Skip to main content
Category: Legal Basis and Consent

Consent Records

Also known as: Consent Logs, Customer Consent Records, Consent Documentation
Simply put

Consent records are the documented proof that an individual agreed to have their personal data collected, used, or stored in a specific way. They typically capture what the person agreed to, when they agreed, and how the agreement was obtained. Keeping these records helps an organization show that it actually secured valid consent, rather than merely claiming it did.

Formal definition

Consent records are the evidentiary artifacts an organization maintains to demonstrate that it obtained valid consent where consent is the lawful basis relied upon for processing personal data. Under the EU GDPR and UK GDPR, consent is defined (Article 4(11)) as any freely given, specific, informed, and unambiguous indication of the data subject's wishes; consent records are the means of satisfying the accountability principle by evidencing that such consent was obtained. Per ICO guidance, records for online consent should generally capture the data submitted along with a timestamp linking the agreement to the relevant version of the data capture form, so the specific terms consented to can be reconstructed. Consent is only one of several lawful bases for processing, and consent records are relevant only where consent is the chosen basis; they do not substitute for a Records of Processing Activities obligation and are not themselves a data inventory. This entry addresses the nature and evidentiary function of consent records and does not cover consent withdrawal mechanics, retention periods for the records, cross-border transfer implications, or treatment under regimes outside the EU/UK GDPR framework, where requirements differ.

Why it matters

Under the EU GDPR and UK GDPR, consent is only one of several lawful bases for processing personal data, and where an organization chooses to rely on it, the accountability principle requires the organization to demonstrate, not merely assert, that valid consent was obtained. Consent records are the evidentiary artifacts that satisfy this demonstrable-accountability requirement. Without them, an organization relying on consent has no defensible way to show that the agreement was freely given, specific, informed, and unambiguous, as required by Article 4(11). Stating that consent was secured is not the same as being able to prove it.

The practical value of consent records lies in reconstruction. Because valid consent is tied to what the individual was actually told and agreed to, records that capture the terms presented at the moment of agreement allow an organization to show precisely what a given data subject consented to and when. Where consent was given online, ICO guidance indicates that records should generally include the data submitted along with a timestamp linking it to the relevant version of the data capture form, so the specific terms can be reconstructed later. This matters most when an individual disputes the scope of their agreement or when a supervisory authority asks the organization to substantiate its chosen lawful basis.

It is important not to overstate what consent records do. They are relevant only where consent is the lawful basis being relied upon, and they do not by themselves guarantee compliance, which depends on the quality of the consent obtained and the surrounding processing. They are also not a substitute for the separate Records of Processing Activities obligation, and they are not a data inventory. Retention of the records, withdrawal mechanics, cross-border transfer implications, and treatment under regimes outside the EU/UK GDPR framework fall outside the scope of this concept and are governed by separate requirements.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads need consent records to demonstrate compliance with the accountability principle where consent is the chosen lawful basis. They are typically responsible for ensuring that records capture enough detail, such as the submitted data and a timestamp tied to the relevant form version, to reconstruct what each data subject agreed to, and for confirming that consent is genuinely the appropriate basis rather than defaulting to it.
Privacy Engineers and Product Teams
Teams building consent capture into digital forms and interfaces implement the mechanisms that record the data submitted and the timestamp linking it to the specific version of the capture form. Their design decisions determine whether the organization can later reconstruct the exact terms presented, which is central to the record's evidentiary value.
Compliance and Legal Professionals
Compliance officers and legal advisers rely on consent records when substantiating the organization's lawful basis to a supervisory authority or responding to a data subject dispute over scope. They should be aware that these records are specific to consent-based processing, do not satisfy the separate Records of Processing Activities obligation, and do not by themselves guarantee compliance.
Information Governance Leads
Governance leads oversee the ownership, stewardship, and policy surrounding consent documentation so that records remain reliable and demonstrable evidence rather than stated intent. Note that retention periods for these records and their broader lifecycle are governed by separate requirements outside the scope of the consent record concept itself.

Inside Consent Records

Identity of the Consenting Data Subject
A reference linking the consent to a specific individual, allowing the record to be tied to the person whose personal data is processed. This is typically retained in a form that supports later verification of who gave consent.
Scope and Purposes of Processing Consented To
A description of what the data subject agreed to, including the specific processing purposes. Because consent under the EU GDPR and UK GDPR is generally expected to be specific and granular, the record should reflect the distinct purposes rather than a single blanket agreement.
Timestamp and Method of Consent
The date and time consent was obtained and the mechanism used to capture it, such as a web form or another affirmative action. This supports the accountability expectation that consent be demonstrable rather than merely asserted.
Information Presented at the Time of Consent
A record of what the data subject was shown or told when consenting, such as the version of the notice, privacy information, or consent wording, so it can be shown that consent was informed.
Consent Status and Withdrawal History
The current state of consent (given, withdrawn, expired) and a history of changes. Because data subjects generally have the right to withdraw consent, records should capture withdrawal events and their timing.

Common questions

Answers to the questions practitioners most commonly ask about Consent Records.

Does having a valid consent record mean we are compliant with our processing obligations?
No. A consent record demonstrates that consent was obtained and captures its details, but consent is only one of several lawful bases for processing under regimes such as the EU GDPR and UK GDPR. Even where consent is the chosen basis, a record alone does not guarantee compliance; the underlying consent must have been freely given, specific, informed, and unambiguous, and other obligations (transparency, data minimization, retention limits, and security) continue to apply independently. Compliance depends on context, jurisdiction, and implementation, not on the existence of the record itself.
If we rely on consent, does that cover all of our processing activities?
Not necessarily. Consent should not be conflated with the other available lawful bases, and it is generally tied to specific, defined purposes. Processing for purposes beyond those the individual consented to typically requires a separate lawful basis or fresh consent. Some processing may be better grounded in another basis entirely. Consent records evidence only the consent-based processing they document; they say nothing about activities relying on other lawful bases.
What information should a consent record typically capture?
A consent record generally captures who consented, when consent was given, what the individual was told at the time (including the purposes and, where relevant, the version of the notice or wording presented), the method by which consent was collected, and the scope of what was agreed. It should also reflect any subsequent withdrawal. This entry does not prescribe a fixed schema, and specific field requirements vary by jurisdiction, regime, and implementation.
How should withdrawal of consent be handled in the record?
Withdrawal should be recorded with equivalent detail to the original consent, including when and how it was made, and the record should make clear that it must be as easy to withdraw consent as to give it in regimes such as the EU GDPR and UK GDPR. The record should support demonstrating that processing based on that consent ceased where required. Note that withdrawal generally does not affect the lawfulness of processing carried out before withdrawal, and it does not by itself trigger deletion, which is governed by separate retention rules outside the scope of this entry.
Who is responsible for maintaining consent records?
The controller, as the party determining the purposes and means of processing, generally bears accountability for maintaining consent records and being able to demonstrate valid consent. A processor may operate the systems that capture or store consent on the controller's behalf under instruction, but this does not transfer the controller's accountability. Under governance frameworks, accountability requires demonstrable evidence, so the controller should be able to produce these records rather than merely assert that consent was obtained.
How do consent records relate to records of processing activities and data inventories?
They are distinct. Consent records evidence individual-level consent for consent-based processing. A records of processing activities obligation is an organization-level description of processing operations and is not the same as a data inventory tool, and neither is equivalent to a consent record. Some information may overlap, but maintaining one does not satisfy the others. This entry does not cover retention scheduling, cross-border transfer mechanics, or enforcement consequences, which are governed separately.

Common misconceptions

Consent records prove that processing is compliant.
Consent records demonstrate that consent was captured, but they do not by themselves guarantee compliance. Compliance depends on context, jurisdiction, and implementation, and consent is only one of several possible lawful bases for processing under the EU GDPR and UK GDPR. Consent should not be conflated with other lawful bases.
Keeping consent records is the same as maintaining a records of processing activities (ROPA) or a data inventory tool.
Consent records document individual data subjects' agreement to specific processing, whereas a records of processing activities obligation is a distinct accountability requirement, and neither is equivalent to a data inventory tool. These serve different purposes and should not be collapsed into one another.
Once consent is recorded, the record can be treated as static and permanent.
Consent can be withdrawn, and data subjects generally have the right to withdraw it. Consent records therefore need to reflect status changes and withdrawal events over time rather than being treated as a one-time capture.

Best practices

Capture consent in a granular, per-purpose form so records reflect the specific purposes agreed to rather than a single blanket agreement, consistent with the specificity expectation under the EU GDPR and UK GDPR.
Retain evidence of what the data subject was shown at the time of consent, including the version of the notice or consent wording, so consent can be shown to have been informed.
Record a timestamp and the method used to obtain consent to support the accountability principle that consent be demonstrable rather than merely stated.
Maintain withdrawal history and current consent status so records remain accurate as data subjects exercise their right to withdraw consent.
Do not rely on consent records alone to establish compliance; verify that consent is the appropriate lawful basis for the processing in the relevant jurisdiction and that other requirements are met.
Keep consent records distinct from, but consistent with, other accountability documentation such as records of processing activities, recognizing these serve different purposes.