22-12-2025 - Well, with the recent judgment of the Court of Justice of the European Union, it seems that it may be easier than many of us think.
In practice, many organisations regularly send marketing/promotional emails to customers without first obtaining consent, often without a clear understanding of whether they actually meet the conditions required to rely on the soft opt-in exception. The Court’s latest judgment provides welcome clarification on some of those conditions and is therefore highly relevant for marketing teams and compliance professionals alike.
This blog will first briefly explain what the ‘soft opt-in’ mechanism is under the ePrivacy Directive (2002/58/EC) and then describe the new interpretations provided by the Court regarding the soft opt-in in its judgment in Case C-654/23 (Inteligo Media SA) of 13 November 2025.
Soft opt-in
Under the e-Privacy Directive (applicable throughout the EU), the “soft opt-in” mechanism is a limited exception to the general rule that electronic marketing emails require prior consent from customers. It allows a business to send marketing emails without prior consent where:
So, this mechanism is designed to balance commercial communication with privacy protection by recognising an existing customer relationship.
What happened in this case?
Inteligo operates the Romanian online news site avocatnet.ro, which publishes daily updates on legislative changes. In 2018, it introduced a “Premium Service”: readers could view up to six articles per month for free but had to create a free account to access two additional articles and the option of paid full access. Registered users also received a daily email newsletter, “Personal Update”, summarising recent legislative developments with links to the site, with opt-out available at sign-up and in every email. In 2019, Romania’s data protection authority fined Inteligo, claiming the newsletter was sent without valid consent and that account data had been reused improperly. Inteligo challenged the fine, prompting the Bucharest Court of Appeal to ask the Court of Justice of the EU (the Court) to clarify how the e-Privacy rules and the General Data Protection Regulation (the GDPR) apply in this context.
Judgement of the Court
The dispute, at its core, was about what legal regime governs sending that newsletter and whether Inteligo needed prior consent:
Short answer: Yes. The Court reiterated that “direct marketing” covers communications with a commercial purpose, sent directly and individually. Even if the newsletter contains informational content, it encourages recipients to click through, consume their free quota, and be nudged toward paid subscription content. Thus, the concept of direct marketing can be interpreted quite broadly.
Short answer: again, Yes! Although the account was free, the Court treated the arrangement as part of an economic transaction: the “free” service functions as a promotional mechanism for paid content, and its costs can be seen as indirectly remunerated through subscription revenue. So, collecting an email address during account registration for that service can fall within “sale of a service” for soft opt-in.
Now the answer is a ‘No’! The Court held that Art. 13.2 of the ePrivacy Directive lays down specific obligations governing this type of processing (lex specialis), and Art. 95 GDPR prevents the GDPR from imposing additional obligations where the e-Privacy already regulates the matter with the same objective.
What does this judgement mean for your organisation?
The Court treated the “Personal Update” daily newsletter as direct marketing, even though it was largely informational. In the Court’s view, this was because the newsletter was structured to drive traffic back to the publisher’s platform, ultimately nudge them towards a paid subscription. This shows that the ePrivacy Directive may apply earlier than many organisations expect; organisations therefore need to take this into account when sending such emails to their customers
More importantly, the Court concluded that a “sale of a service” can include free account creation. Even where no money changes hands, a service can still fall within the notion of a sale if it is economically funded indirectly. In this case, the free account and newsletter formed part of a business model designed to promote paid content, which was enough to satisfy the requirement that the email address be obtained “in the context of the sale of a product or service”.
As discussed, the soft opt-in mechanism is built around the idea of an existing customer relationship. Following this judgement, it appears that simply creating an account may be enough to establish such a relationship. Now an important question raises: is it no longer necessary to have an actual paid product or service in place to be able to rely on the soft opt-in mechanism? Well, in some jurisdictions, this has already been the case. For example, the UK ICO accepts that electronic marketing emails may be sent where the recipient has previously negotiated to buy a similar product/service. By contrast, some other EU member states have traditionally taken a stricter approach. The Dutch AP, for instance, has stated that someone is an existing customer only if they have actually purchased a product/service. The French CNIL has also previously held that account creation alone does not amount to a purchase.
Although this case arose in Romania, the Court’s interpretation applies across the EU! The data protection authorities in all EU member states will have to align their enforcement practices with this judgement. What should your organisation do now to align with this ruling? Here are some tips:
If you would like more information on this topic or need assistance assessing your email marketing practices, feel free to reach out to Considerati’s legal consultants.
Ensure your use of the soft opt-in meets the clarified EU standards, reassess how you collect email addresses, and confirm opt-out mechanisms are compliant. Need help? Contact our legal experts to stay ahead of enforcement.
Our services ContactRecente blogs
18-07-2025 – The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) recently issued a Joint Opinion on the European Commission’s…