Newsletter consent data flow.
This GDPR data flow diagram maps a basic newsletter signup from the subscriber to the application and then to an email delivery provider. It separates the public internet, the organization’s application and the external processor so boundary crossings are visible. The consent service writes both the subscriber record and an auditable consent event, which makes the purpose of each store clear. A privacy team can use the diagram as a starting point for a record of processing, vendor review or consent review. Add the actual vendors, retention periods and legal bases used by the organization before relying on it for compliance work. The diagram documents a flow; it does not by itself establish GDPR compliance.
Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.
Scenario
Privacy review
Key decisions
- Consent evidence: Record the consent event in an audit log.
- Processor boundary: The email provider is outside the application boundary.
- Data minimization: The flow starts with an email address and consent.
When to reuse this
Use this DFD when documenting a newsletter process for a privacy review.
Frequently asked questions
Why include a consent audit log?
What is a processor boundary?
Does this prove consent is valid?
More privacy examples
Try the diagram makers.
Tweak it with chat, export PNG/SVG, or fork it for your own use case.