FieldRegister
Every field · Consent, preferences and rights

Consent or opt-in record

A consent record is the evidence that marketing is lawful. It must hold what was consented to, when, and how (Art. 7(1)).

personal data
personal data?
standard
sensitivity
usable
AI use
this field IS the evidence of the basis
lawful basis usually relied on

Keep it how long

For as long as the consent is relied on, plus the limitation period (commonly 6 years).

The gap we see most

A checkbox value with no timestamp, no wording version and no source, which does not prove consent.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Consent records GDPR Art.7 · ISO/IEC 27701:2019 7.2.4 · ISO/IEC 27701:2019 7.3.4 · CCPA/CPRA CCR §7100-7102
GDPR Art.7 Conditions for consent

Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain ...

Evidence an auditor accepts: Consent records capturing who consented, when, to what wording, and through what mechanism; The consent wording and interface as presented, versioned, so an old record can be tied to what was actually shown; The withdrawal mechanism, with evidence it works and takes no more steps than giving consent did
ISO/IEC 27701:2019 7.2.4 Obtain and record consent

The organization must obtain and record consent according to its documented process, recording it so that on request it can produce the details of the consent given, including when it was given, the identity of the individual and the consent statement itself, having first provided the information re...

Evidence an auditor accepts: Consent records holding timestamp, individual identity and the exact statement consented to; The version of the information presented before consent, retained alongside; Evidence consent was freely given, meaning a real alternative existed
ISO/IEC 27701:2019 7.3.4 Providing mechanism to modify or withdraw consent

The organization must provide a mechanism for individuals to modify or withdraw consent, inform them of their rights to withdraw at any time, use a withdrawal mechanism consistent with the one used to obtain consent, treat modification as capable of restricting processing including restricting delet...

Evidence an auditor accepts: Withdrawal mechanism on the same channel as consent collection; Withdrawal records held to the same standard as consent records; Evidence of propagation to internal systems and to third parties who received the data
CCPA/CPRA CCR §7100-7102 Recordkeeping Requirements

Businesses must maintain records of consumer requests and the businesses response for at least 24 months. The records must include the date of request, nature of request, manner in which it was made, date and nature of response, basis for any denial. Records shall not be used for any purpose other t...

Evidence an auditor accepts: Centralised request management system retaining records for 24 months; Audit logs of access to request records; Record schema covering required fields

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Date of birth or age · Opt-out, do-not-contact or unsubscribe flag