Analytics and Tracking

Consent Log

Also called consent record, consent receipt

An auditable record of which visitor agreed to what, when they agreed, and which wording they were shown.

Quick facts: Consent Log

Category
Analytics and Tracking
Also called
consent record, consent receipt
Level
Intermediate
Affects
Legal defensibility, email deliverability, data retention decisions
Where to see it
Your consent management platform's records export, CRM consent fields, form submission logs
In this article4
  1. How a consent log works
  2. Why a consent log matters
  3. Where consent logs go wrong
  4. How to act on it

The log is written by your consent platform at the moment a choice is made. A record that is actually worth keeping holds a pseudonymous identifier for the browser or account, a timestamp, the exact set of purposes granted and denied, the version of the banner and policy wording that was on screen, and the route the choice came through — banner, preference centre or a tick box on a form.

Because consent can be withdrawn or changed, the log is a history rather than a current state. Each change appends a new entry and nothing is overwritten. That is what lets you answer the harder question: not only whether this person consents today, but whether they consented on the day you sent that campaign.

Under most privacy laws the burden of proof sits with you, not with the person complaining. “Our banner was configured correctly” is an assertion. A record showing the wording that was displayed and the button that was pressed is evidence, and it is the only thing that turns a policy into something you can defend.

It earns its keep internally too. When you rewrite your privacy notice or add a new purpose, only the log tells you which people agreed to the old version and therefore need asking again. It also settles the recurring argument between a sales team certain a lead opted in and a marketer about to delete the contact.

The commonest weakness is a record that stores a yes or no and a date and nothing else. It proves somebody clicked something; it does not prove what they were told. If your wording has changed since, that entry is close to useless.

The opposite failure is stuffing the log with personal detail — full names, addresses, anything not needed to identify the choice — so the compliance record becomes its own privacy problem. The third is retention: keeping the log for less time than the marketing it justifies, so the proof expires while the emails carry on going out.

How to act on it

Ask your consent platform three questions: where the records are stored, how you export them, and how long they are kept. Export a sample and check you can find one individual’s full history without help from the vendor. If you cannot, you do not really have a log, you have a dashboard.

Then look outside the banner. Newsletter boxes, enquiry forms and offline sign-ups all capture consent too, and they usually write nowhere. Route them into the same record with the same fields, and make sure withdrawal is logged as carefully as agreement. A wider consent management review is the natural place to do that tidy-up.

Do and do not

Do

  • Store the wording shown, not just a yes or no
  • Append every change so the record stays a history
  • Log withdrawals as carefully as agreements

Do not

  • Fill the record with personal detail you do not need
  • Delete the proof while still marketing to the person
  • Assume form and newsletter consents are captured automatically

Questions people ask about this

How long should I keep consent records?

There is no single answer that fits every law, but the practical rule is simple: keep the record for at least as long as you rely on the consent, plus the period in which someone could challenge it. Deleting the proof while still emailing the person is the one combination that never defends well. Write your chosen period into your retention policy.

Is a screenshot of my cookie banner enough?

No. A screenshot shows what the banner looked like on the day you took it, not what any individual saw or chose. Evidence has to be per person: their identifier, their timestamp, their granted and denied purposes, and the version of the wording on screen at that moment. Keep the screenshot as supporting material, not as the record.

Do I need a log if people only join my list by asking?

Yes, and that is the case where it is easiest to build. Store the form used, the time, the page it sat on, the wording of the consent line and the confirmation step if you use one. Inbox providers and regulators both ask the same question when a complaint lands, and a dated record answers it in seconds.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.