Proof of consent: how to record it so it holds up with a regulator
Article 7 puts the burden on you to demonstrate that consent was given. A true/false column demonstrates nothing. Here is what a defensible record contains and how to keep it for the years you will need it.
Most consent problems are not consent problems. The shop did ask, the customer did agree, and nobody did anything wrong. The problem arrives two years later when somebody complains and the only evidence is a boolean column that says true.
The regulator's question is not "did they consent". It is "show me". Those are different questions and only one of them is answerable from a flag.
What a defensible record contains
Per person, per channel, per purpose:
- Timestamp, in UTC, of the moment consent was given.
- Source — which form, on which page, in which context. "Checkout newsletter box" and "footer signup" are separate consents with separate evidence.
- The exact wording shown, or a reference to a stored version of it.
- The channel and purpose consented to. Email marketing is not SMS marketing is not sharing with ad platforms.
- The confirmation event, where double opt-in was used — its own timestamp, which is the strongest single piece of evidence you can hold.
- Subsequent changes: withdrawals, re-subscriptions, preference changes, each with its own timestamp, appended rather than overwriting.
Version the wording, or the record means nothing
Store the consent text as versioned content, and record which version each consent refers to. This is unglamorous and it is the difference between a record that answers the question and one that raises a new one.
- A version identifier on every consent row.
- The full text of every version retained, not just the current one.
- The same for the privacy notice in force at the time, which is what "informed" rests on.
Append, never overwrite
Consent state is a current value derived from a history of events. Storing only the current value destroys the history, and the history is the evidence.
- Every consent event is a row — given, confirmed, withdrawn, re-given.
- The current state is computed from the latest event per channel.
- A withdrawal never deletes the earlier grant. You need to be able to show that mail sent before the withdrawal was lawful.
- Keep the events after the person unsubscribes. Suppression is not deletion, and a record proving you stopped is exactly what you want to have.
How long to keep it
There is no single prescribed period, and the answer follows from what the record is for: defending against a claim. So keep consent evidence for as long as a claim could be brought, plus a margin — commonly a few years after the relationship ends, aligned with your national limitation period.
Two things that follow from that:
- Consent records outlive the marketing relationship. Somebody unsubscribed in 2024 should still have their 2021 consent record in 2026.
- They are not exempt from a deletion request, but you may generally retain what is necessary to establish or defend legal claims. Document that reasoning once rather than deciding per request.
What to do about consents you inherited
Migrated lists, acquisitions and agency handovers routinely arrive with a subscribed flag and nothing else. You cannot retroactively create evidence, and you should not pretend to.
- Record what you actually received, including that provenance is unknown, and keep the original import file.
- Do not overwrite the unknown with today's date — that turns a thin record into a false one, which is materially worse.
- Re-permission the doubtful portion: one campaign asking people to confirm, then suppress everybody who does not. Painful, finite, and it converts an open-ended risk into a known list.
- From that point on, every new consent has a full record, because the collection path refuses one without a source.
Sources and further reading (4)
- GDPR Article 7 — Conditions for consent
- EDPB — Guidelines 05/2020 on consent under the GDPR
- GDPR Article 17 — Right to erasure
- GDPR Article 30 — Records of processing
Checked on 23 September 2026. Provider prices, mailbox rules and legal guidance change — verify anything you plan to act on.
Consent that cannot be recorded without a source
Auralata refuses to record a subscribe event that arrives with no source, stores the timestamp and channel alongside it, and keeps the history rather than overwriting a flag — so the record still answers the question in three years.