Consent Records
Consent records are the documented proof that an individual agreed to have their personal data collected, used, or stored in a specific way. They typically capture what the person agreed to, when they agreed, and how the agreement was obtained. Keeping these records helps an organization show that it actually secured valid consent, rather than merely claiming it did.
Consent records are the evidentiary artifacts an organization maintains to demonstrate that it obtained valid consent where consent is the lawful basis relied upon for processing personal data. Under the EU GDPR and UK GDPR, consent is defined (Article 4(11)) as any freely given, specific, informed, and unambiguous indication of the data subject's wishes; consent records are the means of satisfying the accountability principle by evidencing that such consent was obtained. Per ICO guidance, records for online consent should generally capture the data submitted along with a timestamp linking the agreement to the relevant version of the data capture form, so the specific terms consented to can be reconstructed. Consent is only one of several lawful bases for processing, and consent records are relevant only where consent is the chosen basis; they do not substitute for a Records of Processing Activities obligation and are not themselves a data inventory. This entry addresses the nature and evidentiary function of consent records and does not cover consent withdrawal mechanics, retention periods for the records, cross-border transfer implications, or treatment under regimes outside the EU/UK GDPR framework, where requirements differ.
Why it matters
Under the EU GDPR and UK GDPR, consent is only one of several lawful bases for processing personal data, and where an organization chooses to rely on it, the accountability principle requires the organization to demonstrate, not merely assert, that valid consent was obtained. Consent records are the evidentiary artifacts that satisfy this demonstrable-accountability requirement. Without them, an organization relying on consent has no defensible way to show that the agreement was freely given, specific, informed, and unambiguous, as required by Article 4(11). Stating that consent was secured is not the same as being able to prove it.
The practical value of consent records lies in reconstruction. Because valid consent is tied to what the individual was actually told and agreed to, records that capture the terms presented at the moment of agreement allow an organization to show precisely what a given data subject consented to and when. Where consent was given online, ICO guidance indicates that records should generally include the data submitted along with a timestamp linking it to the relevant version of the data capture form, so the specific terms can be reconstructed later. This matters most when an individual disputes the scope of their agreement or when a supervisory authority asks the organization to substantiate its chosen lawful basis.
It is important not to overstate what consent records do. They are relevant only where consent is the lawful basis being relied upon, and they do not by themselves guarantee compliance, which depends on the quality of the consent obtained and the surrounding processing. They are also not a substitute for the separate Records of Processing Activities obligation, and they are not a data inventory. Retention of the records, withdrawal mechanics, cross-border transfer implications, and treatment under regimes outside the EU/UK GDPR framework fall outside the scope of this concept and are governed by separate requirements.
Who it's relevant to
Inside Consent Records
Common questions
Answers to the questions practitioners most commonly ask about Consent Records.