Email Consent Records: Proving Opt-In Under Poland’s New Telecom Law
Email consent records are the stored evidence of who agreed to receive your newsletter, when, where and to what wording. Can’t produce them? Then you can’t show the opt-in ever happened. Simple as that. For Polish companies the topic got urgent when the Electronic Communications Law (Prawo komunikacji elektronicznej, Dz.U. 2024 poz. 1221, act of 12 July 2024) entered into force on 10 November 2024. What follows is a practical overview for people who run a company newsletter. It is not legal advice.
What does the new Polish law change for newsletter senders?
Email marketing still needs the recipient’s prior consent. That part is not new. What changed is where the rules live: they now sit in the Prawo komunikacji elektronicznej, in force since 10 November 2024. And for an office manager the practical upshot is short: the sender is the one who has to show that consent exists. So the record matters as much as the checkbox on the form. Company addresses? Same logic. Before the next campaign goes out, I’d check how marketing consent in B2B works.
Why does proof of consent matter more than the consent itself?
Because consent you can’t demonstrate is treated the same as consent you never had. The EDPB guidelines on consent put the burden on the controller, who must be able to show that a person agreed and what they were told at the time. How you do it is up to you. The evidence just has to hold up.
And requests for proof of consent rarely land at a convenient moment. A subscriber complains that they never signed up. The data protection officer asks a question. Or the company switches email tools and nobody knows what the old one stored (a classic, honestly). Keeping the evidence ready is part of complying with GDPR in email, not a separate project.
What should email consent records contain?
A useful record answers five questions: who, when, where, what they were told and how they confirmed. Each of them maps to a field you can store right next to the contact:
- Who - the email address and any identifier of the subscriber.
- When - the date and time of signup.
- Where - the form, page or channel that collected it.
- What they were told - the exact consent wording and the privacy notice version shown.
- How they confirmed - a checkbox ticked by the person, a double opt-in confirmation click.
Version your form text. Really. When the wording changes, old opt-in records must still point to the old text, otherwise you end up showing a sentence the subscriber never saw. And a pre-ticked box or a vague “stay in touch” line? Weak record. It doesn’t show a clear action taken for a specific purpose.
How double opt-in confirmation strengthens the consent log
A confirmation click adds a second, timestamped event. It shows that the owner of the mailbox agreed, not someone who merely typed the address. So the consent log holds two entries instead of one: the signup and the confirmation, both tied to the same address and form. A nice side effect: mistyped and fake addresses never reach the list.
MailCraft offers double opt-in, embeddable signup forms and a subscriber activity log, so this two-step trail is covered without extra work. Still on the fence? The comparison of double versus single opt-in explains what each approach means for list quality.
Imported lists and integrations: where opt-in records get lost
Consent evidence usually disappears when contacts move between systems. Why? Because only the email address gets carried over. Before importing a list, go through these steps:
- Confirm where each contact originally agreed.
- Carry the signup date and source as fields in the file.
- Keep the original form wording alongside the export.
- Leave out contacts whose origin nobody can explain.
- Note who did the import and when.
Shop and CMS signups deserve the same care. The newsletter checkbox in the store is the consent moment, so its wording and timestamp need to travel with the contact. The MailCraft PrestaShop module syncs signups and that checkbox, and has GDPR hooks for a consent registry, data export and erasure.
What happens to the record when someone withdraws consent?
Withdrawal stops the sending. It does not erase the history - you keep a note of when the person opted out and stop mailing them from that moment. According to the EDPB guidelines, withdrawing must be as easy as giving consent, so an unsubscribe link that works in one step is the baseline. Nothing fancy.
Record the unsubscribe date and method next to the original opt-in, and the full timeline stays visible. Leave the address on a suppression list (a set of contacts that must never be mailed), so a later import doesn’t quietly re-add it. Erasure requests, by the way, are a different matter from unsubscribes and belong in your data protection process.
A short routine for keeping proof of consent in order
You don’t need extra tools for this. A few fixed habits do the job. Give signup forms one owner, so every change goes through the same person. Maintain a dated archive of consent wording. Check the log after each form change or import. And run a test signup now and then to see what actually gets stored (it can be an eye-opener).
Well-kept email consent records turn the rules in force since 10 November 2024 from a worry into a routine task: when someone asks how to prove newsletter consent, you open the entry and show it. Done. Specific legal questions about your situation belong with a lawyer or your data protection officer.
FAQ
Is a ticked checkbox enough as proof of consent?
Only if you can also show when it was ticked, on which form and next to what wording. The tick alone says nothing about what the person agreed to. A pre-ticked box is weaker still, since it doesn’t show an active choice.
How long should opt-in records be kept?
For as long as you send on the basis of that consent and can be asked to demonstrate it. There is no single figure that fits every company, so the period should follow your own retention policy. Ask your data protection officer to confirm it in writing.
Do old subscribers need to confirm again after 10 November 2024?
Not automatically. What counts is whether the existing consent was valid and can be demonstrated. Record missing? Then asking for fresh confirmation is the safer route. Treat this as general guidance, not legal advice.


