Consent Record
A consent record is documented proof that a person agreed to have their personal data collected, processed, or stored. In the cookie context, it typically captures what a user consented to and when, so an organisation can later show that valid consent was obtained. These records support an organisation's ability to demonstrate compliance, but keeping records does not by itself guarantee that the underlying consent was validly obtained.
A consent record is a retained account of a data subject's consent, generally intended to help a controller demonstrate that consent meets applicable standards. According to ICO guidance, records should typically capture when consent was given (for example, a dated document or online records including a timestamp, or, for oral consent, a note of the time and date). In practice, consent records for cookies and similar technologies (including pixels, local storage, and SDKs) are often generated and stored by a consent management platform (CMP) and may also capture the version of the notice shown and the specific categories or purposes accepted or refused; however, the precise fields and retention practices depend on the applicable framework and are not fully specified by the evidence here. Consent records support accountability obligations but do not substitute for meeting the substantive requirements for valid consent, and specific record-keeping expectations may vary across the EU, the UK, and other regimes.
Why it matters
Under the GDPR and its UK equivalent, controllers must be able to demonstrate that valid consent was obtained. A consent record is the practical means of meeting that accountability expectation: when a data protection authority, a user, or an internal auditor asks whether consent was given, the record is what an organisation points to. Without documented proof of what a person agreed to and when, an organisation may struggle to show that it relied on a lawful basis for placing non-essential cookies or processing the personal data that follows, even if consent was in fact collected.
It is important to keep the limits of a consent record in view. Holding a record does not, by itself, mean the underlying consent was validly obtained. If the consent mechanism was defective, for example, relying on pre-ticked boxes, implied consent from continued browsing, or a design that did not meet the standard of a clear affirmative action, then a tidy log of that interaction does not cure the defect. The record supports the demonstration of compliance; it does not substitute for the substantive requirements that consent be freely given, specific, informed, and unambiguous.
Expectations for what a record should contain and how long it should be kept vary across the EU, the UK, and other regimes, and specific fields and retention practices are not fully settled by any single source. ICO guidance indicates that records should generally capture when consent was given, such as a dated document or online records including a timestamp, but organisations should treat record-keeping as one part of a broader compliance posture rather than a guarantee in itself.
Who it's relevant to
Inside Consent Record
Common questions
Answers to the questions practitioners most commonly ask about Consent Record.

