Establish jurisdiction and responsibility
Identify the relevant organizations, people, regions, channels, and purposes with the responsible privacy or legal adviser. Rules differ across jurisdictions and activities. Consent is not the only possible basis for every processing activity, and a lawful basis for one purpose does not authorize all others.Build the control system
- Inventory data flows. Map collection, enrichment, CRM, analytics, sending tools, partners, exports, and deletion paths. Record categories, purpose, source, recipients, and accountable owner.
- Document the approved use. Record the applicable basis, notices, consent evidence where required, restrictions, and vendor responsibilities. Review new purposes or destinations before extending an existing workflow.
- Minimize access and retention. Collect what the task requires, restrict access by role, and set purpose-based review or deletion rules. Avoid a universal retention period copied from another business.
- Operationalize rights and preferences. Provide an intake route, verify identity proportionately, assign an owner, and follow applicable deadlines. Propagate corrections, withdrawals, objections, or deletion decisions through connected systems and processors as required.
- Handle exceptions deliberately. Some records may need restricted retention for a valid obligation or suppression purpose. Document that decision and limit use; do not promise unconditional deletion of every record or retain everything “just in case.”
- Test and review. Use synthetic records to verify preference changes, exports, access controls, and deletion propagation. Review incidents and vendor changes, and retain evidence that controls actually ran.
Worked example
A fictional contact asks to stop marketing. The request updates the CRM and email platform, but a weekly enrichment import could recreate the old eligibility field. The operator fixes the import precedence and tests the complete flow with a synthetic record. A minimal suppression record is handled under the approved policy so the person is not re-added by another source. The team distinguishes this marketing restriction from any separately justified service or recordkeeping need rather than assuming all communication has the same purpose.Data-use register
Review before a new campaign
Check whether the audience source, destination, purpose, or jurisdiction has changed. Escalate unresolved legal questions to the appropriate adviser; do not hide uncertainty behind a checked box. The operational evidence should show which decision was made, by whom, and how it is enforced.Try it with your own work
Use a synthetic contact to trace one preference change through your tools and imports. Record where the update stops. Resolve legal uncertainty with the responsible adviser before changing the real process.Sources and scope
- ICO: data protection principles is a UK-specific primary reference. Apply current requirements for the actual jurisdiction and activity with appropriate advice.
What to read next
MarTech governance · Contact research · Lifecycle email Chapter guide · All playbooksCopyright © 2026 Ivan Xu. All rights reserved. See the copyright and reuse terms. Canonical source: github.com/weilun88313/B2B-Playbook