Is not being creepy sufficient? My understanding is that you need consent to collect literally any PII, e.g. an email address.
This extends to many areas, including e-mail, if they are required to deliver your services you may just save them. However, you may not use the e-mail to send newsletters. Of course, you want to double opt-in e-mails in any case unless you don't mind false or malicious entries and being labeled as a spammer. But that has nothing to do with the GDPR.
* the type of data is of importance when we are talking about data breaches and fines. Losing e-mail addresses is bad, losing prescriptions is much worse.