Can an abandoned cart follow-up legally skip the opt-in checkbox and unsubscribe link? In the vast majority of cases, no. The criterion that separates a transactional email from commercial prospecting comes down to who initiated the request: a transactional message executes an operation the person themselves started, while an abandoned cart follow-up tries to trigger a purchase that never happened. Yet many merchants still label their e-commerce scenario “transactional” to skip consent, until the day campaigns end up in spam without anything on the emailing SaaS dashboard flashing red.
The deciding criterion: the operation requested by the person
The CNIL (the French data protection authority) distinguishes the two regimes with a principle it restated in a fact sheet updated on June 10, 2026. This principle rests on a single question: was the message requested by the customer or by the merchant? Answering that question is enough to place any e-commerce scenario on one side of the line or the other.
Commercial prospecting refers to sending messages meant to promote, directly or indirectly, a company’s products, services, or image. So-called “transactional” communications are necessary to manage or fulfill a contract or service requested by the person. (CNIL, Electronic communications to prospects and customers: which rules apply?, updated June 10, 2026)
This principle applies just as much to an order confirmation as to a password reset email. Both respond to an action the recipient has just taken voluntarily, without any operation requested by the merchant itself.
Who requested what in an abandoned cart scenario?
Adding an item to a cart, or closing a browser tab, isn’t a request the customer makes to the merchant. A customer adds a pair of shoes to their cart, closes the tab, and never comes back. The merchant schedules an email 4 hours later, then a second one the next day with a discount code. The scenario exists because the merchant wants to win back a sale that’s slipping away, exactly what the CNIL classifies as commercial prospecting. An order confirmation, a password reset email, or an invoice, on the other hand, respond to an explicit action: clicking “pay,” clicking “forgot password.”

Consent and unsubscribing: what the law actually requires
For a prospect who has never bought anything, sending a cart follow-up requires prior consent, collected via an opt-in checkbox when the address is gathered. The CNIL allows an exception for a customer who has already made a purchase: products similar to their earlier purchase, information given at the time of collection, and a simple, free opt-out available at any time. This exemption, set out in Article L34-5 of the French Postal and Electronic Communications Code and known as soft opt-in, requires a sale to have already taken place; an account created without a purchase falls outside its scope, no matter how many fields were filled in at signup. Some providers invoke legitimate interest to follow up with a visitor without consent. That same Article L34-5 requires prior consent for any message sent to an individual. A GDPR legal basis doesn’t override this special rule: only messages sent to a professional address, related to the recipient’s role, fall under the simple right to object. Deciding who falls under the exception is a matter of email segmentation before it’s a matter of copywriting. The unsubscribe link, meanwhile, remains mandatory on a cart follow-up just as on any newsletter. An easy unsubscribe always costs less than a complaint.
The technical flow matters as much as the message
Classifying a cart follow-up as marketing isn’t enough if it’s sent from the same shared IP pool as invoices and order confirmations. A poorly isolated scenario drags its complaint rate and deferrals onto the reputation of the transactional email flow, the same one that carries forgotten passwords. Mailbox provider feedback loops penalize the entire IP without distinguishing good intent from a bad flow. Invoice deliverability drops right along with follow-up deliverability. List hygiene needs to happen before sending, on the sample feeding the scenario; bounces that come back three days later arrive too late to protect the IP’s reputation. The mechanics of automated scenarios, Klaviyo chief among them, deserve a detour through e-commerce marketing automation.
What if payment failed along the way?
Take a customer who makes it all the way to payment and whose card gets declined by the bank. Their cart stays technically “abandoned,” but they’ve already committed to the purchase, and the follow-up starts to resemble a transactional message. This person filled out the payment form, clicked “confirm,” and watched the transaction fail for a reason outside their control. The CNIL’s criterion, the operation requested by the person, seems to apply differently here: the message completes a transaction already underway, much like an unpaid invoice reminder, which stays transactional rather than marketing.
No CNIL ruling settles this exact case in black and white, so generalizing this reading to every payment retry scenario would be premature. The reasoning relies on the general criterion of an operation already underway, applied by analogy to a situation the doctrine hasn’t directly addressed yet. Payment platforms themselves seem to lean this way for subscriptions and invoices: Stripe and PayPal each offer automatic follow-ups on failed payments, presented to merchants as transaction-related notifications rather than prospecting campaigns. Neither one follows up on a one-time payment that failed at checkout, which leaves that case to the merchant’s judgment. A failed-payment follow-up email that slips in a discount code or a sales pitch immediately shifts into prospecting; Trusted Shops cites the example of an order confirmation paired with a promotional offer, which then changes nature in the eyes of the law.
The cost of ignoring the distinction
A reclassification as unlawful prospecting exposes a company to GDPR penalties of up to โฌ20 million or 4% of annual revenue, to which Trusted Shops adds the formal notices issued by the CNIL on this front. The open rate of a transactional email frequently exceeds 70%, still according to Trusted Shops. A flow that mixes invoices with marketing follow-ups eventually loses that trust, with a complaint rate that climbs across the entire infrastructure, invoices included. Campaigner recommends, in its June 2026 analysis, removing a contact from the cart sequence as soon as they’ve bought; letting a scenario keep running on someone who just paid sends that customer the clearest possible signal: their purchase history was never read.
Clicking “add to cart” has never counted as a signature.
