For years, data-driven marketing has operated according to a simple principle: the larger the contact database, the better. Many companies collected email addresses, phone numbers, and consents "in passing"—in forms, terms and conditions, contests, newsletter signups, or during sales calls. The problem is that some of these consents exist only on paper. Consents are often too general, hidden within lengthy text, impossible to prove, or don't cover the channel through which the company actually communicates with the customer.
In 2026, this topic may return with much greater force. The Personal Data Protection Office (UODO) has announced inspections of marketing entities (https://uodo.gov.pl/pl/138/4029), particularly regarding the legal basis for processing data for marketing purposes. For businesses, this means one thing: saying "we have consent" isn't enough. It's also necessary to demonstrate when, how, for what, and to whom the consent was granted.
In practice, the most common mistake is treating any consent as a universal gateway to every marketing activity. However, consent should be specific. Consent to a newsletter is one thing, consent to a sales call is another, and customer profiling to tailor an offer is quite another. If a customer signs up to download an e-book, it doesn't always mean they've agreed to periodic sales calls. If they provided a phone number in a contact form, it doesn't always mean they've consented to text messages with promotional information.
The second problem is the lack of evidence. In the event of an audit, a company should be able to recreate the consent history: the content of the message visible to the user, date, source, channel, form ID, checkbox version, and whether consent was later withdrawn. A table in the CRM with a "consent: yes" mark may not be sufficient.
The third risk area is purchasing contact databases. While such databases can be tempting for sales, from a compliance perspective, they are one of the most sensitive operating models. A company using the database should know where the data comes from, who collected it, for what purpose, on what basis, and whether the data subject has been informed about the continued sharing of their data. Without this, the risk shifts to the entity that ultimately sends the message or places the call.
It's also worth remembering that GDPR is only part of the puzzle. The Electronic Communications Act also plays a role in marketing emails, text messages, and phone calls, requiring prior consent to use certain communication channels for sending commercial information, including direct marketing. In other words, even if a company has a basis for processing data in CRM, it doesn't automatically mean it can call or send an offer.
So what should a company do before an audit? First and foremost, conduct an audit of consent and data sources. It's worth checking forms, checkboxes, clause content, CRM configuration, mailing lists, call center scripts, and the process for handling consent withdrawals or objections. It's also important to ensure that marketing and sales understand the difference between a lead, a customer, a newsletter subscriber, and someone who has consented to commercial contact.
The Personal Data Protection Office (UODO) inspections don't mean the end of marketing. Rather, they mark the end of the fiction in which consent was treated as a formality. In 2026, the advantage will be held by companies that can conduct effective marketing while also knowing where their data comes from, what they can do with it, and how to prove it.
This article is for informational purposes only and does not constitute legal advice
Legal status as of June 16, 2026
Author:
Series editor:
