The consent chain is the unbroken record proving that a person agreed to the processing and forwarding of their data. It captures which person consented when, where and to what, linking their consent to every step from the first contact to the resale of a lead.
What the consent chain contains
A reliable consent chain is made up of several tightly linked records:
- Timestamp – the exact moment consent was given.
- IP address and source – where the record came from and through which channel.
- Form wording – the precise text the person agreed to, including recipients and purpose.
- Confirmation step – ideally a double opt-in, where consent is verified by clicking a confirmation link.
Only when these elements are documented together can it later be reconstructed beyond doubt what a given consent actually referred to.
Example
A prospect enters their details into a comparison form for solar panels and actively ticks the box allowing specialist partners to contact them. The system stores the timestamp, IP, the exact consent text and the form source. Once confirmed by double opt-in, the proof is complete – the lead may be passed to a matching buyer.
Why it matters for lead trading
Anyone who sells leads is forwarding personal data. Without documented consent, this transfer is unlawful under the GDPR and can become expensive. The consent chain shifts the burden of proof onto a verifiable basis: it shows that the individual agreed to being forwarded to exactly this group of recipients. That protects sellers and buyers alike and makes the origin of a record transparent.
Relation to Leadnodes
Leadnodes does not generate leads itself but takes them on from the moment of capture – via API, webhook, email, CSV, Zapier or Make. On intake, the platform automatically checks whether documented consent via double opt-in exists and stores the associated evidence such as timestamp, source and form wording alongside the record. Only then does rule-based, real-time distribution to the matching buyer take place, based on location and vertical. This keeps the consent chain intact and auditable across the entire path – from intake to delivery. All data is held on servers in Germany in full GDPR compliance.
Frequently asked questions
Is a simple opt-in checkbox enough for the consent chain?
An active checkbox is a good start but rarely sufficient on its own. For a solid proof record, the timestamp, IP, form wording and source should be stored alongside it. An additional confirmation step via double opt-in significantly strengthens its evidential value.
How long must the consent chain be retained?
The records should be kept at least as long as the data is being processed or a duty to inform or provide proof may exist. In practice, that means beyond the entire period the lead is in use. The exact retention period depends on the individual case and the applicable legal basis.
What happens if the consent chain has gaps?
If individual records are missing, the consent cannot be reliably proven in case of dispute – the lead can then not be resold safely. Such records should be sorted out or re-qualified. An automated check at intake prevents incomplete leads from entering distribution in the first place.
Would you like your leads' consent checked automatically and documented without gaps? Book a demo