Web60 Features
Email Marketing Rules in Ireland: What Your Signup Form Commits You To

There is a signup box somewhere on your website. It might sit in the footer, it might slide up after a few seconds, and there is a fair chance you have not thought about it since the site was built.
It is quietly the most legally loaded element on the page. Not the cookie banner. Not the terms link. The signup box.
I want to walk you through what Irish law asks of you the moment somebody types an address into it, because the thing that catches business owners is almost never the thing they worry about.
The headline rule is about four lines long
The instrument you care about is S.I. No. 336 of 2011, the ePrivacy Regulations, and specifically Regulation 13. Strip away the subsections about fax machines and automated calling and the core of it is short. You may not send an unsolicited direct marketing email to an individual unless that person has notified you that they consent to receiving it [1].
That is the whole headline rule. Consent, first, from them.
Consent here carries its meaning from data protection law, which means freely given, specific, informed and unambiguous. In practice that rules out a few things you still see on Irish websites every week. A box that is already ticked when the page loads is not consent, because the person did nothing. Consent bundled into acceptance of your terms and conditions is not specific. An address collected for a quote request does not become a marketing permission because the wording underneath was vague.
So what does that mean at street level? It means the tickbox beside your signup field starts empty, it says what the person is actually agreeing to receive, and it is separate from every other tickbox on the form.
What the Commission actually prosecutes
Now the part that reframes this whole topic.
Ask a room of business owners what gets you in trouble with email marketing and almost all of them will say buying a list. Reasonable answer. It is also not what the Data Protection Commission has been bringing to court.
Look at the outcomes announced in October 2024. At Dublin Metropolitan District Court, Sky Ireland pleaded guilty to a charge of sending a marketing SMS to a customer after that customer had opted out. Google Ireland pleaded guilty to two charges of unsolicited marketing calls after an opt-out. Stella Novus pleaded guilty to two charges of sending marketing emails after an opt-out. Each was directed to pay 1,500 euro to charity along with the DPC's legal costs, in lieu of a conviction and fine [2].
Read the charges again. Not one of them is about a stranger's address. Every one is about somebody who was already a contact, who asked to be left alone, and who kept hearing from the company anyway.
The escalation path is visible in the same announcement. Sky had a warning from the DPC in 2019. Google had one in 2023. Stella Novus had one in 2023. The Commission warns, and then it prosecutes when the same conduct comes back.
The volume is climbing too. The DPC concluded 275 electronic direct marketing investigations during 2025, an 88% rise on the year before, and issued 50 warning letters off the back of unsolicited marketing complaints [3]. I would read that number with some care, because a jump in concluded investigations partly reflects how many complaints arrived and how quickly the office worked through them, not purely a collapse in standards. The direction of travel is still hard to argue with.

Consider a dance school in Wicklow, and take this as an illustrative composite rather than a named business, because the pattern is common enough that the specifics do not matter. Parents' addresses were collected at enrolment, term after term, going back years. One spring the school emails a summer camp offer to every address it has ever held. Among them are families who left in 2023, and at least one parent who replied "please take me off this" two seasons ago to a person who no longer works there.
That reply is the exposure. Not the list. The reply nobody actioned.
The exemption that expires
There is an exemption, and it is genuinely useful, but it is narrower than most people assume. Regulation 13(11) lets you market to an existing customer without asking permission first, provided four conditions are all satisfied at once [1].
All four. Not three.
| Condition in Regulation 13(11) | What it means in practice | Where it usually fails |
|---|---|---|
| Your own product or service | You may market what you sell, not what a partner sells | Affiliate offers and "our friends at" emails |
| Similar to what they bought | The offer has to resemble the original purchase | A single unrelated line added to a promo |
| Opt-out at collection and in every message | Free and easy to refuse, at signup and every time since | A message that goes out without an unsubscribe |
| Sale within the previous 12 months | The clock runs from the sale or the last compliant message | Dormant lists reactivated after a quiet year |
Your own product or service
The exemption covers what you sell. If you email your customer list about a neighbouring business's offer, however friendly the arrangement, you have stepped outside it and you are back to needing consent.
Similar to what they bought
The test is whether the thing you are marketing is of a kind similar to what the customer actually bought from you. Somebody who booked a service is not automatically fair game for an unrelated product line. This is where a single bolted-on paragraph does real damage, because it changes the character of the message.
An opt-out at collection and every time since
This condition has two halves and the second is the one that gets missed. The customer must be clearly and distinctly given a free and easy chance to object when you collect the address, and again in every message you send afterwards. Every message. A campaign that goes out without a working unsubscribe link fails the condition even if the original signup was immaculate.
The twelve-month clock
The sale has to have happened no more than 12 months before you send, or the address has to have been used for compliant marketing inside that window. Let a segment go quiet for longer than a year and the exemption has lapsed for those people. It does not come back because you have decided to start emailing again.
I gave a business owner bad advice on exactly this a few years ago. Everyone on the list had bought something, so I told him he was covered. I never asked when they had bought. A decent share of that list had gone quiet well over a year earlier, which put it outside the exemption entirely. The lesson stuck: with the customer exemption, the date matters as much as the relationship.
Business addresses are a different question, not a free pass
People assume business-to-business email is unregulated in Ireland. It is looser. It is not unregulated.
Regulation 13(2) says that an email address which reasonably appears to be used mainly by someone in the context of their commercial or official activity falls outside the individual consent rule, so long as your message relates solely to that activity [1]. A generic accounts or info address at a company domain sits comfortably here. A named personal address at the same domain is greyer, because the same inbox is often somebody's working identity, and the safe read is to treat it as individual.
Then Regulation 13(4) closes the loop. Once a business subscriber has told you it does not consent, sending further marketing email is an offence, full stop. The looser entry rule does not survive an opt-out either.
The sentence that decides who wins the argument
Two provisions do more work than everything else in Regulation 13, and neither is widely known.
The first is Regulation 13(13)(b). The sending of each unsolicited communication constitutes a separate offence [1]. Your exposure is not one incident because you pressed send once. It scales with the size of the segment.
The second is Regulation 13(14). Where consent is in issue in proceedings, the onus of establishing that the person unambiguously consented lies on the defendant [1]. Read that as the practical instruction it is: if you cannot demonstrate consent, you do not have it. The complainant does not have to prove a negative. You have to produce the record.
As for what is at stake, an offence carries a class A fine on summary conviction, which under the Fines Act 2010 tops out at 5,000 euro, and on conviction on indictment a fine of up to 250,000 euro for a company or 50,000 euro for an individual [1] [4]. Those are statutory ceilings and courts rarely go near them, as the 1,500 euro charitable contributions in the 2024 cases show. Regulation 25 is the one to sit with, though: where an offence is committed with the consent, connivance or neglect of a director, manager or secretary, that officer commits a separate offence in their own right [1].
So the record is the whole ball game, and it lives on your website. What you want stored, for every address, is the date and time it arrived, the exact wording displayed at that moment, the page it came from, and every subsequent opt-out with its own timestamp. Storing the wording matters more than it sounds. Consent is judged on what the person was shown, so a form you redesigned last year leaves you defending a sentence you can no longer produce.
That data deserves the same treatment as the rest of your customer records, which is to say backed up, restorable and hosted somewhere you can actually point to. Running your site on Irish infrastructure where your data stays in Ireland keeps a straightforward answer available when somebody asks where consent records are held, and it removes a conversation you would otherwise have to have. The habits are the ones covered in our WordPress security and backup guide for Irish websites, applied to a table most people forget is sensitive.
One connected point. When somebody exercises the right to have their data erased, your suppression list is the awkward exception, because you generally need to retain enough of a record to keep honouring the opt-out. We worked through how those requests ripple across a site in our piece on what a data deletion request actually touches.

Where the line actually sits
Here is the honest limitation, and it is one you should know before a customer raises it rather than after.
Not every email you send is direct marketing. The DPC has accepted this directly. In a published case study, an individual complained about an airline email asking for feedback on a recent flight with no unsubscribe option. The Commission found the message compliant, on the basis that a communication sent solely for informational or feedback purposes is not direct marketing and therefore did not require one [5].
Useful. Also genuinely blurry in daily practice. A booking confirmation is not marketing. A booking confirmation with a line about next month's offer has become marketing, and the whole message now needs to satisfy Regulation 13. The distinction is the content, not the template name, and the temptation to add one promotional sentence to a transactional email is exactly where honest businesses drift across the line without noticing.
And the fair concession: if you are sending to tens of thousands of people with real segmentation, a dedicated email platform will manage suppression lists, bounce handling and consent audit trails better than a form and a plugin on your own site. That infrastructure exists for a reason. For a business emailing a few hundred customers a handful of times a year, it is overhead you do not need, and an email list captured on your own website remains the cheapest owned channel you have.
Five things to verify before your next send
- Trace the source. For any segment you are about to email, be able to say where those addresses came from and roughly when.
- Check the clock. If you are relying on the existing customer exemption, confirm the sale or last compliant contact falls inside 12 months.
- Test the unsubscribe. Actually click it, from a real address, and verify the address is suppressed afterwards rather than merely flagged.
- Reconcile the suppression list. Every opt-out ever received, including replies to a mailbox and requests made in person, needs to be reflected before send.
- Confirm the reply address works. Regulation 13 requires a valid contact address in the message, and a no-reply that bounces is not one.
None of that takes an afternoon once it is set up. Most of it is a habit rather than a project.
Conclusion
The uncomfortable truth in the Irish enforcement record is that the businesses getting prosecuted are not cowboys with scraped lists. They are established companies whose opt-out handling had a gap in it, usually because the request arrived somewhere other than the unsubscribe link.
Which makes this less a legal problem than an operational one. Somebody asked to be left alone, and the message did not reach the system that decides who gets emailed next.
You already know which addresses on your list you could not explain the origin of. That is where to start, and a quiet hour with the signup form and the suppression list is worth more than any amount of policy wording.
Frequently Asked Questions
Do I need consent to send marketing emails in Ireland?
Yes. Regulation 13(1) of S.I. No. 336 of 2011 prohibits sending unsolicited direct marketing email to an individual unless that person has notified you that they consent. Consent carries its GDPR meaning, so it must be freely given, specific, informed and unambiguous. A pre-ticked box does not qualify, and neither does consent bundled into your terms and conditions. There is a limited exemption for existing customers under Regulation 13(11).
Can I email people who bought from me without asking permission first?
Sometimes, under the existing customer exemption. Four conditions must all be met: you are marketing your own product or service, it is similar in kind to what the customer bought, the customer was given an easy free chance to object both when you collected the address and in every message since, and the sale happened within the previous 12 months. Fail any one of the four and the exemption does not apply to that person.
Is it legal to email business addresses in Ireland without consent?
The rules are looser but not absent. Regulation 13(2) means an address that reasonably appears to be used mainly for someone's commercial or official activity falls outside the individual consent rule, provided your message relates solely to that activity. However, Regulation 13(4) makes it an offence to keep sending marketing email to a business subscriber that has told you it does not consent. Personal-format addresses at a company domain are a grey area, so treat them as individual addresses.
What happens if someone unsubscribes and still gets emails?
That is the single most common route to prosecution in Ireland. The DPC typically issues a warning letter first and prosecutes if the conduct recurs. In October 2024 at Dublin Metropolitan District Court, Sky Ireland, Google Ireland and Stella Novus each pleaded guilty to charges involving contact after an opt-out, and each was directed to pay 1,500 euro to charity plus the DPC's legal costs in lieu of a conviction and fine.
How long should I keep proof of email marketing consent?
Keep it for as long as you are relying on it, plus a sensible margin afterwards. Regulation 13(14) places the burden of proving unambiguous consent on the sender, so a record you have deleted is a defence you no longer have. Store the date and time, the exact wording shown at signup, the page it was submitted from, and every later opt-out with its timestamp.
Are newsletters and service updates the same as marketing emails?
Not automatically. The DPC has accepted that a message sent solely for informational or feedback purposes is not direct marketing and does not require an unsubscribe option. The distinction is content, not the label on the template. A genuine service notice carrying a promotional line has become a marketing message, and Regulation 13 then applies to the whole email.
Sources
Eamon leads sales at Web60 and SmartHost, working directly with Irish business owners making the switch from cheap shared hosting to managed WordPress. With a background in enterprise technology sales — including Oracle and multiple Irish SaaS businesses — he understands the questions Irish SMEs ask before committing to a hosting platform. He writes about hosting comparisons, total cost of ownership, web design for Irish businesses, and how to evaluate what you’re actually buying.
More by Eamon Rheinisch →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
Your Website Calls It Eco-Friendly. New Green Claims Rules Start 27 September.
New green claims rules hit Irish business websites on 27 September 2026. What eco-friendly, sustainable and carbon-neutral can still say, and what must go.
Recurring Payments on Your Own Website: What Has to Work Every Month
Taking recurring payments on your own website means expiring cards, lapsed mandates and refund windows. What has to work every month, and what breaks.
