Consent isn't consent
until you can prove it.
CookieLet's Consent Log captures a tamper-evident record of every choice your visitors make — a unique Consent ID, the country it came from, the exact UTC timestamp, and a downloadable proof-of-consent receipt. When a regulator, auditor, or customer asks you to demonstrate compliance, the answer takes seconds, not weeks.
Consent Log
View your visitor consents and download proof of consent to demonstrate compliance with privacy regulations and laws
| Consent ID | Date / Time (UTC) | Status | Proof of Consent |
|---|---|---|---|
| 15341519-2d84-4499-b47c-e8c32d2997b7 | 2026-08-05T04:40:09.548Z | Accepted | ▤ View Proof |
| a7f2c9e1-4b60-4d18-9c33-71ba0e4f52dd | 2026-08-05T09:12:44.101Z | Custom | ▤ View Proof |
| 3c8b1d05-9e77-4a2f-8f41-2d6c93ba17ee | 2026-08-06T16:03:27.882Z | Rejected | ▤ View Proof |
| e60a4471-58c2-42d9-b0aa-cc19f7d3b845 | 2026-08-07T11:48:55.309Z | Accepted | ▤ View Proof |
A cookie banner is a promise. A consent log is the receipt.
Under GDPR, the burden of proof sits with you — not with the visitor. Showing a banner is only half the obligation. If you can't produce evidence of what a specific person agreed to, and when, you are treated as having no consent at all.
"Show us your evidence"
A data protection authority opens an inquiry and asks for consent records covering a date range. Screenshots of your banner won't satisfy them. Without per-visitor records, every cookie you dropped is treated as unlawful processing.
The subject access request
A visitor emails asking what you collected and what they agreed to. You have 30 days to respond substantively. Digging through server logs and analytics exports is not a process you want to run under a legal clock.
The enterprise security review
A large customer's procurement team sends a 200-line vendor questionnaire. "Describe how you record and retain end-user consent." A vague answer stalls the deal; an exported log and a sample receipt closes it.
Every consent decision, written down the moment it happens
The instant a visitor interacts with your CookieLet banner — accept all, reject all, or a custom category selection — the Consent Log writes an immutable record. Nothing is sampled, nothing is aggregated away, and nothing depends on the visitor's browser still holding a cookie weeks later.
- ✓Server-side and permanent. Records live in CookieLet's infrastructure, so clearing browser storage never erases your evidence.
- ✓Pseudonymous by design. A random Consent ID identifies the record — you're not building a new database of names to protect.
- ✓Write-once. Entries are never edited in place. A visitor who changes their mind creates a new record, preserving the full history.
- ✓Queryable in seconds. Filter, search by Consent ID, and export — without opening a support ticket or writing SQL.
A shareable, self-contained record — attach it to an audit response or a DSAR reply as-is.
Built for the moment someone actually asks
Nine things the Consent Log does so your legal, privacy, and engineering teams don't have to.
Unique Consent ID
Every record carries its own UUID. Give it to a visitor, quote it in a DSAR response, or paste it into the search box to pull up a single decision out of millions — no personal data required to find it.
Precise UTC timestamps
Stored to the millisecond in ISO 8601 UTC, so records from visitors in Mumbai, Munich, and Miami sort into one unambiguous sequence. No timezone arguments during an audit.
Country of origin
Each consent is tagged with the visitor's country code, derived at the moment of interaction. Instantly show which records fall under EU, UK, Brazilian, Indian, or US-state law.
Full status detail
Accepted, Rejected, or Custom — and for custom choices, exactly which categories were switched on and off. Proving a rejection was honoured matters as much as proving an acceptance.
View Proof
Open a human-readable proof-of-consent document for any record: what was shown, what was chosen, when, from where, and against which version of your banner and policy.
One-click download
Download an individual receipt as a portable file you can email, attach to a ticket, or file in your evidence folder. No screenshots, no re-typing, no chance of transcription error.
Export as CSV
Pull the whole log — or any filtered slice of it — into a spreadsheet, your data warehouse, or your GRC platform. Perfect for periodic evidence archiving and board reporting.
Search & filter
Search directly by Consent ID, or filter by status, country, and date range. Tabbed counts for Total, Accepted, Rejected, and Custom give you the shape of your consent rates at a glance.
Per-website separation
Run multiple domains from one account and keep their logs cleanly separated. Switch sites from the sidebar; each one keeps its own independent, exportable consent history.
Anatomy of a consent record
Regulators don't just want to know that someone clicked. They want to know what was in front of them when they did. Here's what CookieLet stores — and why each field matters.
| Field | What it captures | Why it matters |
|---|---|---|
| Consent ID | A random UUID assigned to this decision, e.g. 15341519-2d84-4499-b47c-e8c32d2997b7 | Lets you locate and cite a single record without storing a name or email. |
| Consent status | Accepted · Rejected · Custom | The headline answer to "did this person agree?" — including the ones who said no. |
| Category choices | Per-purpose state for necessary, analytics, marketing, preferences and any custom groups | GDPR requires consent to be specific and granular. Category-level detail is the proof of it. |
| Date & time (UTC) | ISO 8601 timestamp to millisecond precision | Establishes whether a tag fired before or after consent — the single most common audit finding. |
| Country | Two-letter country code inferred at the time of consent | Determines which legal regime applies and whether geo-targeted banner rules behaved correctly. |
| Website / domain | The property the consent was given on | Keeps evidence unambiguous across multi-brand and multi-domain estates. |
| Banner & policy version | The configuration and cookie-policy revision live at that moment | Reconstructs what the visitor actually saw — you can't prove informed consent otherwise. |
| Interaction method | Which control was used: Accept All, Reject All, Save Preferences, or a later withdrawal | Demonstrates the consent was an unambiguous affirmative action, not implied by scrolling. |
| Proof document | A rendered, downloadable receipt bundling all of the above | The artefact you hand to an auditor, a customer, or a data subject — self-contained and portable. |
Nothing to build. Nothing to maintain.
If your CookieLet banner is live, your consent log is already filling up.
Install the banner
Add one lightweight script to your site — or drop in the WordPress, Shopify, Webflow or GTM integration. Logging is on from the first pageview.
Visitor chooses
They accept, reject, or open preferences and pick categories. CookieLet blocks scripts accordingly and simultaneously writes the record server-side.
Record is sealed
The entry receives its Consent ID, timestamp, country, and a snapshot of the banner and policy version in force. It is never overwritten.
Retrieve on demand
Search, filter, view a proof document, download a single receipt, or export the entire log as CSV — whenever evidence is requested.
"Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data."
One log, many regulators
Privacy laws differ on the details, but nearly all of them converge on the same requirement: keep records. Here's how the Consent Log maps to the frameworks most likely to apply to you.
GDPR (EU) & UK GDPR
Article 7(1) puts the burden of demonstrating consent squarely on you, and Article 7(3) requires withdrawal to be as easy as giving it. Timestamped, per-visitor records with category-level granularity and a full history of changes address both.
ePrivacy Directive
The "cookie law" requires prior informed consent before non-essential storage. Because each record captures the banner and policy version in force plus a millisecond timestamp, you can show consent preceded the tag firing.
CCPA / CPRA and US state laws
Opt-out signals, sale/sharing preferences and limits on sensitive data all need an auditable trail. Rejected and Custom records prove you honoured a "do not sell" preference at a specific moment in time.
LGPD (Brazil)
Article 8 §2 places the burden of proving consent on the controller and requires it to be given for specific, identified purposes. Category-level records satisfy the specificity test.
DPDP Act (India)
India's framework centres on free, specific, informed and unambiguous consent with a clear withdrawal path — and expects Data Fiduciaries to maintain records that evidence it.
PIPEDA (Canada) & others
Meaningful consent guidance expects organisations to be able to show what individuals were told and what they agreed to. Portable proof documents travel well across jurisdictions.
CookieLet provides tooling to help you meet these obligations. It is not legal advice — your specific obligations depend on your business, your data, and your jurisdictions.
Four moments the Consent Log pays for itself
Responding to a regulator
An authority requests evidence of consent for a 90-day window. Filter the log to the date range and affected country, export as CSV, and attach a handful of individual proof documents as samples. What used to be a fire drill becomes a ten-minute task.
Answering a data subject
A visitor asks what they consented to. If they can supply their Consent ID, search pulls up the record instantly. Send them the downloadable receipt — a complete, honest answer that also demonstrates good faith.
Passing a vendor review
Enterprise buyers and their security teams routinely ask how end-user consent is captured and retained. Screenshot the log, attach a sample receipt, and move the questionnaire forward instead of escalating it to legal.
Understanding your visitors
The Total / Accepted / Rejected / Custom tabs are also a live read on consent rates by country. Use them to test banner copy, layout and placement — and to know exactly how much of your analytics data is consented.
What most cookie banners give you
- ✕A consent cookie in the visitor's browser — gone the moment they clear it
- ✕Aggregate counts with no way to isolate a single decision
- ✕Consent records locked behind an enterprise tier or an API-only endpoint
- ✕No record of what banner or policy the visitor actually saw
What CookieLet gives you
- ✓Durable server-side records, independent of the visitor's browser
- ✓Per-consent detail down to the individual category toggle
- ✓Proof documents and CSV export in the dashboard, no engineering needed
- ✓Banner and policy versioning captured with every single record
Evidence-grade by default, not as an upsell
Plenty of tools will show a banner. Far fewer will hand you a defensible record of what happened afterwards — and the ones that do usually reserve it for their most expensive plan.
CookieLet treats the log as the point of the product. It sits alongside automatic cookie scanning, a customisable banner, multi-language support, geo-targeted rules, and generated privacy and cookie policies — so the thing you show visitors and the thing you show auditors are always describing the same reality.
FAQ
Questions we get asked
Does the Consent Log store personal data like names or IP addresses?
The log is built to be pseudonymous. Records are keyed by a randomly generated Consent ID rather than by identity, and country is derived at the point of consent rather than stored as a precise location. The goal is to give you defensible proof without creating a new store of personal data that itself becomes a compliance burden.
What happens if a visitor changes their mind?
A withdrawal or update creates a new record rather than editing the old one. That gives you a complete chronological history: what they originally chose, when they changed it, and what the new state is. GDPR Article 7(3) requires withdrawal to be as easy as giving consent, and being able to show it was honoured immediately is the other half of that obligation.
How long are consent records retained?
Records are retained for the duration of your plan so they remain available for the periods most regulators and auditors look back over. Because you can export the full log as CSV at any time, you can also maintain your own archive on whatever retention schedule your legal team specifies.
Can I export everything, or only what's on screen?
Both. "Export as CSV" respects whatever filters you have applied — so you can export a single country, a single status, or a date range — and with no filters applied it exports the complete log for that website.
Why are timestamps in UTC rather than my local time?
Because your visitors aren't in your timezone. A single UTC clock means records from every country sort into one unambiguous order, with no daylight-saving gaps or overlaps to explain. It is also the format auditors and legal teams expect to receive.
Does logging slow down my site?
No. The banner script is lightweight and the record is written asynchronously after the visitor interacts, so it never blocks rendering or delays your page. Visitors experience the banner exactly as they would without logging enabled.
Can I manage several websites from one account?
Yes. Switch between properties from the website selector in the sidebar. Each site keeps its own independent consent log, cookie scan, banner configuration and policies, so evidence never gets mixed between brands or domains.
Is the Consent Log enough to make me compliant?
It's a necessary piece, not the whole picture. Compliance also depends on genuinely blocking non-essential scripts before consent, describing your cookies accurately, making rejection as easy as acceptance, and honouring withdrawals. CookieLet covers those areas too — but your specific obligations depend on your business and jurisdictions, and this page isn't legal advice.
Keep the receipt for every consent
Every decision your banner records is written down with a unique consent ID, a UTC timestamp and the full status — ready to export the day somebody asks.
Free plan available · No credit card required