Appearance
Consent records
Every decision a visitor makes is recorded, so you can answer the one question a data protection authority actually asks: prove that this visitor agreed, and show what they were shown. You will find them in your dashboard under Consent log.
What a record contains
| Field | Notes |
|---|---|
| Consent ID | Random per-visitor ID, also in the visitor's cw_consent_id cookie |
| Date and time | When the decision was made |
| Country | Two-letter code resolved at the edge |
| Accepted / rejected categories | The visitor's actual choices |
| Config version | Which version of your banner they saw — see below |
| Consent status | Accepted all / rejected all / partial |
| GPC | Whether the browser sent a Global Privacy Control opt-out |
| TC and AC strings | On TCF sites only: the exact strings the CMP wrote |
One record per decision, not per pageview: a returning visitor whose stored choice is simply replayed does not create a new row. Changing a choice later does.
No personal data beyond the pseudonymous ID
Records hold no IP address, name or email. The country is derived at the edge and only the two-letter code is kept. The consent ID is random and links only to itself. Traffic identified as a bot is not recorded at all.
Why the config version matters
Consent is only valid if you can show what was consented to. Every time you publish a change to your banner, its version increments, and each record stores the version that visitor actually saw. A record therefore points at a specific banner text and category set — not merely at "they clicked accept".
Finding one visitor's record
Search the consent log by consent ID. A visitor can find their own in the cw_consent cookie under consentId, and you can read the same value from your own code — see Consent cookie & events.
Export
Export CSV downloads up to 10,000 most recent records with these columns:
created_at, consent_id, action, accept_type, accepted_categories,
rejected_categories, config_version, country, gpc, tc_string, ac_stringtc_string and ac_string are the verbatim IAB TCF strings and are empty for non-TCF sites. They are exported unmodified on purpose: only the original string can be replayed through an IAB decoder, which is what settles a dispute about what a CMP stored.
Turning recording on or off
Recording is on by default. The switch is in Settings → General → Consent logging.
Turning it off does not change anything a visitor sees — the banner still works and their choices are still honoured — but nothing is written, so you cannot produce consent proof for the period it was off. Sites created before this became the default may still have it switched off; the consent log page warns you when that is the case.
Retention
Records are kept for 12 months and then deleted automatically.
Next
- Consent cookie & events — read the decision from your own code.