Does Your Marketing Team Actually Know Who Consented?

The gap almost nobody notices

Among the violation categories SDAIA has publicly named: direct marketing without explicit consent, missed response windows on data-subject requests, missed 72-hour breach notification, inadequate protection measures, and a DPO not appointed when required.

The first one happens the most, day to day. The DPO writes the policy, but the marketing team runs its campaigns against a database it has no real visibility into: who consented, when, and through which channel.

Policy alone doesn’t close it

Consent needs to be free, informed, specific to its purpose, and revocable at any time. Without a live record linking every contact to their actual consent status, the marketing team ends up operating blind, which is exactly the pattern SDAIA keeps publishing as a violation.

See where your own data actually stands → free scan