Definition
Consent roles and purview in email marketing refer to who is responsible for capturing, storing, managing and proving consent under data protection rules. Regulators distinguish between the controller — the organisation that decides how and why personal data is used — and the processor, which handles data on the controller's behalf, such as an email service provider.
Understanding these roles matters because the controller, not the processor, holds the legal duty for consent in email marketing. Both parties must cooperate to keep records accurate and compliant.
Controllers vs Processors
| Role | Responsibilities | Example |
|---|---|---|
| Controller | Decides the purpose and means; responsible for valid consent | The brand sending email |
| Processor | Handles data on the controller's instructions | ESP, list manager or agency |
| Joint controller | Shares decisions and obligations | Two brands running a campaign together |
The liability for valid consent sits with the controller, even when a processor stores the records.
What Each Role Owns
- The controller decides what consent is needed, what the consent text says and how long records are kept.
- The processor stores the consent records and returns them to the controller, but does not decide consent policy.
- Joint controllers must divide obligations clearly in an arrangement with each other.
Why Roles and Purview Matter
- Accountability: The controller must respond to a subscriber's right to withdraw consent.
- Audit readiness: Records must identify who gave consent, when, and how.
- Vendor management: A contract with the processor must specify consent handling.
- Sub-processors: Permission is needed before passing data to additional processors.
How to Get Roles Right
- Clarify who is the controller: Confirm which organisation determines the purpose of the marketing email.
- Contract processors clearly: Specify consent capture, storage, retention and deletion responsibilities.
- Document joint arrangements: When two brands share consent, define each one's duties in writing.
- Keep consent records accessible: Ensure the controller can retrieve and prove consent on request.
Related Glossary Terms
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Cold Email
A cold email is an unsolicited message sent to a recipient who has not previously opted in, commonly used for B2B outreach, sales prospecting and networking.
Consent Banner
A consent banner is an on-site notice that informs visitors about data collection and allows them to agree to or manage email marketing preferences.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Frequently Asked Questions
The controller is the organisation that decides why and how personal data is used, including how consent for marketing email is captured and managed. The controller holds the legal responsibility for valid consent.
The processor is a service provider that handles personal data on the controller's instructions, such as an email service provider or agency. It stores and manages consent records but does not decide consent policy.
Because the controller, not the processor, is accountable for valid consent. Misunderstanding the roles can leave the wrong party owning liability or consent records and can fail an audit or a data-subject request.
Two controllers running a shared campaign should document who decides consent requirements, who captures and stores records, and how duties such as withdrawal and deletion are divided. This arrangement should be recorded in writing.