Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Consent Records

Consent Record

Also known as: Consent Log, Customer Consent Record, Consent Documentation
Simply put

A consent record is documented proof that a person agreed to have their personal data collected, processed, or stored. In the cookie context, it typically captures what a user consented to and when, so an organisation can later show that valid consent was obtained. These records support an organisation's ability to demonstrate compliance, but keeping records does not by itself guarantee that the underlying consent was validly obtained.

Formal definition

A consent record is a retained account of a data subject's consent, generally intended to help a controller demonstrate that consent meets applicable standards. According to ICO guidance, records should typically capture when consent was given (for example, a dated document or online records including a timestamp, or, for oral consent, a note of the time and date). In practice, consent records for cookies and similar technologies (including pixels, local storage, and SDKs) are often generated and stored by a consent management platform (CMP) and may also capture the version of the notice shown and the specific categories or purposes accepted or refused; however, the precise fields and retention practices depend on the applicable framework and are not fully specified by the evidence here. Consent records support accountability obligations but do not substitute for meeting the substantive requirements for valid consent, and specific record-keeping expectations may vary across the EU, the UK, and other regimes.

Why it matters

Under the GDPR and its UK equivalent, controllers must be able to demonstrate that valid consent was obtained. A consent record is the practical means of meeting that accountability expectation: when a data protection authority, a user, or an internal auditor asks whether consent was given, the record is what an organisation points to. Without documented proof of what a person agreed to and when, an organisation may struggle to show that it relied on a lawful basis for placing non-essential cookies or processing the personal data that follows, even if consent was in fact collected.

It is important to keep the limits of a consent record in view. Holding a record does not, by itself, mean the underlying consent was validly obtained. If the consent mechanism was defective, for example, relying on pre-ticked boxes, implied consent from continued browsing, or a design that did not meet the standard of a clear affirmative action, then a tidy log of that interaction does not cure the defect. The record supports the demonstration of compliance; it does not substitute for the substantive requirements that consent be freely given, specific, informed, and unambiguous.

Expectations for what a record should contain and how long it should be kept vary across the EU, the UK, and other regimes, and specific fields and retention practices are not fully settled by any single source. ICO guidance indicates that records should generally capture when consent was given, such as a dated document or online records including a timestamp, but organisations should treat record-keeping as one part of a broader compliance posture rather than a guarantee in itself.

Who it's relevant to

Privacy and data protection officers
DPOs and privacy teams rely on consent records to meet accountability obligations and to respond to regulator queries or user requests. They typically define what fields a record should capture and how long records are retained, bearing in mind that these expectations vary across the EU, the UK, and other regimes.
Legal and compliance counsel
Counsel use consent records as evidence when demonstrating that consent was obtained, while recognising that a record does not by itself prove the consent was valid. They assess whether the underlying consent mechanism met applicable standards and advise on record-keeping practices where guidance is unsettled or differs by jurisdiction.
Web developers and CMP implementers
Developers and those configuring a CMP are responsible for ensuring that consent interactions are captured accurately, including timestamps and, where applicable, the notice version and the categories or purposes accepted or refused. This extends to consent for pixels, local storage, and SDKs, not only conventional cookies.
Marketing and analytics teams
Teams deploying advertising and analytics technologies depend on consent records to confirm which tracking a given user permitted before activating tags. Accurate records help ensure non-essential technologies are only used where valid consent supports them, though the record does not remove the need for a compliant consent flow.

Inside Consent Record

User or device identifier
A reference that links the consent record to the individual or the device from which consent was captured, such as a pseudonymous ID, session identifier, or hashed value. This should be retained in a way that allows the record to be reconciled with a specific consent event without collecting more personal data than necessary.
Timestamp of the consent action
The date and time at which the user granted, refused, or modified consent. This supports demonstrating when consent was obtained and helps assess whether it remains current, since consent may need to be refreshed periodically depending on applicable guidance.
Scope of consent
The specific purposes or categories of cookies and similar technologies (for example, analytics, advertising, or functional) to which the user consented or objected. Because valid consent under the GDPR must be specific, the record should reflect granular choices rather than a single blanket acceptance.
Consent status per purpose
A record of whether each purpose or category was accepted or rejected, capturing partial consent where a user agrees to some purposes but not others.
Information presented at the time
A reference to the version of the cookie notice, banner text, or privacy information shown to the user, so it is possible to demonstrate what the user was informed of when the choice was made. This supports the requirement that consent be informed.
Method of consent capture
Details of the mechanism through which the affirmative action was taken, such as clicking an accept or reject control or configuring preferences, which helps evidence that consent was unambiguous and given by a clear affirmative action rather than inferred.
Technical and configuration metadata
Supporting data such as the CMP or its version, the applicable framework signals (for example TCF strings or Global Privacy Control), and jurisdiction or geolocation context that influenced which consent model was applied. This is context that helps interpret the record but does not by itself establish lawfulness.

Common questions

Answers to the questions practitioners most commonly ask about Consent Record.

Does a consent record itself prove that valid consent was obtained?
Not on its own. A consent record documents that a consent interaction occurred and captures details about it, but the record cannot cure defects in the underlying consent. If the consent was not freely given, specific, informed, and unambiguous, or was collected through a mechanism widely considered non-compliant in the EU (such as pre-ticked boxes, implied consent from continued browsing, or a cookie wall), then a well-formed record simply documents invalid consent. The record supports the accountability principle by evidencing what happened; it does not substitute for the legal validity of the consent itself. Whether consent was valid depends on the facts of the collection, not the existence of a log.
Is keeping a consent record only relevant under the GDPR, or does the ePrivacy Directive matter too?
Both regimes can be relevant, and they address different things. The ePrivacy Directive (and its national implementations) governs the placing of and access to information on a user's device, so it is central to the cookie consent that a record often documents. The GDPR governs the processing of any personal data that follows and contains the broader accountability and demonstrability expectations that shape how records are kept. A consent record frequently sits at the intersection of the two: it evidences consent relied on for device access under ePrivacy rules while also serving GDPR-oriented record-keeping expectations. Treating record-keeping as a purely GDPR matter risks overlooking the ePrivacy basis for the consent being recorded. Scope and specific obligations vary by jurisdiction, so national implementations should be checked.
What information is typically captured in a consent record?
Practice varies, but consent records commonly aim to capture enough detail to demonstrate the circumstances of the consent interaction. This may include a timestamp, an identifier for the user or device, the specific purposes or cookie categories the user accepted or rejected, the version of the consent notice or banner presented, and the mechanism through which the choice was made. Some organizations also retain the wording or configuration of the notice shown at that time so they can show what the user actually saw. There is no single universally mandated schema; what is appropriate depends on the jurisdiction, the technologies in use, and the guidance of the relevant data protection authority. Organizations should treat the specific fields as a matter for legal and technical judgment rather than assuming a fixed template applies everywhere.
How long should consent records be retained?
There is no single retention period that applies universally, and this definition does not fix one. Retention typically needs to balance the ability to demonstrate that valid consent was obtained against data minimization expectations, since a consent record may itself contain personal data whose retention must be justified. Some organizations align retention with the period over which the relevant consent is relied upon, plus a margin to address potential disputes or regulatory inquiries. Because guidance from data protection authorities evolves and expectations differ between the EU, the UK, and other regimes, the appropriate period is a fact-specific determination that should involve legal input rather than a default number.
Where do consent management platforms (CMPs) and frameworks like the IAB TCF fit into consent record-keeping?
A CMP commonly handles the collection and storage of consent records as part of its function, and frameworks such as the IAB Transparency and Consent Framework (TCF) define structured formats for representing and transmitting consent signals. These tools can standardize and automate much of the record-keeping burden. However, they support compliance rather than guarantee it: the configuration, the notices presented, and the underlying legal analysis remain the organization's responsibility. Reliance on a CMP or the TCF does not replace legal judgment about whether the consent being recorded meets the applicable standard, and the interpretation of some framework mechanisms has been subject to ongoing regulatory attention in the EU.
How do consent records relate to opt-out signals such as Global Privacy Control under US state laws?
The record-keeping picture differs depending on the legal model. In most EU jurisdictions, records typically document affirmative opt-in consent for non-essential cookies. Under several US state privacy laws (for example the CCPA and CPRA in California), the model often relies on opt-out rather than opt-in, so what needs to be documented may center on honoring opt-out requests and recognized signals such as Global Privacy Control. In practice this means an organization operating across regimes may need to evidence both affirmative consents and processed opt-out signals, depending on where users are located. The specific obligations, scope, and evidentiary expectations vary by jurisdiction, and this definition does not resolve how any particular framework treats a given signal.

Common misconceptions

Keeping a consent record automatically makes cookie practices compliant.
A consent record is evidence that supports accountability and helps demonstrate that consent was obtained, but it does not replace the underlying legal requirements. Consent must still be freely given, specific, informed, and unambiguous, and the record cannot cure a consent mechanism that failed those standards. Tools such as CMPs support compliance but do not guarantee it.
One consent record satisfies both the ePrivacy rules and the GDPR.
In the EU, the ePrivacy Directive and its national implementations govern the placing of and access to information on a device, while the GDPR governs any subsequent processing of personal data. A record should be capable of evidencing consent for both where applicable, and consent obtained under one regime does not automatically satisfy the other.
The same consent record content is required everywhere.
Record-keeping expectations vary by jurisdiction. EU and UK practice generally emphasizes evidencing opt-in consent, whereas several US state frameworks such as the CCPA and CPRA often rely on opt-out mechanisms, meaning what should be logged and how differs. The scope of any requirement depends on the applicable law and evolving guidance from data protection authorities.

Best practices

Capture granular records that reflect the specific purposes or categories a user accepted or rejected, rather than storing only a single accept-all outcome, to support the requirement that consent be specific.
Retain a reference to the version of the notice or banner shown at the time of consent so you can demonstrate what information the user was given, and update records when the information or purposes change.
Log enough context to evidence a clear affirmative action, including timestamp, method of capture, and consent status per purpose, while minimizing the personal data collected for this purpose.
Align retention and refresh practices with the applicable regime and current regulatory guidance, recognizing that expectations differ across the EU, the UK, and individual US states and may evolve over time.
Where you rely on a CMP or a framework such as the IAB TCF or Global Privacy Control signals, record the relevant configuration and signal data, but treat these tools as support for compliance rather than a substitute for legal judgment.
Ensure records can evidence both the ePrivacy consent to store or access information and any GDPR basis for subsequent processing where both apply, and consult qualified advice on jurisdiction-specific record-keeping obligations that fall outside this definition.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps