Home / Blog / Re-consent cadence: how often should you re-ask visitors for cookie consent?

The Consent Receipt: What to Show Users After They Choose

Most consent banners end the conversation at the click. The visitor chooses accept or reject, the banner disappears, and nothing confirms what just happened. Compare that to any other meaningful transaction online: you get a receipt for a purchase, a confirmation for a booking, a summary for a settings change. Consent, which is a legal act with real consequences, gets no receipt at all. That is a missed opportunity for trust and a gap in the compliance story.

The consent receipt is a simple idea: after the visitor makes their choice, show a brief confirmation of what they chose and how to change it later. Not a legal document. A human-readable summary: you accepted necessary cookies and declined marketing cookies. Change your choices anytime via the link in the footer. Two sentences that turn an opaque click into an informed decision.

Why the receipt matters

For the visitor, the receipt solves a real problem: most people cannot remember what they clicked. They accepted everything in a hurry, or rejected everything defensively, and later they wonder why the site behaves the way it does. A receipt gives them a reference point and, more importantly, a visible path to change their mind. That path is what regulators actually care about: consent that cannot be easily withdrawn was never freely given.

For the business, the receipt is evidence. If consent is ever questioned, a logged receipt showing what the visitor chose, when, and what they were told is far stronger than a banner impression in an analytics tool. The receipt is the moment the consent record becomes complete: not just the choice, but the confirmation that the choice was communicated back.

Designing the receipt

Keep it small and dismissible. A toast or a compact inline confirmation that appears where the banner was, visible for a few seconds, with a persistent link to the preference center. It should name the categories in plain language, not cookie names. Visitors chose marketing cookies, not _ga and _fbp. The receipt speaks their language.

Include the change path in the receipt itself, not just in the footer. A manage preferences link inside the receipt teaches the visitor where control lives, which increases the chance they use it instead of clearing all cookies or installing a blocker. Every visitor who manages preferences instead of blocking everything is a visitor whose consented data you keep.

Logging the receipt

The receipt should correspond to a consent record: timestamp, the choices made, the banner version shown, and the receipt confirmation. Store it server-side where possible, not just in the browser, because browser storage gets cleared and disputes do not. The record does not need to identify the person beyond a pseudonymous ID; it needs to prove that a choice was offered, made, and confirmed.

One caution: do not make the receipt itself a dark pattern. It should confirm, not upsell. A receipt that says you declined marketing cookies, click here to reconsider is not a receipt. It is a second banner wearing a receipt costume, and it undermines the trust the receipt was supposed to build. Confirm the choice. Offer the control. Then get out of the way.

Get a free consent audit of your website

Free consent audit