Consent Timestamp
A consent timestamp is the recorded date and time at which a user gave (or updated) their consent, for example the moment they clicked "Accept" on a cookie banner. It helps an organization show when consent was obtained and whether it is still current. On its own, a timestamp does not prove that the consent was valid; it is one part of a broader consent record.
A consent timestamp is a data point within a consent record capturing the exact time a user performed a consent-related action, such as accepting, refusing, or modifying their choices. It is typically stored alongside other evidence in a consent log (for example the choices made, the user or session identifier, and the applicable policy version) to support the accountability and demonstrability expectations associated with valid consent under the GDPR and comparable frameworks. Consent timestamps also underpin operational functions such as tracking the age of consent against internal renewal or re-consent policies, and may be exposed programmatically (for example via an API field like "consented_at"). The timestamp itself records only when an action occurred; whether that consent was freely given, specific, informed, and unambiguous depends on the surrounding facts and is out of scope for the timestamp field alone. Requirements around what must be logged, and for how long, differ across jurisdictions and evolving regulatory guidance.
Why it matters
Under the GDPR and comparable frameworks, organizations relying on consent are expected to be able to demonstrate that consent was obtained. A consent timestamp is one of the core pieces of evidence supporting this accountability expectation: it records when a user performed a consent-related action, such as clicking "Accept" on a cookie banner. Without a reliable record of when consent was given or updated, an organization may struggle to show a data protection authority, or the individual concerned, that a lawful basis existed at the relevant time.
The timestamp also plays an operational role in keeping consent current. Consent is not necessarily valid indefinitely, and many organizations set internal policies governing how long they treat a given consent as active before seeking renewal or re-consent. As one practitioner discussion illustrates, tracking the beginning of the consent period is what allows a business to apply such an internal retention or renewal policy and to determine when a fresh consent action is needed. The timestamp is the anchor point for that calculation.
It is important not to overstate what a timestamp proves. Recording the moment of a click does not, by itself, establish that consent was freely given, specific, informed, and unambiguous; those qualities depend on the surrounding circumstances, such as the design of the banner and the choices actually presented. The ICO notes, for example, that where an individual has no real choice, consent is not freely given and will be invalid. A timestamp is therefore best understood as one component of a broader consent record rather than as standalone proof of valid consent. What must be logged, and for how long, varies across jurisdictions and continues to evolve with regulatory guidance.
Who it's relevant to
Inside Consent Timestamp
Common questions
Answers to the questions practitioners most commonly ask about Consent Timestamp.

