Build Consent Instead of Risking Cold Email: The Opt-in Funnel
Email advertising requires prior consent. How to collect it lawfully through ads and your own content, what makes it valid, and the four mistakes that make an otherwise usable list unusable.
Not legal advice. This article describes the legal position in Germany in general terms. It is not legal advice, does not replace review of your specific case, and creates no attorney-client relationship. Use at your own risk. CegTec is not a law firm. The provisions cited are German and EU law; other jurisdictions differ.
The question that comes after the legal position
Email advertising requires prior express consent, with no B2B exception. That is the legal position, and it is set out with every channel and the statutory citations in Which outreach channel needs which consent?.
It does not follow that email is out as a channel. It only follows that the consent has to exist before the first advertising email. Consent is therefore not an obstacle but a component: something you can build, with ads and your own content as the inflow.
This article covers what makes consent valid, what the funnel behind it looks like, and the four mistakes that make an otherwise usable list unusable.
What makes consent valid
Six requirements that have to be met together. The first three come from German unfair-competition law, the other three from the GDPR:
- Prior. The consent exists before the first advertising email, not after. A “please confirm we may write to you” email is itself advertising if it promotes something.
- Express. An affirmative act. A pre-ticked checkbox does not qualify — the ECJ made that clear for cookies in Planet49, and the same logic applies to advertising consent. An opt-out is not consent.
- Specific to advertising by email. The declaration has to make clear who advertises and for what. General agreement to “terms” does not carry it.
- Provable. Art. 7(1) GDPR puts the burden of proof on the controller. In practice: timestamp, technical process, and the wording that was agreed to, in a version that is still findable later.
- Withdrawable, and withdrawal as easy as giving it. Art. 7(3) GDPR. An unsubscribe link in every message that works without a login.
- Not tied to something unrelated. Making access to content conditional on accepting advertising weakens the voluntariness, and with it the consent itself.
The funnel: four stages
1. Inflow: ads or content
Ads are the paid route. LinkedIn and Google deliver volume within days and can be cut to ICP criteria. They cost per contact, permanently, and the inflow stops when the budget stops.
Your own content is the compounding route. An article that ranks for a purchase-adjacent question still delivers contacts months later at no extra cost. It needs lead time, often two to three quarters before it works.
In practice the two complement each other: ads finance the learning curve while the content builds. For the role of ads further down the funnel — as an amplifier rather than a standalone lead source — see the Academy guide Demand Detection Funnel.
2. The asset someone gives an address for
The inflow needs a reason. Which four formats actually lead to a conversation in DACH B2B, and which only produce downloads, is covered in B2B lead magnets that produce meetings — not repeated here.
For the consent only one property matters: the asset has to justify the value of the address. Anyone demanding consent to sales outreach for a thin PDF gets throwaway addresses and a list that does not reply.
3. The page where the consent comes into being
This is where it is decided whether the list is usable later. Concretely:
- Two separate transactions. The address for sending the asset is one. Consent to future advertising emails is the other — as its own, not pre-ticked checkbox with its own text.
- The text names sender and purpose. Who advertises, for what, roughly how often. And that withdrawal is possible at any time.
- The asset arrives without the checkbox too. Otherwise the consent is tied and open to challenge. That costs consent rate, and is precisely why it is the honest route.
- Privacy notice at the point of collection, linked, with the Art. 13 GDPR information.
4. Double opt-in and the record
The confirmation link is not the point. The record is the point. For every contact, keep:
- the timestamp of the declaration and the timestamp of the confirmation
- the technical process and the source (campaign, page, form)
- the version of the wording that was agreed to
- the withdrawal status, as soon as one occurs
Without those four you have an address and an assertion. With them you have proof — and that is the difference that counts in a dispute. The same documentation also answers a data subject access request, if one arrives: Art. 15(1)(g) GDPR asks for exactly that provenance.
The four mistakes
1. Mistaking a registration for consent. The most common and most expensive. A content gate collects addresses in exchange for access. That is consent to the access, not to advertising. Anyone later using that list for sales emails is sending advertising without consent — the same risk as cold outreach, with the addition that the recipients experience a breach of trust. And if the form said “no spam, no subscription”, the starting position is worse still.
2. Interpreting the scope broadly afterwards. Consent to a subject-matter newsletter does not carry an individual sales pitch if that was never mentioned. The scope determines what may be sent. Anyone wanting to send more broadly has to ask more broadly — and truthfully.
3. Platform lead ads without your own proof. LinkedIn and Meta forms pre-fill and submit in two clicks. Without your own, actively ticked consent declaration, no consent to advertising email arises. And even if the checkbox was there: check whether the export carries the wording and the timestamp. Many do not — then the proof is missing even though everything was set up correctly.
4. Building the record only when it is needed. Consent records cannot be created retroactively. Anyone adding logging after the first thousand contacts has a thousand contacts without proof.
What it costs, honestly
The opt-in funnel is not the free version of cold outreach. It shifts the effort forward: budget for ads or time for content, an asset worth the trade, and clean logging. In return you get a list you are allowed to send to, and a channel that does not depend on a risk assessment.
What it does not replace: reaching target accounts who will never fill in a landing page. For those, the channels that work without consent remain — postal mail consent-free, telephone B2B under presumed consent, professional networks with a staged approach. The classification is in the channel matrix.
The robust setup is therefore both: an opt-in funnel that builds a sendable list over months, and consent-free channels for the accounts too valuable to wait on a form.
Implementing it in five steps
- Check what the existing list actually is. For every source, record: was there a separate, not pre-ticked consent to advertising emails? Is the wording findable? If not, the list is not an advertising distribution list, however large it is.
- Rebuild the landing page around two separate transactions — asset delivery and advertising consent, the latter optional.
- Switch on double opt-in with logging, including the wording version. Only then buy inflow.
- Start the inflow, with ads for speed and a purchase-adjacent article for durability.
- Measure two numbers, not one: cost per consented contact, and the reply rate of that list. A funnel with a high sign-up rate and a low consent rate produces addresses you are not allowed to use.
Sources
- German Act Against Unfair Competition (UWG), Sec. 7(2) No. 2 (advertising by electronic mail) and Sec. 7(3) Nos. 1–4 (existing-customer advertising). Numbering per the version in force since the 2021 UWG amendment.
- GDPR, Art. 6(1)(a) (consent), Art. 7 (conditions, burden of proof, withdrawal) and Art. 13 (information duty at collection).
- ECJ, judgment of 1 October 2019, C-673/17 (Planet49) — on the invalidity of pre-ticked checkboxes.
Common questions
Is registering for a download already consent to advertising emails?
No. A registration is consent to what it was given for, usually access to a piece of content. Section 7(2) No. 2 UWG requires prior express consent to advertising by electronic mail. That has to exist as its own declaration and make clear who will advertise and for what. Anyone using a download list for sales emails does not have consent — they have an email address.
Is single opt-in enough, or do I need double opt-in?
The law prescribes no particular procedure, but Art. 7(1) GDPR puts the burden of proof on the controller. In practice double opt-in is the established proof mechanism: a confirmation link, logged with timestamp, IP and the exact wording that was agreed to. Without that record it is assertion against assertion in a dispute, and the burden sits with you.
Can I collect consent through LinkedIn or Meta lead ads?
Yes, but with a pitfall. The platforms' forms pre-fill and submit in two clicks; without your own, actively ticked consent declaration no consent to advertising email arises. Also check whether the export carries the wording and the timestamp — many platform exports do not, and then the proof is missing even though the checkbox was there.
Does newsletter consent cover sales outreach?
Only as far as it recognisably extends that far. The scope of the consent determines what may be sent. Consent to a subject-matter newsletter does not carry an individual sales pitch if that was never mentioned. The sensible approach is to phrase the purpose broadly enough and truthfully up front, not to interpret it broadly afterwards.