PRIVACY

Newsletter consent data flow.

This GDPR data flow diagram maps a basic newsletter signup from the subscriber to the application and then to an email delivery provider. It separates the public internet, the organization’s application and the external processor so boundary crossings are visible. The consent service writes both the subscriber record and an auditable consent event, which makes the purpose of each store clear. A privacy team can use the diagram as a starting point for a record of processing, vendor review or consent review. Add the actual vendors, retention periods and legal bases used by the organization before relying on it for compliance work. The diagram documents a flow; it does not by itself establish GDPR compliance.

UPDATED 2026-09-24
EXAMPLENewsletter consent data flow.
Make this diagram your own.

Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.

CASE ANALYSIS

Scenario

Privacy review

Key decisions

  • Consent evidence: Record the consent event in an audit log.
  • Processor boundary: The email provider is outside the application boundary.
  • Data minimization: The flow starts with an email address and consent.

When to reuse this

Use this DFD when documenting a newsletter process for a privacy review.

FAQ

Frequently asked questions

Why include a consent audit log?01
It makes the separate record of the consent event visible in the data flow.
What is a processor boundary?02
It separates an external service provider from the organization’s own systems.
Does this prove consent is valid?03
No. The diagram shows where consent information moves and is stored; the consent process still needs legal review.
Open this example in the editor →

Tweak it with chat, export PNG/SVG, or fork it for your own use case.