DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Rights & evidence

What is a Consent Receipt?

A consent receipt is a structured record of a user's consent decision that captures what the user agreed to, when the decision was made, which purposes and processing activities were covered, and the notice or policy presented at the time.

A consent receipt helps an organisation demonstrate and audit consent rather than relying on a simple “consent = true” database value or a screenshot of a consent banner.

Under GDPR, when processing is based on consent, the organisation must be able to demonstrate that the individual consented. Effective consent records should therefore preserve information such as who consented, when consent was given, what the individual was told, and how consent was obtained.

In India, the DPDP Act also provides that where consent is the basis for processing and the validity of consent is questioned, the Data Fiduciary must be able to prove that the required notice was given and consent was obtained in accordance with the Act and applicable rules.

Consent Receipt in simple terms

Think of a consent receipt as a digital proof of a consent decision.

For example, a visitor opens a website and chooses:

  • Analytics cookiesAllowed
  • Advertising cookiesDenied
  • Personalised advertisingDenied
  • Functional cookiesAllowed

A useful consent receipt can preserve the decision together with the context needed to reconstruct it, such as:

  • Consent receipt or transaction ID
  • Date and time
  • User or pseudonymous identifier
  • Consent categories or purposes
  • Services, vendors, or processing activities covered
  • Consent status for each purpose
  • Version of the privacy or consent notice
  • Method or channel through which consent was collected
  • Relevant jurisdiction or regulatory context
  • Timestamp of a later withdrawal or change
  • Evidence linking the decision to the applicable notice

The exact fields depend on the implementation, jurisdiction, and use case.

Why are Consent Receipts important?

A consent banner only shows the interface presented to users. It does not necessarily prove what a particular user selected at a particular time.

A consent receipt provides an auditable representation of an individual consent transaction.

This is especially important when an organisation needs to answer questions such as:

  • What did this user consent to?
  • When did they consent?
  • Which privacy notice did they see?
  • Which purposes were covered?
  • Did they later withdraw consent?
  • What consent state was active when processing occurred?

A strong consent-management system should therefore preserve enough evidence to reconstruct the relevant consent event.

The ICO's guidance recommends maintaining an effective audit trail and recording who consented, when they consented, what they were told, and how consent was obtained.

Consent Receipt vs Consent Record

The terms consent receipt and consent record are closely related but should not automatically be treated as identical.

Consent record

A consent record is the underlying evidence maintained by an organisation or consent-management system.

It may contain detailed technical information about:

  • The consent event
  • User identifier
  • Timestamp
  • Notice version
  • Purposes
  • Vendors or services
  • Consent status
  • Collection method
  • Withdrawals
  • Changes to preferences
  • Jurisdiction
  • Technical metadata

Consent receipt

A consent receipt is a representation of that consent transaction that can be presented to or made available to the individual and used as evidence of the decision.

The Kantara Consent Receipt Specification describes a consent receipt as a record of authority granted by an individual to a controller for processing personal information and defines a human-readable representation that can also be represented in JSON.

Why the distinction matters

A database may contain thousands of internal consent events, while a user-facing consent receipt may provide a clear representation of a particular individual's consent decision.

What should a Consent Receipt contain?

There is no single universal field list that every organisation must use for every consent transaction.

However, a robust consent receipt should contain enough information to establish the context and substance of the decision.

1

Consent identifier

A unique identifier allows the organisation to locate and reference a particular consent transaction.

2

Timestamp

The receipt should record when the consent decision occurred, ideally with appropriate timezone or UTC information.

3

User or subject identifier

The record should identify the relevant individual or device in a proportionate way.

Depending on the implementation, this could be an account identifier, pseudonymous identifier, session identifier, or another appropriate reference.

4

Consent status

The receipt should show whether a particular purpose, category, or processing activity was:

  • Granted
  • Denied
  • Withdrawn
  • Changed

A granular record is generally more useful than a single overall “accepted” value.

5

Purposes

The receipt should identify what the consent covered.

For example:

  • Analytics
  • Personalised advertising
  • Marketing communications
  • Personalisation
  • Data sharing
  • Specific product functionality

Consent should not be represented as broader than the purposes for which it was actually obtained.

6

Notice or policy version

The organisation should be able to identify the privacy notice, consent notice, or other information presented when consent was obtained.

This is particularly important when notices change over time.

A record saying “user consented” is much weaker than one that can establish:

User → consent event → purpose → notice version → timestamp.

7

Collection method

The receipt can record how consent was obtained, such as:

  • Website consent banner
  • Preference centre
  • Mobile application
  • Account settings
  • Consent Manager
  • Written form
  • Other supported channel
8

Services or vendors

Where relevant, the receipt can identify the services, vendors, cookies, tags, or processing activities associated with the decision.

This is particularly useful for cookie consent and advertising technology environments.

9

Withdrawal or subsequent changes

Consent is not necessarily a permanent decision.

A consent-management system should therefore be able to associate later preference changes or withdrawals with the original consent history.

Is a Consent Receipt required by GDPR?

GDPR requires demonstrable consent when consent is used as the lawful basis for processing, but it does not simply mandate a document called a “Consent Receipt” in every case.

Article 7(1) requires the controller to be able to demonstrate that the data subject consented to processing. The practical implication is that organisations need reliable evidence of consent.

A consent receipt can be an effective way of representing that evidence, but organisations should distinguish between:

  • The legal requirement to demonstrate consent; and
  • A particular technical implementation for recording or presenting that evidence.

This distinction is important for accurate GDPR compliance content.

Consent Receipts and GDPR consent

For consent to be useful as a GDPR lawful basis, the underlying consent must meet the applicable requirements.

A consent receipt does not make invalid consent valid.

For example, a receipt cannot fix a consent mechanism that:

  • Uses pre-ticked boxes where affirmative action is required
  • Bundles unrelated purposes together
  • Does not provide sufficient information
  • Makes withdrawal unnecessarily difficult
  • Records consent without preserving the relevant context
  • Misrepresents a refusal as consent

The receipt proves the decision that occurred. It does not replace the requirement to collect valid consent in the first place.

What does GDPR require you to record about consent?

The ICO recommends keeping records that demonstrate:

  • Who consented
  • When they consented
  • What they were told
  • How consent was obtained

The organisation should also retain sufficient information to demonstrate the consent decision for as long as it is relying on consent as the basis for processing.

This makes notice versioning particularly important.

For example:

Consent date
10 September 2026
Notice version
Privacy Notice v4.2
Purpose
Analytics
Decision
Granted
Collection method
Website CMP
Receipt ID
CR-XXXXXXXX
Status
Active

The precise implementation can differ, but the evidence should be meaningful and reconstructable.

Consent Receipts under the DPDP Act in India

The Digital Personal Data Protection Act, 2023 (DPDP Act) uses the terminology Data Principal and Data Fiduciary rather than GDPR's “data subject” and “controller” terminology.

Section 6 provides that consent must be free, specific, informed, unconditional and unambiguous, given through clear affirmative action and limited to the personal data necessary for the specified purpose.

Importantly, where consent is the basis for processing and its validity is questioned, the Data Fiduciary must prove that the required notice was given and consent was obtained in accordance with the Act and applicable rules.

The final DPDP Rules also contain specific requirements for registered Consent Managers. A Consent Manager must maintain records of consents given, denied or withdrawn, notices preceding or accompanying consent requests, and certain sharing of personal data. The rules also provide for Data Principal access to those records and machine-readable availability on request, with specified retention requirements.

This makes consent evidence particularly relevant to ConsentX's India-focused compliance content.

Consent Receipt vs Consent Banner

These are not the same thing.

Consent BannerConsent Receipt
User interface for collecting a decisionRecord or representation of the decision
Appears before or during consentCreated from the consent event
Shows available choicesRecords what was actually selected
Focuses on user interactionFocuses on evidence and auditability
May change when the website design changesShould preserve the historical consent context
Does not by itself prove an individual's choiceCan provide evidence of the individual's decision

A screenshot of a consent banner can show what a website looked like.

A consent receipt should help demonstrate what a particular individual decided.

Consent Receipt vs Cookie Consent

Cookie consent is a specific use case for consent management.

A website may collect consent for:

  • Analytics cookies
  • Advertising cookies
  • Personalisation
  • Social media technologies
  • Other non-essential trackers

The consent receipt can preserve the resulting choices.

For example:

  • AnalyticsGranted
  • AdvertisingDenied
  • FunctionalGranted

The underlying consent system should also maintain the relevant timestamp, notice version, and other evidence needed to interpret the decision.

Consent Receipt vs Consent Management Platform

A Consent Management Platform (CMP) is the technology used to collect, manage, enforce, and often record consent preferences.

A Consent Receipt is evidence or a representation of a particular consent transaction.

In simple terms:

CMP =

system that manages consent.

Consent record =

evidence stored by the system.

Consent receipt =

representation of a consent decision.

A CMP can therefore generate or maintain consent receipts as part of its broader consent-management functionality.

What is a tamper-evident Consent Receipt?

A tamper-evident consent receipt is designed so that unauthorised changes to the evidence can be detected.

This can involve techniques such as:

  • Cryptographic hashes
  • Hash chains
  • Digital signatures
  • Immutable or append-only storage
  • Versioned records
  • Secure timestamps
  • Audit logs

The purpose is not to make a consent record magically “legal proof,” but to improve the integrity and auditability of the evidence.

For example, a hash chain can link successive consent records so that unauthorised modification of an earlier record can be detected.

ConsentX uses tamper-evident consent records and describes its implementation as using a SHA-256 hash chain. The current ConsentX glossary page specifically positions this as a mechanism for making consent evidence independently verifiable and difficult to backdate.

Is a screenshot enough to prove consent?

Usually, a screenshot alone is weak evidence.

A screenshot can demonstrate what a consent interface looked like at a particular point in time, but it generally does not establish that a particular individual made a particular selection.

Stronger evidence can connect:

individual or identifier + timestamp + consent decision + purposes + notice version + collection method.

This is why consent records and receipts are important for audit readiness.

What happens when a user withdraws consent?

Withdrawal should be treated as part of the consent lifecycle.

A useful consent system should preserve:

  • The original consent decision
  • The date and time of consent
  • The purposes covered
  • The later withdrawal or preference change
  • The date and time of withdrawal
  • The resulting consent state
  • Evidence that downstream processing or technologies were updated where required

For example:

  1. 10 SeptemberAnalytics consent granted
  2. 18 SeptemberAnalytics consent withdrawn
  3. 18 SeptemberConsent status changed to denied

This creates a much clearer audit trail than simply overwriting the original value.

What is consent evidence?

Consent evidence is the broader set of information an organisation maintains to demonstrate that consent was validly obtained and managed.

It may include:

  • Consent receipts
  • Consent records
  • Notice versions
  • Consent logs
  • Preference changes
  • Withdrawal records
  • CMP configuration
  • Audit logs
  • Timestamp information
  • Vendor or processing information
  • Technical records showing enforcement

A consent receipt can therefore be one component of a wider consent evidence and audit system.

Consent Receipt and audit readiness

A mature consent-management process should make it possible to answer an auditor or regulator's questions without manually reconstructing historical events.

For each relevant consent event, an organisation should ideally be able to determine:

  • Who made the decision?
  • When was it made?
  • What did they consent to?
  • What did they refuse?
  • What information was presented?
  • Which notice version applied?
  • How was consent obtained?
  • Was consent later withdrawn?
  • What consent state was active when processing occurred?
  • Can the record be shown in a human-readable form?
  • Can its integrity be verified?

This is the practical value of consent receipts.

How Consent Receipts work

A typical consent-receipt workflow looks like this:

1

Present notice

The organisation presents the relevant privacy or consent information.

2

Collect the user's choice

The user makes a clear choice for one or more purposes.

3

Create a consent record

The system records the decision and relevant contextual information.

4

Generate the receipt

A human-readable representation of the consent event is generated.

5

Preserve the evidence

The organisation securely stores the consent record and associated metadata.

6

Enforce the decision

The user's choice is applied to relevant cookies, trackers, processing activities, or other technologies where applicable.

7

Record later changes

If the user changes or withdraws consent, the system records the subsequent event.

8

Provide evidence when required

The organisation can retrieve the relevant record for audits, compliance reviews, data-rights requests, disputes, or regulatory enquiries.

What makes a good Consent Receipt?

A strong implementation should be:

Specific

It should identify the purposes and processing covered by the decision.

Time-stamped

The organisation should know when the decision occurred.

Traceable

The receipt should be associated with the relevant user, session, or other appropriate identifier.

Versioned

The organisation should be able to identify the notice or policy version presented at the time.

Granular

Where consent is collected separately by purpose, the evidence should preserve those individual choices.

Secure

Consent evidence should be protected against unauthorised access and alteration.

Auditable

The organisation should be able to retrieve and interpret historical records.

Privacy-conscious

Consent evidence can itself contain personal information and should therefore be handled appropriately.

Consent Receipts and privacy by design

Consent evidence should not create unnecessary privacy risks.

A consent receipt may contain identifiers, timestamps, preferences, and information about an individual's interaction with a service.

Organisations should therefore consider:

  • Data minimisation
  • Access controls
  • Encryption
  • Retention periods
  • Pseudonymisation
  • Secure deletion
  • Audit logging
  • Appropriate user access

The goal is to create reliable evidence without collecting more personal information than necessary.

Common Consent Receipt mistakes

Mistake 1

Storing only “consent = true”

A Boolean value does not explain what the individual agreed to, when they agreed, or what they were told.

Mistake 2

Not versioning notices

If the privacy notice changes, the organisation may struggle to establish which version was presented when consent was obtained.

Mistake 3

Recording only acceptance

Refusals and withdrawals can be just as important as positive consent decisions.

Mistake 4

Overwriting historical consent

Replacing an old consent state with a new value can destroy useful audit history.

Mistake 5

Treating the receipt as proof of valid consent by itself

A receipt documents a consent event. It does not make an otherwise invalid consent mechanism compliant.

Mistake 6

Ignoring downstream enforcement

Recording “marketing consent withdrawn” is not enough if the organisation continues sending marketing communications based on that consent.

Mistake 7

Treating a banner screenshot as a consent record

The interface is not the same as the user's individual decision.

Mistake 8

Ignoring consent evidence security

Consent records can contain personal information and should be protected accordingly.

Consent Receipt and ConsentX

ConsentX is designed to help organisations collect, manage, enforce, and prove consent across privacy and consent workflows.

For consent evidence, ConsentX provides Consent Records & Audit Evidence, allowing organisations to maintain a structured record of consent decisions and their supporting context.

The current ConsentX implementation also describes tamper-evident consent records using a SHA-256 hash chain, designed to make unauthorised changes easier to detect and provide stronger auditability.

This can help organisations move from:

“We think the user consented.”

to:

“Here is the record showing what the user consented to, when, and under which consent context.”

Consent Receipt: Key Takeaways

  • A Consent Receipt is a structured representation of a user's consent decision.
  • A Consent Record is the underlying evidence maintained by an organisation or consent system.
  • GDPR requires organisations relying on consent to be able to demonstrate that consent was obtained.
  • A receipt does not make an otherwise invalid consent mechanism legally valid.
  • Good consent evidence should preserve who consented, when, what they were told, and how consent was obtained.
  • Notice and policy versions are important for reconstructing historical consent.
  • Withdrawals and preference changes should form part of the consent history.
  • Consent Receipts are useful for audits, compliance reviews, disputes, and evidence requests.
  • India's DPDP framework places specific evidentiary and record-keeping requirements around consent and Consent Managers.
  • Technical integrity measures such as hashing can strengthen auditability but should not be presented as a substitute for lawful consent.

Move from “we think they consented” to proof

ConsentX is designed to help organisations collect, manage, enforce, and prove consent across privacy and consent workflows. Its Consent Records & Audit Evidence maintain a structured record of consent decisions and their supporting context, with tamper-evident records built on a SHA-256 hash chain.

Frequently asked questions