Suggested answer

The starting point is that the platform gives you tools, not compliance — the legal position has to be defined with the privacy team first.

Practically: capture consent explicitly at the point of collection with unchecked opt-in fields and clear wording, and store both the consent value and its timestamp and source in prospect fields so you can evidence it later. Use an email preference centre so people can narrow what they receive rather than only leaving entirely.

Honour the opt-out mechanics properly: 'opted out' for marketing, and understand that operational sends still reach those prospects. Support erasure requests with a documented process covering both Account Engagement and the synced Salesforce record, since deleting one side alone can restore the other.

I would also review tracking — cookie consent for the tracking code where required — and set data retention expectations for prospects who have never engaged.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.