Glossary

What is Consent Log?

A consent log is the evidentiary record in which a visitor's decision about cookie or data processing consent is stored together with its date, choice details and context. In consent-based processing, the burden of proof lies with the data controller; the accountability approach of the KVKK and GDPR requires being able to document that consent was obtained. A timestamp, the selected categories and the text version shown at the moment of consent are typical contents.

A party that processes data based on consent must be able to show that the consent was actually obtained; saying 'the user accepted' is not enough during a dispute or an audit. The accountability approach of the KVKK and GDPR expects compliance not only to exist but to be documentable. The consent log is the practical answer: it stores, in a verifiable form, when the visitor consented, which options they selected and which text they saw. A good log contains a timestamp, the choices given or refused per category, the version of the banner and policy text shown, the method of consent (an active action such as a button click) and an identifier that describes the visitor without excess.

Data minimization applies here as well: collecting more personal data than proof requires turns the evidence tool into a new risk. Withdrawal of consent must be recorded in the same structure, so the log tracks preference changes, not just acceptance. In practice these records cannot be kept by hand; consent management platforms log every decision automatically and produce exportable reports when needed. The site owner's job is to verify the setup: make sure the version number increases when banner texts change, the records are accessible and backed up, and the retention period is aligned with the validity period of the consent.

Frequently asked questions

How do you prove cookie consent?

By presenting the record of the moment of consent: a timestamp, the visitor's choices per category, the version of the banner and policy text on screen at the time, and confirmation that consent was given through an active action such as a button click. These records are kept automatically by the consent management platform and exported as a report in case of an audit or complaint. Claiming 'consent exists' without version information weakens the evidence.

How long should consent logs be kept?

The law does not set a single fixed period; the measure is the reasonable time during which the record can serve its evidentiary function. The established approach is to keep the log for as long as the consent is valid, plus the period during which a dispute or audit could arise. When setting the period, apply data minimization, delete expired records regularly and document the retention decision together with its reasoning.

This content is for information only and is not legal advice.