Home / Blog / Consent receipts: keeping proof of what each visitor actually chose

Consent receipts: keeping proof of what each visitor actually chose

September 29, 2026 · ConsentVigil

A consent banner records a choice in the moment. A consent receipt records the proof that the choice happened: who was asked, what they saw, what they picked, and when. When a regulator asks for evidence about a specific visitor, the banner screenshot does not help. The receipt does. Yet most consent setups store the preference and nothing else, which is like keeping the vote count and shredding the ballots.

Why receipts matter in 2026 enforcement

Enforcement actions this year keep circling the same evidentiary question: can the site operator prove what a specific visitor was shown and what that visitor chose? A stored preference string says the current state of consent. It does not say whether the banner was readable, whether the options were fair, or whether the choice was made on the first visit or the fifteenth. Regulators have started asking for the banner version, the exact wording, and the timestamp. Sites that keep receipts answer in an afternoon. Sites that do not spend months reconstructing history from logs.

The pattern is familiar from financial compliance. Nobody keeps transaction logs because they expect an audit tomorrow. They keep them because when the audit comes, reconstruction is impossible and expensive. Consent is now held to the same standard: the obligation is not just to obtain valid consent, it is to be able to demonstrate that the consent was valid.

What a good receipt contains

A useful consent receipt is small and boring. It records the visitor's identifier (a pseudonymous one, not raw personal data), the timestamp, the exact consent state granted, the version of the banner and policy shown, and the page where the choice was made. If the visitor later changes their mind, the receipt log appends a new entry rather than overwriting the old one, so the full history of the choice is visible. That is the whole thing: identity, time, choice, context, version.

What it should not contain is the visitor's personal data in cleartext. The receipt is metadata about a decision, not a dossier. Tie it to the same pseudonymous ID the consent system already uses, and it works for both the regulator's question and the visitor's own access request. Keep it for the retention period your policy promises, then delete it like everything else.

Where receipts usually go wrong

The most common failure is overwriting. Many consent tools update a single record per visitor, so the receipt of the original choice is destroyed the moment the visitor changes it. The second failure is storing the state without the context: a string that says "statistics: yes" with no record of what the banner promised statistics meant. The third is keeping receipts in a vendor dashboard that the site operator cannot export. When the audit letter arrives, the evidence lives in someone else's system under someone else's retention policy.

Another quiet failure is the banner version gap. Sites redesign their banners, change the wording, add or remove categories, and the receipt still says "consent: granted" with no link to which banner produced it. A choice under last year's banner and a choice under this year's banner are different legal facts. Version every banner change and stamp the version on every receipt.

How to start without a new vendor

You probably do not need new tooling. Most consent platforms already log choice events with timestamps; the gap is that nobody configures the export or the retention. Start by checking what your current tool records when a visitor chooses: does it keep the history or just the latest state? Can you export it? Is the banner version included? If the answers are yes, your receipt system already exists and just needs a retention policy. If the answers are no, a simple append-only event log on your own side, keyed to the consent ID, covers the gap in an afternoon of work.

Then close the loop: make sure the receipt log is covered by the same retention and deletion schedule as everything else, and that your privacy policy says you keep consent evidence and for how long. Receipts are proof, and proof kept past its promised retention period becomes its own finding. Keep them, version them, export them, and delete them on schedule.

Get a free consent audit of your website

Free consent audit