Consent records: the six fields you must be able to produce

A boolean column in your CRM is not a consent record. The minimum schema that survives a Board query.

If the Data Protection Board asks about one individual, you have to produce what they agreed to and when. Almost every Indian marketing stack stores a true or false flag, which answers none of that.

The six fields

  • Data principal identifier, stable across systems
  • Timestamp with timezone, at the moment of the affirmative action
  • Source: the exact form, page URL or offline collection point
  • Purpose consented to, one record per purpose rather than a list in one row
  • Notice version identifier shown at that moment
  • Status and status-change history, including withdrawal timestamp

Why one row per purpose

If someone consents to service messages but not promotions, a single row cannot represent that without encoding a list, and lists are where audits fall apart. One row per purpose keeps the record answerable.

Where to store it

Not only in your email platform. Providers get switched, and consent history living inside a vendor is history you can lose during migration. Keep the authoritative record in a system you control and sync outward.

The test to run this week

Pick five people from your list at random. For each, produce all six fields. The proportion you complete is your actual position. Most first attempts land well under half.

Where records are missing, a re-permission campaign is the remedy. It costs list size and buys defensibility, which is the trade the deadline is forcing anyway.

General information, not legal advice. Rules current as of July 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *