- Opt-in data is contact information from people who agreed to receive marketing.
- Single opt-in means a person submitted their details and agreed. Double opt-in adds a confirmation step.
- Permission is specific to a channel: agreeing to email is not agreeing to calls or texts.
- Permission-based data tends to produce fewer complaints and better deliverability.
Almost every data provider describes its data as opt-in or permission-based. The terms are used so loosely that it is worth being clear about what they should mean, and about what to ask when you hear them.
What opt-in means
Opt-in data is contact information collected from people who agreed to be contacted for marketing. The agreement is given at the point where the person provides their details, for example by ticking a box or submitting a form that states how the information will be used. Permission-based data is another name for the same thing.
The opposite is data gathered without the person's agreement, such as addresses scraped from websites. Using that kind of data damages response rates and sender reputation, and it can create legal exposure.
Single opt-in and double opt-in
- Single opt-in. The person submits their details and agrees to be contacted. Nothing further is required.
- Double opt-in. After submitting, the person receives a confirmation message and must click a link to confirm. This proves the address is real and belongs to the person who entered it.
Double opt-in produces smaller lists with fewer invalid addresses. Single opt-in produces larger lists that need more validation. Neither is wrong, but you should know which one you are buying.
First-party and third-party permission
When someone signs up on your own website, that is first-party permission: they agreed to hear from you. When you obtain data from a provider, the permission was given to someone else, with the understanding that the information could be shared with marketing partners. That is third-party permission. Both are legitimate, but third-party contacts do not know your brand yet, so your first message has to introduce you clearly.
Permission is specific to a channel
Agreeing to receive email is not the same as agreeing to receive phone calls or text messages. In the United States, commercial email is governed by the CAN-SPAM Act, which requires, among other things, accurate sender information and a working way to opt out. Telemarketing calls and texts fall under the Telephone Consumer Protection Act and related rules, which set stricter consent requirements, particularly for automated calls and texts to mobile phones. Other countries have their own laws, and some are stricter.
This article is general information, not legal advice. Check the rules that apply to your channel, your industry, and the places you market to, and consult counsel where needed.
Why permission-based data performs better
- Fewer spam complaints. People who agreed to receive marketing are less likely to report it.
- Better deliverability. Lower complaint and bounce rates protect your sender reputation. See why emails go to spam.
- Higher response. An audience that expects marketing engages with it more.
- Lower risk. Documented permission is your starting point for compliance.
How to check a provider's claim
- Ask how and where the permission was collected.
- Ask which channels the permission covers.
- Ask how opt-outs are handled and how quickly they are removed.
- Ask how recently the records were collected or confirmed.
Our list of questions to ask before you buy marketing data goes further.
Keeping permission intact
Permission is not permanent. Honor every opt-out promptly, keep a suppression file, and apply it before every send. Remove contacts who have not engaged in a long time. Ongoing list management keeps a permission-based list in good standing.
R1D Media Group's database is 100% permission-based. To discuss an audience, see our data leads page or contact us.