By goal
By industry
View all industriesBy capability
Integrations
All integrationsYour AI agent live in under 1 hour
No code. Trained on your catalog. Converts on every channel.
Start free trial Book a demoThis article was written by Marc Parrish of PieEye and contributed to the Zipchat blog as part of our partnership program. First published: July 28, 2026.

Cart recovery consent rules trip up most merchants because recovery messages count as marketing, not service messages, under GDPR and ePrivacy. That means you need consent, a valid soft opt-in, or a lawful basis before you send one. WhatsApp requires explicit opt-in with no soft opt-in exception. This piece covers the legal test, retention limits, and a compliance checklist.
Recovery emails and WhatsApp nudges recover a meaningful share of abandoned carts. The average documented cart abandonment rate is 70.22%, based on an aggregate of 50 studies from the Baymard Institute (Baymard Institute, 2025). That volume is exactly why regulators pay attention to how recovery messages get consent.
Get the legal basis wrong, and you are not looking at a failed A/B test. You are looking at a Privacy and Electronic Communications Regulations (PECR) or GDPR complaint, a blocked WhatsApp Business account, or a CCPA opt-out violation. All three are common enforcement paths for marketing-by-messaging in 2026.
The legal test is for purpose, not timing. A message sent 45 minutes after abandonment can still be purely transactional, like a payment failure notice. Add a discount, a product recommendation, or a “still interested?” line, and it becomes marketing under the ePrivacy Directive and UK PECR.
This distinction matters because transactional messages need no marketing consent. Marketing messages do. Under UK PECR regulation 22, you cannot send electronic mail marketing to an individual without specific consent, unless a soft opt-in exception applies (ICO, 2024).
Most cart recovery flows blend both message types. The first email might be neutral: “You left something in your cart.” The second adds a coupon code.
That second email is marketing, full stop, regardless of what the first one was. Treat any message with an incentive or a cross-sell line as marketing. Build your consent check around message content, not campaign name.
The soft opt-in is the exception that keeps most cart recovery programs legal without a fresh consent prompt. It applies when a customer already bought, or negotiated to buy, a similar product from you (ICO, 2024).
For a cart abandoner who is also a past customer, the soft opt-in applies only if all three hold:
Miss any one of the three, and you need specific consent instead.
The soft opt-in does not cover first-time visitors who abandoned a cart before ever buying anything. It does not cover contacts from a purchased list or a co-marketing partner. It does not cover non-commercial messages either.
First-time visitors are often the largest share of abandoned carts. For that segment, you need an opt-in checkbox at signup. A retroactive assumption of interest will not hold up.
WhatsApp has no soft opt-in equivalent. Meta’s WhatsApp Business Messaging Policy requires two things before you message someone: their phone number, and a separate opt-in to receive messages from you.
Email marketing law lets a past purchase substitute for consent in narrow cases. WhatsApp’s policy carves out no such exception for existing customers.
Picture a customer who bought from you last month but never opted into WhatsApp messaging. You can legally send them a recovery email under the soft opt-in. You cannot legally send them a WhatsApp cart reminder.
Meta also recommends category-specific opt-in. Get separate permission for order updates versus promotional offers. A merged, vague opt-in raises the odds a customer blocks you after one unwanted message.
Outside a 24-hour window since the customer’s last message, WhatsApp Business Platform rules require an approved Message Template for anything you initiate, cart recovery included. That template needs its own approval, and you can’t edit it freely to add urgency after the fact, which shapes how you set up WhatsApp broadcasts for ecommerce.
California’s rules work differently from GDPR. The CCPA and its CPRA amendments don’t require opt-in consent to send a cart recovery email to an adult shopper. They govern the cart and browsing data behind that email instead, giving consumers the right to know what’s collected and to opt out of its sale or sharing (California Attorney General, 2025).
The email itself falls under the federal CAN-SPAM Act, which requires an opt-out: you need a working unsubscribe link and honest headers, not prior consent (Federal Trade Commission).
Say you pass an abandoner’s email or device ID to an ad platform for off-site retargeting. That transfer usually counts as “sharing” for cross-context behavioral advertising under CPRA. California residents can opt out of that sharing, separate from any consent you already got for the recovery email itself.
A visitor’s browser can send a Global Privacy Control signal. When it does, you must treat that signal as a valid opt-out of sale and sharing, with no separate account-level request needed.
A cart recovery stack that pixels every visitor for retargeting before checking for that signal is the most common CCPA gap in ecommerce today.
GDPR’s storage limitation principle sets the standard: keep personal data “for no longer than is necessary for the purposes for which [it is] processed” (Art. 5(1)(e) GDPR). There is no fixed number of days written into the law.
You set the retention period, document the reasoning, and defend it if asked.
Retention threshold table
| Data type | Reasonable retention | Trigger to delete or anonymize |
|---|---|---|
| Active cart contents | 30-45 days | No return visit or purchase after this window |
| Marketing profile built from abandonment | 12-24 months | Customer unsubscribes, opts out, or goes inactive |
| Completed transaction records | 6-10 years | Set by local tax and accounting law, not by GDPR |
| WhatsApp opt-in and consent logs | Life of the relationship, plus a statute-of-limitations buffer | Needed to prove consent if challenged |
Keep the consent record even after you delete the marketing profile. You need proof of when and how someone opted in, not just proof they eventually unsubscribed.
Run this sequence against your current cart recovery flow:
| Requirement | Email (GDPR/PECR) | |
|---|---|---|
| Consent for new contacts | Opt-in required | Opt-in required |
| Exception for past customers | Soft opt-in available | None |
| Opt-out required in every message | Yes | Yes, plus category-level opt-out |
| Rules outside a defined time window | None specific | Approved Message Template required after 24 hours |
| Regulator/enforcer | ICO, EU data protection authorities | Meta platform enforcement |
Regulators and platforms are narrowing the gap between “technically compliant” and what users experience as respectful. Meta has already pushed WhatsApp’s opt-in guidance toward category-specific permissions instead of one blanket opt-in.
Expect that granularity to spread. More US states are passing CPRA-style laws, and their definitions of “sharing” are likely to tighten around retargeting.
Retention limits will get more scrutiny too. A merchant holding 18 months of abandoned-cart browsing data with no documented reason becomes an easy audit target as more states add CPRA-style audit rights.
The practical shift for merchants: consent management is moving from a one-time checkbox to a tracked system. That system logs consent per channel, per message category, and per data use. Build it now, not after a complaint arrives.
These rules assume you are messaging consumers in the UK, EU, or California. B2B marketing to a corporate email address is generally exempt from PECR’s individual consent rules, though a suppression list is still good practice.
None of this applies if you never use email or WhatsApp for recovery. On-site notifications and browser push fall outside PECR’s electronic mail definition entirely.
If you serve no UK, EU, or California customers, GDPR’s marketing consent rules do not bind you directly. Most global platforms, including WhatsApp, still enforce their own opt-in policy regardless of jurisdiction.
Finally, this article is not legal advice. Consent requirements shift by country and by how a regulator interprets “similar products” or “necessary” retention in a given case. Confirm your specific setup with counsel before relying on any single interpretation here.
Cart recovery messaging is not illegal by default. Most flows accumulate compliance debt one added channel and one added retargeting pixel at a time.
Run the six-step checklist above against your current flow this week. Start with message classification: that single step determines which consent rule applies to everything downstream.
Here is the concrete next step. Pull your last 90 days of cart recovery sends and tag each as transactional or marketing.
Then check that every marketing send maps to a documented consent or soft opt-in record. If you cannot produce that mapping in an afternoon, rebuild your consent tracking before your next campaign, not after a complaint.
Consent tracking is where a platform like PieEye fits in. It automates cookie consent capture, DSAR requests, and PII scanning for ecommerce brands, which is the record-keeping layer this checklist depends on.
Only if the email is marketing rather than purely transactional. A pure payment-failure notice needs no marketing consent. A recovery email with a discount or product recommendation needs specific consent or a valid soft opt-in.
No. The soft opt-in is a PECR and ePrivacy concept for email and text. WhatsApp’s Business Messaging Policy requires a separate, explicit opt-in with no past-customer exception.
GDPR sets no fixed number of days. Set and document a retention period tied to your actual purpose, then delete or anonymize the data once that purpose ends. Typical practice: 30-45 days for active cart contents, up to 24 months for a marketing profile.
No. CCPA and CPRA do not require opt-in consent for the email itself. They do require you to honor opt-outs of “sale” or “sharing,” including automatic Global Privacy Control signals, when abandoner data reaches an ad platform.
Yes. B2B messages to a corporate, non-sole-trader email address are generally exempt. So are recovery channels outside email, text, and WhatsApp, such as on-site or browser push notifications.
Marc Parrish founded PieEye to help e-commerce brands automate GDPR and CCPA compliance, from cookie consent to DSAR automation and PII scanning. He works directly with Shopify and DTC merchants on consent management across marketing, support, and checkout. PieEye's blog publishes ongoing analysis of data privacy law for online merchants. LinkedIn: https://www.linkedin.com/in/marcparrish/
Read more from PieEye at PieEye
Learn how price transparency turns skeptical discount shoppers into confident buyers, with data, a trust framework, and the metric worth tracking.
Compare the best Tidio alternatives for ecommerce. See how AI-first support tools handle the agent-seat wall and pricing cliffs, with picks by store size.
Compare the best ManyChat alternatives for ecommerce. See AI-first tools for WhatsApp and Instagram that go beyond flow-builder bots, with pricing and picks.
Compare the 7 best Gorgias alternatives for Shopify in 2026. See how AI resolution double-billing adds up and the best pick for cross-platform revenue.