A form has a checkbox at the bottom. The label says something close to: tick here to be contacted. Eleven months later somebody asks whether a particular person on the list agreed to receive the email that was just sent to them, and the honest answer is that the checkbox was ticked, the wording has been edited twice since, and nobody recorded which version was on screen at the time.
That is the actual failure mode. It is not that consent was never collected. It is that what was collected cannot be reconstructed, and consent that cannot be reconstructed is worth roughly what no consent is worth. The design problem is therefore less about the wording of the checkbox than about what gets stored beside it.
Consent is a record, not a setting
Article 4(11) of the GDPR defines consent of the data subject as any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. Each of those five words rules something out, and the last one rules out the most.
Article 7(1) is the part that changes system design: where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented. Demonstrate means produce evidence, to somebody who was not there, about an event that happened months ago.
Recital 32 fills in what does not count. Silence, pre-ticked boxes or inactivity should not constitute consent. An unticked box that the user ticks is a clear affirmative action. A box that arrives ticked is not, no matter how clearly it is labelled.
Article 7(2) adds a presentation rule for the common case where the consent sits inside a longer declaration. Where consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. A marketing consent buried in a paragraph of terms fails that test even if the sentence itself is accurate.
The practical consequence is that the consent belongs in the response record, not in a settings page. A global preference that says this contact accepts marketing tells nobody what was agreed, when, or on which form.
What has to be stored with every yes
Six items, and the first three are the ones normally missing.
The exact wording shown. Not a reference to the current version of the text, which will change, but the text itself or an immutable version identifier that resolves to it. This single item is the difference between evidence and an assertion.
The timestamp. With a time zone, not a date.
Where it happened. Which form, on which page. The same person may have said yes to a product update list and nothing else.
What the box was set to by default. Recording that the checkbox was unticked when the page loaded answers the pre-ticked question directly.
What was ticked, separately per purpose. One record per purpose, not one combined flag.
How it was withdrawn, if it was. Along with when, so that the gap between the request and the change is visible.
Storing those six things beside the submission rather than in a separate consent system has a practical advantage beyond tidiness. When a question arrives about one person, the answer is one response record, with the wording they saw attached to it. Every response keeping its own state, rather than updating a shared contact row, is what makes that possible, which is a specific instance of the more general case for response management.
Separate purposes need separate boxes
The word in Article 4(11) that does the most work in practice is specific. One box covering several different uses is the most common defect in real forms, and it is usually not deliberate. It comes from writing the label after the form was built.
| What is being asked | Is a separate box needed | Why |
|---|---|---|
| Reply to this enquiry | No | Necessary to answer what the person asked |
| Follow up on this enquiry later | Usually no, same purpose | Still the enquiry being answered |
| Add to a marketing list | Yes | A different purpose, unrelated to the enquiry |
| Pass details to a partner or reseller | Yes, naming them | Cannot be inferred from anything else |
| Use the response as a public quotation | Yes, with the name to be shown | Publication is a distinct act |
| Send text messages or place calls | Yes, and see the rules below | Channel specific rules apply |
The first row is worth stating plainly because it causes unnecessary work. Somebody who fills in a contact form asking a question has asked to be answered. Adding a checkbox that asks permission to reply to the enquiry they just sent does not improve the legal position and does make the form look confused. What needs a box is anything the person did not come to the form to get.
The row about partners is the one that fails silently. A consent phrased as your details may be shared with selected partners cannot be specific, because the person cannot know who agreed to what. Naming the recipients is the only version of that sentence that survives.
Channel rules that sit on top of consent
Email, text and voice are governed separately in several jurisdictions, and the requirements are narrower than general data protection consent.
In the United States, prior express written consent for automated marketing calls and texts has a definition in the regulations. 47 CFR 64.1200(f)(9) describes it as an agreement, in writing, bearing the signature of the person called, that clearly authorises the seller to deliver advertisements or telemarketing messages using an automatic telephone dialing system or an artificial or prerecorded voice, and the telephone number to which the signatory authorises them to be delivered. Three specifics follow from that text: the seller has to be identified, the number has to be the one the person gave for that purpose, and the record has to be an agreement rather than an inference.
The same regulation sets an operational deadline on the way out. Under 47 CFR 64.1200(a)(10), a called party may revoke consent by any reasonable method, replies such as stop, quit, end, revoke, opt out, cancel or unsubscribe are reasonable per se, and all requests to revoke made in any reasonable manner must be honoured within a reasonable time not to exceed ten business days from receipt. The provision also states that the caller may not designate an exclusive means to request revocation, which rules out the pattern of accepting removal only through a specific web form.
Commercial email in the United States carries a similar window from a different statute. Under 15 U.S.C. 7704(a)(4)(A), it is unlawful to send a commercial message to a recipient more than 10 business days after receipt of their opt out request.
The shape those rules share is that the outbound side is timed. Collecting consent is a design task with no deadline. Honouring a withdrawal is a process with a clock on it, and it is the half that is usually unowned.
Confirming the address, and what it is actually for
A confirmation step, where the person receives an email and has to click before anything is sent to them, gets described as a compliance measure. It is better understood as two separate things, only one of which is about consent.
The part that is about consent is proof that the address belongs to the person who typed it. A form submission on its own shows that somebody entered an address, not that the owner of that address agreed to anything. Where a marketing list is being built from a public form, that gap matters, because the most common way an address ends up on a list without its owner's agreement is somebody else typing it, occasionally by mistake and occasionally not.
The part that is not about consent is deliverability. Confirmation removes typos, disposable addresses and bot submissions before they enter the list, which is a quality benefit and has nothing to do with the legal basis.
The cost is real and worth naming, because a confirmation step loses people who genuinely intended to sign up and simply never opened the email. That trade is usually worth taking for a marketing list and usually not worth taking for an enquiry form, where the reply itself is the confirmation and an extra step delays the answer the person came for. A form tool that can apply confirmation per form rather than globally is what makes that distinction available, and the use cases where it matters are almost always the ones that feed an outbound list rather than an inbox.
Withdrawal is the part that breaks
Article 7(3) of the GDPR states that the data subject shall have the right to withdraw consent at any time, that withdrawal does not affect the lawfulness of processing carried out before it, and that it shall be as easy to withdraw as to give consent.
That last sentence is a system requirement disguised as a principle. If consent was given by ticking one box on one form in ten seconds, then withdrawal cannot require a signed letter, a phone call during office hours, or an account that the person never created.
Three failures recur, in order of frequency.
Withdrawal arrives in the wrong place. Somebody replies to a newsletter saying remove me, and that reply lands in a mailbox that the sending system does not read. The request is valid the moment it is received, and the clock started then, not when somebody notices.
Withdrawal reaches one list and not the others. A person who ticked two boxes on two different forms has to be found in both. This is the practical reason to key responses to the person as well as to the form, since a search by email address is the only reliable way to answer the question.
The withdrawal is applied but not recorded. Six months later there is no way to show when the request arrived or when it took effect, which is exactly the evidence problem that started this article, now in reverse.
A workable arrangement is that every inbound channel a person might use, including a plain reply, reaches a place where somebody owns it and can act on it, and that the action and its timestamp end up attached to the same record as the original consent. The questions people ask about a form tool tend to concentrate here, because it is the point at which collection and correspondence stop being separate jobs.
What to change first
Store the exact consent wording, the timestamp and the form it came from with each response, rather than a single flag on a contact record, because that is the difference between evidence and a claim. Then split any combined checkbox into one box per purpose, and make sure a plain email saying remove me reaches somebody who can act on it and record when it arrived. Seeing how Halict keeps each response and its own state together is a quick way to judge whether the current setup could answer a question about one person from eleven months ago.
Q1. Is a pre-ticked consent box ever acceptable?
Recital 32 of the GDPR states that silence, pre-ticked boxes or inactivity should not constitute consent, so a box that arrives already ticked does not produce valid consent regardless of how clearly it is labelled. Recording the default state of the box at page load is worth doing, because it answers this question directly if it is ever raised.
Q2. Does a contact form need a consent box to allow a reply?
Answering the enquiry the person sent is the purpose they submitted it for, so a separate box asking permission to reply adds nothing. What needs its own box is anything beyond that, such as adding the address to a marketing list, sharing it with a named partner, or publishing the response.
Q3. How long is there to act on a withdrawal request?
Two United States rules set explicit windows: 47 CFR 64.1200(a)(10) requires revocation of consent for calls and texts to be honoured within a reasonable time not to exceed ten business days, and 15 U.S.C. 7704(a)(4)(A) prohibits commercial email more than 10 business days after an opt out request. Under the GDPR, Article 7(3) sets no number but requires withdrawal to be as easy as giving consent.
Q4. Can removal be required to go through a specific form?
For calls and texts covered by 47 CFR 64.1200(a)(10), no. The provision states that a called party may revoke by any reasonable method and that the caller may not designate an exclusive means to request revocation, which means a plain reply has to be accepted even if a preference page exists.
Q5. What is the minimum that has to be stored to prove consent?
The exact wording that was displayed, the timestamp with a time zone, and which form it came from, held per purpose rather than as one combined flag. Article 7(1) requires the controller to be able to demonstrate that the person consented, and a boolean field on a contact record does not demonstrate anything about what they were shown.