Product1 distinct publisher3 min readPublished
The UK regulator's direct-marketing guidance says the right answer to an opt-out is a suppression list rather than deletion, which means your erasure job and your campaign tooling have to agree on which identifiers survive.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A customer replies to a dispatch email with "stop emailing me". The reply lands in a shared inbox rather than at an unsubscribe endpoint, and the agent reading it picks from a menu built for tickets. The guidance turns on a purpose that menu does not model: the record is kept so that future sends can be checked against it [1].
Counting the rights makes the tension easier to size. The ICO lists four things a person can do, which are object, opt out or unsubscribe, withdraw consent, and ask you to delete their information [7]. Three of those four land on the suppression list, because the regulator says complying with an objection does not automatically mean deletion and that suppression is preferable in most cases [6][12]. The fourth arrives as a deletion request, and the guidance treats it as a separate question [13].
Which makes suppression a match-key problem. A list you check against needs whatever identifier the campaign would otherwise have used, which is why the ICO's own identity example is confirming an email address or a phone number in order to stop using those details [10]. Lead scores and the inferred interests that profiling produced do no work in that check, and profiling sits inside the scope of the objection in any case, alongside passing details to third parties [3].
Intake is where most tooling is thin. There is no required form of words, an objection can be verbal, and it can arrive at any part of the organisation, which is the ICO's stated reason for expecting firms to have a process that recognises one [4]. The channels that implies are the phone queue and a rep's inbox. Objecting also has to be free, and can happen before you have ever marketed to the person [9][11], and the deadline for telling people the right exists is at the latest your first communication, set out separately and in plain language [8].
One more column earns its place on the suppressed record: a reason. You cannot go back later to ask an objector whether they have changed their mind, since that contact is itself direct marketing for the purpose they objected to [5]. A re-engagement flow reading a blank send history as dormancy will mail somebody who told a salesperson, out loud, to stop.
So the test I would run through the contact schema this week: for each column, say whether it matches a future send or evidences that you honoured the request. Columns that do neither are what an erasure workflow should be allowed to take, and columns that do either are what has to survive it. The forcing function that follows is cheap. A colleague objects by the least convenient route you support, verbally, to someone in sales, and you measure two things afterwards: how many days pass before a campaign send is actually blocked, and whether the suppression row is still standing after the next deletion run. If the answer to the second is no, you have built the delete button the guidance warns about, and the person who asked you to stop will hear from you again.
Ranked by verification strength, evidence, and original report placement.
ICO direct-marketing guidance says that if someone no longer wants their information used for direct marketing, you should put their details onto a suppression or 'do not contact' list instead of deleting them, so you can check against the list and not use their information for direct marketing by mistake in future.
There is no form of words people must use to object; they can object verbally as well as in writing, and this might be directed to any part of your organisation, so the ICO says you should have a process in place to recognise and deal with direct marketing objections.
If someone has objected to your direct marketing, you cannot contact them at a later date to ask if they have changed their mind, because that contact would still be for the direct marketing purposes they objected to.
The ICO says that while you must comply with an objection, this does not automatically mean you need to delete the person's information, and that in most cases it is preferable to suppress their details.
People can object at any time, including straight away or before you have used their information for direct marketing.
The ICO says people have a legal right to object to their information being used for direct marketing, that you must stop using it if they object, and that there are no reasons you can use to refuse their objection.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary regulator text, single voice
Every load-carrying statement here is quoted from the ICO's own published guidance, which is as close to the source of truth as UK direct-marketing rules get — nothing is second-hand. What holds the number below the high 80s is that there is no second reading of it: the excerpt in front of us breaks off mid-sentence exactly where the guidance begins explaining how an opt-out differs from an objection, and that distinction matters for anyone deciding what to suppress.
No implementation signal
Nothing in this reporting shows anyone doing this. There is no count of organisations running suppression lists, no complaint or enforcement data, no vendor or product detail — only the rule. Guessing at uptake from the existence of guidance would be inventing a number.
One carve-out sanded off
The framing is close to honest restatement — the tooling headache really does follow from the regulator's own preference for suppression. The small overshoot is in the flat 'you cannot contact them again' reading: the ICO permits a preference reminder as a minor, incidental addition to a message sent for another purpose, and that softening did not survive into the summary.
The enforcer explains itself
No commercial interest is in play — the ICO is not selling a suppression product and has no reason to inflate the story. But it is the only voice here and it is also the body that would investigate you, so its interpretation of the law arrives with the authority of the referee and no counterparty to argue the edges.
Right about the rule, silent on the practice
Treat the compliance requirements as reliable: they come straight from the authority that sets them. Treat any claim about how systems behave today as untested — one publisher, no practitioner corroboration, and a truncated passage at the opt-out distinction keep this short of high confidence.