GDPR by design: what should you record at the point of collection?
Five records: the date and time of collection, the exact wording displayed, the collection point, the channel, and an identifier for the person. The ticked box is only the outcome; Article 7(1) of the GDPR asks you to demonstrate the conditions under which it was ticked. On Brevo and on Mailchimp those five items all exist, but they live in different places and they don't all survive the same settings.
Whether your collection is compliant gets decided before the first send, in the structure of the form. Afterwards it's too late. You can't back-date a consent timestamp, and nobody accepts a good-faith reconstruction.
That's the whole point of the phrase "by design". It isn't about intent, it's about plumbing. Here's what that plumbing has to produce, and what your tools actually produce today.
Key takeaways
- The burden of proof sits with you: Article 7(1) requires the controller to "be able to demonstrate that the data subject has consented" (GDPR, art. 7(1)).
- Five records to keep: date and time, exact wording, collection point, channel, identifier for the person. France's CNIL suggests keeping a register of them.
- Brevo files the proof across two logs: event logs for the submission, transactional logs for the confirmation. A retention rule caps out at 24 months, and changing it is retroactive.
- Mailchimp turns its GDPR fields on per audience, so one team can be collecting cleanly while another collects nothing at all.
- Three years is the window the CNIL allows for prospect data, running from collection or from the prospect's last contact.
What do you actually have to prove?
That the person consented, when, and in what terms. Article 7(1) of the GDPR is blunt: "the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data" (GDPR, Regulation (EU) 2016/679, Article 7). In 2025, France's CNIL received 20,150 complaints, ten percent more than in 2024.
The word "demonstrate" does all the work. It turns a good practice into a documentation duty. You don't have to prove that your form is well built. You have to prove what one specific contact saw, and did, on one specific day.
The CNIL puts it plainly: the controller must be able to demonstrate at any time that the person did consent, under valid conditions (CNIL, Conformité RGPD: comment recueillir le consentement des personnes?). "At any time" includes three years after collection.
Consent can be perfectly valid and legally useless. Valid, because the person did tick a box that was freely given, specific, informed and unambiguous. Useless, because nothing in your system lets you replay it: not the date, not the text shown that day.
Public debate almost always lands on validity. Real exposure lands on retention. It's the difference between being right and being able to show it.
This proof duty doesn't stand alone. Article 5(2) sets out the controller's general accountability, which includes being able to demonstrate compliance. For the full framework, see our GDPR email compliance guide for marketing teams.
The five records to keep at every collection
The CNIL asks controllers to document the conditions under which consent was collected, and suggests keeping a register of consents (CNIL, Conformité RGPD: comment recueillir le consentement des personnes?). That register comes down to five columns, and each one answers a question a complainant can ask.
| The record | The question it answers | Where it gets lost |
|---|---|---|
| Date and time | When did the person consent? | Purged logs, import with no timestamp |
| Exact wording shown | What did they say yes to? | Form edited since, no version kept |
| Collection point | Which page, which event? | Field absent from the export, another team's form |
| Channel and mechanism | Box ticked, email confirmed? | Boolean attribute with no context |
| Identifier for the person | Who are we talking about? | Duplicate merges, changed address |
The five records follow from the conditions of collection the CNIL asks controllers to document. The right-hand column lists losses we have watched happen on shared accounts.
Look at that third column. None of those losses comes from bad intent. Every one of them comes from a default setting, a rushed import, or a form rebuilt without keeping the old one. That is precisely what Article 25 of the GDPR aims to head off, by requiring measures "at the time of the determination of the means for processing".
Why does the exact wording matter more than the box?
Because consent has to be specific, and specificity lives in the words. The CNIL notes that consent must correspond to a single processing operation, for a defined purpose (CNIL, Conformité RGPD: comment recueillir le consentement). A ticked box without its text therefore proves no purpose at all.
Take the common case. You rebuild your form in March, widening the notice to "our offers and those of our partners". A contact who signed up in January never saw that sentence. Without an archive of January's wording, nothing in your list separates the two populations any more.
Mailchimp has understood this and documents it. For an audience with GDPR fields enabled, the vendor says it records "a plain-text version of your form" at signup (Mailchimp, Collect Consent with GDPR Forms). That's the wording, frozen, as it was seen.
Mailchimp's help page leaves no room for doubt about the scope of its own feature: "Enabling GDPR fields on your signup forms doesn't make you compliant. It's the first step in the process." Rare, coming from a vendor, and accurate.
Brevo keeps the wording too, just somewhere else. The consent text you add to your form ends up inside the double opt-in confirmation email, whose content gets logged. Brevo calls that log "crucial", because it proves you asked for consent and gave the person the information they needed.
The difference is one of filing, and it matters later. On Mailchimp the wording is attached to the audience; on Brevo it's attached to a log. Logs get purged. Audiences don't.
What do Brevo and Mailchimp actually keep?
Both keep the essentials, but not in the same place. Mailchimp exposes four dated fields in an audience export: OPTIN_TIME, OPTIN_IP, CONFIRM_TIME and CONFIRM_IP (Mailchimp, View or Export Your Contacts). Brevo files the proof in its logs instead.
And it splits it across two distinct logs. The event log holds the form submission, its time and the address. The transactional log holds the confirmation email, its content, then the date of confirmation. Brevo's own conclusion: "Exporting both log types is essential to track the end-to-end DOI process" (Brevo, Double opt-in (DOI)).
One detail is reassuring and worrying at once. The transactional log keeps the content of the confirmation email, "including the confirmation link and consent text you've added". So the wording is retained, but inside a log rather than on the contact's record.
What Mailchimp is missing sits elsewhere, and it stings during an audit. The vendor lists email signup source among the data that is "not included" in an audience export (Mailchimp, View or Export Your Contacts). You read it one contact at a time, in the interface.
While wiring our Brevo and Mailchimp integrations we ran this exercise on real audiences. Answering "where did this contact come from?" for one person takes ten seconds in the interface. Doing it for forty thousand contacts isn't an export question, it's a code question.
Concretely: the day your data protection officer asks for a breakdown of the list by collection point, nobody can produce it from a CSV. The opt-in timestamps and IPs, on the other hand, are right there in the export.
The blind spot: a retention ceiling below the retention window
A Brevo retention rule can store logs "anywhere between 1 and 24 months" (Brevo, Configure a custom retention period for your transactional logs). The CNIL, meanwhile, allows three years of prospect data retention. The ceiling on the proof sits twelve months below the floor of the need.
Good news first. With no rule configured, logs are stored indefinitely, so the default doesn't betray you. The risk only appears the moment somebody decides to tidy up.
Brevo spells it out: log retention changes are retroactive, and a new rule "will apply to both your existing logs and new logs going forward". Once the period ends, logs are "permanently deleted and cannot be recovered".
Translated: somebody setting retention to one month to lighten the account destroys three years of consent dates in the same click. The setting isn't a choice about the future, it's an immediate purge.
Who in your organisation knows that this slider touches compliance? It lives in the transactional email settings, under a heading that talks about performance and storage. Nothing in that screen mentions consent.
A second limit applies to high volumes. Since 1 January 2025, an account that has accumulated more than ten million email events has anything older than twenty-four months deleted, whatever its own settings say (Brevo, About the data retention policy for email events).
That deletion doesn't only hit the logs. It also strips those events from the history shown on your contacts' own detail pages. And Brevo notes that you can't currently view your account's event count, so you don't know whether you're near the threshold.
The fix fits in one sentence, and Brevo is the one who supplies it. The vendor recommends extracting transactional logs from the platform regularly, for archiving. In other words: get the proof out of the sending tool.
Why does multi-team sending break traceability?
Because compliant collection is configured at audience level, not account level. Mailchimp enables its GDPR fields audience by audience, through each one's form settings (Mailchimp, Collect Consent with GDPR Forms). Three teams, three audiences, three possible standards of rigour.
The scenario repeats everywhere. The central team wires its main audience properly. A regional team spins up its own for a trade show without enabling GDPR fields, because the option doesn't appear in the creation flow. Six months later the two audiences get merged.
Mailchimp lets you import marketing permissions into a GDPR-enabled audience, and says so without hedging: "It's your responsibility to ensure you can demonstrate that your contacts have consented to the marketing permissions you import."
In other words, a CSV import creates contacts that look consenting in the interface, with no trace originating from the tool. It's the most common source of unverifiable consent, and the easiest to trigger: all it takes is write access to the audience.
Which brings compliant collection back to a question of access. Who can create an audience, import a file into it, edit a form? On Mailchimp, audience-level access control doesn't exist at any tier, as we set out in our piece on restricting a Mailchimp user to certain audiences.
On Brevo the problem takes another shape. Granular permissions do exist, but they don't cover everything, and some account settings stay bundled with other powers. We documented that mechanism for billing in who can change the plan or buy an add-on.
How do you wire compliance into collection?
In four moves, none of which means changing tools. Article 25 of the GDPR asks for measures taken "at the time of the determination of the means for processing", and Article 25(2) requires that by default only necessary data is processed. These four moves turn both paragraphs into settings.
Enable consent fields on every audience, not just the main one
List your audiences and lists, then check them one by one. An audience created for a one-off event counts as much as the one that receives your weekly campaigns.
Archive the wording every time the form changes
Keep a dated capture of the text displayed and version it. On Brevo, copy that text into the double opt-in confirmation email, so it becomes a document the contact holds too.
Get the proof out of the sending tool, every quarter
Brevo itself recommends extracting its transactional logs regularly for archiving. A dated export, stored outside your ESP, survives retroactive purges and the 24-month ceiling.
Treat an import as a collection, with the same requirements
Ask the importing team for the date, the source and the wording of the original collection, before the import rather than after. Without those three, the file doesn't go in.
The fourth one holds up least well on its own, because it rests on the discipline of teams that don't have GDPR as a priority. It holds up better when imports go through a person, or through a layer, rather than through direct access to the audience.
The natural next reading splits in two. How sharing one account redistributes responsibility, in our guide to Mailchimp governance for teams. And how uncoordinated sending degrades a reputation everybody shares, in our piece on deliverability on a shared account.
Fewer hands in the account means fewer collections outside the rules.
Sendgate sits on top of your existing Brevo or Mailchimp account, with no migration. Teams compose and send from Sendgate, with only the lists and senders assigned to them, and no direct access to the account. Audiences, forms and retention settings stay with the people who own compliance. Brevo and Mailchimp are both supported today.
Start free →Email sending governance · Not affiliated with the brands mentioned
What to take away
The ticked box is not the proof. Article 7(1) asks you to demonstrate consent, which takes five records: the date and time, the exact wording displayed, the collection point, the channel, and an identifier for the person. The CNIL talks about a register of consents and documented conditions of collection.
Your tools keep some of that. Mailchimp exposes opt-in timestamps and IPs in the export and archives the form wording, but leaves signup source out of that export and only enables its GDPR fields audience by audience. Brevo splits the proof across two logs, whose retention rule caps out at 24 months and applies retroactively to what already exists.
Hence the one rule that survives contact with time, and Brevo is the one recommending it: get the proof out of the sending tool. Then treat every import as a collection. The rest is settings, and settings change.
Frequently asked questions
Is double opt-in required to prove consent?
How long do you have to keep proof of consent?
What do you record besides the ticked box?
Does Mailchimp record where a contact signed up?
OPTIN_TIME, OPTIN_IP, CONFIRM_TIME and CONFIRM_IP.Where does Brevo store proof of consent?
Sources
- Regulation (EU) 2016/679, Article 7(1) and Article 5(2), official text, retrieved 2026-08-01. eur-lex.europa.eu
- Regulation (EU) 2016/679, Article 25, data protection by design and by default, retrieved 2026-08-01. eur-lex.europa.eu
- CNIL, Conformité RGPD: comment recueillir le consentement des personnes?, retrieved 2026-08-01. cnil.fr
- CNIL, Questions-réponses sur les référentiels relatifs à la gestion des activités commerciales, retrieved 2026-08-01. cnil.fr
- CNIL, Annual report 2025 (20,150 complaints received, up 10% year on year), retrieved 2026-08-01. cnil.fr
- CNIL, Sanctions and corrective measures, 2025 review (83 sanctions, of which 10 decisions on commercial prospecting), retrieved 2026-08-01. cnil.fr
- Mailchimp, Collect Consent with GDPR Forms, retrieved 2026-08-01. mailchimp.com
- Mailchimp, View or Export Your Contacts, retrieved 2026-08-01. mailchimp.com
- Brevo, Double opt-in (DOI): what it is and how to track user sign-ups, retrieved 2026-08-01. help.brevo.com
- Brevo, Configure a custom retention period for your transactional logs and email previews, retrieved 2026-08-01 (page revised 2026-04-27). help.brevo.com
- Brevo, FAQs – About the data retention policy for email events, retrieved 2026-08-01. help.brevo.com
- Brevo, Guidelines for a GDPR-compliant sign-up form, retrieved 2026-08-01. help.brevo.com
Vendor settings verified on 1 August 2026 against the Brevo and Mailchimp help pages as published on that date. This article describes product mechanics and public texts; it isn't legal advice. The CNIL's reference frameworks aren't binding: you may apply different retention periods provided you can justify them.
