Definition
An email consent log is a record that documents how and when a subscriber gave permission to receive email marketing, including the source, timestamp, and the specific consent language shown. It is the evidence an organization keeps to demonstrate that it obtained lawful consent for each address on its list. Under privacy laws such as the GDPR, this proof is essential to justify processing subscriber data.
How It Works
When a person signs up for email, the organization captures more than just the address. The consent log records details such as the date and time of signup, the form or page where consent was given, the IP address in some cases, and the exact wording of the consent statement presented at that moment. This allows the organization to reconstruct, for any subscriber, what they agreed to and when.
The log matters because email consent must be demonstrable. If a subscriber or regulator questions whether consent was valid, the organization must be able to show the record. Without a log, the organization may be unable to prove lawful basis, exposing it to penalties. Consent logs are therefore a core part of a compliant data strategy.
Best Practices
- Capture the source, timestamp, and consent text for every signup.
- Store the log securely and keep it unchanged over time.
- Link consent records to the specific email address they apply to.
- Update the log when consent is withdrawn.
- Retain records according to a documented retention policy.
Example
A newsletter uses a signup form stating, "I agree to receive weekly updates and offers. I can unsubscribe at any time." When a visitor submits the form, the platform records the email address, the timestamp, the form URL, and the exact consent text shown. Later, if the subscriber questions the subscription, the organization can produce this record to demonstrate valid email consent.
Was this useful?
Related Glossary Terms
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
Australia Spam Act 2003
The Australian Spam Act 2003 bans unsolicited commercial email, requiring consent, accurate sender information and a clear, working unsubscribe facility on every message.
Brazil LGPD Email Marketing
Brazil's LGPD regulates personal data use for marketing, requiring a legal basis such as consent or legitimate interest, plus transparency and clear opt-out in email campaigns.
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Canada CASL Guide
CASL (Canada's Anti-Spam Legislation) requires express or implied consent, clear identification, and a functioning unsubscribe mechanism before sending commercial electronic messages to Canada.
Frequently Asked Questions
At minimum, the source, timestamp, and the consent language shown at signup, and ideally a link to the applicable privacy policy.
To demonstrate lawful consent when challenged, which is a requirement under GDPR compliance and similar laws.
Retention should follow a documented policy, typically as long as processing continues and for a period afterward, consistent with documented retention practices.