Store consent source and date properly: Keep contact details, time with timezone, and exact wording used; Record the sender, channel, and marketing purpose at the time of consent; Note any later changes, withdrawals or new permissions with their own timestamps
Image: Automation Marketing Lab

Consent Approvals

Part of Consent-aware marketing automation under Australian law

Storing the source and date of a marketing permission

Record who gave marketing permission, when, how and for what scope, while preserving later changes and withdrawals.

Store enough evidence to show who permitted what, how and when. A timestamp beside consent = yes cannot show which sender, channel or purpose the person understood, or whether a later withdrawal changed the decision.

Capture the event

For express permission, retain the contact reference, address or channel identifier, collection route, time with timezone, wording shown, affirmative action and organisation covered. For a form, keep its wording or version and the field that captured the choice. For permission given by phone or in person, record the method and the authorised person or process that captured it.

The extra fields below make that evidence usable. They are a proposed record design, not a statutory field list.

Field / What to preserve

Person and address
Stable contact reference and the address or number covered
Scope
Sender, channel and marketing purpose
Source
Particular form and version, conversation or other verified route
Event time
Recorded time and timezone
Evidence
Wording and affirmative action, or facts supporting an inference
Later state
Each withdrawal, correction or later permission with its own time

Keep source and scope together

A source label such as “website” cannot distinguish a newsletter choice from a file request. Preserve the particular form or conversation and the wording in force then, rather than pointing only to a page that may change.

Do not turn a purchase or enquiry into an express permission event. If an organisation assesses consent as inferred, record the relationship, relevant product or service, reason for the expectation, assessment date and reviewer. Label the assessment as inference, not as a ticked box.

Record the scope and timing of any permission relied on. Where APP 7 applies, a person may also request the source of the personal information used for direct marketing, subject to a stated exception.

The information source and the permission event are different records.

Preserve changes

Record a new event when a person changes a preference, withdraws or later gives permission with a different scope. Calculate the current operational state from the relevant events and exclusions. Do not overwrite a withdrawal with an imported yes merely because the import is newer.

For a migrated list, label what is actually known. A list name and import date do not establish when each person agreed. Hold records whose evidence cannot support the proposed use, and investigate their source. Do not invent a consent date from the migration time.

To assess the record design, try reconstructing the basis for a proposed message at a particular time for an express permission, an inferred-consent assessment and a later withdrawal. If the wording, scope or subsequent change cannot be identified, the record is not yet sufficient to approve that send.

More from Consent Approvals

Consent Approvals

Propagating suppression changes across marketing tools

Track suppression updates through every sending tool, reconcile failures and prevent stale syncs from restoring eligibility.