From 3.4% to 73.8% | plus France's June 19 deadline, three new US state laws, and Europe's biggest audit yet. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
dataships-logo-banner-colour (2)

Hey there,

 

France just handed subscription brands a homework deadline (June 19), three more US states quietly went live with their own privacy laws while Connecticut tightens the threshold further, Europe's 25 regulators kicked off their biggest coordinated transparency audit to date.

 

Also, Bella Freud just took their UK email opt-in from 3.4% to 73.8%, which is the kind of number worth a look.

 

💙 Matt

 

Bella Freud

🇬🇧 Bella Freud 21X'd Their Email Opt-In. Their GDPR Setup Didn't Change.

Bella Freud's UK checkout was capturing 3.4% of shoppers as email subscribers. It now captures 73.8%, and nothing about their legal basis changed.

 

Most UK brands have accepted sub-10% checkout opt-in as the post-GDPR reality. That number is Shopify's default experience, not what UK law actually permits.

 

Soft opt-in under UK GDPR has a much higher practical ceiling. Most brands just never get near it.

 

Dataships replaces the static default with dynamic consent optimization. Dataships picks the highest-converting compliant interface for each UK shopper, operates within soft opt-in and ICO guidance, and logs every interaction to the audit trail.

 

For Bella Freud, that shift produced:

→ A 21X lift in email MCR (3.4% → 73.8%)

→ 823 new marketing subscribers

→ 41% more repeat orders from those subscribers → $80K in incremental LTV

 

If your UK opt-in rate is sitting under 50%, your ceiling is your interface, not the regulation.

👉 See Your Consent Ceiling
France update

 🇫🇷 France's New Withdrawal Rule Hits Online Subscriptions June 19

France is extending its consumer protection rules again. Starting June 19, 2026, every online business selling into France must provide a clearly labelled, free withdrawal function directly on their website - giving consumers a simple way to exercise their 14-day right of withdrawal on any distance contract.

 

A "distance contract" is the EU legal term for a sale concluded without the buyer and seller being physically present together: which covers basically all ecommerce purchases.

 

This applies to product subscriptions and distance contracts, not marketing consent.

 

This builds on France's existing “3-clicks to cancel” law from 2023, which already required subscription brands to make cancellation as easy as sign-up. The new rule, transposing EU Directive 2023/2673, goes further: it now covers the right of withdrawal specifically, not just ongoing contract cancellation.

 

The function must be permanently accessible, clearly labelled, and work even for guest shoppers, no account required. Non-compliance carries penalties up to €75,000.

 

Worth noting: this is an EU directive. France is transposing it first, but the requirement applies across the bloc. If you're selling into Europe, this is the direction of travel.

👉 Read the Directive

Connecticut

🇺🇸 Three New US Privacy Laws Are Live And Connecticut Is Tightening

2026 started with three new comprehensive state privacy laws taking effect: Indiana, Kentucky, and Rhode Island - all live as of January 1st. That brings the total to 19 US states with active consumer privacy legislation.

 

But the shift worth watching is Connecticut. Starting July 1, 2026, the threshold for compliance drops from 100,000 to just 35,000 consumers. That pulls significantly more mid-market and growing DTC brands into scope. Colorado is also removing its cure period - meaning businesses will no longer get a grace window to fix violations before penalties apply.

 

The pattern is clear: state-level privacy enforcement in the US is accelerating, not levelling off. The thresholds are dropping, the scope is widening, and the timeline for compliance is shortening.

 

If you're unsure whether your consent setup covers the states you're selling into, it may be worth checking.

 

👉 Review Your Consent Setup

EU

🇪🇺 25 European Regulators Are Now Auditing Consent Transparency

On March 19, the European Data Protection Board launched its 2026 Coordinated Enforcement Framework (CEF) and the focus is transparency. 25 Data Protection Authorities across Europe are simultaneously auditing how businesses handle privacy notices and consent disclosures under Articles 12–14 of the GDPR.

This isn't a future risk. It's happening now, across multiple jurisdictions at once.

The audits target how clearly businesses inform users about data collection: what's being collected, why, and on what legal basis. For ecommerce brands operating in the EU, this means your checkout consent language, cookie notices, and privacy disclosures are all in scope.

This is the EDPB's most coordinated enforcement push to date. It signals that transparency is far from being optional, and it's now becoming more routinely checked.

If you haven't reviewed your consent language recently, this is a good reason to.

 

👉 More Info

Dataships, NovaUCD, Stillorgan Rd, Belfield, Dublin, Ireland D04, Ireland

Unsubscribe Manage preferences