Skip to content
Academy
Marketing Academy · Field Work●Email & Lifecycle
CoreAudit· 35 minutes

The Global List Audit: Which Subscribers Need GDPR Consent You Don't Have

Wise (formerly TransferWise)

Objective: Given a supplied subscriber list with country and consent-source data, apply the lesson's opt-out-vs-opt-in framework to flag every subscriber sitting on an invalid legal basis.

You're auditing Wise's combined US/EU newsletter list before a compliance review. The list was built from a single global opt-out signup form.

Segment the supplied subscriber sample by country and consent source, then flag every row that violates GDPR's opt-in requirement.

Before you start

What you'll need

Free path (everything below is enough to finish)

FreeSegment the subscriber sample by country and consent source

Free, fast filtering for a compliance audit of this size

FreemiumBuild the suppression segment and the re-consent flow

Free tier supports segments and flows up to 250 contacts

The process

2 steps

Step 01 of 02

The Key Difference: Opt-Out vs. Opt-In

CAN-SPAM lets you email first and requires an opt-out; GDPR requires opt-in consent before the first send. Where the subscriber lives, not where the company is registered, determines which law applies.

The supplied sample has 40 rows from a single global opt-out list. How many rows are EU/UK subscribers who never gave opt-in consent?

Google Sheets— Import the subscriber sample, filter by country column, then cross-check consent_source against 'opt-out-implied'.

Procedure

  1. Filter the list by country: US, EU/UK, other
  2. For every EU/UK row, check the consent_source field for an explicit opt-in event
  3. Flag any EU/UK row with consent_source = 'added via opt-out signup' as non-compliant
Sample output
SEGMENT RESULTS (40 rows)
US: 22 rows, opt-out compliant if unsubscribe link present
EU/UK: 14 rows, consent_source = 'opt-out signup' for all 14 -> FLAGGED
Other: 4 rows, CASL applies, check implied-consent expiry

Healthy

Every EU/UK row traces back to a logged, specific, unticked opt-in event.

Unhealthy

EU/UK subscribers added through the same opt-out form as US subscribers, with no separate consent record.

What this means

Running one global opt-out list is the most common compliance mistake for US-based email marketers; it silently puts every EU subscriber on an invalid basis.

So what do I do about it?

SymptomActionEffort
EU/UK subscribers show no opt-in consent recordSuppress those rows from sending immediately and route them through a re-consent campaignhalf day
YouYou can do this yourself, no engineering access required.

Step 02 of 02

Common Mistakes That Get Marketers Fined

Not logging consent is a common, expensive mistake because proving consent is the marketer's burden, not the regulator's.

For the 14 flagged EU/UK rows, what's the compliant remediation path, delete them or re-consent them?

Klaviyo— Build a suppression segment for the flagged rows, then draft a re-consent email as a separate Klaviyo flow.

Procedure

  1. Suppress the 14 flagged rows from all marketing sends immediately
  2. Draft a re-consent email with a specific, unticked, single-action opt-in link
  3. Log the timestamp, IP, and form wording for anyone who re-consents; delete anyone who doesn't respond within a set window
Sample output
REMEDIATION PLAN
Step 1: Suppress 14 rows (immediate)
Step 2: Send re-consent email, single 'Yes, keep me subscribed' link, unticked
Step 3: Log consent_timestamp + ip_address for responders; delete non-responders after 30 days

Healthy

Flagged subscribers either give fresh, logged opt-in consent or are removed from the list entirely.

Unhealthy

Leaving flagged subscribers on the list because deleting them 'hurts the numbers.'

What this means

A list that shows growth built on unlawful consent isn't an asset; it's fine exposure waiting for an audit.

So what do I do about it?

SymptomActionEffort
Compliance review finds ungated EU subscribersRun the suppress-then-re-consent flow before the next scheduled send, not afterhalf day
YouYou can do this yourself, no engineering access required.

Final deliverable

A segmented audit of the subscriber sample flagging every non-compliant EU/UK row, plus a suppress-then-re-consent remediation plan.

See a reference example
Sample output
PolicyBazaar, List Audit (excerpt)

EU/UK flagged rows: 9 of 35
Remediation: suppressed immediately, re-consent email scheduled for 2026-08-20, non-responders deleted 2026-09-19

Success criteria

You're done when you can:

  • Correctly identifies every EU/UK row lacking a logged opt-in event
  • Proposes suppression before re-consent, not re-consent while still sending
  • Remediation plan includes a specific non-responder deletion window