An email consent audit checks whether your records support sending this particular campaign to these particular people. Start with the proposed audience, trace each collection source back to its evidence, remove people who have opted out, and keep uncertain records out of the send while you investigate. A label saying “subscribed” is a starting point, not the whole answer.
For a small business, the useful outcome is a documented decision: who is ready for this campaign, who needs review and who must be excluded. You do not need an elaborate dashboard to make that decision. You need evidence you can retrieve and recipient rules that work in your actual sending system.
This guide provides a practical review method, not legal advice or a compliance certificate. It uses UK guidance checked on 18 September 2026; other jurisdictions and particular circumstances may require different treatment. For the wider setup, see the beginner’s guide to email marketing.
Define the campaign before auditing the list
Write a one-paragraph description of what you intend to send. Name the sending business, the email’s subject matter, the selected audience and the sending system. Include any partner promotion or change from the usual newsletter. Without that scope, an audit can end with a reassuring spreadsheet that answers the wrong question.
For example, “our monthly studio newsletter” and “a partner’s software promotion” are different proposed uses. A record reviewed for one should not automatically be approved for the other. Likewise, someone’s presence in a customer database does not tell the reviewer why that person is in the marketing audience.
Keep two questions separate: what permits this type of email, and what permits the associated use of personal information. The ICO explains the relationship between PECR and data protection rules. A lawful basis for processing personal data does not cancel a PECR consent requirement.
The ICO’s detailed electronic-mail rules distinguish individual and corporate subscribers, consent and limited soft opt-ins. Do not record an exception as consent someone never gave. If you rely on an exception, identify it and have the responsible person check all its conditions. Unclear subscriber types or cross-border audiences belong in review, not an assumption based on the address ending.
Date context matters: the ICO updated its detailed guidance on 28 April 2026 to include the charitable-purposes soft opt-in. That is not blanket permission for an ordinary business campaign. Some older brief guidance remains marked as under review, so use the current detailed source when resolving an exception.
Collect evidence without creating another uncontrolled database
Begin with a saved audience selection or a restricted working export, then note its creation time. List the routes by which those records arrived: current signup form, retired form, event sheet, checkout or a previous email provider. Grouping by source and collection period often makes missing evidence easier to find.
Use internal record identifiers in the audit worksheet where possible. Keep contact details in the approved system and link to evidence stored with appropriate access controls. A shared audit file should not become a new copy of your entire customer database.
The ICO’s consent-record guidance calls for evidence of who agreed, when, how, what they were told and whether they withdrew. Historical form wording matters: today’s improved signup page does not prove what someone saw last year.
Build the review around these fields:
- Record and source: internal ID, collection route and source-system reference.
- Evidence reference: where the event record and relevant form or script version can be retrieved.
- Campaign fit: which sender, channel and subject matter the review covers.
- Current restrictions: withdrawal, objection, preference or operational exclusion affecting this send.
- Decision: ready, hold or suppressed, with a specific reason.
- Accountability: reviewer, review time, next action and its owner.
Keep the distinction between source facts and your assessment. “Form version unavailable” is an observed gap. “Probably subscribed through the website” is a guess. Put the gap in the record and assign someone to investigate it; do not convert the guess into a new consent event.
Use three working decisions, not one vague consent flag
These are practical audit labels, not statutory categories. They help the person preparing the campaign understand what to do next.
Ready for this campaign
The reviewer can retrieve the relevant evidence, explain why it covers the intended message and confirm that the current exclusion checks do not rule the record out. Record the scope of that decision. “Ready for September studio newsletter” is more useful than “approved forever”.
Hold for review
There is a missing document, conflicting status, uncertain scope or unresolved rule. Exclude the record from this campaign while the named owner investigates. A hold is not proof that the person never consented; it means the current review has not established readiness.
Do not automatically send a “please consent” email to fix the gap. Asking someone to agree to future marketing can itself be direct marketing. Check whether you are permitted to send the request before choosing that route. An internal evidence search or a fresh choice made when someone independently returns to your site is different from emailing an uncertain list.
Suppressed from the relevant marketing
The person has opted out or objected, or another established exclusion applies. Keep withdrawal-based restrictions distinguishable from deliverability exclusions so nobody mistakes fixing an address for restoring marketing permission.
The ICO’s guidance on respecting preferences recommends keeping the minimum information needed to prevent future marketing by mistake. Simply deleting an opt-out from one list can allow a later import to bring it back. Do not contact someone who objected just to ask whether they have changed their mind.

A useful review therefore has two separate outputs: evidence decisions and enforced audience exclusions. Finishing the first without testing the second leaves a gap between the audit and the actual send.
A worked example: six records, three different next steps
Imagine a fictional design studio preparing its monthly tips email. The following six records are invented to demonstrate the method; they are not a sample from a real campaign or a claim about typical list quality.
- Record A: the current form event links to the matching newsletter wording, and no restriction appears. The reviewer marks it ready for the scoped newsletter.
- Record B: an old import contains “subscribed”, but the original collection route is unknown. It stays on hold while the owner checks the migration archive.
- Record C: the original opt-in is documented, but a later unsubscribe appears in another system. It is suppressed from the newsletter; the older positive flag does not win.
- Record D: a form version exists, but the subscriber’s event does not identify which version was used. It stays on hold until the evidence can be linked reliably.
- Record E: the record is already excluded after a permanent delivery failure. It remains operationally excluded; that label is kept separate from a withdrawal.
- Record F: the relevant newsletter evidence is retrievable and the current preference matches this campaign. It is marked ready, subject to the final sending-system checks.
The working result is two ready records, two holds and two exclusions. That arithmetic is a reconciliation aid, not a legal conclusion. The important part is that each non-ready record has a reason and that the sender can reproduce the same selection.
Suppose the owner later finds Record B’s original form and event. The reviewer checks them, records the new evidence and makes a fresh decision. They do not overwrite the historical import date with today’s date or quietly change every record from the same file to ready.
If the studio changes the campaign to promote an unrelated partner offer, it reopens the scope review. It does not reuse the newsletter decision just because the email addresses have not changed. This is the practical difference between collecting addresses and maintaining the relationship described in the truth about building an email list.
Test the exclusions in the system that will send
Do this with addresses you control and an approved test process, not by experimenting on subscribers. A worksheet cannot reveal whether an integration will overwrite an unsubscribe or whether an automation uses a different audience from a broadcast.
Create a small test set representing a ready record, a review hold and a marketing opt-out. Use the platform’s supported audience preview or test mode to inspect who would receive the campaign. A tool’s “test email” feature may bypass normal recipient selection, so receiving a design preview does not prove that suppression works.
Check the routes your business actually uses:
- A normal broadcast excludes the hold and opt-out test records.
- A permitted test import does not silently reactivate an opted-out address.
- Relevant automations and connected systems retain the same restrictions.
- The unsubscribe route is usable, and the resulting status reaches the system that controls sending.
Record the observed result, the system and the test time. If an exclusion fails, pause the affected send and identify which rule or integration is responsible. Re-test the same path after a scoped repair. Avoid a broad database cleanup when a single import setting is the actual cause.
Keep this audit separate from ordinary campaign checks such as broken links, incorrect dates and reply handling. Both matter, but a correct consent decision does not make an inaccurate email ready to send. The context-first approach to email advice is useful here: test the claim that matters instead of trusting a familiar checklist label.
Save a short campaign sign-off
Before scheduling, rebuild or refresh the audience against the latest preferences. Save the selection rules and record counts from that same version. If the list changes after review, reconcile the changes before sending; do not compare a morning export with an unrelated evening audience.
This compact template gives the next reviewer enough context to understand the decision:
Campaign and sender:
Message scope:
Audience selection and snapshot time:
Evidence sources and versions:
Ready count:
Hold count and reason references:
Excluded count and restriction types:
Exclusion tests and observed results:
Reviewer and approval time:
Unresolved actions, owner and review date:
Use counts after deduplication and explain any overlap between restriction types. A contact may have both an unsubscribe and a delivery failure; counting that person twice would make your totals look wrong even if the exclusion is correct.
Keep the sign-off with the approved campaign version. If someone asks why a record was included, the answer should not depend on whoever happens to remember the import.
Make the next audit easier
When a signup form changes, save the previous wording and its effective dates. When you migrate providers, include evidence references and restrictions in the migration plan, then test the resulting selection. When someone reports an unexpected email, trace the exact entry route instead of assuming the current form was responsible.
Set review triggers around meaningful changes: a new collection route, a different sender or message purpose, an import, a provider migration or a detected exclusion failure. A calendar reminder can support that process, but it should not replace checking changes that affect the next send.
Retain evidence and audit files according to your documented retention needs, with restricted access and removal of unnecessary working copies. There is no universal retention period supplied by this template. Ask the person responsible for data protection to resolve the appropriate period and any competing obligations.
Reader Q&A
Is a subscribed flag enough for an email consent audit?
Not by itself. Treat it as a pointer to evidence, then check the collection record, the relevant wording, the intended campaign and any later restriction. If the evidence cannot be retrieved, record the gap instead of guessing.
Should I delete contacts whose evidence is missing?
Keep them out of the affected campaign while the responsible person reviews the gap and the applicable retention rules. Missing evidence, a marketing objection and an obsolete record are different situations; do not apply one automatic deletion rule to all three.
Can I email everyone to ask for consent again?
Do not assume that you can. A request for marketing consent can itself be marketing. Check permission for that request before sending, and do not use it to bypass an existing objection.
Does an email consent audit replace a deliverability check?
No. Consent evidence addresses permission and scope; deliverability checks address whether messages can reach the intended inboxes. A record may pass one review and still be excluded by the other.
Do I need a new spreadsheet for every campaign?
No. You can use an approved system with saved selections, evidence references and an audit history. What matters is being able to reconstruct the decision for the campaign without maintaining unnecessary copies of personal data.
When should I repeat the review?
Revisit it when the collection route, message scope, sender, provider or audience changes, and when a test reveals a problem. Refresh the final audience against current preferences before sending rather than relying on an old snapshot.
Start with one real campaign
Choose the next email you actually intend to send. Define its scope, trace its collection sources, record the unresolved gaps and test the exclusions. The goal is not to make every row green. It is to make the final audience decision understandable, evidence-based and repeatable.


[…] choosing a campaign audience, audit the evidence behind your email consent records. The worked example separates records ready for that campaign from those needing review or […]