List Building
Part of Email platform selection and migration
Exporting subscriber permissions before changing providers
Preserve signup evidence, subscription status and opt-outs before moving email contacts to a new provider.
Before importing contacts into a new email provider, export permission evidence and exclusions. Preserve what each person agreed to, when, through which route, and their current marketing status. A CSV labelled “subscribed” does not by itself explain why its addresses may receive the next campaign.
The Spam Act 2003 (Cth) prohibits sending commercial electronic messages without recipient consent, and the Australian Communications and Media Authority (ACMA) enforces the Act. Consent may be express or inferred, so preserve the evidence for the basis you rely on rather than treating a subscription status as proof.
Key Compliance Requirements Under the Spam Act 2003 (Cth)
- Enforcement Authority
- Australian Communications and Media Authority (ACMA)
- Consent Types Required
- Express or inferred (with commercial relationship basis)
- Evidence Must Include
- Method, terms seen, date/time, action taken, consent category
- Prohibited Practices
- Burying consent terms in privacy policies or using pre-ticked boxes
Inventory the evidence
List every route an address entered the old system: signup forms, checkout choices, events, staff entries, connected apps and earlier imports. For each route, find the wording shown to the person and the action that recorded a marketing choice. Keep earlier form versions when the promise changed.
Create an evidence record for each contact and route. Capture the method, the terms or wording in force, the date and time collected, the consent action, the consent category and the current status; these method, terms and date/time details are among the consent records ACMA recommends maintaining.
Record the action that demonstrates the choice, such as submitting a form or ticking a box; do not treat a pre-ticked box as an affirmative choice. Forms, website boxes, phone and face-to-face conversations are routes through which express consent can be given. If the person confirmed by email, retain that confirmation action too.
Classify the basis as express or inferred consent. For inferred consent, keep evidence of the existing commercial relationship and its relevance to the marketing; a one-off purchase or the mere publication of an email address is not enough by itself.
Evidence may sit in a form archive, customer system or support log rather than an audience export. For checkout logs, support tickets, staff entries and other external records, retain a copy or a clear reference linked to the contact and route; do not assume one provider field can hold the whole history.
ACMA recommends express consent based on clear terms accessible when consent is sought, and says consent terms should not be buried in fine print or long privacy policies. Keep the wording the person saw so the team can distinguish what was agreed to from a later version.
Record to preserve / Question it helps answer
- Address and source system
- Where can a discrepancy be investigated?
- Collection route and date
- In what context was the address obtained?
- Signup wording or form version
- Which sender and emails were offered?
- Consent action and confirmation, if used
- What did the person do?
- Current status and later changes
- Was there a later opt-out or other decision?
- Scope or topic choice
- Does the planned email fit the choice?
Inspect the export
Export relevant status groups, including unsubscribed contacts. If the old provider holds several audiences, inspect each one. Keep original files unchanged and document generation times, status label definitions and record counts.
Export contents and status fields vary by provider. Record which groups, fields and status details the files actually contain, and check the account’s current export controls rather than assuming another provider’s menu path or fields apply.
In Ghost Admin, open the Members area, select the settings icon and choose Export all members. The CSV includes id, email, name, note, subscribed_to_emails, complimentary_plan, stripe_customer_id, created_at, deleted_at and labels.
Ghost's member export includes a subscribed_to_emails field. Treat it as a status field, not a complete consent history; do not assume created_at records the date and time marketing consent was given.
Where available, pair exported status data with form records or other permission evidence. Keep the source record associated with the contact and route, and retain the actual wording and action evidence alongside the export.
Sample records from every collection route. Look for missing dates, blank permission fields, conflicting statuses, and addresses whose only recorded event is a purchase or import. Where permission for that message cannot be established, hold contacts out of the proposed marketing import.
Reconcile exclusions
Combine current opt-outs and other do-not-send decisions from every relevant marketing route. If records conflict, exclude the address until the evidence is reviewed. Keep reasons distinct: a requested unsubscribe, invalid address, missing permission and an organisation-initiated pause do not mean the same thing.
Check how the destination applies exclusions, including whether they cover separate audiences and how existing contacts are handled during suppression imports. Mailchimp provides an Import Suppression Lists workflow; check the destination’s documented scope and verify the outcome. An import summary alone cannot prove every exclusion took effect.
Prepare the handover
After the permission and exclusion review, create an eligible import file. Keep a reconciliation record of source files, extraction times, status mapping, unresolved records and the decision owner. Include the contact and route, consent terms, action, date/time, consent category and the reason for any exclusion so the decision can be traced to evidence.
Limit access to personal data and retain it under the organisation's applicable arrangements. Keep original exports unchanged and preserve links or copies of evidence held outside the provider, such as checkout or support records.
Before sending, compare controlled or appropriately authorised destination records with their source evidence. Include a recent signup, an older signup, an opt-out, a record lacking permission and an address found in more than one source.
Check the stored status and the audience rule that uses it. The handover is ready when the team can explain why the proposed marketing group is eligible and how later opt-outs will remain effective.


![Check if subscribers still want emails: Under the Spam Act 2003 (Cth), consent and a working unsubscribe link are mandatory.; Use Mailchimp’s inactive segment only as a starting point—verify permission and signup context.; If no response by [date], pause the newsletter, not unsubscribe, per policy. Asking subscribers whether they still want emails](/covers/asking-subscribers-whether-they-still-want-emails-640.webp?v=5d185c05)
