Consent records
The operational record of a person’s current choice for a site and policy.
Consent
Collect a choice once, keep the consent log, and let the person withdraw without losing the audit trail of what was agreed.
Consent management is the practice of presenting a privacy choice, recording what the person decided, letting them change or withdraw that choice, and applying the current choice to the systems that process their data.
Teams often store a boolean on a profile and call it consent. That boolean cannot show the notice, the purposes, or a later withdrawal. Consent tracking needs those fields.
Consent Guru records the decision, the policy snapshot, and subsequent changes. Current state and historical evidence are not the same row rewritten in place.
Step 1
The banner or preference center asks for a specific action against the purposes you defined.
Step 2
The consent record includes an identifier, timestamp, locale, and the notice snapshot.
Step 3
Status can move from granted to denied or withdrawn. Analytics summarizes outcomes. The evidence snapshot remains.
Step 4
A consent receipt can carry cryptographic proof of the recorded decision for the snapshot that was signed.
The operational record of a person’s current choice for a site and policy.
Changing a choice writes the new decision. Automated cleanup does not delete historical evidence unless retention is explicitly configured and no legal hold applies.
Workspace audit logs cover configuration and access changes alongside the consent evidence itself.
A visitor can change or withdraw optional purposes in the preference center. The SDK follows the updated record.
Show a purpose list that matches the processing the product actually performs.
Look up a consent identifier when someone asks what they agreed to.
Exchange portable consent across domains that you have explicitly configured.
Consent is only one lawful ground. Do not label a record as consent if the organization is relying on another basis.
Retention of evidence can itself be personal data processing. Set retention in the product to match the policy you have adopted, and use legal holds when a matter requires preservation.
Server-side collection and lookup go through authenticated API keys, separate from the public SDK endpoints the browser calls.
Consent and rights events can be posted to your endpoint with an HMAC SHA-256 signature.
It is the ongoing process of collecting, storing, updating, and enforcing a person’s choices about specific purposes.
It is the retained history of the decision and of administrative changes, so a reviewer can see what was recorded and what was later configured.
No. The current choice updates, and historical consent evidence is kept according to your retention settings and any legal hold.
This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.