How a consent log works
The log is written by your consent platform at the moment a choice is made. A record that is actually worth keeping holds a pseudonymous identifier for the browser or account, a timestamp, the exact set of purposes granted and denied, the version of the banner and policy wording that was on screen, and the route the choice came through — banner, preference centre or a tick box on a form.
Because consent can be withdrawn or changed, the log is a history rather than a current state. Each change appends a new entry and nothing is overwritten. That is what lets you answer the harder question: not only whether this person consents today, but whether they consented on the day you sent that campaign.
Why a consent log matters
Under most privacy laws the burden of proof sits with you, not with the person complaining. “Our banner was configured correctly” is an assertion. A record showing the wording that was displayed and the button that was pressed is evidence, and it is the only thing that turns a policy into something you can defend.
It earns its keep internally too. When you rewrite your privacy notice or add a new purpose, only the log tells you which people agreed to the old version and therefore need asking again. It also settles the recurring argument between a sales team certain a lead opted in and a marketer about to delete the contact.
Where consent logs go wrong
The commonest weakness is a record that stores a yes or no and a date and nothing else. It proves somebody clicked something; it does not prove what they were told. If your wording has changed since, that entry is close to useless.
The opposite failure is stuffing the log with personal detail — full names, addresses, anything not needed to identify the choice — so the compliance record becomes its own privacy problem. The third is retention: keeping the log for less time than the marketing it justifies, so the proof expires while the emails carry on going out.
How to act on it
Ask your consent platform three questions: where the records are stored, how you export them, and how long they are kept. Export a sample and check you can find one individual’s full history without help from the vendor. If you cannot, you do not really have a log, you have a dashboard.
Then look outside the banner. Newsletter boxes, enquiry forms and offline sign-ups all capture consent too, and they usually write nowhere. Route them into the same record with the same fields, and make sure withdrawal is logged as carefully as agreement. A wider consent management review is the natural place to do that tidy-up.