Consent evidence: what auditors actually ask for
When a regulator or customer asks “prove it,” screenshots of a banner are not enough. Here is the evidence pack a CMP should produce.

Proof of consent usually includes: who the user was (or a durable pseudonymous ID), when they chose, what they saw, which purposes they accepted or rejected, which policy version applied, and how withdrawal was later honored.
IP addresses and user agents can support integrity but are themselves personal data. Minimize what you store and lock retention to a defensible period.
Make export boring
The best audit is a boring export: a consent ID, a JSON of decisions, and a link to the policy snapshot. Consent Guru is designed so that record is a product feature, not a forensic project.
Educational overview only — not legal advice. Confirm requirements with counsel for your products and markets.


