
Many organisations are confident they have consent to send marketing emails. However, far fewer may be in a position to prove it. That distinction matters.
Under GDPR and the Irish ePrivacy Regulations, obtaining consent is only half the job. One of the questions I regularly help organisations consider as part of our data compliance work is not simply whether they have valid marketing consent, but whether they could actually demonstrate that consent were it ever challenged by a recipient or the Data Protection Commission.
If somebody complains that they never signed up to receive your marketing emails, the important question is not whether they are incorrect, but whether you can show the Data Protection Commission that you got the required consent, and what specifically the user consented to.
The Burden Is on the Organisation
One of the principles that surprises many businesses is that they are expected to demonstrate consent if it is ever challenged. Simply saying “they must have signed up” is unlikely to satisfy a regulator.
Ideally you should be able to show the how, the when and the what. This means how consent was obtained, when it was agreed to, and what they agreed to when opting in to marketing communications. If those records don’t exist, proving consent becomes much more difficult. This is one of the reasons many organisations use a double opt-in process.
While GDPR does not explicitly require double opt-in, double opt-in creates strong evidence that the owner of the email address actively confirmed they wanted to receive marketing emails.
What Evidence Should You Keep?
When advising organisations on marketing compliance, one of the questions I often ask is not “Do you have consent?” but “How are you documenting evidence of consent?”
In most cases, businesses should be able to produce:
- The date and time the person signed up;
- The date they confirmed their subscription, where double opt-in is used;
- The email address used;
- The IP address recorded during the sign-up process, where available;
- The wording that the subscriber agreed to.
The first four pieces of information are often recorded automatically. Whether your sign-up form is provided by your email marketing platform, your website’s form builder, or a CRM, those pieces of information are usually captured as part of the subscription process.
It is the fifth piece of data that is not normally retained.
Keep the Words, Not Just the Data
Marketing evolves. Newsletters change. Privacy notices are updated. Sign-up forms are redesigned. All of that is perfectly normal. However, if someone challenges their consent several years later, today’s sign-up form may not be the one they actually saw.
For that reason, it is good practice to keep copies of the wording used on your sign-up forms and confirmation emails whenever they change.
Even a simple PDF showing the version that was live during a particular period can make it much easier to explain exactly what information was provided when consent was obtained. Without that evidence, organisations may find themselves trying to reconstruct historical records from memory.
A useful exercise is to imagine receiving a letter from the Data Protection Commission. The complaint says the individual never agreed to receive your marketing emails. How would you respond? Could you produce the sign-up record? Could you show the confirmation email? Could you demonstrate exactly what the person was told before they clicked subscribe?
GDPR Compliance Depends on Good Record-Keeping
Many organisations think of consent as a single click on a website. In reality, consent is a process that begins with clear information and ends with good record-keeping. The records you keep today may become some of the most important evidence your organisation has several years from now.

