The Consent Banner Is Not the Privacy Programme
A GDPR-compliant consent banner is just the start: organisations must be able to justify, limit, find and delete personal data across their systems.

A GDPR-compliant consent banner is just the start: organisations must be able to justify, limit, find and delete personal data across their systems.
The UK GDPR requires organisations to have a lawful basis for every use of personal data. But the Information Commissioner's Office (ICO) guidance states that the lawful basis must be determined before processing begins Article 6(1) GDPR lists the six main options for your clear and specific reason for processing: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Each has a different standard, with consent being the basis that requires explicit permission - typically a yes click.
The banner is only the vehicle for consent as a basis. Switch to this basis and the banner must reflect that and no other basis, but consent is only one door to meeting the GDPR's requirements - and may not be the right one. [Verified fact 1 / 3 / 4]
When consent is this basis, the requirement to keep the data or records for no longer than necessary overrides all other retention policies. There is no general rule on how long the consent record, or the underlying data, should be kept. But certain events require deletion. Article 5(1)(e) GDPR says ID data that exceeds even a lengthy retention period must be deleted, as must data that is no longer necessary or wanted, or for which there are no other lawful bases. When any of those events happen, the retention limit has been reached, and the organisation must meet the GDPR's erasure requirement. This is not just about the visual representations of the consent process, such as the banner. It is about the data itself. [Verified fact 5 / 6 / 11]
Consent is never consent for life. Article 6(3) GDPR says processing under Article 6(1)(c) and 6(1)(e) must be based on Union or Member State law. Even where this rule is a consent-collection banner, it no longer applies to the controller after the person withdraws their consent and furnishes their reason to do so. If there is no other basis to retain the data, it must be deleted. Similarly, where an organisation relies on its legitimate interests gateway fallback, and the person objects, the data is no longer necessary. The organisation will have to comply, unless it finds a compelling interest in a private matter, and when the law permits counterbalancing, and is not outweighed by the data subject's objection to processing. [Verified fact 8]
At this point, the GDPR is clearly distinct from the consent banner. The separation is equally strong as Individuals gain rights: where a controller receives a lawful access request under Article 15 of the GDPR, it is under a legal duty to search for and retrieve the responsive personal data. Are you able to reconstruct which users saw the banner, left it, withdrew their consent? Does your notification history include a banner fact, an opt-in fact, consent specification, a delete refusal? If so, you have the minimum requirement.
But most of the obligation is rarely mentioned in consent-banner compliance stores. You must also have a record of the data subject's data in all the places it resides. That could include a CRM, database, CMS, spreadsheet, IM system and more.
There is no regulatory guidance on the specific form of the record, but the GDPR expects controllers to create exactly this when a person objects to lawful processing. Where this objection has merit, the law requires storage to cease. Data controllers must cease processing and efface the relevant information from the CRM, the database, the CMS, the spreadsheet, the IM system, and anywhere else the data has been copied.
That means not just the consent banner, but a comprehensive set of logs - if that is the process. The ICO states it creates an "electronic case file" containing the requester's details and relevant information.
Most importantly, that requirement is framed as operational, not cosmetic: you must respond. The EDPB's Opinion 08/2024 states erasure is required where there is no other lawful basis or processing is unlawful.
For rights requests, it is not enough to have the banner visible. The controller needs a map of the data's presence in all systems, and the records of processing it permits
Organisations need not only the consent-banner user interface, but an observable record of contact, consent, consent withdrawal, processing logs, and mechanisms to delete records, within and beyond websites or CMS systems. Only organisations that can end processing where the law says no, access and delete as the law says yes, and justify the retention for as the law allows, are storing data where the UK GDPR allows. Consent banners and records are the visible part, but GDPR compliance takes this much more.
- 01Security & Privacy
What are dynamic proxies, and are they worth using?
Dynamic proxy servers are a key part of network infrastructure, playing an essential role in ensuring network traffic security, efficiency, and privacy. But what…
- 02Security & Privacy
Privacy by Design in Gambling Apps: A Practical Guide
The email starts like this: “We’re sorry to tell you there was a data breach. Your ID, bank info, and bet history may be exposed.” No team wants to send that note.…
- 03Security & Privacy
KYC and Age Verification Technologies: Balancing Compliance and UX
Your user is almost there. Card is ready. Then the app asks for a selfie and an ID scan. The light is bad. The timer is strict. The user quits. This scene plays out…
- 04Security & Privacy
Responsible Gambling Tools: Tech-Driven Safeguards and Self‑Exclusion
Sunday. Late. One more spin. Then two. You tell yourself you will stop at midnight. Your screen says you can add funds in a tap. Your pulse says “go.” Your plan…