FieldRegister
Every field · Contact details

Email address

An email address is a direct identifier and the key to most CRM records. Marketing use needs consent or a soft opt-in and an opt-out.

personal data
personal data?
standard
sensitivity
needs a basis
AI use
contract, or consent for marketing use
lawful basis usually relied on

Keep it how long

With the relationship; marketing use ends on opt-out.

The gap we see most

Personal (webmail) addresses treated the same as work addresses for marketing.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Direct identifiers (name, email, phone) GDPR Art.6 · GDPR Art.13 · GDPR Art.30 · ISO/IEC 27701:2019 7.2.8
GDPR Art.6 Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exerci...

Evidence an auditor accepts: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task
GDPR Art.13 Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis...

Evidence an auditor accepts: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule
GDPR Art.30 Records of processing activities

Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the ca...

Evidence an auditor accepts: The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists; Version history showing when each entry was last reviewed and by whom; Reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well
ISO/IEC 27701:2019 7.2.8 Records related to processing PII

The organization must determine and securely maintain the records that support its obligations for processing, typically an inventory of processing activities covering the type of processing, its purposes, the categories of personal data and of individuals including any special cases such as childre...

Evidence an auditor accepts: Processing inventory carrying each required element; Named owner accountable for its accuracy and completeness; Evidence the inventory is maintained through change, not rebuilt for audits
Contact details used for marketing GDPR Art.6 · GDPR Art.7 · GDPR Art.21 · CCPA/CPRA §1798.120 · ISO/IEC 27701:2019 7.2.4
GDPR Art.6 Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exerci...

Evidence an auditor accepts: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task
GDPR Art.7 Conditions for consent

Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain ...

Evidence an auditor accepts: Consent records capturing who consented, when, to what wording, and through what mechanism; The consent wording and interface as presented, versioned, so an old record can be tied to what was actually shown; The withdrawal mechanism, with evidence it works and takes no more steps than giving consent did
GDPR Art.21 Right to object

Where processing is based on the performance of a public interest task, official authority or legitimate interests, including profiling on those bases, the data subject may object at any time on grounds relating to their particular situation, and processing must stop unless the controller demonstrat...

Evidence an auditor accepts: Objection records that distinguish direct marketing objections, which are absolute, from Article 21(1) objections, which are balanced; The compelling legitimate grounds analysis for every Article 21(1) objection that was refused; Evidence the right to object was presented clearly and separately at first communication, such as the template or screen as sent
CCPA/CPRA §1798.120 Right to Opt Out of Sale or Sharing of Personal Information

Consumers have the right, at any time, to direct a business that sells or shares PI about the consumer to third parties to stop selling or sharing the consumer's PI. Businesses that sell or share PI of consumers under 16 must obtain opt-in consent (parent/guardian if under 13). Once a consumer opts ...

Evidence an auditor accepts: Do Not Sell or Share My Personal Information mechanism; Age verification and opt-in records for minors; 12-month re-solicitation cooldown tracking
ISO/IEC 27701:2019 7.2.4 Obtain and record consent

The organization must obtain and record consent according to its documented process, recording it so that on request it can produce the details of the consent given, including when it was given, the identity of the individual and the consent statement itself, having first provided the information re...

Evidence an auditor accepts: Consent records holding timestamp, individual identity and the exact statement consented to; The version of the information presented before consent, retained alongside; Evidence consent was freely given, meaning a real alternative existed

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Vehicle registration or VIN · Phone or mobile number