- Consolidated EU-level text for Article 5(3) terminal-equipment consent and exception framing.
"terminal equipment"
Record why each cookie, SDK, pixel, local-storage item, or similar tracker is treated as consent-based, exempt, disabled, or escalated.
Use the workflow to preserve banner versions, user signals, withdrawal paths, cookie inventory data, controller and vendor facts, technical tests, and the limits of each Article 5(3) decision.
Structured answer sets in this page tree.
Cited legal and guidance references.
The law does not prescribe one EU consent-log form or a fixed list of fields. is a freely given, specific, informed, and unambiguous indication made through a clear affirmative action, and the controller relying on it must be able to demonstrate it. The evidence must show that consent existed before a consent-required cookie or similar technology stored or accessed information, and that the live implementation respected the recorded choice. For each technology and purpose, link the Article 5(3) classification, banner text and version, user action, withdrawal path, controller and vendor facts, and technical test results. Keep only the personal data needed to demonstrate that link, set a reasoned retention period rather than retaining event-level records indefinitely, and reopen the workflow when a purpose, vendor role, device-access method, or material processing fact changes.
Create one record for each cookie, pixel, SDK call, local-storage key, device identifier, or similar technology that stores information on, or accesses information from, a user's terminal equipment. Base the record on the Article 5(3) operation and its purpose rather than the vendor's marketing category.
Classify the item as consent required, exempt under the transmission exception, exempt because it is strictly necessary for a service explicitly requested by the user, disabled until review, or escalated because the implementation facts are incomplete. If the item has multiple purposes, record each purpose separately because an exemption for one purpose does not extend to a non-exempt tracking purpose. National implementing law and regulator guidance can affect the final answer.
A should demonstrate that a user gave a clear affirmative signal for the named purpose before the non-exempt storage or access occurred. Article 7(1) GDPR requires the controller to be able to demonstrate consent, but it does not prescribe a particular log. The EDPB also warns that proof should not create excessive additional data processing.
Store enough to prove the consent state and reconstruct the decision: a pseudonymous user or device key where needed, timestamp, region or locale variant, banner version, purpose toggles, vendor list version, policy version, user action, and event source. Keep rejection and no-action states only to the extent needed to enforce and explain blocking; do not turn the proof system into a separate tracking record.
The withdrawal record is part of the consent evidence. Show where the user can reopen privacy settings, when the consent state changes, whether existing cookies or identifiers are deleted, disabled, or allowed to expire under a documented rule, and how later tags, SDK events, server-side events, and vendor calls based on the withdrawn consent are stopped. Withdrawal does not make earlier consent-based processing unlawful, and it does not automatically erase data held for another valid purpose or legal basis.
The log should distinguish withdrawal of consent from a new refusal, browser deletion, opt-out for exempt analytics, and objection to later processing. Where the same user has multiple devices or browsers, record the scope of the signal honestly instead of implying a universal withdrawal that the system cannot enforce.
Close the workflow only when the team can export a focused evidence pack for a product release, vendor change, regulator question, customer inquiry, or internal audit. The pack should show the decision, the live implementation, the source basis, retention rules, and known limits.
Do not add country-specific penalties, regulator-specific banner rules, or analytics exemptions unless the cited source in the evidence pack supports them. For EU-wide ePrivacy content, record when local counsel or a market owner must review national implementation details.
Sorena can help map your cookie inventory, banner versions, consent and withdrawal events, and vendor evidence into a reviewable Article 5(3) workflow.
Ask questions tied to cited sources about Article 5(3), consent evidence, exemptions, banner records, and withdrawal proof using the cited sources on this page.
Review your consent-log fields, tracker inventory, vendor evidence, and audit outputs with Sorena.
"terminal equipment"
"list the cookies placed"
"withdraw consent"
"different technical solutions"
"interplay between the ePrivacy Directive and the GDPR"
"Users must be in control"
"if substantial doubts remain"