Proof of Consent
Proof of consent refers to the records an organization keeps to demonstrate that a person actually agreed to something, such as the use of non-essential cookies. In the cookie context, it is not enough to obtain agreement; an organization generally needs to be able to show what a user was told and that they took a clear action to consent. These records help demonstrate accountability if a regulator or individual later questions whether valid consent was obtained.
Proof of consent is the documented evidence used to demonstrate that valid consent was obtained, reflecting accountability expectations under regimes such as the UK GDPR and EU GDPR. Under UK ICO guidance, valid consent requires that it be obvious the individual has consented and clear what they consented to, which in practice means records should capture who consented, what they were told (the information presented), when and how consent was given, and the specific scope of what was agreed. For cookies and similar technologies, this typically means logging the consent action alongside the version of the consent notice or banner and the categories accepted or rejected, since consent must be a clear affirmative action rather than implied. The evidence provided does not specify mandated retention periods, technical logging formats, or jurisdiction-specific record-keeping rules, and requirements and enforcement positions may differ across the EU, UK, and other regimes; consult applicable law and current data protection authority guidance for specifics.
Why it matters
Under the accountability principle reflected in the UK GDPR and EU GDPR, an organization must be able to demonstrate that it obtained valid consent, not merely assert that it did. In the cookie context, this means that securing a user's agreement to non-essential cookies is only part of the obligation; if a regulator or an individual later questions whether consent was valid, the organization generally needs records showing what the user was told and that they took a clear affirmative action to agree. Without such proof, an organization may struggle to defend its practices even where consent was, in fact, sought.
This matters because valid consent is not a one-time technical event but a demonstrable state. UK ICO guidance indicates that it must be obvious the individual has consented and clear what they consented to, which requires more than a confirmation that terms were read. Records that capture the information presented, the scope of what was agreed, and the affirmative action taken help an organization show that these standards were met. The absence of reliable records can leave an organization exposed if the lawfulness of its cookie use is challenged.
Because requirements and enforcement positions may differ across the EU, the UK, and other regimes, proof-of-consent practices should be aligned with applicable law and current data protection authority guidance rather than assumed to be uniform. The evidence here does not specify mandated retention periods, technical logging formats, or jurisdiction-specific record-keeping rules, so organizations should treat those details as matters to be resolved by reference to the specific regimes that apply to them.
Who it's relevant to
Inside Proof of Consent
Common questions
Answers to the questions practitioners most commonly ask about Proof of Consent.

