Keep six provenance fields beside each creator email: its source URL, the route connecting it to the creator, the published business purpose, the first observation date, the last confirmation date, and the next review action. Keep the address itself in one contact record. This gives a teammate enough information to retrace the source without saving the creator's whole profile.
Creator email provenance answers where an address came from and what you saw there. Your team still needs a separate decision about whether its proposed message is permitted.
The six-field template
Use these fields on an existing contact record that already identifies the creator and the business email. They are a recommended record design, not a platform requirement or a complete privacy-compliance record.
| Field | What to retain | What to avoid |
|---|---|---|
| Source URL | The final page URL where the address appeared | A search-results URL or a vendor homepage |
| Connection to creator | A short route, such as creator profile to linked contact page | An unsupported claim that a matching name proves ownership |
| Published purpose | A short summary of the business label and any regional or topic limits | Turning an unlabelled address into a sponsorship contact |
| First observed | The date your researcher first saw this address at this source | The date someone imported an old spreadsheet |
| Last confirmed | The date someone reopened the source and confirmed the address and purpose | Updating it because the record was exported |
| Next review action | A dated action and reason, including hold or removal review where needed | A date that rolls forward without anyone reviewing the record |
If your CRM already records who edited a contact, use that audit history. Avoid repeating staff details in every provenance field. Assign responsibility for the review queue in your team's workflow.
The source URL should identify the contact location as closely as possible. Remove unnecessary tracking parameters. Never save session tokens or temporary signed access links as provenance.
For YouTube, the official business-inquiry help describes opening a channel's About section and selecting its email-address option. The address is visible only if the channel owner supplied one. A record should therefore name the channel URL and that route. A YouTube homepage link cannot tell a reviewer which channel supplied the address.
When the source is an external site, record how you reached it from the creator's profile. Use the contact-page ownership check when that connection is unclear.
Two completed examples
These are hypothetical records. The names, identifiers, domains and dates illustrate the template. No real email address appears here. Each column belongs to an existing contact record, so there is no need to copy the address into the provenance notes.
| Provenance field | Contact C-014, fictional creator Rowan | Contact C-027, fictional creator Mira |
|---|---|---|
| Source URL | https://rowan.example/contact | https://mira.example/partnerships |
| Connection to creator | Contact page linked from creator's public profile | Partnerships page linked from creator's own site |
| Published purpose | Sponsorship inquiries for Rowan | Manager handles UK partnerships for Mira |
| First observed | 2026-09-10 | 2026-09-12 |
| Last confirmed | 2026-09-24; address and label unchanged | 2026-09-12; manager address and UK scope observed |
| Next review action | Recheck on 2026-10-01 before proposed outreach | Hold; review on 2026-09-28 because proposed campaign is outside UK |
The dates are workflow examples, not email expiry periods. Rowan's row lets the reviewer reopen the source before outreach. Mira's row preserves a restriction that an address-only export would lose. The team should resolve the regional mismatch before considering a message.
When a source changes, do not mark the old address as freshly confirmed. Record the observed change and put the contact on hold while the team reviews it. If the new page has no business route, do not guess a replacement address.
Retain enough context, then stop
For teams subject to UK GDPR, the ICO's data-minimisation guidance says the data held must be adequate for its purpose and limited to what that purpose requires. That supports keeping a usable source trail while excluding unrelated personal details.
For this workflow, prefer a short note about the contact route over a full-page screenshot. A screenshot may capture personal photos, unrelated addresses or other details that do not help the next reviewer. If your organisation needs evidence of wording that may change, follow its approved evidence policy and capture only the relevant material.
Leave birthdays, family details, private profiles and speculative personality notes out of the provenance record. They do not explain where the business address came from. Keep contracts and correspondence in their own governed records, with access and retention suited to those purposes.
Modash's relationship-management article recommends onboarding material for new teammates and clear relationship ownership. A small source record can support that handoff: the next teammate can inspect the contact route without inheriting a folder of unrelated research.
Give review dates a decision
A review date should trigger two questions:
- Does the source still support this contact route and business purpose?
- Does the team still need to retain this record for its stated purpose?
These questions can have different answers. An address may still appear on a page after the campaign that justified collecting it has ended.
Under the ICO's storage-limitation guidance, retention needs a purpose-based justification. UK GDPR does not prescribe one fixed retention period for all contact records. Set your schedule with the person responsible for privacy, taking account of your purposes and applicable obligations. Both ICO pages currently carry notices that the guidance is under review following the Data (Use and Access) Act.
Use the next-review field to name the decision due: confirm the source, resolve changed representation, or review removal after a campaign closes. For the wider pre-campaign queue, follow the contact-list refresh process.
Do not erase a necessary no-contact control when cleaning up prospect data. The ICO's storage guidance recognises retaining enough information to avoid including someone in future direct marketing after an objection. Handle that limited record separately under your organisation's policy.
Check one record before exporting
Ask a teammate to reopen one source using only the six fields. Can they find the address, connect it to the creator and understand its published purpose? If they cannot, hold that record out of outreach until the gap is resolved.
A published business address alone does not establish permission for your proposed marketing. Limit any proposed contact to creator-welcomed business inquiries where applicable rules permit it. Use the public-contact import review for that separate decision.
Add the six fields to your next research batch, then assign the first dated review action before handing the records to outreach.



