Consent Metadata
Consent metadata is the supporting information recorded whenever a person gives or refuses permission for their data to be used, such as when the choice was made and what they were told at the time. It acts as a record that helps an organization show what a person actually agreed to. This information is generally kept so the organization can demonstrate that valid consent was obtained.
Consent metadata comprises the descriptive and contextual data fields captured alongside a consent decision, typically used to evidence and manage that decision within a consent management system. It may include details such as the identity or pseudonymous identifier of the data subject, the timestamp of the action, the specific purposes and processing scope consented to, the version of the notice or policy presented, the mechanism of the affirmative action, and any subsequent withdrawal. In the EU and UK context, such metadata supports the accountability and record-keeping expectations associated with demonstrating that consent met the standard in Article 4(11) of the GDPR/UK GDPR, namely freely given, specific, informed and unambiguous, though the precise fields required are not fixed by that definition and depend on the processing context. This entry addresses consent metadata as an organizational and technical construct; the specific data model, retention approach, and sufficiency for any given regulatory regime fall outside its scope and require separate legal assessment, as requirements and enforcement positions differ across jurisdictions.
Why it matters
Under the GDPR and UK GDPR, an organization relying on consent as its lawful basis is expected to be able to demonstrate that valid consent was obtained. Consent metadata is what makes that demonstration possible: without a record of when a choice was made, what the person was shown, and what they agreed to, an organization has little more than an assertion. Because valid consent under Article 4(11) must be freely given, specific, informed, and unambiguous, being able to point to contextual evidence, such as the version of the notice presented and the affirmative action taken, is generally central to meeting accountability and record-keeping expectations in the EU and UK.
Consent metadata also supports the ongoing management of a person's choices, not just the initial moment of collection. Consent can be withdrawn, notices can change, and processing purposes can evolve, so a record that captures timestamps, purpose scope, and any subsequent withdrawal helps an organization apply the right permissions over time. This matters both for honoring individual rights and for reconstructing, after the fact, what a given person actually agreed to.
The precise fields that count as sufficient are not fixed by the GDPR definition and depend heavily on the processing context and jurisdiction. Retaining consent metadata itself involves processing personal or pseudonymous data, so the record-keeping approach must be assessed against the same data protection principles rather than treated as a standalone technical exercise. Requirements and enforcement positions differ across the EU, the UK, and other regimes, so metadata that is adequate in one context may not be in another.
Who it's relevant to
Inside Consent Metadata
Common questions
Answers to the questions practitioners most commonly ask about Consent Metadata.

