Is your author mailing list actually legal? A quick audit
· 5 min read
Most authors set up a mailing list, add a reader magnet, and never think about the legal side again. Usually that is fine. Occasionally it is not, and the gaps tend to surface at the worst moment: your emails start landing in spam, a reader complains, or you switch email platforms and discover you cannot show how half your list joined. This is a quick, plain-English audit you can run in ten minutes. It is general guidance, not legal advice, so check the specifics for your situation and jurisdiction.
If any of the checks below make you wince, the good news is that every one of them is straightforward to fix. Start with our plain-English guide to consent for the underlying principles, then use this as your checklist.
The two rule sets that matter
You do not need to memorise the law, but it helps to know which rules apply. Two come up most for authors, and handling both well is simpler than it sounds.
- GDPR covers readers in the UK and the EU. It expects consent that is freely given, specific, and recorded: an unticked box, plain wording, and a record of what each person agreed to and when.
- CAN-SPAM covers email to readers in the United States. It is less strict about opt-in, but every email needs a truthful sender identity and subject line, a real postal address, and a working unsubscribe link that you honour promptly.
A few countries are stricter still, for example Canada's CASL expects clear express consent. You do not need to track where each reader lives. If you collect a clear opt-in, keep a record of it, and make leaving easy, you are covering the essentials for almost everyone.
The audit: eight quick checks
Go through these honestly. Each "no" is a gap worth closing.
- Is your consent box unticked by default? A pre-ticked box does not count as consent under GDPR. The reader has to tick it themselves.
- Does your signup wording say what readers will actually get? "Subscribe" is too vague. "New releases and occasional news, unsubscribe any time" tells people what they agreed to.
- Can readers get the book without being forced onto your list? Making the list optional is friendlier and cleaner. If you do require it, say so clearly at signup. See single vs double opt-in for the trade-offs.
- Do you have a record of each reader's consent? If someone asked "how did I end up on this list?", could you show the wording they agreed to and the date? If not, see how to prove email consent.
- Does every email have a working unsubscribe link? It must be easy to find and it must work. This is non-negotiable under both rule sets.
- Do you honour unsubscribes promptly? Remove people quickly and do not add them back, even to a "different" list.
- Is there a postal address in your emails? CAN-SPAM requires one. A PO box or a service address is fine if you would rather not use your home.
- Are you avoiding importing old, unconsented contacts? Dropping a pile of addresses you gathered years ago into a new list is exactly the sort of thing that harms deliverability and trust.
The most common gaps, and how to fix them
Three problems account for most author mailing list trouble.
- The quiet add. Automatically subscribing everyone who downloads a free book, with no separate opt-in, is the single most common mistake. Fix it by giving readers the book and a separate, clearly worded choice about emails.
- No record of consent. Many authors collect a perfectly good opt-in but keep no proof of it. The fix is to use a tool that records the wording and timestamp for every signup, so the proof exists without you thinking about it.
- The neglected unsubscribe. An unsubscribe link that is buried, broken, or ignored turns a minor issue into a real one. Test yours, and make sure removals happen quickly.
Why this protects you, not just your readers
Compliance sounds like a chore, but every item on the list above also makes your list work better. People who clearly chose to join open more of your emails, which lifts your engagement and keeps you out of spam folders. A clean, consented list reaches inboxes. And if anyone ever questions a signup, a record settles it in seconds. Doing this properly is good marketing, not just good manners.
Frequently asked questions
Do I really need to worry about this as a small author?
The rules apply regardless of list size, but the practical risk is usually about deliverability and trust rather than enforcement. Either way, the fixes are quick and they make your emails perform better, so there is little reason not to.
I think my list has some old, unconsented contacts. What now?
The safest option is to stop emailing the ones you cannot account for, or to send a single re-permission email asking them to opt in again and removing anyone who does not. A smaller list that wants to hear from you is worth more than a large one that does not.
Does using a reader magnet tool make my list compliant automatically?
It makes the essentials much easier, clear consent wording, an unticked box, and a stored record, but you still need to write honest wording, include your address, and honour unsubscribes. Storyfinch handles the consent capture and record for you.
Grow your list with your next book
Give readers a free book and turn them into subscribers, with secure delivery and consent built in.
Create your free accountFree plan · No card required · Set up in minutes