Consent Receipt
A consent receipt is a record that captures what a person agreed to, when they agreed, and under which version of a policy or notice. It serves as evidence that consent was given for a specific processing purpose. It is typically issued or stored at the point where consent is collected and can be retrieved later to demonstrate what was agreed.
A consent receipt is a time-stamped, often tamper-evident record documenting a data subject's consent transaction, capturing the specified purposes of processing, the applicable policy or notice version, and, in some implementations, a verifiable hash for integrity. Operationally, receipts are generated at collection points and stored or retrieved via consent management systems (for example, through APIs that submit consent transactions or retrieve a receipt by identifier). A consent receipt functions as accountability evidence supporting a consent-based lawful basis; however, its existence does not by itself establish that consent was validly obtained, freely given, informed, or specific, nor that consent is the appropriate lawful basis for the processing in question. This definition addresses the record artifact and its typical contents only. It does not cover the substantive validity requirements for consent, the mechanics of withdrawal, jurisdiction-specific standards, retention obligations, or cross-border transfer considerations, which vary by legal regime and implementation.
Why it matters
Under accountability-oriented frameworks, an organization relying on consent as its lawful basis for processing generally needs to be able to demonstrate that consent was obtained, not merely assert it. A consent receipt provides a concrete, retrievable artifact capturing what a person agreed to, when, and under which version of a policy or notice, which supports that demonstrable evidence requirement. Without such a record, a controller may struggle to show what a data subject was told and agreed to at the moment of collection, particularly where policy text changes over time.
It is important to keep the record artifact separate from the substantive validity of consent. A consent receipt documents that a consent transaction occurred and what it referenced, but its existence does not by itself establish that the consent was freely given, specific, informed, or unambiguous, nor that consent was the appropriate lawful basis in the first place. Experts should avoid treating a stored receipt as proof of valid consent; it is evidence of the transaction, and the underlying collection mechanism must still meet the applicable legal standard. Similarly, a receipt does not address whether or how consent can be withdrawn, which is a distinct obligation.
Because treatment of consent differs across legal regimes, the value and required contents of a receipt depend on the jurisdiction and implementation context. A receipt should be understood as one accountability control among others rather than a compliance guarantee. It does not resolve retention, cross-border transfer, or jurisdiction-specific validity questions, all of which must be handled separately.
Who it's relevant to
Inside Consent Receipt
Common questions
Answers to the questions practitioners most commonly ask about Consent Receipt.