Skip to main content
Promotional banner for the pentest readiness checklist
Category: Consent Records

Proof of Consent

Also known as: Consent Record, Consent Logging, Record of Consent
Simply put

Proof of consent refers to the records an organization keeps to demonstrate that a person actually agreed to something, such as the use of non-essential cookies. In the cookie context, it is not enough to obtain agreement; an organization generally needs to be able to show what a user was told and that they took a clear action to consent. These records help demonstrate accountability if a regulator or individual later questions whether valid consent was obtained.

Formal definition

Proof of consent is the documented evidence used to demonstrate that valid consent was obtained, reflecting accountability expectations under regimes such as the UK GDPR and EU GDPR. Under UK ICO guidance, valid consent requires that it be obvious the individual has consented and clear what they consented to, which in practice means records should capture who consented, what they were told (the information presented), when and how consent was given, and the specific scope of what was agreed. For cookies and similar technologies, this typically means logging the consent action alongside the version of the consent notice or banner and the categories accepted or rejected, since consent must be a clear affirmative action rather than implied. The evidence provided does not specify mandated retention periods, technical logging formats, or jurisdiction-specific record-keeping rules, and requirements and enforcement positions may differ across the EU, UK, and other regimes; consult applicable law and current data protection authority guidance for specifics.

Why it matters

Under the accountability principle reflected in the UK GDPR and EU GDPR, an organization must be able to demonstrate that it obtained valid consent, not merely assert that it did. In the cookie context, this means that securing a user's agreement to non-essential cookies is only part of the obligation; if a regulator or an individual later questions whether consent was valid, the organization generally needs records showing what the user was told and that they took a clear affirmative action to agree. Without such proof, an organization may struggle to defend its practices even where consent was, in fact, sought.

This matters because valid consent is not a one-time technical event but a demonstrable state. UK ICO guidance indicates that it must be obvious the individual has consented and clear what they consented to, which requires more than a confirmation that terms were read. Records that capture the information presented, the scope of what was agreed, and the affirmative action taken help an organization show that these standards were met. The absence of reliable records can leave an organization exposed if the lawfulness of its cookie use is challenged.

Because requirements and enforcement positions may differ across the EU, the UK, and other regimes, proof-of-consent practices should be aligned with applicable law and current data protection authority guidance rather than assumed to be uniform. The evidence here does not specify mandated retention periods, technical logging formats, or jurisdiction-specific record-keeping rules, so organizations should treat those details as matters to be resolved by reference to the specific regimes that apply to them.

Who it's relevant to

Privacy and data protection officers
Those responsible for demonstrating accountability need proof-of-consent records to show that valid consent was obtained if a regulator or individual raises questions. They typically oversee what information is logged, including the notice version presented and the categories a user accepted or rejected.
Legal and compliance counsel
Counsel advising on cookie practices rely on consent records to assess whether the standard that it be obvious an individual consented, and clear what they consented to, can be evidenced. They also help determine record-keeping expectations under the specific regimes that apply, since requirements may differ across the EU, UK, and other jurisdictions.
Web developers and CMP implementers
Those configuring consent banners and consent management platforms are typically responsible for capturing the consent action alongside the banner version and the specific categories accepted or rejected, ensuring the log reflects a clear affirmative action rather than implied consent.
Marketing and analytics teams
Teams deploying non-essential cookies, pixels, SDKs, and similar technologies depend on reliable consent records to confirm that a given user agreed to the relevant categories before those technologies are used, supporting compliance without assuming that agreement alone is sufficient.

Inside Proof of Consent

Consent record
A stored account of an individual user's consent decision, typically capturing which categories or purposes (for example analytics or advertising) were accepted or refused. This underpins the GDPR accountability principle, which requires controllers to be able to demonstrate that valid consent was obtained.
Timestamp
The date and time the consent choice was made or subsequently changed, allowing an organization to show when consent was captured and, where relevant, to manage re-consent as guidance or configurations evolve.
Consent scope and purposes
A record of the specific purposes the user consented to, reflecting the GDPR requirement that consent be specific and granular. Because ePrivacy rules govern the placing of and access to information on the device while the GDPR governs any subsequent processing of personal data, the record may need to reflect both dimensions.
Version of the consent notice or configuration
A reference to the wording, banner version, or CMP configuration presented to the user, so that an organization can show what information the user was given at the time consent was collected, supporting the informed element of valid consent.
Method of capture
Details of how the affirmative action was obtained, which is relevant to demonstrating consent was freely given, specific, informed, and unambiguous under the GDPR. Records may also note where an opt-out mechanism was used instead, as is common under certain US state frameworks rather than the EU opt-in model.
Signal or identifier reference
Where applicable, a reference linking the record to a technical mechanism such as a CMP entry, a TCF string, or a browser-based signal like Global Privacy Control. These references help tie the stored proof to the actual behavior of consent technologies, though they do not by themselves establish legal validity.

Common questions

Answers to the questions practitioners most commonly ask about Proof of Consent.

Does storing a user's consent choice in a cookie count as adequate proof of consent?
Not on its own. A cookie or local storage value that reflects the user's current preference helps enforce that choice on the user's device, but it is not a reliable record of how and when consent was obtained. Proof of consent generally refers to server-side or otherwise durable records that capture the relevant details of the consent event, because device-based values can be cleared, altered, or lost. In most EU jurisdictions, controllers are expected to be able to demonstrate consent under the GDPR's accountability principle, and a client-side flag alone typically falls short of that expectation.
If I use a consent management platform, does it automatically satisfy my obligation to demonstrate consent?
A CMP can support this obligation by logging consent events, but it does not by itself guarantee compliance. The controller remains responsible for ensuring the records are complete, accurate, retained appropriately, and reflect consent that was genuinely freely given, specific, informed, and unambiguous. You should verify what your CMP actually logs, how long it retains records, and whether those records align with the version of the consent notice presented. Tools support compliance; they do not replace legal judgment or accountability.
What information should a proof-of-consent record generally capture?
There is no single universally mandated schema, but records are typically expected to help demonstrate that valid consent was given. In practice this often includes an identifier for the user or session, the date and time of the consent action, the specific purposes or cookie categories consented to, and a reference to the version or content of the notice and consent interface shown at that moment. Some organizations also capture the mechanism of consent (for example, the affirmative action taken). What is sufficient can depend on the jurisdiction and the applicable data protection authority's guidance, so treat any specific list as illustrative rather than definitive.
How long should consent records be retained?
Retention should generally be tied to the purpose of keeping the record, which is being able to demonstrate valid consent for as long as the related processing relies on it, plus any period needed to defend against potential claims. There is no single fixed retention period that applies everywhere, and requirements can differ between the EU, the UK, and individual jurisdictions. At the same time, the record itself may contain personal data, so it should not be kept indefinitely without justification. Setting a documented, purpose-based retention approach and reviewing it against applicable guidance is advisable.
How should proof-of-consent records be linked to changes in the consent notice over time?
Because valid consent must be informed, the record should be able to show what the user was actually presented with when they consented. This is commonly handled by versioning the notice, banner text, and purpose descriptions, and storing a reference to the applicable version alongside each consent event. When the notice or purposes change materially, a new consent interaction may be needed rather than relying on prior records. The exact point at which re-consent is required can be a matter of interpretation, so this is an area to assess with legal input.
How does proof of consent differ where opt-out frameworks apply instead of opt-in?
The core concept shifts with the applicable regime. In most EU jurisdictions, where prior opt-in consent is typically required for non-essential cookies, records aim to demonstrate that affirmative consent was obtained. Under several US state privacy laws that rely on opt-out mechanisms, the relevant demonstration often relates to honoring opt-out requests and, where applicable, respecting signals such as Global Privacy Control, rather than proving affirmative opt-in. Because obligations and record-keeping expectations vary by jurisdiction, you should scope your proof-of-consent approach to the specific frameworks that apply to your users.

Common misconceptions

Using a consent management platform automatically produces adequate proof of consent and guarantees compliance.
A CMP can generate and store consent records, but tools support compliance rather than replace legal judgment. Whether the retained records actually demonstrate freely given, specific, informed, and unambiguous consent depends on how the CMP is configured and on the legal assessment of the underlying practice.
Proof of consent obtained for placing cookies also proves lawful processing of any personal data collected afterward.
The ePrivacy rules govern the placing of and access to information on a device, while the GDPR governs any subsequent processing of personal data. Consent captured under one regime does not automatically satisfy the other, so proof may need to address both aspects separately.
One record-keeping approach satisfies obligations everywhere.
Requirements differ by jurisdiction. In most EU jurisdictions the emphasis is on demonstrating opt-in consent, whereas frameworks such as certain US state privacy laws often rely on opt-out signals, so the nature and content of the proof that is expected can vary and should be assessed against the applicable regime.

Best practices

Record the key elements of each consent decision, including the purposes accepted or refused, a timestamp, and the version of the notice or configuration shown, to support the GDPR accountability principle.
Keep the proof for placing or accessing information on the device distinct from the proof supporting any subsequent processing of personal data, since the ePrivacy and GDPR requirements are separate.
Capture the method by which the affirmative action was obtained, and where an opt-out model applies under a US state framework, record that mechanism rather than assuming an opt-in record applies.
Confirm that records reflect genuine affirmative choices, since pre-ticked boxes, implied consent from continued browsing, and cookie walls are widely considered non-compliant in the EU and would not constitute valid proof there.
Align retained records with the applicable jurisdiction or jurisdictions, and document the scope so it is clear which regime a given record is intended to evidence.
Treat CMP-generated logs as supporting evidence rather than a compliance guarantee, and periodically review the configuration and legal basis with qualified advisers as regulatory guidance evolves.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide