The Global List Audit: Which Subscribers Need GDPR Consent You Don't Have
Objective: Given a supplied subscriber list with country and consent-source data, apply the lesson's opt-out-vs-opt-in framework to flag every subscriber sitting on an invalid legal basis.
You're auditing Wise's combined US/EU newsletter list before a compliance review. The list was built from a single global opt-out signup form.
Segment the supplied subscriber sample by country and consent source, then flag every row that violates GDPR's opt-in requirement.
Before you start
What you'll need
Free path (everything below is enough to finish)
Free, fast filtering for a compliance audit of this size
Free tier supports segments and flows up to 250 contacts
The process
2 steps
Step 01 of 02
CAN-SPAM lets you email first and requires an opt-out; GDPR requires opt-in consent before the first send. Where the subscriber lives, not where the company is registered, determines which law applies.
The supplied sample has 40 rows from a single global opt-out list. How many rows are EU/UK subscribers who never gave opt-in consent?
Procedure
- Filter the list by country: US, EU/UK, other
- For every EU/UK row, check the consent_source field for an explicit opt-in event
- Flag any EU/UK row with consent_source = 'added via opt-out signup' as non-compliant
SEGMENT RESULTS (40 rows) US: 22 rows, opt-out compliant if unsubscribe link present EU/UK: 14 rows, consent_source = 'opt-out signup' for all 14 -> FLAGGED Other: 4 rows, CASL applies, check implied-consent expiry
Healthy
Every EU/UK row traces back to a logged, specific, unticked opt-in event.
Unhealthy
EU/UK subscribers added through the same opt-out form as US subscribers, with no separate consent record.
What this means
Running one global opt-out list is the most common compliance mistake for US-based email marketers; it silently puts every EU subscriber on an invalid basis.
So what do I do about it?
| Symptom | Action | Effort |
|---|---|---|
| EU/UK subscribers show no opt-in consent record | Suppress those rows from sending immediately and route them through a re-consent campaign | half day |
Step 02 of 02
Not logging consent is a common, expensive mistake because proving consent is the marketer's burden, not the regulator's.
For the 14 flagged EU/UK rows, what's the compliant remediation path, delete them or re-consent them?
Procedure
- Suppress the 14 flagged rows from all marketing sends immediately
- Draft a re-consent email with a specific, unticked, single-action opt-in link
- Log the timestamp, IP, and form wording for anyone who re-consents; delete anyone who doesn't respond within a set window
REMEDIATION PLAN Step 1: Suppress 14 rows (immediate) Step 2: Send re-consent email, single 'Yes, keep me subscribed' link, unticked Step 3: Log consent_timestamp + ip_address for responders; delete non-responders after 30 days
Healthy
Flagged subscribers either give fresh, logged opt-in consent or are removed from the list entirely.
Unhealthy
Leaving flagged subscribers on the list because deleting them 'hurts the numbers.'
What this means
A list that shows growth built on unlawful consent isn't an asset; it's fine exposure waiting for an audit.
So what do I do about it?
| Symptom | Action | Effort |
|---|---|---|
| Compliance review finds ungated EU subscribers | Run the suppress-then-re-consent flow before the next scheduled send, not after | half day |
Final deliverable
A segmented audit of the subscriber sample flagging every non-compliant EU/UK row, plus a suppress-then-re-consent remediation plan.
See a reference example
PolicyBazaar, List Audit (excerpt) EU/UK flagged rows: 9 of 35 Remediation: suppressed immediately, re-consent email scheduled for 2026-08-20, non-responders deleted 2026-09-19
Success criteria
You're done when you can:
- Correctly identifies every EU/UK row lacking a logged opt-in event
- Proposes suppression before re-consent, not re-consent while still sending
- Remediation plan includes a specific non-responder deletion window