Quick Answer: CRM systems should store consent as immutable, timestamped, channel-specific records tied to a unique lead identity, not as a single editable checkbox. Each opt-in or withdrawal event should capture the source, legal basis, purpose, jurisdiction, proof of consent, and the exact version of the notice presented so the business can demonstrate compliance on demand.
A compliant CRM model treats consent as a lifecycle event, not a static field. Best practice is to maintain a normalized consent ledger linked to the lead record, where every opt-in, opt-out, suppression, and preference change is logged with metadata such as timestamp, acquisition channel, campaign or form ID, IP address where lawful, consent language version, jurisdiction, and processing purpose. This creates an auditable trail that supports GDPR, CCPA/CPRA, CAN-SPAM, TCPA, and similar regulations while preventing downstream systems from using stale or ambiguous permission states. The CRM should also separate marketing consent from transactional communications, store the current status plus historical events, and enforce synchronization to email, SMS, outbound calling, and ad audiences so compliance is preserved across every activation point.