PrivacyForgeSign In
Back to Blog

Back-in-Stock Emails and GDPR: When Alerts Become Marketing

Learn when a back-in-stock email becomes direct marketing under GDPR, whether the PECR soft opt-in covers a shopper who never bought, and how Ireland differs.

PFMariyan ValevSep 1, 2026 · 15 min read
GuideGuide

Key Takeaways

  • A restock alert stays a service message only while it stays neutral. The ICO's rule is blunt: if a service message "has elements that are direct marketing, even if that is not the main purpose of your message, then it will count as direct marketing." One "Shop now — 10% off" block converts the whole email.
  • Submitting a back-in-stock form is not consent to a newsletter. The ICO's closest worked example says that submitting an online form indicates consent for that purpose, but "will not, however, be enough by itself to show valid consent for any further uses of the information."
  • In the UK, PECR Regulation 22(3)(a) reaches contact details obtained "in the course of the sale or negotiations for the sale" — and the ICO states plainly that "a person doesn't need to actually buy anything from you."
  • Ireland and Germany did not copy that wording. Irish Regulation 13(11) requires details obtained "in the context of the sale", a product similar to one actually supplied, and a sale — or a qualifying use of the details — within the previous 12 months. Germany's § 7(3) UWG requires the address to be obtained "im Zusammenhang mit dem Verkauf" — in connection with the sale.
  • In Ireland, breaching that rule is a criminal offence, each message counts as "a separate offence", and a body corporate faces a fine "not exceeding €250,000" on conviction on indictment.

Introduction

A shopper lands on a sold-out product, types their email into a "notify me" box, and leaves. Nothing was bought. Nothing was agreed beyond one narrow request: tell me when this is back.

Six weeks later the product returns, and your restock email goes out carrying a discount code and a "you may also like" grid — to an address that has never once been asked whether it wants marketing. That email is where a well-meaning flow quietly becomes an enforcement question.

Three questions decide it: whether a restock alert is direct marketing or a service message, whether the UK's soft opt-in reaches someone who never bought, and why the same form can be defensible in Manchester and unlawful in Munich. This is informational content, not legal advice.

Is a Back-in-Stock Email Direct Marketing or a Service Message?

A back-in-stock email is a service message while it only reports the fact the shopper asked for. It becomes direct marketing the moment it promotes anything: the ICO says a message that "actively promotes or encourages people to make use of a particular service, special offer, or upgrade" is "likely to be direct marketing."

The line the ICO actually draws

PECR defines direct marketing as "the communication (by whatever means) of advertising or marketing material which is directed to particular individuals", and the ICO notes that the "advertising or marketing material" element "is interpreted widely and covers any advertising, promotions or marketing material."

Against that, the ICO describes service messages as communications that "aren't promotional but are for administrative or customer services purposes" — its own examples are messages that remind people how to contact you, check contact details are correct, confirm appointments, or update terms and conditions.

A restock alert the shopper explicitly requested sits naturally in that family. It is factual, it is about a specific thing they asked to be told, and it is information "they need to know as part of their relationship with you" — the ICO's own phrasing for what tips a message towards being a service message.

What tips a restock alert into marketing

Then comes the rule that catches most stores. In the ICO's words: "If your service message has elements that are direct marketing, even if that is not the main purpose of your message, then it will count as direct marketing." The regulator does carve out one relief — "if your service message contains general branding or logos, this doesn't count as direct marketing."

The ICO illustrates it with a mobile network telling a customer they are approaching their data limit. Purely informative, it is a service message. Add "we have a special data offer just for you" and the same text becomes direct marketing.

Translate that to a restock template and the failure modes are obvious: a cross-sell grid, a percentage-off code, a "limited stock — order now" line, or a footer promoting three other collections each carry the converting element. Our position: keep the restock alert surgically boring. Product name, that it is available, a link, and your normal branding. The trade-off is real — that email converts worse than a promotional one — but a plain alert you can defend beats a decorated one that drags the whole send under PECR Regulation 22.

Does the PECR Soft Opt-In Cover Someone Who Never Bought?

In the UK, quite possibly yes. PECR Regulation 22(3)(a) covers contact details obtained "in the course of the sale or negotiations for the sale of a product or service", and the ICO confirms that "a person doesn't need to actually buy anything from you. It's enough if 'negotiations for the sale' took place."

The "negotiations for the sale" limb

The ICO puts a condition on that generosity: the person "must actively express an interest in buying your products or services." Its listed qualifying acts are "signing up to a free trial of your product or service, requesting a quote or asking for more details about what you offer."

Two of its worked examples draw the line precisely. Good practice: "A customer sends an online enquiry to ask if the company can order a particular product. This could constitute negotiations for a sale and satisfy this part of the soft opt-in." Bad practice: "A customer logs into a company's website to browse their range of products. This is not enough to constitute negotiations ..."

A "notify me when this specific product is available" request is an express communication, about a specific product, motivated by wanting to buy it. It sits far closer to the enquiry than to passive browsing. Our read is that a UK store has a genuine argument that a restock request satisfies this limb — and that this is the opposite of what most merchants assume.

One honest wrinkle. The ICO's own short summary of the rule in its Guide to PECR describes it as an existing-customer rule and says it "does not apply to prospective customers or new contacts (eg from bought-in lists)." That summary is why so many merchants believe a purchase is mandatory. The detailed guidance is the more specific statement and tracks the statutory words "or negotiations for the sale", so that is what we follow — but a store relying on this should document its reasoning rather than assume the point is settled.

The four other requirements most restock forms fail

Clearing limb (a) is where merchants stop reading, and it is the least of their problems. The soft opt-in is cumulative — the ICO lists five requirements, and all must hold.

  1. You collected the details yourself. The ICO: "There is no such thing as a third-party marketing list that is compliant with the soft opt-in." It does not even survive sharing between companies in one group.
  2. The marketing is your similar products and services only. The test is "whether, based on previous interactions, people reasonably expect direct marketing about your product or service."
  3. You offered an opt-out when you collected the address. This is the requirement restock widgets fail almost universally, because the widget is usually one field and one button. The ICO is explicit: "You must offer the opt-out when you collect the contact details. Including an opt-out in an order confirmation email is not sufficient."
  4. You offer an opt-out in every subsequent message, and you do not gate it behind a login — "You should not ask people to create an account to unsubscribe or ask them to log into their existing account to change their preferences."

Requirement 3 is the one that decides most cases. A "notify me" box with no marketing opt-out beside it cannot support the soft opt-in later, however good the argument on limb (a).

If a shopper does tick a genuine marketing box on the restock form, you have consent and none of the above matters. What you cannot do is manufacture it. Quoting Recital 32, the ICO states that "silence, pre-ticked boxes or inactivity should not therefore constitute consent", and adds that "there is no such thing as 'opt-out consent'." You must also be able to prove it: "Article 7(1) makes it clear you must be able to demonstrate that someone has consented." Keeping that evidence is a records problem as much as a UX one — the same discipline covered in our guide to proof-of-consent records.

The most useful authority here is an analogy. The ICO's example of someone submitting an online survey concludes that by doing so "they are clearly indicating consent to process their data for the purposes of the survey itself. Submitting the form will not, however, be enough by itself to show valid consent for any further uses of the information." Read that across: a back-in-stock submission is consent to be told when that product returns, and not, by itself, consent to a newsletter.

Why Ireland and Germany Answer Differently

The UK's "negotiations" wording is not the European norm. National implementations of the ePrivacy existing-customer exception are drafted more narrowly, so a restock-request address that a UK store can arguably market to is one an Irish or German store generally cannot.

RequirementUK — PECR reg. 22(3)Ireland — S.I. 336/2011 reg. 13(11)Germany — § 7(3) UWG
Trigger for collecting the address"in the course of the sale or negotiations for the sale""in the context of the sale of a product or service""im Zusammenhang mit dem Verkauf einer Ware oder Dienstleistung"
Purchase required?No — ICO: "doesn't need to actually buy anything"On the wording, yesOn the wording, yes
Similarity test"similar products and services only"similar "to that supplied to the customer in the context of the sale""eigene ähnliche Waren oder Dienstleistungen"
Time limitNone in the regulationSale — or qualifying use of the details — within 12 monthsNone in the provision
Opt-out timingAt collection and in each messageAt collection and in each messageAt collection and on every use

Ireland's Regulation 13(11) is the strictest of the three on two counts. The marketed item must be "of a kind similar to that supplied to the customer in the context of the sale" — supplied, meaning something actually changed hands — and paragraph (d) requires that "the sale of the product or service occurred not more than 12 months prior to the sending of the direct marketing communication ..." The clause continues: "or, where applicable, the contact details were used for the sending of electronic mail for the purposes of direct marketing within that 12 month period" — so the window is a rolling one that continuous, compliant marketing keeps open, rather than a hard cut-off 12 months after the sale.

The consequences are correspondingly sharper. Contravening Regulation 13(11) "commits an offence"; "the sending of each unsolicited communication or electronic mail ... constitutes a separate offence"; and on conviction on indictment the fine for "a body corporate" is one "not exceeding €250,000". Regulation 13(14) then puts the burden of proof on the sender: "the onus of establishing that the subscriber or user concerned unambiguously consented ... lies on the defendant." A store that cannot produce its consent evidence has already lost the point.

Germany's § 7(3) UWG sets four cumulative conditions, the first being that the trader obtained the customer's electronic mail address "im Zusammenhang mit dem Verkauf einer Ware oder Dienstleistung von dem Kunden" — in connection with the sale of goods or a service, from the customer. There is no negotiations limb. Condition 4 also goes further than the UK's: the customer must be told clearly, "bei Erhebung der Adresse und bei jeder Verwendung" — at collection and on every use — of the right to object at any time, free of charge beyond basic transmission costs.

The practical consequence for anyone shipping across the Channel: do not run one restock flow on the UK's rules. If you sell into Ireland or Germany, the defensible design is to collect an explicit, separate marketing opt-in on the restock form and rely on that everywhere, rather than maintaining one legal argument per market. It costs you signups. It also means one flow instead of three, and the same list logic that governs abandoned cart emails to people who never completed a purchase.

How to Build a Restock Flow You Can Defend

None of this needs a new app. It needs the restock form to carry the same consent architecture as every other collection point on the store — the discipline set out in our complete guide to GDPR compliance.

  1. Split the two purposes on the form. One field for the restock alert, one clearly-labelled and unticked box for marketing. Never require the box to submit the alert request.
  2. Put the marketing opt-in on the widget itself, not in the confirmation email. PECR Regulation 22(3)(c) requires the refusal opportunity "at the time that the details were initially collected".
  3. Keep the alert email neutral. Product, availability, link, branding — nothing promotional.
  4. Store the two states separately. "Wants restock alerts for SKU X" and "consented to marketing" are different records with different scopes; merging them at the ESP is how stores end up marketing to people who only ever asked about one product.
  5. Log what the form said and when. Article 7(1) requires you to demonstrate consent, and Irish Regulation 13(14) puts the onus on you — a screenshot of today's form does not evidence last year's.
  6. Set your rules to the strictest market you ship to.

Common Mistakes

1. Treating the restock signup as a newsletter signup. The most common and the most expensive, because the recipient remembers asking about one product and complains accordingly.

2. Pre-ticking the marketing box, or making it required. Both are void: "silence, pre-ticked boxes or inactivity should not therefore constitute consent", and a box you cannot submit the form without is not freely given.

3. Putting the opt-out only in the email. Fails PECR Regulation 22(3)(c) outright — the ICO's order-confirmation example settles it.

4. Decorating the alert. A 10% code in a restock email is a small revenue idea with a large legal consequence: it converts a defensible service message into direct marketing.

5. Assuming one European ruleset. The UK's "negotiations for the sale" wording is not what Ireland and Germany enacted, and the gap is where a cross-border store gets caught.

6. Keeping no record. In Ireland the defendant carries the burden of proving consent. An unlogged opt-in is, evidentially, no opt-in.

How PrivacyForge Helps

The hard part of this is not the legal reading — it is that the evidence lives in four systems. The restock request sits in an app, the marketing state in your ESP, the form wording in your theme, and the proof of what a shopper actually saw nowhere at all.

PrivacyForge's consent management keeps the two states as distinct, timestamped records with their scope attached, so "asked about one product" never silently becomes "subscribed", and it answers the Article 7(1) demonstrability requirement and the Irish burden-of-proof problem with the same artefact. The data mapping side records which systems hold restock requests, which matters the moment someone asks you to delete theirs. None of that decides your legal position — but when a complaint arrives you are reading records rather than reconstructing a form from memory.

Frequently Asked Questions

Is a back-in-stock notification direct marketing under GDPR?

Only if it promotes something. A neutral alert reporting that a requested product is available is a service message. The ICO's rule is that a service message with "elements that are direct marketing, even if that is not the main purpose", counts as direct marketing — so a discount code or cross-sell block converts it. General branding and logos do not.

Can I add back-in-stock subscribers to my marketing list without asking?

No. The ICO's worked example on form submissions states that submitting a form indicates consent "for the purposes of the survey itself" but "will not, however, be enough by itself to show valid consent for any further uses of the information." A restock request is consent to be told about that product, not consent to a newsletter. Ask separately, with an unticked box.

Does the PECR soft opt-in apply if the shopper never bought anything?

In the UK it can. Regulation 22(3)(a) covers details obtained "in the course of the sale or negotiations for the sale", and the ICO confirms "a person doesn't need to actually buy anything from you" provided they "actively express an interest in buying". Its qualifying example is an enquiry about ordering a particular product; passive browsing does not qualify.

Can I put the marketing opt-out in the restock email instead of on the form?

No. PECR Regulation 22(3)(c) requires a simple means of refusal "at the time that the details were initially collected". The ICO is explicit that "you must offer the opt-out when you collect the contact details. Including an opt-out in an order confirmation email is not sufficient." The opt-out must then also appear in every subsequent message.

Do the same rules apply in Ireland and Germany?

No, and this is where cross-border stores get caught. Irish Regulation 13(11) requires details obtained "in the context of the sale", a product similar to one actually supplied, and a sale (or qualifying use of the details) within 12 months. Germany's § 7(3) UWG requires the address obtained "im Zusammenhang mit dem Verkauf". Neither has the UK's "negotiations" limb.

Conclusion

The restock alert itself is the easy part: keep it factual and it is a service message in every one of these jurisdictions. Everything difficult happens at the form, where one text field quietly decides whether you have a marketing permission at all.

The UK gives stores more room than they think — the ICO's own examples suggest a "notify me about this product" request can meet the "negotiations for the sale" limb. But that room evaporates on the opt-out-at-collection requirement, which almost no restock widget satisfies, and it does not exist at all under the Irish and German wording.

So the recommendation is the boring one, and we would give it even to a UK-only store: ask for marketing consent explicitly on the restock form, with an unticked box, and log what you showed. Audit your back-in-stock flow this week — the form, the email template, and where the two consent states are stored.

Sources