FieldRegister
Every field · Behaviour, engagement and scoring

Email opens and clicks

An open is a pixel firing and a click is a rewritten link; both are behavioural monitoring of a named person and need a notice, and in most regimes consent.

personal data
personal data?
standard
sensitivity
needs a basis
AI use
consent for the tracking pixel and rewritten links, plus a basis for any scoring built on it
lawful basis usually relied on

Keep it how long

Short: 12 months, then aggregate.

The gap we see most

Open and click counts used to score people in a country where the pixel itself needed consent.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Scoring and profiling of people GDPR Art.22 · GDPR Art.13 · GDPR Art.35 · CCPA/CPRA §1798.185(a)(16) · ISO/IEC 27701:2019 7.3.10
GDPR Art.22 Automated individual decision-making, including profiling

Do not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the co...

Evidence an auditor accepts: An inventory of automated decisions with the assessment of whether each produces legal or similarly significant effects; The exception relied on for each in scope decision, and for contract based ones the necessity reasoning rather than a convenience argument; The human intervention process, showing the reviewer has the authority and the information to change the outcome
GDPR Art.13 Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis...

Evidence an auditor accepts: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule
GDPR Art.35 Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operat...

Evidence an auditor accepts: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval
CCPA/CPRA §1798.185(a)(16) Automated Decisionmaking Technology Access and Opt-Out

Consumers have rights regarding businesses use of automated decisionmaking technology (ADMT), including profiling. Businesses must, per CPPA regulations: provide meaningful information about the logic involved and a description of likely outcomes; allow consumers to opt out of certain ADMT uses; and...

Evidence an auditor accepts: ADMT inventory and use-case classification; Pre-use notice describing logic and outcomes; Opt-out and access mechanisms specific to ADMT
ISO/IEC 27701:2019 7.3.10 Automated decision making

The organization must identify and address the obligations, including legal obligations, that it owes to individuals arising from decisions it makes about them based solely on automated processing of their personal data, taking account of jurisdictions that impose specific obligations where such dec...

Evidence an auditor accepts: Inventory of decisions made solely by automated processing, with their effect on individuals assessed; Obligations register per jurisdiction for those decisions; Notification content disclosing the existence and logic of automated decision making
Behavioural tracking synced to the record GDPR Art.6 · GDPR Art.7 · CCPA/CPRA §1798.135(b) · ISO/IEC 27701:2019 7.2.3
GDPR Art.6 Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exerci...

Evidence an auditor accepts: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task
GDPR Art.7 Conditions for consent

Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain ...

Evidence an auditor accepts: Consent records capturing who consented, when, to what wording, and through what mechanism; The consent wording and interface as presented, versioned, so an old record can be tied to what was actually shown; The withdrawal mechanism, with evidence it works and takes no more steps than giving consent did
CCPA/CPRA §1798.135(b) Opt-Out Preference Signals (Global Privacy Control)

A business that sells or shares PI shall process an opt-out preference signal (such as Global Privacy Control) sent with the consumer's consent through a platform, technology, or mechanism, indicating the consumer's intent to opt out of sale or sharing. The signal shall be treated as a valid consume...

Evidence an auditor accepts: GPC/opt-out signal detection logic in web stack; Test evidence showing signal honored across browsers and devices; Suppression flag propagation to adtech vendors
ISO/IEC 27701:2019 7.2.3 Determine when and how consent is to be obtained

The organization must determine and document a process by which it can demonstrate whether, when and how consent to processing was obtained, clearly documenting when consent is needed and what obtaining it requires, correlating purposes with how consent is obtained, and taking into account jurisdict...

Evidence an auditor accepts: Documented consent process covering when consent is required and what valid consent demands; Mapping from each purpose to whether and how consent is obtained; Analysis of jurisdiction specific consent requirements and how the mechanism meets them

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Lead score, propensity or ranking · Website visits, page views, sessions