Cookie Compliance

Cookie Consent Records: Why They Matter and How OneTrust Helps

Why cookie consent records matter under GDPR Article 7 and how OneTrust Capture Records of Consent, receipts, and retention support demonstrable consent.

Working summary: Lawful cookie consent is not only a banner. Controllers must be able to show what was presented and what the person chose. OneTrust can capture consent receipts when you enable logging on geolocation rules and publish the CDN. Without that switch (or an equivalent first-party log), you have UX theatre and weak evidence.

  • Why: GDPR Article 7 places the burden of demonstrating consent on the controller. Similar accountability pressure shows up in enterprise questionnaires and in India’s DPDP consent quality expectations.
  • What to store: Time, region/rule, purposes/categories, Accept / Reject / custom mix, policy or notice version, and a durable identifier for the interaction.
  • OneTrust: Enable Capture Records of Consent per geolocation rule; publish Production then Testing CDNs; review receipts and transactions in Consent / Cookie Consent views.
  • Ops: Retention policies, export paths, and a runbook for “show me consent for this visitor” requests.

This is article 9 of the Cookie Compliance series. Articles 3 and 4 cover GDPR and DPDP notice/consent quality. Article 7 flagged records as a CMP vs manual decision. Article 8 covers Consent Mode signals. Here the topic is proof.

A banner that disappears after Accept does not prove the interaction. When a user, customer, or authority asks “on what basis did you set this advertising cookie?”, you need more than a screenshot of today’s template.

Under the GDPR, Article 7 requires that where processing is based on consent, the controller must be able to demonstrate that the data subject consented. Article 5(2) accountability and Article 24 organisational duties point the same way: keep evidence as a living control, not as a reconstruction after a complaint.

India’s DPDP Act frames consent as free, specific, informed, unconditional, and clear, with notice duties that the Rules will make more concrete. Even before every Rule date, buyers and partners already ask for consent evidence in security reviews. California-style opt-out regimes still benefit from logs of “Do Not Sell/Share” and GPC honours when you claim you honour them.

Exact fields vary by counsel. A working minimum for website CMP interactions usually includes:

  • Timestamp (with timezone clarity)
  • Site / domain / collection point
  • Geolocation rule or region applied
  • Template or notice version shown
  • Purposes or cookie categories offered
  • Choices (grant / deny per purpose, or Reject All / Accept All)
  • Interaction type (first-layer banner vs Preference Center vs withdrawal)
  • Anonymous or pseudonymous visitor key used by the CMP
  • Whether Auto-Blocking or Consent Mode updates ran (ops note, even if stored elsewhere)

A raw server access log that only shows “POST /consent” without purposes is not enough for Article 7-style demonstration.

How OneTrust helps

OneTrust’s Logging Consent Records guidance explains that banners and Preference Centers can log consent preferences when you enable capture on each geolocation rule where you want transactions. Visitors are tied to a unique anonymous cookie after they express preferences; OneTrust states that cookie does not contain personal identifiable information at that point.

Steps in product terms:

  1. Open the geolocation rule.
  2. Enable Capture Records of Consent (OneTrust also references related analytics options in the same area).
  3. Repeat for every rule that should send interactions (you may intentionally skip some audiences).
  4. Publish the Production CDN, then the Testing CDN, so the change applies.

OneTrust notes that publishing Production creates a Collection Point for each combination of domain, rule group, rule, and template in the Consent module, with purposes mapped for categories. After that, Testing CDN traffic can also collect and show in the Cookie Consent dashboard.

Receipts and transactions

OneTrust describes receipts as immutable records of each interface interaction (Collection Point or Preference Center), including purposes, purpose preferences, and optionally privacy notices. Receipts are stored encrypted. When a data subject is identifiable, receipts can be processed into per-purpose transaction records visible on a Transactions view. Cookie Consent also exposes a Receipts search UI when the relevant permission (CookieV2 Cookie Receipt UI in OneTrust’s naming) is enabled.

Retention and extraction

Consent retention policies in OneTrust’s Universal Consent & Preference Management area can automate data subject, profile, and receipt retention or redaction. Controllers often keep receipts longer than marketing profiles so evidence survives account deletion where counsel requires it; configure that deliberately.

For bulk extraction, OneTrust documents encrypted Azure blob storage and a process to request read-only SAS access via your OneTrust consultant (token validity described as four weeks in their extract article). Day-to-day support tickets should not be your only retrieval path; practice one export before you need it in a dispute.

Enablement checklist

  1. Decide which geolocation rules must log (EEA/UK almost always; others per counsel).
  2. Turn on Capture Records of Consent; publish Production then Testing CDNs.
  3. Confirm a test Accept, Reject, and Preference change each create a receipt.
  4. Map who in privacy/ops can search receipts (permission / role).
  5. Set retention aligned with legal hold and deletion procedures.
  6. Document the runbook: ticket intake, how to find a receipt ID, what you disclose to the requester.
  7. Keep banner and Preference Center version history so receipts point at text that still exists in your archive.

Records without OneTrust

Manual or lighter CMPs can satisfy the same duty if eng stores the fields above in a durable store, protects access, and defines retention. Article 7 does not name a vendor. It names demonstrability. DIY fails when the log is a browser console experiment that never reached production.

  • Consent Mode shows Google what to do now. A receipt shows what the user chose then. You need both for a complete story (article 8).
  • Withdrawal: A new receipt (or transaction) should reflect deny after Preference Center changes; tags and Consent Mode must update in the same moment.
  • DSAR / access requests: If you can identify the person, you may need to locate their consent history across channels. OneTrust positions cross-channel consent history as a platform capability; website-only anonymous receipts may not join to a CRM identity until you design that join carefully with counsel.

Common gaps

  • Banner live for a year; Capture Records still off.
  • Logging only on the Testing CDN.
  • No one with Receipt UI permission in the privacy team.
  • Template copy changed without version notes, so old receipts cannot be interpreted.
  • Assuming GA4 events are a consent proof archive (they are not).

FAQ

For many website-only interactions, yes for proving that device/browser instance consented. Linking to a named account needs extra identity design and legal review.

Do we log Reject as well as Accept?

Yes. Demonstrating that Reject was available and used is part of showing a real choice, not only grants that favour marketing.

How long should we keep receipts?

Ask counsel. Factors include limitation periods, contractual audits, and deletion rights. OneTrust retention policies exist so you can automate an answer instead of keeping everything forever by accident.

Sources and further reading

  • GDPR Articles 5(2), 7, and 24 (accountability and demonstration of consent).
  • OneTrust MyOneTrust: Logging Consent Records; Viewing Consent Receipts & Transactions; Setting Up Consent Retention Policies; Extracting Consent Receipts from the Application.
  • Series: GDPR cookie consent, DPDP checklist, CMP vs manual, Consent Mode v2.

Next in this series

Up next: From CCPA to GDPR: Managing Global Cookie Compliance with OneTrust. Records and Consent Mode sit inside geo rules that must differ by region without becoming five disconnected CMPs.

Disclaimer

This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.

Last updated on 25 September 2026

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *