Definition
Consent evidence records are the stored details that show a subscriber gave valid consent for email marketing. For a compliant, defensible programme these records capture not just that consent happened, but the circumstances: who consented, when, through what mechanism, and to what it actually applied.
Under consent-based law such as the GDPR, the burden is on the sender to demonstrate consent. Without clear evidence, a claimed consent is hard to defend in an audit or a regulator enquiry.
What a Consent Record Should Capture
| Field | Purpose |
|---|---|
| Subscriber identity | Who gave consent (email address / account) |
| Date and time | When consent was given |
| Source and mechanism | Where and how (form, checkbox, in-person) |
| Consent text | What the subscriber agreed to |
| Consent version | Which wording was current at the time |
| Notification preference | What types and frequency were accepted |
Linking each record to the exact wording the subscriber saw is important, because wording changes after the fact can invalidate the evidence.
How to Store Consent Evidence
- Capture at the point of opt-in: Record the consent data automatically when the subscriber consents.
- Snapshot the wording: Store the version of consent text the person actually accepted.
- Keep it retrievable: Store records so they can be produced quickly for a request.
- Preserve a timestamped log: Keep a reliable record of when consent was given and by which method.
- Retain appropriately: Keep records for as long as the list is active and erase when no longer required.
How to Keep Records Audit-Ready
- Review periodically: Confirm records match the current subscription state.
- Link withdrawal: Show clearly when and how a subscriber withdrew consent.
- Test retrieval: Rehearse producing evidence for a sample of subscribers.
- Document the basis: Separate records for consent, soft opt-in and legitimate interest.
Related Glossary Terms
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Cold Email
A cold email is an unsolicited message sent to a recipient who has not previously opted in, commonly used for B2B outreach, sales prospecting and networking.
Consent Banner
A consent banner is an on-site notice that informs visitors about data collection and allows them to agree to or manage email marketing preferences.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Frequently Asked Questions
Consent evidence records are the stored documentation that prove a subscriber consented to email — who gave it, when, through what mechanism, and to what wording. They make a consent claim defensible in an audit or regulator enquiry.
Under consent-based rules like the GDPR, the burden of proving consent sits with the sender. Storing clear, timestamped records that link each subscriber to the consent wording they accepted protects your programme in a compliance check.
Capturing the subscriber identity, the date and mechanism of consent, the exact consent text and version, and the accepted notification preferences. This lets you show precisely what the person agreed to and when.
Keep them for as long as the subscriber remains on the relevant list and is being mailed under that consent, and erase them once they are no longer needed for that purpose, following your data retention policy.