INNOVATION

GDPR-Compliant Klaviyo Flows: Which Triggers Need Consent (and the Abandoned-Cart Question)

You have built the retention stack: a welcome series, browse abandonment, an abandoned-cart sequence, a winback. In Klaviyo they are all just flows, triggered by behavior, ready to send. To an EU or UK contact, they are not all equal. One constraint sits upstream of every one of them and decides which are even allowed...

Last updated: 22 Jul 2026

GDPR-Compliant Klaviyo Flows_ Which Triggers Need Consent (and the Abandoned-Cart Question)

CONTENTS

You have built the retention stack: a welcome series, browse abandonment, an abandoned-cart sequence, a winback. In Klaviyo they are all just flows, triggered by behavior, ready to send. To an EU or UK contact, they are not all equal. One constraint sits upstream of every one of them and decides which are even allowed to fire: whether you have a lawful basis to send it.

This piece maps the common Klaviyo flows to the basis each one relies on, so you can see at a glance which are cleared to send to European contacts, which need explicit marketing consent first, and which sit in the one genuinely debated middle ground. A note before that map, because it matters here more than usual: this is operational guidance, not legal advice. The lawful basis for a given flow depends on your specific circumstances, and the right people to confirm it are your DPO or legal counsel.

The constraint that decides everything: lawful basis

Under GDPR, you cannot send a marketing message to an EU or UK contact without a lawful basis for it, and for most marketing flows that basis is consent. This is the constraint the whole retention stack has to be built around, not a compliance step bolted on after the flows are live. Consent under GDPR has to be freely given, specific, and informed, which in practice means a real opt-in the contact chose, recorded with what they agreed to and when.

Treating consent as the gate rather than a checkbox changes the order of work. Klaviyo’s own guidance on collecting GDPR-compliant consent is built around exactly this: a documented opt-in, granular where it needs to be, and flow filters that keep non-consented European contacts out of anything that qualifies as marketing. The flows do not decide who they reach. The lawful basis does, and the flow is configured to respect it.

What the constraint rules out

The constraint rules out sending your marketing flows to European contacts who never opted in. A profile that landed in Klaviyo because someone checked out, entered a giveaway, or was imported from another system is not, on its own, a marketing contact. Klaviyo marks these as “never subscribed,” and while such a profile is technically able to receive a flow email because it is not suppressed, sending it a marketing sequence is the exposure this whole exercise exists to close.

Concretely, the flows that read as marketing are the ones this rules out for non-consented EU and UK contacts: the welcome series, browse abandonment, winback and re-engagement, post-purchase cross-sell and replenishment campaigns, and any broadcast campaign. Each of these is promotional in purpose, so each one needs the contact to have given marketing consent before it sends. That does not mean deleting the flows. It means filtering them so European contacts without consent do not enter, which is a build step, covered further down.

the flow-by-flow map

The flows that still work, mapped to their basis

Not everything needs marketing consent, and knowing which is which is what keeps a compliant setup from quietly switching off half your automation. Three categories cover almost every flow, and the practical rule is to sort each flow into one before you turn it on for Europe.

FlowUsual basisEU/UK rule of thumb
Order confirmation, shipping updates, password reset, account noticesTransactional (contract)Send without marketing consent; keep it strictly service content
Abandoned checkout / abandoned cartDebated (legitimate interest, see below)The one genuine grey area; resolve deliberately
Welcome series, browse abandonment, winback, cross-sell, campaignsMarketing (consent)Send only to contacts who gave marketing consent

The transactional row is the clean one. A message that helps a customer complete or manage a purchase they initiated (their order confirmation, a shipping notice, a password reset) rests on your contract with them, not on marketing consent, so it can send. The discipline is keeping those messages genuinely transactional: the moment an order confirmation grows a “you might also like” block, part of it becomes marketing, and the clean basis gets muddier. Keep service messages to service content and the row stays clean.

The marketing row is the one most teams underestimate, because browse abandonment and winback feel like automation rather than advertising. Under GDPR they are marketing: they exist to bring someone back and sell to them. For European contacts, they belong behind a consent filter with the rest of the campaigns.

the abandoned-cart question

The abandoned-cart question, and the ePrivacy layer most guides skip

The abandoned-cart flow is the one that does not sort cleanly, and it is worth being honest that the answer is genuinely unsettled rather than pretending otherwise. Klaviyo’s own GDPR FAQ puts it plainly: the position is not entirely clear, but many organizations take the view that an abandoned-cart email can be sent under legitimate interest, treating it as a communication relevant to a transaction the shopper themselves started. Browse abandonment and winback, by contrast, it treats as needing prior marketing consent. The reason abandoned cart is arguable and browse abandonment is not comes down to intent: a filled cart is a clearer signal of an in-progress transaction than a viewed product page.

Two nuances decide how much weight that argument can carry. The first is a distinction most flow setups blur: abandoned checkout versus abandoned cart. If the shopper reached checkout and entered their email themselves, the message is closer to helping them finish a transaction they were actively completing. If the email was captured some other way and they only added to a cart, the legitimate-interest footing is weaker. The second nuance is the layer many discussions leave out entirely. GDPR’s Article 6 is not the only law in play: electronic direct marketing is also governed by the ePrivacy rules (PECR in the UK), which generally look for consent for marketing emails and are not satisfied simply by a legitimate-interest basis under GDPR. A soft opt-in can apply for existing customers in some circumstances, but the point is that clearing the GDPR question does not automatically clear the ePrivacy one, and this varies by jurisdiction.

Where that leaves a careful team is with a process rather than a verdict. If you intend to rely on legitimate interest for abandoned cart, the expected step is a Legitimate Interest Assessment: name the interest, show the email is necessary to it, and balance it against the shopper’s rights and expectations. Klaviyo also notes that the strength of the basis depends on specifics like how many emails you send and how long after abandonment, so a single, prompt, genuinely cart-focused reminder rests on far firmer ground than a five-part sequence a week later. The conservative default, if you would rather not carry the ambiguity, is to require consent for abandoned cart too and lean on your consented segment. Either way, this is the flow to put in front of your DPO or counsel by name.

building it in Klaviyo

Building the constraint into Klaviyo

Once each flow is sorted, the build is mechanical, and it lives in two places: a segment and a filter. Create a segment that identifies your EU and UK contacts, and for every non-transactional flow, add a flow filter that only lets through people who have given the relevant marketing consent or who fall outside the EU and UK. That single filter pattern is what keeps welcome, browse abandonment, winback, and campaigns from reaching non-consented European contacts, and Klaviyo’s consent documentation walks through the exact conditions.

From there you have a design choice for the grey-area and edge cases. You can exclude non-consented EU contacts from a flow entirely, or you can use a conditional split to send them a different, lighter message: less marketing language, focused on the item and the transaction rather than the promotion. For an abandoned-cart flow relying on legitimate interest, that second path is often the more defensible one, because the content itself stays close to the transactional intent the basis depends on. Whichever you choose, keep the consent records Klaviyo stores (what the contact agreed to, and when), because the ability to show consent is as much a part of compliance as collecting it. Building the consented segment cleanly in the first place is the same discipline that underpins deliverability and lifecycle work generally, which is why it belongs in the Klaviyo data and flow architecture rather than being patched on per flow.

Frequently asked questions

Do abandoned cart emails need consent under GDPR? 

The position is genuinely debated. Many organizations, and Klaviyo’s own guidance, take the view that an abandoned-cart email can rest on legitimate interest as a communication relevant to a transaction the shopper started, provided it is prompt and limited. But the ePrivacy rules (PECR in the UK) may still expect consent for marketing emails, and the strength of the basis depends on timing and frequency. Confirm the approach with your legal counsel.

What’s the difference between abandoned cart and abandoned checkout for consent? 

Whether the shopper entered their email themselves. At abandoned checkout, the contact typically provided their address while actively completing a purchase, which strengthens a transactional or legitimate-interest reading. An abandoned cart where the email was captured another way is a weaker basis, because the signal of an in-progress transaction is less direct. The distinction is worth building into how you scope the flow.

Do transactional emails need marketing consent? 

No. Order confirmations, shipping updates, password resets, and similar service messages rest on your contract with the customer, not on marketing consent, so they can send to EU and UK contacts. The condition is that they stay genuinely transactional. Adding promotional blocks turns part of the message into marketing and undermines the clean basis.

How do I stop EU contacts from entering a marketing flow in Klaviyo? 

Build a segment that identifies EU and UK contacts, then add a flow filter to each non-transactional flow that only admits contacts who have given marketing consent or who are outside the EU and UK. As an alternative to excluding them, a conditional split can route non-consented European contacts to a lighter, transaction-focused message where a lawful basis supports it.

Key takeaways

  • Lawful basis, not the trigger, decides which Klaviyo flows may reach an EU or UK contact. Build the stack around consent rather than adding it afterward.
  • Transactional flows (order, shipping, password) can send without marketing consent, as long as they stay strictly service content.
  • Welcome, browse abandonment, winback, cross-sell, and campaigns are marketing, and need explicit consent for European contacts.
  • Abandoned cart is the one real grey area. Legitimate interest is arguable, the abandoned-checkout version is stronger, and the ePrivacy layer means clearing GDPR does not automatically clear the consent question.
  • If relying on legitimate interest, run a Legitimate Interest Assessment and keep the flow prompt and limited. The conservative default is to require consent here too.
  • Implement with an EU/UK segment plus a consent flow filter, keep consent records, and put the abandoned-cart basis in front of your DPO or counsel.

THINKING

How to calculate the Total Cost of Ownership (TCO) for your eCommerce store

Running a successful eCommerce business requires more than just a great product and marketing strategy. Understanding the Total Cost of Ownership (TCO) is crucial for making informed decisions about your platform, tools, and long-term scalability. Whether you’re on Shopify, Magento, or another platform, calculating your TCO can help you uncover hidden costs and optimize your...

Why 'More Ad Spend' Stopped Being a Growth Strategy for DTC Brands

Why ‘More Ad Spend’ Stopped Being a Growth Strategy for DTC Brands

For most of the last decade, a direct-to-consumer brand could grow by spending more. Put another dollar into acquisition, get more than a dollar back, repeat. That loop has quietly broken, and the reason is arithmetic rather than fashion: acquisition costs have climbed while the margin that has to absorb them has shrunk, so the...

Traffic up, revenue flat_ how to find where your store actually leaks conversion

Traffic up, revenue flat: how to find where your store actually leaks conversion

When traffic is up and revenue is flat, the money is leaking somewhere between the click and the payment, and the usual reflex, blame the ads and buy more traffic, sends good money after a leak it cannot reach. Revenue is traffic multiplied by conversion rate multiplied by average order value, so if traffic rose...

Shopify Specialist, Creative Studio or Full-Service Commerce Agency

Shopify Specialist, Creative Studio or Full-Service Commerce Agency: Which Model Fits Your Team?

The Shopify specialist vs full-service ecommerce agency decision is not a contest between depth and breadth. It is a question of dependencies. Choose a specialist when the assignment is narrow and your team can coordinate the surrounding work. Choose a creative studio for brand-led experience. Choose full-service when several commerce workstreams must move as one....

The Shopify Agency Shortlist Scorecard (100-Point Tool)

The Shopify Agency Shortlist Scorecard: Compare Technical Fit, Delivery Risk and Growth Support

A polished pitch can make Shopify agencies sound equally capable while concealing different teams, assumptions, and operating models. A Shopify agency shortlist scorecard turns that ambiguity into a 100-point comparison of technical fit, delivery risk, and growth support. It combines weighted criteria with pass/fail gates so presentation quality cannot compensate for a capability gap. Copy...

Project Handover or Long-Term Partner_ Choosing a Shopify Post-Launch Model

Project Handover or Long-Term Partner? Choosing a Shopify Post-Launch Model Before You Sign

Choose a Shopify agency post-launch support model by assigning each operational workstream to the team with the right capability, capacity, and accountability. A complete handover works for capable internal teams. A retained partner suits continuing specialist demand. A hybrid model divides ownership. Define that model before signing, not in the final week before launch. The...

12 Questions to Ask a Shopify Agency Before You Approve Discovery

12 Questions to Ask a Shopify Agency Before You Approve Discovery

The most useful questions to ask a Shopify agency test whether discovery will produce a decision, not merely start a relationship. Before approval, confirm the business outcome, unknowns, participants, deliverables, ownership, price, and exit options. A credible discovery proposal should show how each unresolved question becomes evidence your team can act on. Discovery is often...

How Evaluate Shopify Agency Case Study

How to Read a Shopify Agency Case Study: Evidence, Gaps and Questions to Ask

How to evaluate Shopify agency case study? A Shopify agency case study should help you judge whether an agency can handle a project like yours. Evaluate it through six signals: project comparability, agency attribution, measurement context, independent verification, delivery insight, and recency. A polished result matters less than a clear evidence chain connecting the starting...

How to Compare Shopify Agency Proposals Without Letting Price Decide

How to Compare Shopify Agency Proposals Without Letting Price Decide Everything

To compare Shopify agency proposals fairly, normalize each response into the same scope, ownership, risk, and commercial structure before comparing totals. Mark every requirement as included, excluded, optional, assumed, or unclear. Then score delivery confidence and fit alongside total commercial exposure. Price matters, but only after you know what each price buys. Three proposals can...

What 'Enterprise-Ready' Actually Means in a Shopify Agency

What ‘Enterprise-Ready’ Actually Means in a Shopify Agency

The most important enterprise Shopify agency requirements concern control, not prestige. An enterprise-ready partner can change a revenue-critical commerce operation without losing control of dependencies. The test is whether it can govern architecture, data, decisions, releases, operational continuity, and post-launch ownership across multiple teams and connected systems. Enterprise language is easy to borrow. Shopify Plus...

Best Shopify Agency in the Netherlands_ A Decision Framework for Finding the Right Fit

Best Shopify Agency in the Netherlands? A Decision Framework for Finding the Right Fit

Search for the best Shopify agency in the Netherlands and you will find rankings, partner tiers, portfolios, and polished claims. The right agency is the one whose verified experience, delivery model, technical scope, and post-launch ownership match your project. That answer changes with your platform, integrations, markets, team, and commercial model. Once three proposals land...