Compliance

Email Consent Records: What to Store and How to Audit Them

If someone asks how a contact joined your list, can you answer in thirty seconds? Here is what a solid email consent record contains and how agencies and small businesses keep them audit-ready.

By SaaSVisionary Team · · 6 min read

Illustration for the article: Email Consent Records: What to Store and How to Audit Them

A subscriber replies to your newsletter: “I never signed up for this. Where did you get my email?” If the honest answer is “we’re not sure, it was on a spreadsheet from a trade show,” you have a problem that goes beyond one annoyed reader.

Consent records are the paper trail behind every marketing email you send. They protect you in a complaint, help keep your sending reputation healthy, and make it easy to honor people’s choices. For agencies running email for several clients, they also keep one client’s list from bleeding into another’s.

This article explains what to capture, where to store it, how unsubscribes fit in and how to audit a list you’ve inherited.

What the rules actually require

Rules differ a lot by country, which is why a clear record matters wherever you operate.

  • United States (CAN-SPAM): The law doesn’t require prior opt-in for commercial email. It does require accurate headers, a non-deceptive subject line, a valid physical postal address, a clear way to opt out, and honoring opt-outs within 10 business days. The FTC’s compliance guide at ftc.gov is the primary reference.
  • European Union (GDPR and ePrivacy rules): Marketing email to individuals generally needs freely given, specific, informed consent, and you must be able to demonstrate it. Guidance from the European Data Protection Board covers what valid consent looks like.
  • Canada (CASL): Generally requires express or implied consent and keeps specific record-keeping expectations.

Beyond the law, mailbox providers set their own bar. Gmail and Yahoo expect bulk senders to authenticate their domains, offer one-click unsubscribe and keep complaint rates low. Even where opt-in isn’t legally required, mailing people who never asked is a fast route to the spam folder.

This is general information, not legal advice. Check the rules for each country your contacts live in.

Store consent on the contact record itself, not in a separate file nobody can find. At minimum:

Field Example Why it matters
Consent status Subscribed / unsubscribed / pending confirmation Controls who can be mailed
Channel Email Keeps email and SMS consent separate
Date and time 2026-03-14 10:42 UTC Proves when it happened
Source “Spring guide download form” Answers “where did you get my email?”
Method Web form, double opt-in, in-person, phone Shows how strong the consent is
Wording shown “Yes, send me monthly tips and offers from Tidewater Kayak Tours” Proves what they agreed to
Brand or business Tidewater Kayak Tours Essential for agencies with many clients
Confirmation Double opt-in link clicked at 10:47 UTC Stronger evidence where required
IP address or staff ID Form submission IP, or the employee who recorded it Supports the record
Unsubscribe date Blank or date Proves you honored the request

You don’t need every field for every contact, but source, date, method and wording should always be present for anyone added after you set up the process.

On web forms

  • Use an unchecked checkbox for marketing consent. Pre-ticked boxes don’t count as consent under GDPR.
  • Name the business and the type of email: “monthly tips and offers,” not “updates.”
  • Keep marketing consent separate from terms of service. Agreeing to one shouldn’t force the other.
  • Save the form name and the exact wording at the time of submission.

Double opt-in or single opt-in?

Double opt-in sends a confirmation email that the person must click. It proves the address is real and that its owner agreed. It costs some signups but produces cleaner lists. Consider it for high-volume public forms, giveaways, and any audience in countries with strict consent rules. Single opt-in can be reasonable for warm leads, like a customer who asks for your newsletter during a purchase.

At events or on calls, record who collected it, when, and what was said. A shared sign-up tablet with a proper form is better than a clipboard you type in later.

Unsubscribes and suppression

An opt-out must stick. The most common failure is not the unsubscribe link itself but what happens afterward:

  1. Honor it everywhere. An unsubscribe should cover every marketing list for that brand, not just one newsletter.
  2. Keep a suppression list. Store unsubscribed addresses so a future import can’t quietly re-add them.
  3. Don’t make people log in or answer a survey to unsubscribe.
  4. Offer one-click unsubscribe in the email header for bulk sends.
  5. Process quickly. Aim for immediate removal, well inside legal deadlines.

Special considerations for agencies

Agencies that run email for clients carry extra risk because data from different brands sits in one system.

  • One workspace or account per client. Never mix client contact lists.
  • Consent is brand-specific. Agreeing to hear from a pizza shop isn’t consent to hear from its sister bakery unless the form said so.
  • Get the client’s consent evidence at onboarding. Ask where each list came from and how people opted in. If they can’t say, don’t mail it yet.
  • Document who owns the list. Usually the client does. Your role is to process it properly.

An invented four-person agency, Lantern & Lark Marketing, added a short consent questionnaire to its onboarding. New clients must name each list’s source and share their form wording before the first send. Lists without clear sources go into a re-permission campaign first.

Auditing an existing list

Inherited or older lists often have gaps. Here’s an audit process:

  • Export all contacts with their source, date and consent fields
  • Flag records with no source or no date
  • Check that every unsubscribed contact is also on the suppression list
  • Look for purchased or scraped lists and stop mailing them
  • Separate contacts in strict-consent countries and confirm their consent is documented
  • Run a re-permission email to contacts without clear records, and suppress non-responders
  • Record the audit date and the result

Repeat at least once a year, and whenever you take on a new client or import a new list.

Where your tools help

The easiest consent records are the ones captured automatically. With lead forms and a custom CRM in SaaSVisionary, form submissions can write source, date and consent wording into custom fields on the contact, and workflows can tag or suppress contacts automatically. Email sends through your own Mailgun or Resend account and verified domains. If you also send outreach, our cold email page covers keeping that separate from your opted-in marketing.

Frequently asked questions

No. CAN-SPAM is an opt-out law. It requires truthful headers and subject lines, a physical postal address, a working unsubscribe method and honoring opt-outs within 10 business days. However, laws in the EU, UK and Canada are stricter, and mailbox providers reward permission-based lists, so opt-in is still the practical standard.

Keep them as long as you email the contact, and for a reasonable period after they unsubscribe so you can prove when consent ended and keep them suppressed. Under GDPR, don’t keep personal data longer than needed. Many businesses define a retention period in their privacy policy and apply it consistently.

Is double opt-in legally required?

Usually not by law, though some countries and regulators strongly favor it. Double opt-in is valuable because it proves the address owner agreed and keeps typos and fake addresses off your list. It’s a good default for public signup forms and audiences in regions with strict consent rules.

Can I email a list a client bought?

It’s risky and usually a bad idea. Purchased lists rarely include valid consent for your client’s brand, often contain spam traps and can damage domain reputation fast. In many countries it may also break consent laws. Instead, build a list through forms and offers, or run a careful re-permission campaign.

Want consent captured automatically on every form? Start a free 14-day trial.

#email consent records#email opt-in#can-spam#gdpr consent#unsubscribe management
SaaSVisionary logo mark

Put every lead, call and payment in one place

Try the plan you choose free for 14 days. Switch plans or cancel any time from your billing settings.

  • 14-day free trial
  • No contract
  • Unlimited contacts
Open in new tab ↗

Loading…