Definition
Consent provenance is the documented origin of a subscriber's email consent — how and where the consent was first given, from which source or campaign it came, and through which mechanism it was captured. Consent versioning is the practice of recording which specific wording and version of a consent statement a subscriber accepted.
Together, provenance and versioning make consent evidence complete and auditable. Because regulators expect the sender to demonstrate consent, showing exactly how and to what a subscriber agreed is far stronger than a bare flag that consent exists.
Provenance vs Versioning
| Factor | Provenance | Versioning |
|---|---|---|
| Focus | Where and how consent originated | Which wording was accepted |
| Question answered | "How did this date come about?" | "What exactly did they agree to?" |
| Recorded detail | Source, mechanism, campaign, date | Version number, wording, effective dates |
Both are usually captured together so every consent record links to its full origin and wording.
Why Provenance Matters
- Source attribution: Shows whether consent came from a form, a checkout or a partner.
- Basis verification: Confirms the mechanism was a genuine opt-in rather than a grey area.
- Audit defence: Gives a clear, reconstructable path for how consent was gathered.
- Regulatory confidence: Demonstrates the sender knew how and why each subscriber opted in.
Why Versioning Matters
- Wording drift: If consent text changes over time, only the wording at acceptance proves what was agreed.
- Preference changes: Varying consent versions may capture different notification choices.
- Accurate records: Ties each subscriber to the exact statement they saw.
- Sound audits: Allows a regulator to see precisely what each person consented to.
How to Capture Provenance and Versioning
- Log the source and mechanism: Record the form, campaign and device that captured consent.
- Store the accepted version: Snapshot the consent wording and its version number with each opt-in.
- Keep an effective-dates log: Document when each consent version was live.
- Link everything to the subscriber: Associate provenance and version data with the consent record.
Related Glossary Terms
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Cold Email
A cold email is an unsolicited message sent to a recipient who has not previously opted in, commonly used for B2B outreach, sales prospecting and networking.
Consent Banner
A consent banner is an on-site notice that informs visitors about data collection and allows them to agree to or manage email marketing preferences.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Frequently Asked Questions
Consent provenance is the documented origin of a subscriber's consent — the source, mechanism and campaign through which they first opted in. It shows exactly how and where consent was captured, making it auditable.
Consent versioning records which specific wording and version of a consent statement a subscriber accepted. Because consent text can change, storing the exact accepted version supports stronger and more accurate evidence.
Because the burden of proving consent sits with the sender. Showing the full origin of consent — the mechanism, source and circumstances — is far more defensible than a bare record that a subscriber opted in.
Snapshot the consent wording and version number with each opt-in, keep a log of when each version was active, and link that version to the subscriber's consent record so you always know what they actually agreed to.