Definition
Consent roles and purview in email marketing refer to who is responsible for capturing, storing, managing and proving consent under data protection rules. Regulators distinguish between the controller — the organisation that decides how and why personal data is used — and the processor, which handles data on the controller's behalf, such as an email service provider.
Understanding these roles matters because the controller, not the processor, holds the legal duty for consent in email marketing. Both parties must cooperate to keep records accurate and compliant.
Controllers vs Processors
| Role | Responsibilities | Example |
|---|---|---|
| Controller | Decides the purpose and means; responsible for valid consent | The brand sending email |
| Processor | Handles data on the controller's instructions | ESP, list manager or agency |
| Joint controller | Shares decisions and obligations | Two brands running a campaign together |
The liability for valid consent sits with the controller, even when a processor stores the records.
What Each Role Owns
- The controller decides what consent is needed, what the consent text says and how long records are kept.
- The processor stores the consent records and returns them to the controller, but does not decide consent policy.
- Joint controllers must divide obligations clearly in an arrangement with each other.
Why Roles and Purview Matter
- Accountability: The controller must respond to a subscriber's right to withdraw consent.
- Audit readiness: Records must identify who gave consent, when, and how.
- Vendor management: A contract with the processor must specify consent handling.
- Sub-processors: Permission is needed before passing data to additional processors.
How to Get Roles Right
- Clarify who is the controller: Confirm which organisation determines the purpose of the marketing email.
- Contract processors clearly: Specify consent capture, storage, retention and deletion responsibilities.
- Document joint arrangements: When two brands share consent, define each one's duties in writing.
- Keep consent records accessible: Ensure the controller can retrieve and prove consent on request.
Was this useful?
Related Glossary Terms
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
Australia Spam Act 2003
The Australian Spam Act 2003 bans unsolicited commercial email, requiring consent, accurate sender information and a clear, working unsubscribe facility on every message.
Brazil LGPD Email Marketing
Brazil's LGPD regulates personal data use for marketing, requiring a legal basis such as consent or legitimate interest, plus transparency and clear opt-out in email campaigns.
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Canada CASL Guide
CASL (Canada's Anti-Spam Legislation) requires express or implied consent, clear identification, and a functioning unsubscribe mechanism before sending commercial electronic messages to Canada.
Frequently Asked Questions
The controller is the organisation that decides why and how personal data is used, including how consent for marketing email is captured and managed. The controller holds the legal responsibility for valid consent.
The processor is a service provider that handles personal data on the controller's instructions, such as an email service provider or agency. It stores and manages consent records but does not decide consent policy.
Because the controller, not the processor, is accountable for valid consent. Misunderstanding the roles can leave the wrong party owning liability or consent records and can fail an audit or a data-subject request.
Two controllers running a shared campaign should document who decides consent requirements, who captures and stores records, and how duties such as withdrawal and deletion are divided. This arrangement should be recorded in writing.