Consent Record
Documented proof that consent was obtained, including details of when, how, and what the individual consented to.
A consent record is a verifiable log that demonstrates an organization obtained valid consent from an individual for specific data processing activities. Under the GDPR’s accountability principle (Article 5(2)), organizations must be able to prove that consent was given. A complete consent record typically includes a unique user identifier, timestamp of the consent action, the version of the privacy notice or consent text presented, specific processing activities or cookie categories consented to, the method of consent collection, and IP address or session identifier.
Consent records are critical during regulatory audits and investigations. Data protection authorities expect organizations to produce consent records on demand, and the inability to do so can itself constitute a compliance violation. Best practices include storing consent records in a tamper-proof format, retaining them for the duration of the processing plus a reasonable period afterward, and maintaining version histories of consent texts so the exact wording presented to each user can be reconstructed.