing emails from Northfield. Unsubscribe any time."
  • A

    The address What the consent attaches to, and the only field most brands actually store.

  • B

    The timestamp Dated proof that the agreement happened, and when.

  • C

    The campaign Which form it came from, so the wording can be traced back.

  • D

    The wording and its version What the person saw. A change in March must not overwrite what a February subscriber agreed to.

Where the record actually lives

The popup collects the consent and your email platform stores it, so the fields have to survive the handoff. Both of the platforms most ecommerce brands run have a place for them, and neither fills it in by default.

Two configurations to check before you trust your records:

  • Klaviyo. Consent-enabled forms write $consent_method, $consent_form_id, $consent_version and $consent_timestamp onto the profile. The version property is the one that answers which variation of your wording a subscriber saw.

  • Mailchimp. Marketing permissions have to be enabled on the audience, and a custom integration sending contacts through the API has to pass the marketing permissions explicitly. Adding an address to a list on its own records no consent.

Where Shopify checkout is also collecting an accepts-marketing flag, confirm it lands on the same profile property as your popup signups. Two sources writing to two different fields is how a subscriber ends up with a consent status nobody can trace.

Subscriber rights and the response window

Subscribers can also come back with a request.

Five of them apply to a marketing list:

  • See the data you hold on them.

  • Have it corrected.

  • Have it deleted.

  • Take it elsewhere in a portable format.

  • Object to the processing altogether.

You get one month to respond, extendable by two more where the request is complex, provided you tell the person about the extension inside that first month.

Withdrawal carries one rule that is easy to miss. When someone withdraws consent, you stop, and you cannot keep sending the same emails by relabeling the basis as legitimate interest.

Swapping the lawful basis after the fact is not available. You pick the basis before you start and you disclose it up front, and switching it when consent runs out would make the right to withdraw meaningless.

The response also has to be free. Charging for a copy of someone's data, or for acting on a deletion request, is available only where a request is clearly unfounded or excessive, and you carry the burden of showing it was.

A deletion request reaches your processors too, so it has to travel to your popup tool and your email platform.

Lists collected before you had valid consent

The GDPR applies to addresses collected before May 2018 as much as to ones collected yesterday. Where you cannot show a valid consent for a segment, a re-permission campaign is the way to sort it.

The email asks the subscriber to confirm, in one click, that they still want to hear from you.

The click is the affirmative act, so three things have to hold:

  • No pre-selected outcome anywhere in the message.

  • No wording that treats silence as a yes.

  • The same purpose named in the original signup, so the confirmation covers what you will actually send.

Everyone who does not confirm comes off the list. A smaller list of people who chose you outperforms a large one that no longer opens anything, and lifecycle campaigns work better against it.

Rebuilding after a re-permission campaign: exit popup examples and popup benchmarks for what to expect.

Get started
in minutes

Start converting more visitors today.
Get started in minutes and see results right after.

Help