Articles bg

Articles

Articles

Marketing emails and cookies after Inteligo Media: what the EU Court of Justice actually decided

Marketing emails and cookies after Inteligo Media: what the EU Court of Justice actually decided

If your website sends customers emails with news, promotions or useful articles, this article explains when you can do that and when you need to ask for permission first.

The key points:

  1. Any email that leads to sales counts as advertising, even if it contains only useful news and no discounts.
  2. You can write to people who gave consent by ticking the box themselves, or to your own customers if they were offered a way to opt out when you collected their address and every email has an unsubscribe link.
  3. A free registration on your site can also make someone a "customer" if free access leads to a paid one. That is good news for services with free and paid tiers.

Many companies still state in their privacy policies that they send digests, product selections and promotions on the basis of "legitimate interest". For email marketing in the EU, that has always been a weak basis. A specific rule applies here: Article 13 of the ePrivacy Directive (2002/58/EC). It leaves two options: prior consent or the so-called soft opt-in for customers.

On 13 November 2025, the Court of Justice of the EU looked at how these rules work in practice in Inteligo Media (C-654/23). For businesses, the outcome was more lenient than many expected.

What happened with avocatnet.ro

The Romanian legal portal avocatnet.ro ran a freemium model. Without registering, users could read six articles a month. A free registration gave them two more articles and a daily newsletter summarising new legislation, with links back to the site. Users could opt out of the newsletter by ticking a box at registration, but by default everyone received it.

The Romanian data protection authority (ANSPDCP) fined the company. Its reasoning was that the addresses were collected to perform the free account agreement but then used for marketing without consent. The Bucharest Court of Appeal referred questions to the EU Court of Justice.

What the Court decided

First, a useful news digest is still marketing. The emails had no discounts or banners, only legislative news. But the newsletter drew readers back to the site and nudged them towards a paid subscription, so the Court classified it as direct marketing. The "we are just informing people" argument did not work.

Second, and this matters most for businesses, a free registration can count as the "sale of a service". If the free account is part of a model that leads to a paid subscription, the address was obtained in the context of a sale. That means the soft opt-in can apply to these users.

Third, where the soft opt-in conditions are met, no separate legal basis under Article 6 GDPR is required. There is no need to rely on "legitimate interest" here; Article 13(2) of the Directive is enough.

The final decision on the fine rests with the Romanian court, which has to check whether all the conditions are met. The Court of Justice also reminded that the exception is interpreted narrowly and does not fit every free service.

On what basis can you send marketing emails

Consent. Required for anyone who is not your customer: blog subscribers, people who downloaded a guide, casual site visitors. The person ticks an empty box themselves. Consent to marketing emails cannot be bundled with accepting the terms of use.

Soft opt-in. You can write without prior consent if three conditions are met. The address was obtained in the sale of a product or service (after Inteligo, this can include a free registration within a paid model). You are promoting your own similar products or services. The person was given a simple, free way to opt out when the address was collected, and the same option is in every email.

Order confirmations, receipts, password reset emails and delivery notifications are not marketing, as long as you don't put advertising in them.

Cookies: separate rules

Inteligo did not concern cookies. They are governed by Article 5(3) of the ePrivacy Directive, and back in 2019 the Court of Justice held in Planet49 (C-673/17) that a pre-ticked box is not consent.

Strictly necessary cookies (login, shopping cart, security) work without consent. Google Analytics, Yandex Metrica, Meta Pixel and similar scripts must not load until the user clicks "Accept" on the cookie banner.

What to check on your website

  1. Your privacy policy and cookie policy. The basis for marketing emails should be consent or the soft opt-in, not "legitimate interest".
  2. Registration and order forms. There should be no pre-ticked boxes for marketing emails.
  3. Checkboxes. "I accept the terms" and "I want to receive marketing emails" must be separate boxes.
  4. The opt-out at the point of collection, if you rely on the soft opt-in. Without it the exception does not apply, and you cannot fix that retroactively.
  5. Unsubscribing. It should take one click, with no need to log in or enter a password.
  6. Your consent log. Record when, through which form and with what wording the person gave consent. Double opt-in is useful as evidence.

FAQ

Can I send abandoned cart reminders?
These emails count as marketing. If the address was given while placing an order and the person was offered a way to opt out at that point, you may be able to rely on the soft opt-in. Whether an unfinished order counts as a "sale" is still an open question, though. In all other cases you need consent.

Do these rules apply in B2B?
Article 13 of the ePrivacy Directive primarily protects individuals. For legal entities, each member state sets its own rules, and approaches differ. At the same time, an address like name@company.com is still personal data under the GDPR, so it is safer to treat it the same way as a personal address.

Is double opt-in mandatory?
No. But it is the simplest way to prove that consent came from the actual owner of the address.

Conclusion

Your privacy policy, forms, cookie banner and script settings need to work together. If one of them is out of line with the rest, the regulator will have something to pick on. Our law firm audits websites and email marketing for compliance with ePrivacy and the GDPR.

Articles

Useful articles

European-Style Taxation: Moldova Changes the Rules for International Business

The Republic of Moldova has begun transposing European rules on direct taxation into its national legislation. On 22 September, the Government approved the relevant draft law. For most entrepreneurs, its provisions may still seem somewhat distant: some are due to take effect in 2027–2028, while others will apply only after the country joins the European Union. However, for companies with foreign shareholders, subsidiaries, loans or intellectual property, the changes may have very practical implications.

Legal Support for Businesses: Reliable Protection for Your Company

Businesses need legal counsel not only when a dispute has already arisen, a regulatory inspection has begun, or a business partner has breached an agreement. It is far more effective to identify and address legal risks before they become serious problems. That is why effective legal support is not about constantly dealing with consequences — it is about taking a systematic and proactive approach to risk management.

GDPR, RoPA and DPIA: How to Stop Being Intimidated by Acronyms and Build an Effective Data Protection Framework

As of 23 August 2026, Moldova applies Law No. 195/2024 on Personal Data Protection, which introduces a modern and comprehensive approach to the processing and protection of personal data and reflects the principles of the European GDPR. For businesses, this means understanding not only which documents are required, but also how personal data actually flows through the company.

Leave a request

Block - Leave a message
Call message Call close