7 minute read
Do you need consent for internal emails?
Most internal communications do not rely on consent at all. The question that decides it is whether somebody could reasonably have expected the message, and whether you could show that if asked.
Last reviewed
Two wrong answers, and where they come from
People usually arrive with one of two positions, and both are wrong in the same direction.
The first is that employment settles it: these people work here, we are allowed to email them. That is right about a great deal and wrong about the rest, and the rest is where complaints come from. Somebody’s employment contract does not by itself make every message you might send them lawful, and it certainly does not mean they cannot object to any of it.
The second is that everything needs consent, imported wholesale from marketing. That is a rule about selling to strangers, and applying it internally produces the strange result that a safety notice looks optional. It also creates a pile of consent records that misdescribe what is actually happening.
The useful question is not “do I have consent”. It is: could this person reasonably have expected this message, and could I show why they are receiving it?
Sort your messages into two piles
Nearly every difficulty here comes from treating one pile as though it were the other.
- Things somebody must receive
- A building closure, a policy change, a safety notice, a payroll deadline. These are part of running the organisation and the recipient does not get to opt out of them. Consent is not the basis and asking for it would be misleading, because you are going to send it either way. A distribution list built from the staff directory is the right tool: it follows the org chart automatically and nobody has to maintain it.
- Things somebody chose to receive
- The cycling group, the site newsletter, the volunteering programme, the parents' network, the union bulletin. Nobody is required to be on these and everybody should be able to leave. This is where a record of choosing matters, because the only answer to 'why am I getting this' is that the person asked to.
- The pile that causes trouble
- Optional communications sent through the mandatory channel. It is the path of least resistance - the all-staff group already exists and already reaches everybody - and it quietly spends the credibility of the channel you most need people to read. A workforce that receives eleven optional newsletters through the all-staff group learns to ignore the all-staff group.
What to actually record
Whatever your lawful basis turns out to be, the practical question is the same: if somebody asks why they are on a list, what can you produce? “Their address is in a spreadsheet” is not an answer. These four things are.
- What they were asked. Not the current version of your form - the version they saw. If you added a question or reworded one after they signed up, the record should still reflect what was in front of them at the time. This is the part almost nothing captures, and the part that settles an argument.
- What they chose. The specific answers, including the ones they declined. A record showing somebody ticked two of six topics is far more useful than one showing they are 'subscribed'.
- When, and from where. A timestamp, and the address and browser the action came from. That last part is what makes it evidence rather than an assertion, because it is the detail nobody could reconstruct afterwards.
- Every change since. Including unsubscribes, and including changes they made themselves. The history matters more than the current state: 'they unsubscribed in March and rejoined in June' is a complete answer, and 'they are currently subscribed' is not.
Five practical rules
None of these depend on which lawful basis applies, which is why they are worth following before you have decided.
- Let people leave, in one click
- Every optional message should carry a way out that works immediately and needs nobody's help. If leaving requires emailing a person who then edits a file, people will not leave - they will stop reading, which looks like success in your open rates and is the opposite.
- Offer a change, not only an exit
- Most people who unsubscribe did not want nothing. They wanted less, or something different. A door marked exit turns 'this is too much' into a permanent departure, when the honest answer was two topics instead of eight.
- Do not import people into optional lists
- Uploading a directory export into a list somebody would be surprised to be on is the single most common way this goes wrong. If you must start from a list you already hold, say so in the first message and make leaving trivial.
- Ask only what changes what you send
- Every field you collect is one you have to justify, keep accurate and eventually delete. If knowing somebody's job title does not change a single message they receive, do not ask for it - it is a liability with no matching benefit.
- Let people see and correct their own record
- Somebody has a right to know what you hold about them and to have it corrected. Building that into the list is far less work than answering it by hand, and it has the side effect of keeping the list accurate, because the person who knows a detail has changed is the only one who reliably does.
Things worth being straight about
- This is not legal advice. Which lawful basis applies to your communications depends on what you are sending, to whom, and in what jurisdiction, and it is a question for your own data protection adviser rather than for a software company. Everything above is about what to record and what questions to ask, both of which are useful whatever the answer turns out to be.
- Consent is not always the strongest basis. It is the most easily withdrawn, and relying on it for something you intend to send regardless is worse than not claiming it. Where a message is genuinely necessary, saying so plainly is more honest than collecting a permission you would ignore.
- A smaller list is usually a better one. Everything here tends to reduce the headline number, because people who would have quietly stopped reading instead narrow what they get, and dead addresses stop being counted. If your reporting is judged on list size, that is a conversation worth having before you start rather than after.
- The record is for you as much as for them. The point of keeping it is not that a regulator will ask. It is that somebody will eventually be annoyed about an email, and the difference between a two-minute answer and a week of archaeology is whether you wrote down what they agreed to at the time.
Read next
Your first list
From nothing to a link you can share, in about the time it takes to make a cup of tea. What to call it, what to ask, and when to publish.
Getting people to actually sign up
A form nobody fills in is a spreadsheet with extra steps. Where to put the link, what to say, and how to reach colleagues who pass a notice board more often than they read an inbox.
Keeping a list clean without chasing anyone
Every list falls out of date - people move team, change site, leave. The answer is not to chase harder; it is to stop being the only person who can make a correction.
How to organise your internal mailing lists
Most internal lists are organised by who somebody is, because that is what the directory knows. Nearly everything people actually want is organised by interest, and the gap between the two is where the administration comes from.
What is a preference centre?
The category these guides assume, defined without selling anything: what one is, what it is not, and who needs one.