Why Broken Unsubscribes Are a Legal Time Bomb
Broken unsubscribe links are not just an annoying tech glitch; they are a real legal risk under UK email unsubscribe law. The ICO is paying close attention to how brands handle marketing emails, especially as spring campaigns, Easter offers and seasonal promos fill inboxes.
When someone clicks unsubscribe and still gets sales emails, complaints follow. Those complaints can lead to investigations, fines and real damage to trust. Boards now ask hard questions about data protection, not just marketing results.
Under UK law, two sets of rules work together: PECR covers direct marketing by email and SMS, and UK GDPR covers consent, lawful basis and the right to object to marketing. If you send marketing emails to UK contacts, both matter.
Here we focus on three common problem areas we see with online businesses: bad suppression lists, forwarding and aliases that ignore opt-outs, and cross-brand marketing inside groups. At Stay Legal, we care about practical fixes that actually work in real systems, not just box-ticking paperwork.
What UK Email Unsubscribe Law Actually Requires
PECR says you must not send unsolicited marketing emails to individuals unless you have consent or you meet the soft opt-in rules. UK GDPR then sets the standards for what valid consent looks like and gives people the right to object to direct marketing at any time.
Key unsubscribe duties include:
- A clear and simple way to opt out in every marketing email
- No charge beyond basic communication costs
- Requests honoured within a reasonable time
In practice, that usually means:
- Automated systems update almost at once, or within a day or so
- Manual processes are handled within a few working days
- No long delays while campaigns keep going out
You might rely on:
- Consent, where people clearly opted in, or
- Legitimate interests, where you use soft opt-in, for example, after a sale
If someone withdraws consent, or objects to marketing where you use legitimate interests, you must stop sending marketing to that person on that channel. It does not matter which tool, team or agency presses send.
You can still send genuine transactional or service emails, such as order confirmations, password resets or important safety notices. The trouble starts when businesses add sales banners, discount codes or promo lines to those emails after someone has unsubscribed. At that point, the message can turn back into marketing.
The basic rule is simple: if they opt out, all direct marketing on that channel stops.
Suppression Lists Done Wrong and Why They Matter
A suppression list is a list of people you must not market to. Under email unsubscribe law, you are expected to keep minimal data so you can make sure you do not email those people again.
Common mistakes include:
- Deleting contacts fully instead of adding them to suppression
- Relying only on a status flag inside your email platform
- Keeping different bits of data in CRMs, plugins and tools that do not match
- No clear audit trail of when and how someone opted out
If you delete a record, your system might later re-import that email from an old CSV or a partner feed. Without suppression, that person can drop back into your campaigns, even though they told you to stop.
From a data protection angle, suppression lists must be:
- Limited to what you need, often just email and opt-out date
- Held securely and shared only with people who need access
- Never used for profiling, lookalike building or win-back pushes
A good approach is to keep one central master suppression list and make sure every email tool checks it before sending. You also need clear rules on who can edit it and how agencies or external senders must use it.
As marketing teams do spring cleaning and re-engagement drives, weak suppression data can drag lapsed or unsubscribed users back into campaigns. That is when complaints land at the ICO.
The key takeaway: a solid suppression list is the base of a defensible unsubscribe process and a clear part of your UK GDPR accountability story.
Forwarding, Aliases and Shared Inboxes That Break Opt-Outs
Many online businesses use inboxes like info@, hello@ or sales@ with forwarding rules and shared access. This is handy for busy teams, but it can easily break unsubscribes.
Some typical issues:
- A contact unsubscribes from news@brand.co.uk but still gets promo emails from events@brand.co.uk that use a different tool
- A shared sales inbox forwards leads into a sales platform that ignores central suppression
- Outsourced sales teams email people who opted out of main marketing lists
From a legal point of view, if the email is direct marketing and clearly from the same business or group, you should treat the unsubscribe as covering all similar marketing emails on that channel. People see one brand, not a maze of aliases and systems.
To fix this, you need to:
- Map every system that can send emails, such as ESPs, CRMs, helpdesks, ticketing tools and sales platforms
- Link each system to the central suppression list and enforce checks before sending
- Include agencies and sales partners within the same rules
Process changes help too:
- Mandatory pre-send suppression checks for all campaigns
- Rules on when aliases can be used for marketing
- Clear steps for support teams who receive manual opt-out requests
The message is simple: unsubscribe rights attach to the relationship, not to a single reply-to address. Your tech and your people should act as one sender.
Cross-Brand Marketing and Group Companies
Cross-brand marketing is tempting when you run a group of online brands. If someone bought from one label, they might enjoy offers from another. But under PECR and UK GDPR, this is high risk if you have not set it up clearly from the start.
You must:
- Be open in your privacy information about who is using the data
- Make sure each marketing email clearly shows who is sending it
- Get valid consent, or meet soft opt-in rules, for each brand that will send marketing
Frequent mistakes include:
- One tick box that supposedly covers multiple brands without naming them
- Assuming consent to one company in a group covers sister brands
- From-names and subject lines that hide which company is contacting the person
Unsubscribes can also get messy. If someone opts out from one brand, does that stop all others? The answer depends on what you told them at sign-up and how you structured your permissions. If you said their details would be used across a group for marketing and they agree, you need brand-aware logic when they later opt out.
Good practice is to build:
- Brand-specific consent records showing who can send what
- A preference centre with options by brand and by channel
- Consistent wording at sign-up, checkout and landing pages
Seasonal campaigns can make this even trickier. A fashion brand might want to plug a partner homeware site during spring sales, but without clear permissions that cross-sell can cut across the law.
The takeaway: if you want cross-brand marketing, design it clearly from day one, with transparent notices, granular consent and unsubscribe tools that respect the structure.
FAQs on UK Unsubscribes, Suppression, and Cross-Brand Marketing
Q1: How quickly do we have to process an unsubscribe request?
A1: The law talks about a reasonable time, but in practice marketing systems should stop within a short period, such as a day or two for automated tools and a few working days for any manual processing. Long delays while campaigns keep rolling are likely to annoy people and raise complaints.
Q2: Can we require users to log in or answer questions before they unsubscribe?
A2: No, the process should be simple and not force people to create or access an account. A one-click unsubscribe is usually best. You can offer a link to a preference centre as an extra, but the simple opt-out must be quick and easy.
Q3: Do we need fresh consent if the UK GDPR or PECR rules change?
A3: You do not automatically need new consent every time guidance shifts. What matters is that your existing consents still meet the standard of being freely given, specific, informed and unambiguous, and that your records and notices reflect current law. If they do not, then new consent may be needed.
Q4: Can we send service emails that include a bit of promotion after someone unsubscribes?
A4: You must be careful here. Genuine service updates that are needed to run the contract are fine, but if you start adding banners, offers or promos, the email can count as marketing again. Once someone has opted out, marketing content in those emails can breach that choice.
Q5: Are B2B marketing emails covered by email unsubscribe law?
A5: PECR applies to corporate subscribers too, and UK GDPR applies whenever you use personal data, even in B2B settings. Some role-based addresses may be treated differently, but from a risk and trust angle, giving people a working unsubscribe in B2B marketing emails is wise.
Key takeaways:
- Broken unsubscribe setups are a legal and reputational risk, not just a tech bug
- Strong suppression lists, joined-up systems and thought-through cross-brand rules are the heart of compliant email marketing
- Treat unsubscribe rights as part of your overall data protection story so you can market with confidence in the UK climate, whatever the season brings
Stay Compliant And Protect Your Customers’ Trust
If you are unsure whether your current mailing lists and opt-outs comply with email unsubscribe law, we can help you review and update your processes with confidence. At Stay Legal, we translate complex legal requirements into practical steps your team can follow. Take the next step towards safer, more transparent email marketing by letting us assess your risks and highlight any gaps. Get in touch so we can help you put the right measures in place before problems arise.


