Skip to main content
email·digit

How to keep email consent records you can defend

Keep consent as a history of events, not as a single yes/no field. Each time someone agrees or withdraws, record when it happened, how they agreed, and who recorded it, and never overwrite the earlier entries. Email Digit keeps a timestamped consent trail for every contact and will not record an opt-in without a source.

Why a checkbox is not a record

Sooner or later someone asks “when did I agree to this?”. It might be the recipient, a mailbox provider looking into a complaint, or a regulator. A field that says consent = true answers none of the follow-up questions: since when, through which form, recorded by whom, and did they ever say no in between?

A single field also loses information every time it changes. If someone opted in, opted out and opted in again, the field shows only the last state. The opt-out, which may be the most important event, is gone.

Laws differ by country and this is not legal advice, but a record that can answer the usual questions has these parts:

PartWhy it matters
TimestampShows consent existed before you emailed them
ActionOpt-in or opt-out, kept as separate events
SourceHow they agreed: a signup form, a purchase, an event
Who recorded itAccountability inside your team
LanguageWhether they agreed in a language they could read
Jurisdiction and basisWhich rules the consent was measured against

Two habits make the record trustworthy. Add rows rather than editing them, so the history is complete. And make the source a choice from a short list rather than free text, because “signup form” is answerable a year later in a way that “see Dan’s note” is not.

  • Every change is a row. Each opt-in and opt-out adds a timestamped entry to the contact’s consent trail, with the channel, the source and, where you supply it, the language consent was given in. For contacts brought in by import, the row also records the jurisdiction (taken from the contact’s phone country when there is one, otherwise marked as stated by you) and the lawful basis.
  • Rows are added, not overwritten. A later opt-out does not erase the opt-in before it, so the trail shows the whole sequence, not only today’s state.
  • Every change has a name. The same change is written to the workspace audit log with the teammate who made it.
  • The source is required. Marking a contact as consented asks how they agreed: signup form, purchase, event, existing customer or other. Without an answer, it does not save. The same applies to re-subscribing someone who had unsubscribed: it needs a new opt-in with a source.

Imports carry their own statement

A CSV import is where consent most often goes missing, so Email Digit treats it as a statement. An import is refused until you say how the people on it agreed to hear from you. The import records who made that statement, the file name and an optional note, and every contact it creates links back to it. Months later, “where did this person come from?” has an answer.

Imports also respect what came before. Anyone on your do-not-send list who appears in a new file is brought in as unsubscribed and never made sendable, and the import result counts them separately, so re-importing an old export cannot quietly bring back people who opted out.

When an old list has no record at all

Most teams discover the gap when they move tools: a spreadsheet of addresses and no idea how half of them got there. Three options, from safest to least safe:

  1. Send only to the part you can account for. Customers who bought, people who signed up through a form you can name. Record that source when you import them.
  2. Ask the rest once. One plain email asking whether they want to keep hearing from you, to the addresses you can justify contacting at all, and keep only those who say yes.
  3. Leave the remainder out. An address you cannot explain is a complaint waiting to happen, and a complaint costs more than the address is worth.

Limits you should know

  • Consent is stated, not verified. Email Digit records what you tell it, with a source and a name attached. It cannot check that a signup really happened.
  • Erasure removes the trail. If you erase a contact under GDPR, their consent trail is deleted with their other details. Their address is first added to your do-not-send list for all mail, so they cannot be imported and emailed again.
  • It does not decide what the law requires. Whether a source counts as valid consent where your recipients live is a question for your own legal advice.

For what to do with contacts who no longer respond, read Stop paying for contacts who never engage.

Share this guideShare on XShare on LinkedIn