CJEU Advocate General Says Consent to Unnamed “Partners” Is Not Enough for Marketing Emails

Table of Contents

A common digital marketing practice in Europe may be facing a major legal challenge.

When consumers sign up for a service, enter a sweepstakes, download content or provide their information to a publisher, they are often asked to consent to receiving offers from the company and its “partners.”

CJEU Advocate General Says Consent to Unnamed “Partners” Is Not Enough for Marketing Emails

Those partner relationships can feed enormous marketing ecosystems involving publishers, lead-generation companies, comparison sites, data brokers and advertisers that did not collect the consumer’s information themselves.

According to an opinion issued September 17 by Advocate General Dean Spielmann of the Court of Justice of the European Union, simply agreeing to receive marketing from unidentified “partners” is not enough.

Spielmann’s conclusion in Groupe Canal+ v. CNIL, Case C-317/25, is straightforward: if consumers were not told which company would eventually use their information for direct electronic marketing, the downstream marketer cannot simply inherit the original consent.

It needs new consent.

If the Court of Justice follows that reasoning in its eventual judgment, the case could have significant consequences for third-party data acquisition and European marketing programs built around broad partner consent.

The Case Involved Marketing to Approximately 3.9 Million People

The dispute dates back to a Groupe Canal+ marketing campaign conducted in 2021.

Groupe Canal+ arranged electronic direct marketing to approximately 3.9 million people whose personal data had originally been collected by two internet service providers.

At the time those people provided their information, they had consented to marketing by the ISPs’ “partners.”

The problem was that those partners were not identified.

Groupe Canal+ later relied on that consent when conducting its own electronic marketing.

France’s Commission nationale de l’informatique et des libertés, better known as the CNIL, concluded the consent was not valid for Groupe Canal+ and imposed a €600,000 fine.

The original CNIL enforcement action involved several compliance issues, including electronic marketing, data-subject rights, processor arrangements and security. The dispute now before the Court of Justice focuses specifically on whether the earlier third-party consent could legally support Groupe Canal+’s marketing.

Groupe Canal+ challenged the decision before France’s Conseil d’État, which referred questions to the Court of Justice.

The European court is now being asked to clarify an issue with implications far beyond one French media company.

Can a person consent to marketing by an unidentified category of future companies?

Spielmann’s answer is effectively no.

Consent Has to Be Informed About Who Is Doing the Marketing

The legal analysis rests on a basic GDPR concept.

Consent must be freely given, specific, informed and unambiguous.

That requirement becomes difficult to satisfy if the person does not know which organization will actually use their information.

The Advocate General reasoned that informed consent requires the individual to be able to identify the data controller involved in the subsequent processing.

Agreeing that information can be used by an ISP’s “partners” does not necessarily mean a person knowingly agreed to receive commercial communications from any business that might later fall into that category.

As the Court’s press release explains, where the identity of the company carrying out the marketing was unknown when the original consent was collected, that company must obtain fresh consent before conducting the marketing.

This is an important distinction.

The opinion does not say a business can never collect consent on behalf of another company.

It says the consumer needs enough information to know who those companies actually are.

“Our Partners” May Be Too Vague

The phrase “our partners” appears constantly in online forms.

A typical notice might say:

“I agree to receive offers from Company X and its trusted partners.”

The consumer may have no idea whether that means three companies or 300.

They may not know which industries those companies operate in, where their information will travel or who will eventually contact them.

Spielmann concluded that a generic reference to “partners” is too vague to establish the kind of informed consent necessary for electronic direct marketing.

The Conseil d’État had also asked the Court a secondary question: if identifying a category of recipients could sometimes be sufficient, how precisely would that category need to be defined?

The Advocate General concluded that the Court does not need to answer that question if it accepts his primary reasoning that the marketer itself needs to be identifiable.

But he addressed the issue anyway.

Even if categories were permissible, Spielmann said they would need to be sufficiently precise for a person to reasonably expect that a particular company might contact them.

A label as broad as “partners” would not meet that standard.

This Could Matter Significantly for Data Brokers and Lead Generation

The consequences could extend well beyond telecommunications companies.

Many marketing businesses do not build their prospect lists entirely from customers who interacted directly with them.

Data can originate with:

  • comparison websites;
  • publishers;
  • lead-generation platforms;
  • contest and sweepstakes operators;
  • data brokers;
  • affiliate networks;
  • marketplaces;
  • membership programs; and
  • other companies collecting information on behalf of commercial partners.

The purchaser or recipient may receive an email address along with an assurance that the individual “consented to partner marketing.”

If the Court adopts Spielmann’s interpretation, the receiving company would need to look beyond that assurance.

Was the company specifically identified when the consumer consented?

If not, the inherited consent may not authorize the company to begin sending promotional emails.

That changes third-party data compliance from a contractual question into an evidence question.

Buying a “Consented” List Would Not Automatically Make Marketing Lawful

This is already consistent with the approach the CNIL takes toward purchased customer and prospect databases.

French guidance states that a company acquiring contact information must ensure that valid consent exists before using it for electronic marketing.

If the purchaser was specifically identified when the original organization collected the consent, the purchaser may be able to rely on that consent.

If the original collector did not obtain consent for that specific purchaser, the acquiring company must obtain its own consent before using the information for electronic marketing.

The pending CJEU case could turn that regulatory position into a broader interpretation of EU law binding on national courts dealing with similar issues.

For buyers of marketing data, that makes due diligence considerably more important.

It may no longer be enough for a data vendor to say, “Everyone on this list opted in.”

A buyer may need evidence showing what the individual actually saw, when consent was collected and whether the buyer itself was identified.

The Consent Chain Becomes Critical

Marketers frequently think of consent as a simple binary attribute attached to a record.

marketing_consent = true

But consent is more complicated than that.

A valid consent record should answer questions such as:

  • Who gave the consent?
  • When was it given?
  • Which company collected it?
  • Which controller or controllers were identified?
  • What purpose was described?
  • Which communication channels were covered?
  • What language did the person see?
  • Was the consent affirmative?
  • Has it since been withdrawn?

In third-party marketing, another question becomes critical:

Was the company now trying to use the consent actually within the consent the individual gave?

That cannot necessarily be answered by looking at a generic “yes” field in a CRM.

A List of Named Partners Could Become Much More Important

One practical response is to identify the relevant partners at the point of collection.

The CNIL’s current guidance already recommends transparency when personal information will be transferred for marketing.

For certain partner-sharing scenarios, the regulator recommends giving individuals access to an exhaustive, current list of partners, including their identity and links to their privacy policies.

That approach has obvious operational complications.

Partner ecosystems change constantly.

Companies join and leave affiliate programs.

A publisher may work with different advertisers from one month to the next.

A data broker may have hundreds of customers.

But that commercial flexibility is precisely what creates the transparency problem.

If the collector does not know who will eventually receive and use the data, it becomes difficult for the individual to know what they are agreeing to.

You Cannot Fix the Original Problem With an Unsubscribe Link

Another important part of Spielmann’s opinion concerns the familiar unsubscribe link.

Groupe Canal+ argued, in part, around safeguards available once the individual received the marketing.

The Advocate General rejected the idea that giving recipients an opportunity to unsubscribe after receiving the communication can repair missing prior consent.

The timing is wrong.

Electronic marketing requiring consent needs that consent before the promotional processing occurs.

An unsubscribe link operates after the marketing message has already been delivered.

It gives the recipient control over future messages, but it does not retroactively authorize the first one.

CNIL guidance similarly distinguishes the requirement to have prior B2C electronic-marketing consent from the separate obligation to provide a simple and free way to opt out of future solicitations.

The First Contact Creates an Interesting Compliance Problem

If a downstream company cannot rely on the original consent, how can it obtain new consent from someone whose email address it already received?

The Advocate General’s reasoning leaves room for a company to seek fresh consent, but the communication used to obtain it cannot simply become the prohibited marketing itself.

That distinction matters.

There is a difference between a neutral communication intended to establish whether the individual consents to marketing and an email advertising products while simultaneously asking the recipient to opt in.

CNIL guidance similarly warns that electronic communications intended to obtain consent from prospects should not themselves promote the sender’s brand, products or services.

Companies designing consent-refresh campaigns therefore need to separate the request for permission from the marketing they hope to send after permission is obtained.

The Case Involves Both GDPR and ePrivacy Rules

Although the discussion often gets summarized as a GDPR consent case, the legal framework is broader.

The Advocate General’s opinion addresses Article 13 of the ePrivacy Directive, which regulates unsolicited electronic direct marketing, alongside the GDPR’s definition of consent and its transparency requirements.

The opinion specifically examines GDPR Articles 4(11), 12, 13 and 14 in the context of data originally collected by one organization and subsequently used by another for direct marketing.

This combination is important because electronic advertising sits at the intersection of general personal-data regulation and sector-specific electronic communications rules.

For B2C email marketing in France, the CNIL’s current position remains that individuals generally need to provide consent before receiving electronic advertising, subject to defined exceptions such as marketing similar products to an existing customer.

This Does Not Mean Every Form of Third-Party Marketing Requires the Same Consent

Companies should also avoid overreading the opinion.

The case involves electronic direct marketing to consumers.

Different rules can apply depending on the communication channel, recipient and factual circumstances.

For example, CNIL guidance distinguishes electronic consumer marketing from certain professional B2B communications and from postal marketing.

Legitimate interests and opt-out mechanisms can sometimes play a larger role in those contexts.

The practical lesson is therefore not that every transfer of contact information requires identical named-party consent.

It is that companies need to analyze the actual downstream use.

When the recipient wants to send B2C electronic marketing requiring prior consent, the consent supporting that marketing needs to cover the recipient and the activity with sufficient specificity.

The Risk Falls on the Downstream Marketer Too

Another important point is that the company sending the marketing cannot necessarily outsource the compliance problem to the company that supplied the data.

A marketer might have a contract requiring a lead provider to collect GDPR-compliant consent.

That contract is useful.

It does not automatically establish that valid consent actually exists.

The downstream organization is still acting as a controller for its own marketing activities and needs a lawful basis for what it does.

This makes evidence obtained during vendor diligence important.

Organizations buying leads or receiving partner data should consider reviewing:

  • the original collection form;
  • the precise consent language;
  • screenshots or archived versions of that language;
  • the list of named partners presented to the consumer;
  • the date and timestamp of consent;
  • the source website or application;
  • the specific communication channel authorized;
  • records of withdrawal or objection; and
  • how changes to the partner list are managed.

A contractual warranty is helpful.

An auditable consent record is better.

The Opinion Could Affect Publisher Monetization Models

Publishers and online platforms may face a particularly difficult problem if the Court follows the Advocate General.

Many websites subsidize free services by sharing leads or customer information with commercial partners.

The commercial value often comes from being able to introduce future partners without redesigning the collection process every time.

Generic language such as “selected partners” provides that flexibility.

But flexibility for the publisher can mean uncertainty for the consumer.

If EU law requires people to know the identity of the controller that will eventually market to them, organizations may need more dynamic partner disclosures and stronger records tying each consumer’s consent to the partner list that existed at the time.

That could also complicate resale models where information moves through several intermediaries.

CNIL guidance already states that consent collected by one organization for its partners does not automatically allow those partners to pass the data onward to their own partners. Fresh consent is required for additional downstream transfers and marketing where consent is necessary.

Privacy Teams Should Start Looking at Their Partner Consent Now

The Court of Justice has not yet issued its judgment.

That is important.

An Advocate General provides an independent legal opinion intended to assist the judges. The opinion does not bind the Court.

The judges have now begun deliberations, and a final judgment will be delivered later.

Organizations therefore should not describe Spielmann’s position as a final CJEU ruling.

But companies do not necessarily need to wait for the judgment before examining their practices.

Marketing teams can already ask a few uncomfortable questions.

Do we use email addresses acquired from other companies?

If so, what exactly did those individuals consent to?

Were we identified by name?

Can we prove that?

Are we relying solely on language referring to “partners,” “selected partners” or “trusted third parties”?

Could we reconstruct the consent notice a particular person saw three years ago?

If the answers are unclear, there is already a consent-governance problem regardless of how the Court ultimately rules.

Consent Is Not a Commodity That Can Be Passed Around Indefinitely

The broader significance of Groupe Canal+ is that it challenges a convenient way of thinking about marketing consent.

Consent is sometimes treated like an asset attached to a contact record.

One company collects it.

The record changes hands.

The consent supposedly travels with it.

Spielmann’s opinion treats consent differently.

It belongs to a particular relationship between the individual, the identified controller and the stated purpose.

Change the controller and the original consent may no longer answer the question.

For marketers, publishers and data brokers, that could make the provenance of a lead almost as important as the lead itself.

The question would no longer be:

“Did this person consent to partner offers?”

It would become:

“Did this person knowingly consent to receive marketing from us?”

If the Court of Justice ultimately adopts the Advocate General’s reasoning, those two questions will no longer be interchangeable.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.