Consent ManagementConsent Records

Consent Records

Monitor consent activity on the Dashboard, search and export receipts, review data subjects and their history, and understand how records are kept and retained.

Every choice a visitor makes in a banner or a preference center becomes a consent record. This page covers the Dashboard, the Consent Records > Receipts list, the Consent Records > Data Subjects list, and how the records behind them are kept, protected, and retained.

Dashboard

Open Consent Management > Dashboard. Two tabs at the top switch between Cookie Consents and Preference Center. On both tabs, click Date Range and pick a start and an end day to limit every card and chart to that period. Close the range chip to return to all time. There is no filter by collection point.

CardMeaning
Total ConsentsBanner submissions in the period.
Accept All, Reject All, CustomizeSubmissions by the button the visitor used.
GPC Signal DetectedSubmissions made by a browser sending the Global Privacy Control signal.
GPC Compliance RateGPC submissions as a share of total consents.

Charts: Consent by Type (Accept All, Reject All, Customise), Category Consents (opt-ins per consent category), Cookies by Host (Accepted and Rejected per host), and Consent Velocity (submissions over time).

Preference Center

Cards: Total Receipts, Data Subjects, Opt-in Rate, Opt-out Rate, GPC Signal Detected, and GPC Compliance Rate. Charts: Receipts by Purpose, Preference Breakdown, Consent Breakdown, and Consent Velocity.

Receipts

Open Consent Records > Receipts. The table lists one row per submission with Receipt Id, Subject Id, User Id, Source (Cookie Banner or Preference Center), Brand, Collection Point, and Created At. Newest receipts are shown first; click Created At to change the sort.

Search matches the subject id. Click Filters to narrow the list:

  • Select Date Range: a from date and a to date, applied to the creation time.
  • Brand: one or more brands.
  • Source: All, Cookie Banner, or Preference Center.

Active filters show as chips above the table.

Receipt Details

Click the view action on a row to open the Receipt Details panel. It shows Receipt Id, Subject ID, User ID, Source, Submitted Date, and Collection Point, followed by the choices:

  • For a cookie banner receipt, Cookie Choices lists each consent category with Accepted or Rejected. Expand a category to see the Services (cookies, scripts, and iframes) it covered at the time.
  • For a preference center receipt, Consent Choices lists each purpose. Expand it to see the Preferences with their values; consent preferences show Accepted or Rejected, other preference types show the chosen value.

Export

Click Export, choose CSV or Excel under Select File format, then tick Export All or select rows first and tick Export Selected. The file has one row per preference with the columns id, subjectId, tenantId, brandId, cpId, createdAt, purpose, preference_name, preference_type, and preference_value. A receipt without preferences exports as a single row.

Export All exports the receipts currently loaded in the table. Raise the rows per page or apply filters before exporting if you need a specific set.

Data Subjects

Open Consent Records > Data Subjects. A data subject is a person with a preference center account. The table lists Email, First Name, Last Name, and Registered At, with a search box labelled Search by email or name. Anonymous banner visitors do not appear here; use Receipts for them.

Click View details to open Data Subject Details. The profile shows Email, First Name, Last Name, Registered, Last Updated, and Subject ID. Below it, Consent History lists every record kept for that person, newest first. Each entry shows the source (Cookie Banner or Preference Center), the record id, a GPC chip reading Detected or Not Detected, the submission time, and the choices with their preferences and values.

When a visitor submits a banner or a preference center, the following is recorded:

  • The subject id (the anonymous identifier stored in the visitor's browser) and, when known, the user id of a signed-in data subject.
  • The brand, the collection point, and the source (banner or preference center).
  • The accepted or rejected value for each category, including the services under it, or the value of each preference under each purpose.
  • The regulation that was matched from the visitor's location when the banner was served, by id and name, so you can show which rule set applied.
  • Whether the browser sent the Global Privacy Control signal.
  • Any attributes the collection point is configured to collect.
  • The submission time and the configuration version of the collection point that was live at that moment.

How records are kept

Consent records are append-only. A change of mind does not overwrite anything: the new choice is written as a new record, and the earlier one stays in the history. Each subject's records form a numbered sequence, and every record is linked to the one before it, so any later alteration or removal of a record is detectable. When Neostra checks a subject's history, the result is either intact, intact with a recorded purge, or altered.

Together with the collection point's Published History, the configuration version on a record lets you show which categories, services, and banner text a visitor saw when they consented. This supports the controller's duty to demonstrate consent under GDPR Article 7, the verifiable consent record expected under DPDPA 2023, and opt-out record keeping under CCPA/CPRA.

Re-solicitation

Each publish of a collection point produces a configuration version derived from the set of category keys and the default consent state (opt-in or opt-out). When a returning visitor arrives and their stored consent was collected under a different version, the stored consent is cleared and the banner appears again. Changing category names, descriptions, translations, or the banner design does not trigger this; adding or removing a category, or switching the default state, does.

Global Privacy Control

When the browser sends the Global Privacy Control signal, the banner records it on the receipt together with the regulation that applied. The Dashboard counts these receipts under GPC Signal Detected, and the Data Subjects history shows the flag on each entry. Banner behaviour for the signal is configured under the collection point's Signals tab; see Collection Points.

Retention

Open Settings > Tenant to see the Data Retention Policy card. Consent Records (CMP) shows the retention period in years for your tenant; the default is 7 years. The value is managed by Neostra; contact support@neostra.io to request a change.

A daily job applies the policy. For each subject whose consent was submitted longer ago than the retention period:

  • The user id on the record is replaced with an anonymous token and the record's metadata is replaced with a purge marker.
  • Preference center choices are removed from the record. Cookie banner choices are kept, as they contain no personal data.
  • The preference center account is anonymised: the email and name are replaced with placeholder values.
  • A purge record is appended to the subject's history, so the sequence remains verifiable and shows when the erasure happened.

The record itself is not deleted, but it no longer identifies the person.

Consent Management is not legal advice. Decide retention periods and record-keeping practices with your DPO or counsel.