Payments & Compliance

Double Opt-In

Double opt-in is a consent flow in which a subscription only becomes active after the person confirms it through a second, independent step — clicking a link in a confirmation email or replying to a message. The first submission registers intent; the confirmation proves the address or number belongs to the person who gave it.

The GDPR does not require it. The regulation asks that consent be freely given, specific, informed and unambiguous, and that the controller be able to demonstrate it — nowhere does it name a confirmation step. Double opt-in is one way of satisfying the evidence requirement, not the requirement itself.

Where it is effectively mandatory, the reason is evidential. German case law is the clearest example: in its 2011 Double-Opt-In judgment (BGH, I ZR 164/09), the Federal Court of Justice held that the sender carries the burden of proving consent for every commercial message, and that a form submission alone does not carry it, because misuse by a third party cannot be ruled out. The confirmation click closes that gap.

It is also list hygiene. The second step removes mistyped addresses, catches people who entered someone else's contact details, and filters automated sign-ups — which protects sender reputation, not only the legal file.

The cost is real. A confirmation step loses everyone who never opens it. And when consent originates from the person, such as someone who messages a business first to ask for updates, a second round adds friction without adding proof.

Why it matters for brands

The useful question is not "is double opt-in required?" but "can I produce evidence for this one contact, years from now?" Where a dispute is plausible, the subscribers lost at the confirmation step cost less than a consent record you cannot prove.

Ready to turn customers into creators?

Try TikJoy for free — integrate TikTok and WhatsApp in seconds and reward your community with JoyBack wallet rewards (no purchase required).