Skip to content

Glossary Double Opt-in

What Is Double Opt-in?

  • Content Marketing
Definition

Double opt-in is a two-step signup process for email lists and newsletters: after submitting the form, the person must confirm their address by clicking a link in a verification email before the subscription becomes active.

A safe door with two separate locks, a key in each one — beside the title Double Opt-in
Two locks: one key alone opens nothing
On this page 6
  1. What is double opt-in and what is it for?
  2. Single opt-in versus double opt-in
  3. How it works
  4. Why it matters: recommendation or real requirement?
  5. Best practices
  6. Common mistakes
In brief

Whether double opt-in is an explicit legal requirement in Germany or a practice that follows from the GDPR's burden of proof, how the confirmation click gets documented, and what to do with signups that never get confirmed.

A safe door with two separate locks, a key in each one — beside the title Double Opt-in
Two locks: one key alone opens nothing

What is double opt-in and what is it for?

Double opt-in is the two-step signup process used by email lists and newsletters. The person fills in a form with their email address and, before receiving any message, has to confirm that signup by clicking a link inside a verification email. Only that click activates the subscription.

The procedure serves two distinct purposes. It stops someone from entering a stranger's address without that person's knowledge, a common problem with publicly open forms. And it leaves a verifiable technical trail of the exact moment that person gave their approval, including the IP address the confirmation link was clicked from.

That second point is why double opt-in has become the standard for email marketing in Germany. It doesn't describe how consent works in general, that's already covered by the GDPR as the broader framework, but how that principle applies specifically to an email signup, usually the first formal touchpoint in an email subscriber's customer journey.

Single opt-in versus double opt-in

AspectSingle opt-inDouble opt-in
When the signup countsImmediately on form submissionOnly after clicking the confirmation email link
Address verificationNone: anyone can type in someone else's emailThe address owner confirms through their own action
Proof of the signupJust the form entryForm entry plus click, IP address, and confirmation timestamp

In Germany, single opt-in leaves the controller with no solid way to prove that the actual owner of the address was the one who asked to receive emails, a gap that becomes decisive if a complaint comes in.

How it works

The process starts with a signup form, usually on a website or landing page, where the user types in their email address. At that point, no commercial content gets sent: the system automatically generates a confirmation email with a unique link, different for each signup and each attempt. Most email marketing platforms ship with this mechanism built in, with no custom coding required.

If the person clicks that link, the system logs the confirmation with date, time, and IP address, and only then does the address move to active status on the list. From that point it can start receiving the newsletter or the campaigns it consented to, a routine step in any inbound marketing strategy that grows subscribers through its own forms instead of purchased lists.

If nobody clicks the link, the address sits in an intermediate, unconfirmed state, without receiving anything in the meantime. Leaving it there indefinitely isn't good practice: after a reasonable window, 24 to 72 hours is common, it should get deleted automatically instead of sitting around with no activity and no legal basis for sending anything. That regular cleanup also keeps the list healthier and saves sending capacity on addresses that never got activated.

Why it matters: recommendation or real requirement?

The term double opt-in doesn't appear anywhere in the GDPR or in Germany's law against unfair competition (UWG): no article names it or requires it word for word. The obligation is indirect, and it's worth being precise about where it actually comes from.

The starting point is Article 7(1) of the GDPR, which puts the burden of proof on the controller: it's the controller who has to be able to show that the person gave consent, not the other way around. Just storing an email address in a database proves nothing on its own.

Building on that, Germany's Federal Court of Justice (BGH) ruled on February 10, 2011 (case I ZR 164/09) that merely logging an IP address, alongside the claim that consent came from that address, isn't enough as proof. It requires fuller documentation: the entire opt-in process, including the exact wording the person agreed to.

The Datenschutzkonferenz (DSK), which brings together Germany's federal and state data protection authorities, folded both elements into its February 2022 guidance on direct-marketing data processing: it calls double opt-in "geboten" (required) for electronically verifying a consent declaration, pointing explicitly to that BGH ruling for the documentation standard. That guidance carries no legal force of its own, it reflects the joint position of the supervisory authorities, but in practice it's the yardstick they use to assess any complaint. That's why double opt-in isn't an explicit legal mandate, but the practical route to meeting the proof obligation in Article 7(1).

Best practices

  • Send the confirmation email within minutes of signup, with no commercial content beyond the confirmation request itself.
  • Log the date, time, IP address, and exact consent wording for every confirmation, as required by BGH case law.
  • Automatically delete signups that stay unconfirmed past a reasonable window, instead of keeping them indefinitely as pending.
  • Give each confirmation link a single purpose: don't use it to slip in another signup or a change of terms.
  • Make unsubscribing just as easy as signing up, with a visible link in every send.
  • Keep the consent record in your CRM even after someone unsubscribes, as evidence against a future complaint.

Common mistakes

  • Treating double opt-in as a minor formality instead of the legal proof that every later send depends on.
  • Storing only the source IP address and assuming that's enough proof of consent, something the BGH explicitly rejected.
  • Letting unconfirmed signups pile up in the database for months, with no time limit and no automatic deletion.
  • Confusing double opt-in with list segmentation: they're different processes, one validates the signup and the other organizes who's already subscribed.
  • Putting promotional content directly in the confirmation email, which can turn that send itself into unconsented advertising.
Manuel Riveiro Rodriguez CEO & Digital Strategist

A technical audit covers this and everything else in one pass.

Request an audit

Frequently asked

Is double opt-in a legal requirement in Germany?

No article names it that way word for word. Article 7(1) of the GDPR requires the controller to prove consent, and the BGH ruled that a single IP address isn't enough proof on its own. The Datenschutzkonferenz (DSK) calls it "required" in its 2022 guidance, and that's the standard used in practice.

What happens if someone never confirms their signup?

The address stays pending and shouldn't receive any commercial email in the meantime. Best practice: delete it automatically after 24 to 72 hours instead of keeping it indefinitely with no activity and no legal basis, following the data minimization principle.

What's the difference between the confirmation email and the newsletter?

The confirmation email only contains the link to validate the signup, with no commercial content of any kind. The newsletter, with its campaigns and updates, can only go out after the person has clicked that link and become active on the list.

Does double opt-in work as proof in a complaint?

Yes, as long as the full process gets logged: date, time, the click's IP address, and the exact wording the person agreed to. The BGH explicitly rejected the idea that storing just an IP address without that surrounding context is enough.

Does double opt-in replace the privacy notice?

No. Double opt-in technically validates the signup to a specific list. The information about what data gets processed and for what purpose is still required separately, under Articles 13 and 14 of the GDPR, and has to be provided on top of it.

Sources

  1. Datenschutzkonferenz (DSK), "Orientierungshilfe der Aufsichtsbehörden zur Verarbeitung von personenbezogenen Daten für Zwecke der Direktwerbung": the joint guidance from Germany's data protection authorities calls double opt-in "geboten" (required) for electronically verifying consent and sets the documentation standard based on BGH case law. Updated February 2022.
  2. Regulation (EU) 2016/679 (GDPR), consolidated text (EUR-Lex): Article 7(1) places the burden on the controller to demonstrate that the person gave consent, the indirect legal basis for double opt-in.
  3. Bundesgerichtshof (BGH), ruling of February 10, 2011, I ZR 164/09: establishes that merely storing an IP address isn't sufficient proof of consent and requires documenting the full opt-in process. Still-standing case law reference.