Record what somebody agreed to, when, and how, at the moment it happens. A list without that record cannot be defended, and the record cannot be produced retrospectively.

The gap between having consent and showing it

Most small businesses believe their mailing list is fine, and they are frequently right that people did agree.

What they cannot usually do is demonstrate it: when each person agreed, to what specifically, and by what action.

That distinction is invisible until somebody complains or asks, at which point the answer has to already exist, because a record of an event cannot be created afterwards.

This is a general description rather than legal advice. The specific requirements differ by jurisdiction and by what you are doing, and where the stakes are meaningful somebody qualified should look at your position.

What a usable record contains

The third is the one most often missing. Knowing somebody signed up is insufficient if you cannot show what the wording said at the time, particularly if it has since changed.

Keep the wording, not just the tick

The single most useful practice and the least common.

Consent is to something specific, so the record needs to include what that something was.

Which means keeping a dated copy of the signup wording each time it changes, so a record from two years ago can be matched to the text that person actually saw.

A screenshot of the form, saved with the date, in the same folder as your other records, is sufficient and takes a minute whenever the wording is edited.

Businesses that redesign a form and keep no copy of the previous version have quietly lost the ability to describe what half their list agreed to.

Where the records usually are not

A list of common gaps, most of which are ordinary rather than careless.

Addresses typed in from business cards collected at an event.

People added because they enquired once, which is a different thing from agreeing to marketing.

A list imported from a previous system, where the original records did not come across.

Names added by a member of staff who no longer works there, on the basis of a conversation nobody recorded.

And a list bought or received from somebody else, where you hold no record because none was ever made.

Each of those may involve people entirely happy to hear from you, and none of them is evidenced.

Separate consent from a transaction

A distinction that prevents most of the difficulty.

Somebody buying something has given you their address in order to receive the thing. That is not agreement to receive marketing, and treating it as such is where a lot of small businesses drift.

The remedy is a separate, unticked option at the point of purchase, with its own wording, recorded separately.

That produces a smaller list and a defensible one, and the people on it are more likely to want what you send, which shows up in the results.

Where rules in your jurisdiction permit contacting existing customers about similar products without separate agreement, that is worth knowing precisely rather than assuming, since the boundaries are narrower than most people expect.

A worked example

A business with a list of about two thousand tried to establish where each address had come from.

The mailing platform held signup dates for roughly eleven hundred, which was better than expected.

Around four hundred had been imported from an older system with no source information at all.

The remainder had been added manually over years: event contacts, enquirers, and people staff had met.

They kept the eleven hundred, and sent the rest a short message saying they were tidying their records, explaining what they send and how often, and asking people to confirm.

About a fifth confirmed, and the rest were removed.

The list dropped by a third and engagement rose sharply, because what remained were people who had actively said yes twice.

The re-permission message

The practical remedy for a list you cannot evidence, and it needs care.

Keep it short, explain plainly what you send and how often, and ask for a positive action to stay.

Do not send it repeatedly, and do not treat silence as agreement, since that defeats the point of the exercise.

Expect a low response, and treat that as information rather than failure: a list where four in five people will not confirm was not producing much anyway.

Note the date you sent it and keep the wording, since this becomes the record for everybody who responds.

Consent beyond mailing lists

Worth extending, because the same principle applies in places nobody labels as consent.

Publishing a photograph of a customer's property, or of a person, where the agreement was verbal and nobody wrote it down.

Using a testimonial, where the customer said something in an email that was not offered for publication.

Recording calls, where a notice is played and no record is kept of which calls it applied to.

And website tracking, where the record of what somebody chose in a consent banner is held by a tool nobody has checked.

In each case the fix is the same: a note of who, when, and to what, made at the time and kept somewhere findable.

The counter-case

This can be applied disproportionately.

A business with forty customers it knows personally does not need a consent management system, and building one is administration in place of judgement.

There is also a version of this that becomes paralysis, where a business stops contacting anybody because it is unsure, which is a worse outcome than a sensible tidy-up and a clear process going forward.

The proportionate response is to fix the process now so new records are good, deal with the historical list once, and stop worrying about it.

Perfect reconstruction of a decade of informal record keeping is not achievable and is not what anybody expects.

What to do

  1. Check what your platform records for each subscriber.
  2. Identify addresses with no source information.
  3. Save a dated copy of your current signup wording.
  4. Separate marketing consent from purchases, unticked.
  5. Send one re-permission message to the unevidenced.
  6. Remove anybody who does not confirm.
  7. Record who, when, what and how from now on.

Step three costs a minute and is the item that makes every future record meaningful.

Tracking you may have forgotten is covered in the pixel you installed and forgot.


Frequently asked questions

What is the difference between having consent and evidencing it?

Believing somebody agreed is not the same as showing when, to what, and by what action. That record cannot be created afterwards, which is why it matters before anybody asks.

What should a consent record contain?

Who, when, what they agreed to in the wording they saw, how they did it, and what else was happening at the time, such as a purchase.

Why keep the signup wording?

Because consent is to something specific. A record from two years ago is only meaningful if you can show the text that person actually saw, which means keeping dated copies when it changes.

Does buying something count as agreeing to marketing?

No. Somebody gave you their address to receive the thing. Use a separate unticked option at purchase, with its own wording, recorded separately.

What do I do with a list I cannot evidence?

Send one short re-permission message explaining what you send and how often, ask for a positive action, and remove anybody who does not confirm. Do not treat silence as agreement.

Does this apply beyond mailing lists?

Yes. Publishing photographs of a property or person, using a testimonial from an email, call recording, and website tracking all need a note of who, when, and to what.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Sure your list agreed?

Check what your platform actually records for each address. The ones with no source information are the whole question.

Start a Conversation