Chat on WhatsApp

Evidence

Consent records, receipts, and evidence

A consent record is the operational memory of a choice. Consent evidence is what you can show later: which notice was live, what the person selected, and when that state changed.

What is a consent record?

A consent record is the stored decision for a person, site, and policy: an identifier, the time, the locale, the purposes, and the status, such as granted, denied, or withdrawn. Consent evidence adds the notice snapshot and, when you export it, cryptographic proof of that recorded decision.

A current toggle is not an audit trail

Privacy teams are often asked what someone agreed to six months ago, not what the banner says today. If the only artifact is the latest cookie, that question cannot be answered.

Consent Guru stores the decision with a consent identifier, timestamp, locale, and a snapshot of the notice that was shown. Changing or withdrawing a choice writes the new decision. It does not rewrite the earlier snapshot. Automated cleanup follows the retention settings you configure, and it skips records under a legal hold.

How a record moves through its life

  1. Step 1

    Collect

    The banner, preference center, or consent API records a specific action against the purposes on the published policy.

  2. Step 2

    Store

    The record keeps the identifier and the policy snapshot so a reviewer can see the wording that was presented.

  3. Step 3

    Prove

    A consent receipt can carry cryptographic proof: a SHA-256 hash of the canonical decision payload, then an HMAC-SHA256 signature.

  4. Step 4

    Update

    Withdrawal or a later preference change becomes the state enforcement follows. Historical evidence stays until retention, or a legal hold, says otherwise.

Key capabilities

Consent logs

Workspace views and audit logs cover the decision itself and the configuration or access changes around it.

Consent receipts

An export can show the recorded decision and the notice snapshot, for the person or the team that needs to explain it.

Consent history

The current choice and the historical snapshot are different objects. One can change while the other remains.

Retention you can describe

Retention windows cover consent evidence, consent records, audit events, and rights requests separately.

What teams use it for

  • A lookup by consent identifier when someone asks what they agreed to.
  • Proof that is tied to a notice version, not a screenshot of today’s banner.
  • Withdrawal that downstream systems can follow.
  • Legal holds when a matter requires the record to stay.

Privacy reviews

Show the snapshot and the audit entry instead of reconstructing a campaign from memory.

Support

Find the decision a person refers to without opening every tag manager.

Regulatory questions

Explain what was recorded. The record does not replace a lawyer’s view of whether the processing was lawful.

Privacy considerations

Evidence of a click is not evidence that every downstream vendor honored it. Pair records with consent enforcement for the tags you control.

Retention of consent evidence is itself processing of personal data. Set it to match the policy you have adopted.

Technical capabilities

Hashes and signatures

Notice snapshots can be hashed with SHA-256. Receipts can be signed with HMAC so a later export can be checked against tampering of the stored decision.

API lookup

Authenticated API keys can read or record consent from your backend. The browser SDK uses a different path and a site key.

Questions

1.What is a consent receipt?

A consent receipt is an export of a recorded decision and the circumstances stored with it: purposes, time, and the policy snapshot. In Consent Guru it can include cryptographic proof of that payload.

2.What is a consent audit trail?

It is the retained history of the decision plus the workspace audit log of configuration and access changes. Together they show what was recorded and what an administrator later changed.

3.Does withdrawal delete the old record?

No. The current choice updates. Historical consent evidence is kept according to your retention settings and any legal hold.

Related pages

This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.