Website representations

An imported mailing list has no reliable permission history

Hold the entire import out of campaign workflows until its provenance is reconstructed. Possessing an address is not evidence of permission to use it, so work segment by segment: identify each record's origin, the notice shown at collection, the recorded choice, and the channel your campaign will use. Records with a documented origin and a matching recorded choice are candidates for the owner to release; records with gaps stay held, not cleaned into circulation. The marketing owner decides releases, with qualified review for the applicable rules and platform terms. Never manufacture a consent record to close a gap.

For: An owner or authorized marketing lead at a research-only merchant who inherited, purchased, or migrated a mailing list whose permission history cannot be established from its records.

Updated 2026-10-01

Quarantine the import before it touches a campaign

The first decision is procedural: no record from this list enters a send, an automation, or an ad-audience upload while its history is unverified. Uploading first and auditing later means uncertain records are already in use, which converts a records problem into a contact problem. Record where the list came from (an acquisition, a previous platform, a supplier handover, a purchase), when it arrived, and who authorized holding it.

Treat the list as several lists until proven otherwise. A single CSV often mixes newsletter signups, past buyers, competition entries, and addresses whose source nobody remembers. The provenance question is per origin segment, not per file, so your first task is segmentation by discoverable source rather than a verdict on the whole.

Reconstruct origin and original notice per segment

For each segment, find the collection mechanism: the form or page, its wording at the time, and the system that stored the result. A previous platform's export may carry timestamps, source tags, or status fields that identify which form produced which records. Where the original wording survives, record what the person was told their address would be used for. A collected address with no notice about marketing use is not documented marketing permission.

Where the origin cannot be established, record that honestly. Unknown origin is a finding, not an inconvenience to be averaged away across the segment. Do not reconstruct a visitor's historical choice from your current form's wording, and do not treat a purchase as consent to marketing; a transaction records a sale, not a subscription.

Match the recorded choice to the intended channel and use

UK ICO guidance on marketing lists makes the same underlying point: before using a list, check its provenance, the permission records behind it, and whether the permissions match the channel and use you intend. Permission captured for email newsletters does not automatically extend to SMS, telephone, or uploaded ad audiences. That guidance sits within UK PECR and is under review; it does not supply rules for other jurisdictions, and any business-to-business or channel exceptions must be checked against current official text rather than assumed.

Your email platform's own terms are a separate gate. Many platforms require demonstrable opt-in for imported contacts regardless of what the law permits, and an import that violates platform terms risks the account independently of legal analysis. Record the platform's import requirements and confirm the segment's evidence satisfies them before release.

Classify, release only what is documented, and escalate the rest

Classify each segment as documented (origin, notice and recorded choice match the intended use), partial (some evidence exists but a gap remains), or unknown. Only documented segments are candidates for release, and the release decision belongs to the marketing or policy owner, not to whoever ran the audit. Partial and unknown segments stay held while the owner decides between re-permission approaches, qualified legal review of the applicable rules, or disposal.

Log the disposition of every segment with dates and evidence references, so the next person does not repeat this audit from scratch. If a re-permission campaign is chosen, its results create new records going forward; they do not retroactively document the old ones. An imported list that cannot survive this review is a liability being carried, not an asset being protected.

List-provenance review

Work per origin segment, not per file. Record evidence references, not addresses. A segment is released only when its row shows a documented match between origin, notice, recorded choice and intended use.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

List-provenance review. The last column is for temporary notes.
Provenance elementWhat it establishes for the release decisionYour finding
Origin segment and source of the listWhich collection mechanism produced these records and whether anyone can attest to it.
Original notice wording at collectionWhat people were told their address would be used for, with the wording version and date.
Recorded choice per segmentWhether a stored action records the choice, tied to its wording, rather than an assumed consent.
Intended channel and campaign typeWhether the documented permission covers this channel and this use, or only a narrower one.
Applicable rules and platform termsWhich jurisdiction's rules and which platform import requirements apply, confirmed from current official sources.
Segment classificationDocumented, partial or unknown, with the evidence gap named for anything not documented.
Owner release decision and dateWho released the segment, or who holds the unresolved decision and the next step.
Fabrication checkConfirmation that no consent record was created or backdated to close an evidence gap.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • Possession of an address is not permission; this page does not decide whether any specific use is lawful, which requires qualified review of applicable rules.
  • UK ICO guidance cited here is jurisdiction-specific and under review; do not generalize its business-to-business or channel exceptions elsewhere.
  • A prior sale is not treated as marketing permission, and no consent record may be reconstructed retroactively.
  • Keep contact lists and individual consent records in authorized systems; never send them through public inquiry forms.

Sources

  • ICO: Using marketing lists — checked 2026-10-01. Before using a marketing list, its provenance, the permission records behind it and the intended channels need checking; possessing contacts does not itself demonstrate permission.
  • Prism features — checked 2026-09-21. An agreed website review can examine the forms, notices and policies involved in list collection; findings are informational and do not establish legal compliance or provider eligibility.

Request a website review

Want a second look at your own storefront pages?