Under GDPR, marketing email to individuals in the EU/UK generally needs an affirmative opt-in (not a pre-checked box, and not mere absence of objection) as the legal basis, along with clear information about what someone is agreeing to and an easy way to withdraw it later.
Transactional and service-related email typically relies on a different legal basis (contract performance or legitimate interest) rather than marketing consent, which is why the transactional/marketing lane distinction also has compliance, not just deliverability, weight.
GDPR consent requirements interact with but don't replace CAN-SPAM-style opt-out obligations; a sender reaching both US and EU/UK recipients generally needs to satisfy both frameworks, not pick whichever is more lenient for a given recipient.