Why this article exists
Our platform assists sending two very different kinds of messages on behalf of our hotel partners:
transactional messages (booking confirmations, stay reminders, pre-arrival information) and
marketing messages (newsletters, promotional offers, re-engagement campaigns) which are sent through Mailchimp. Mailchimp as a member of the CSA (https://certified-senders.org/wp-content/uploads/2024/02/CSA-High-Level-EN.pdf) 'Certified Senders Alliance' needs to ensure their platform will not be associated with spam.
These two message types are governed by different rules, and it's easy to conflate them. This article explains why, using three markets - the EU (Malta), Malaysia, and Australia - as concrete examples of how differently "consent" can be defined from one country to the next, even when the underlying idea (don't email people without permission) is the same everywhere.
Two different laws, two different questions
A recurring source of confusion is treating "we are GDPR-compliant" (or the local equivalent) as the same thing as "we are allowed to send this newsletter." They are not the same question.
General data protection law (GDPR in the EU, and its equivalents elsewhere) asks: may we process this person's data at all - store it, analyze it, share it with a processor like us? For a hotel booking, the answer is usually yes, on the basis of contract performance or legitimate interest, without needing consent as such.
Marketing/electronic-communications law asks a narrower, separate question: may we send this specific person a specific marketing message through email or SMS? This is the layer that actually gates a Mailchimp send, and in almost every jurisdiction we operate in, it has its own dedicated consent standard - sitting alongside general data protection law, not inside it.
This split is universal, but what each layer requires is not. That's the point of the country examples below: the general data-protection question tends to look similar across our markets (some lawful basis is needed, consent is only one option), while the marketing-consent question varies a lot in how strict it is, and in whether a "soft" version of consent is recognized.
Hard opt-in vs. soft/inferred opt-in
Before the country examples, two terms worth defining precisely, since they mean different things in different laws:
Hard opt-in (express consent): the recipient took a clear, affirmative action specifically to agree to receive marketing - ticking an unticked checkbox, replying "yes," submitting a signup form that clearly says what they're signing up for. This is always valid, everywhere.
Soft opt-in (inferred consent): no separate marketing sign-up happened, but the law allows sending marketing anyway because of the context in which the data was collected - typically an existing purchase/booking relationship, where the recipient was told marketing might follow and is given an easy way to stop it. This is an exception, not a default, and how far it stretches differs sharply by country.
Country examples
European Union — Malta
Two separate instruments apply, and both must be satisfied:
- GDPR (Regulation (EU) 2016/679) - the general data protection layer. Governs whether we may hold and process a guest's data at all. For a booking, contract performance or legitimate interest usually covers this; consent is only one of six possible legal bases and is not automatically required just because data is being stored.
- ePrivacy, as implemented in Malta (Processing of Personal Data (Electronic Communications Sector) Regulations, S.L. 586.01) - the marketing-consent layer. Requires prior, explicit opt-in before sending marketing email: freely given, specific to the marketing purpose, informed, given through a clear affirmative action (no pre-ticked boxes), and revocable at any time.
Hard opt-in example: A guest ticks an unticked "Yes, send me offers and news from this hotel" box during checkout, separate from accepting the privacy policy.
Soft opt-in example (narrow exception): A guest books a room and is told, at that point, that their email may be used to market similar offers from the same hotel. No separate opt-in checkbox is required for that specific case - but every message must carry an easy, free opt-out, and the exception only covers the same hotel's similar offers to that same guest, not new prospects, unrelated products, or third-party sharing.
Malaysia
Here the two layers collapse closer together than in the EU, and the local standard is stricter on the marketing side:
- Personal Data Protection Act 2010 (amended 2024) - the general data protection layer, but unlike GDPR it does not offer a "legitimate interest" alternative. Processing personal data for a given purpose, direct marketing explicitly included, generally requires the individual's consent, recorded in writing or another retrievable form (Personal Data Protection Regulations 2013, Reg. 3).
- Section 43, PDPA - a standalone, opt-out-based safeguard on top of that: regardless of any consent given earlier, a data subject can at any time require an organisation to stop using their data for direct marketing, and marketing must not resume without fresh consent.
Hard opt-in example: A guest is shown a written privacy/marketing notice at booking and explicitly agrees (tick box, form, or recorded confirmation) to receive marketing emails - this is effectively the only reliably compliant path.
Soft opt-in: Malaysia's PDPA does not provide a recognized soft-opt-in / inferred-consent carve-out equivalent to the EU's. Relying on an existing booking relationship alone, without a documented consent step, is legally exposed - the safer default for Malaysian contacts is to treat hard opt-in as mandatory in practice.
Australia
Australia is the clearest example of a jurisdiction where the marketing layer explicitly and commonly permits the soft version:
- Privacy Act 1988 (Australian Privacy Principles) - the general data protection layer. APP 7 covers direct marketing generally, but explicitly does not apply to commercial electronic messages (email/SMS) - those are carved out to the Spam Act instead.
- Spam Act 2003 - the marketing-consent layer for commercial electronic messages specifically. Requires consent before sending, but recognizes two forms: express consent and inferred consent, both valid.
Hard opt-in (express consent) example: A guest fills in a signup form, ticks a box, or confirms verbally that they want to receive marketing emails - documented, with proof of when and how.
Soft opt-in (inferred consent) example - commonly used in this market: A guest booked a room directly with the hotel (so the hotel "knowingly and directly" obtained the address) and would reasonably expect marketing about similar offers from that same hotel as a result - e.g. a returning guest being told about a seasonal room package. Every message still needs accurate sender identification and a working unsubscribe, functional for at least 30 days.
What this means for our Mailchimp campaigns
Regardless of which country a contact is in, the same operating rule applies: a Mailchimp marketing send requires marketing consent, not just a general data-processing basis. Concretely, before any contact is added to a newsletter/marketing audience:
| Requirement | Why |
|---|---|
| A dedicated marketing consent flag, separate from general privacy-notice acceptance | "Accepted our privacy policy" and "agreed to receive marketing" are different things everywhere we operate — a booking alone is never proof of marketing consent. |
| A record of how and when consent was captured (source, timestamp, exact wording) | Every regime above places the burden of proof on the sender, not the recipient. |
| An explicit decision on whether soft/inferred opt-in is being relied on for a given contact, and on what basis | Its availability and scope differ by country (available and common in Australia; narrow in the EU/Malta; not a safe default in Malaysia). |
| A working, immediate unsubscribe on every marketing message | Required in every jurisdiction above, and also a condition of maintaining sender reputation with Mailchimp and CSA-network deliverability standards. |
| No promotion of transactional-only contacts into marketing audiences | A guest who only ever received a booking confirmation has not given marketing consent by that fact alone. |
Transactional sends (booking confirmations, stay-related service messages) are unaffected by any of the above - they don't require marketing consent in any of these jurisdictions, since they're necessary to deliver the service the guest already requested.
A note on scope
This article covers the EU (via Malta), Malaysia, and Australia as illustrative examples of how differently the marketing-consent layer can be shaped from one country to the next. It is not an exhaustive list of markets we operate in, and rules can change. This content is for internal/partner education and does not constitute legal advice - country-specific consent design should be confirmed with local counsel before go-live.
Sources: ACMA — Avoid sending spam · OAIC — Direct marketing guidance · DLA Piper — Electronic marketing in Malta · Donovan & Ho — Direct marketing and PDPA in Malaysia · Edwin Lee & Partners — PDPA-compliant marketing individual rights
Comments
0 comments
Please sign in to leave a comment.