The GDPR does not require it. The regulation asks that consent be freely given, specific, informed and unambiguous, and that the controller be able to demonstrate it — nowhere does it name a confirmation step. Double opt-in is one way of satisfying the evidence requirement, not the requirement itself.
Where it is effectively mandatory, the reason is evidential. German case law is the clearest example: in its 2011 Double-Opt-In judgment (BGH, I ZR 164/09), the Federal Court of Justice held that the sender carries the burden of proving consent for every commercial message, and that a form submission alone does not carry it, because misuse by a third party cannot be ruled out. The confirmation click closes that gap.
It is also list hygiene. The second step removes mistyped addresses, catches people who entered someone else's contact details, and filters automated sign-ups — which protects sender reputation, not only the legal file.
The cost is real. A confirmation step loses everyone who never opens it. And when consent originates from the person, such as someone who messages a business first to ask for updates, a second round adds friction without adding proof.
Why it matters for brands
The useful question is not "is double opt-in required?" but "can I produce evidence for this one contact, years from now?" Where a dispute is plausible, the subscribers lost at the confirmation step cost less than a consent record you cannot prove.