Editions Q2 '26 Here all the latest 89 product updates shipped. Learn more
Back to all Posts
Guest Post Marc Parrish , PieEye Last updated: Jul 30, 2026

Is Your Cart Recovery Legal? Cart Recovery Consent Rules for GDPR, CCPA, and WhatsApp

Summarize with:
What you will learn
+37.8% avg. conversion lift

Your AI agent live in under 1 hour

No code. Trained on your catalog. Converts on every channel.

Start free trial Book a demo
Guest contribution

This article was written by Marc Parrish of PieEye and contributed to the Zipchat blog as part of our partnership program. First published: July 28, 2026.

TL;DR

Cart recovery consent rules trip up most merchants because recovery messages count as marketing, not service messages, under GDPR and ePrivacy. That means you need consent, a valid soft opt-in, or a lawful basis before you send one. WhatsApp requires explicit opt-in with no soft opt-in exception. This piece covers the legal test, retention limits, and a compliance checklist.

Recovery emails and WhatsApp nudges recover a meaningful share of abandoned carts. The average documented cart abandonment rate is 70.22%, based on an aggregate of 50 studies from the Baymard Institute (Baymard Institute, 2025). That volume is exactly why regulators pay attention to how recovery messages get consent.

Get the legal basis wrong, and you are not looking at a failed A/B test. You are looking at a Privacy and Electronic Communications Regulations (PECR) or GDPR complaint, a blocked WhatsApp Business account, or a CCPA opt-out violation. All three are common enforcement paths for marketing-by-messaging in 2026.

Recovery Emails Are Marketing, Not Transactional, Under GDPR and ePrivacy

The legal test is for purpose, not timing. A message sent 45 minutes after abandonment can still be purely transactional, like a payment failure notice. Add a discount, a product recommendation, or a “still interested?” line, and it becomes marketing under the ePrivacy Directive and UK PECR.

This distinction matters because transactional messages need no marketing consent. Marketing messages do. Under UK PECR regulation 22, you cannot send electronic mail marketing to an individual without specific consent, unless a soft opt-in exception applies (ICO, 2024).

Why Misclassification Is the Most Common Mistake

Most cart recovery flows blend both message types. The first email might be neutral: “You left something in your cart.” The second adds a coupon code.

That second email is marketing, full stop, regardless of what the first one was. Treat any message with an incentive or a cross-sell line as marketing. Build your consent check around message content, not campaign name.

The soft opt-in is the exception that keeps most cart recovery programs legal without a fresh consent prompt. It applies when a customer already bought, or negotiated to buy, a similar product from you (ICO, 2024).

Three Conditions the Soft Opt-In Requires

For a cart abandoner who is also a past customer, the soft opt-in applies only if all three hold:

  1. The abandoned item is similar to something they already bought from you.
  2. You offered a clear opt-out when you first collected their email address.
  3. Every message since, including this recovery email, has included that opt-out.

Miss any one of the three, and you need specific consent instead.

When the Soft Opt-In Does Not Apply

The soft opt-in does not cover first-time visitors who abandoned a cart before ever buying anything. It does not cover contacts from a purchased list or a co-marketing partner. It does not cover non-commercial messages either.

First-time visitors are often the largest share of abandoned carts. For that segment, you need an opt-in checkbox at signup. A retroactive assumption of interest will not hold up.

WhatsApp Recovery Needs Explicit Opt-In Before the First Message

WhatsApp has no soft opt-in equivalent. Meta’s WhatsApp Business Messaging Policy requires two things before you message someone: their phone number, and a separate opt-in to receive messages from you.

Why WhatsApp’s Rules Are Stricter Than Email

Email marketing law lets a past purchase substitute for consent in narrow cases. WhatsApp’s policy carves out no such exception for existing customers.

Picture a customer who bought from you last month but never opted into WhatsApp messaging. You can legally send them a recovery email under the soft opt-in. You cannot legally send them a WhatsApp cart reminder.

Meta also recommends category-specific opt-in. Get separate permission for order updates versus promotional offers. A merged, vague opt-in raises the odds a customer blocks you after one unwanted message.

The 24-Hour Window and Message Templates

Outside a 24-hour window since the customer’s last message, WhatsApp Business Platform rules require an approved Message Template for anything you initiate, cart recovery included. That template needs its own approval, and you can’t edit it freely to add urgency after the fact, which shapes how you set up WhatsApp broadcasts for ecommerce

CCPA and CPRA Treat Cart Data as Personal Information You Can Sell or Share

California’s rules work differently from GDPR. The CCPA and its CPRA amendments don’t require opt-in consent to send a cart recovery email to an adult shopper. They govern the cart and browsing data behind that email instead, giving consumers the right to know what’s collected and to opt out of its sale or sharing (California Attorney General, 2025). 

The email itself falls under the federal CAN-SPAM Act, which requires an opt-out: you need a working unsubscribe link and honest headers, not prior consent (Federal Trade Commission). 

Opt-Out of Sale/Sharing Applies to Retargeting Cart Abandoners

Say you pass an abandoner’s email or device ID to an ad platform for off-site retargeting. That transfer usually counts as “sharing” for cross-context behavioral advertising under CPRA. California residents can opt out of that sharing, separate from any consent you already got for the recovery email itself.

Global Privacy Control Signals Must Be Honored Automatically

A visitor’s browser can send a Global Privacy Control signal. When it does, you must treat that signal as a valid opt-out of sale and sharing, with no separate account-level request needed.

A cart recovery stack that pixels every visitor for retargeting before checking for that signal is the most common CCPA gap in ecommerce today.

How Long You Can Legally Retain Abandoned Cart Data

GDPR’s storage limitation principle sets the standard: keep personal data “for no longer than is necessary for the purposes for which [it is] processed” (Art. 5(1)(e) GDPR). There is no fixed number of days written into the law.

You set the retention period, document the reasoning, and defend it if asked.

Retention threshold table

Data typeReasonable retentionTrigger to delete or anonymize
Active cart contents30-45 daysNo return visit or purchase after this window
Marketing profile built from abandonment12-24 monthsCustomer unsubscribes, opts out, or goes inactive
Completed transaction records6-10 yearsSet by local tax and accounting law, not by GDPR
WhatsApp opt-in and consent logsLife of the relationship, plus a statute-of-limitations bufferNeeded to prove consent if challenged

Keep the consent record even after you delete the marketing profile. You need proof of when and how someone opted in, not just proof they eventually unsubscribed.

Run this sequence against your current cart recovery flow:

  1. Classify each message in the sequence as transactional or marketing, based on content, not send time.
  2. For every marketing email, confirm you have specific consent or a documented soft opt-in.
  3. For every WhatsApp message, confirm a separate, category-specific opt-in exists before the first send.
  4. Check whether abandoner data feeds a retargeting pixel, and confirm your Global Privacy Control handling covers it.
  5. Set and document a retention window for cart, marketing, and consent data, then automate deletion at that threshold.
  6. Re-run this checklist whenever you add a channel, a discount trigger, or a retargeting partner.
RequirementEmail (GDPR/PECR)WhatsApp
Consent for new contactsOpt-in requiredOpt-in required
Exception for past customersSoft opt-in availableNone
Opt-out required in every messageYesYes, plus category-level opt-out
Rules outside a defined time windowNone specificApproved Message Template required after 24 hours
Regulator/enforcerICO, EU data protection authoritiesMeta platform enforcement

Where Cart Recovery Compliance Is Heading in 2026 and Beyond

Regulators and platforms are narrowing the gap between “technically compliant” and what users experience as respectful. Meta has already pushed WhatsApp’s opt-in guidance toward category-specific permissions instead of one blanket opt-in.

Expect that granularity to spread. More US states are passing CPRA-style laws, and their definitions of “sharing” are likely to tighten around retargeting.

Retention limits will get more scrutiny too. A merchant holding 18 months of abandoned-cart browsing data with no documented reason becomes an easy audit target as more states add CPRA-style audit rights.

The practical shift for merchants: consent management is moving from a one-time checkbox to a tracked system. That system logs consent per channel, per message category, and per data use. Build it now, not after a complaint arrives.

When These Rules Do Not Apply, or Apply Differently

These rules assume you are messaging consumers in the UK, EU, or California. B2B marketing to a corporate email address is generally exempt from PECR’s individual consent rules, though a suppression list is still good practice.

None of this applies if you never use email or WhatsApp for recovery. On-site notifications and browser push fall outside PECR’s electronic mail definition entirely.

If you serve no UK, EU, or California customers, GDPR’s marketing consent rules do not bind you directly. Most global platforms, including WhatsApp, still enforce their own opt-in policy regardless of jurisdiction.

Finally, this article is not legal advice. Consent requirements shift by country and by how a regulator interprets “similar products” or “necessary” retention in a given case. Confirm your specific setup with counsel before relying on any single interpretation here.

Conclusion: Audit Before You Automate

Cart recovery messaging is not illegal by default. Most flows accumulate compliance debt one added channel and one added retargeting pixel at a time.

Run the six-step checklist above against your current flow this week. Start with message classification: that single step determines which consent rule applies to everything downstream.

Here is the concrete next step. Pull your last 90 days of cart recovery sends and tag each as transactional or marketing.

Then check that every marketing send maps to a documented consent or soft opt-in record. If you cannot produce that mapping in an afternoon, rebuild your consent tracking before your next campaign, not after a complaint.

Consent tracking is where a platform like PieEye fits in. It automates cookie consent capture, DSAR requests, and PII scanning for ecommerce brands, which is the record-keeping layer this checklist depends on. 

FAQ

Only if the email is marketing rather than purely transactional. A pure payment-failure notice needs no marketing consent. A recovery email with a discount or product recommendation needs specific consent or a valid soft opt-in.

Can I use the soft opt-in for WhatsApp cart recovery?

No. The soft opt-in is a PECR and ePrivacy concept for email and text. WhatsApp’s Business Messaging Policy requires a separate, explicit opt-in with no past-customer exception.

How long can I legally store abandoned cart data?

GDPR sets no fixed number of days. Set and document a retention period tied to your actual purpose, then delete or anonymize the data once that purpose ends. Typical practice: 30-45 days for active cart contents, up to 24 months for a marketing profile.

No. CCPA and CPRA do not require opt-in consent for the email itself. They do require you to honor opt-outs of “sale” or “sharing,” including automatic Global Privacy Control signals, when abandoner data reaches an ad platform.

Is a cart recovery message ever exempt from these rules entirely?

Yes. B2B messages to a corporate, non-sole-trader email address are generally exempt. So are recovery channels outside email, text, and WhatsApp, such as on-site or browser push notifications.

About the author Marc Parrish PieEye

Marc Parrish founded PieEye to help e-commerce brands automate GDPR and CCPA compliance, from cookie consent to DSAR automation and PII scanning. He works directly with Shopify and DTC merchants on consent management across marketing, support, and checkout. PieEye's blog publishes ongoing analysis of data privacy law for online merchants. LinkedIn: https://www.linkedin.com/in/marcparrish/

Read more from PieEye at PieEye