Best WordPress Plugins for Consent Logging and Audit Trails

WordPress consent logging and audit trail plugins compared on record detail, export and storage

Here is the question a regulator asks, and it is never the one site owners prepare for. Not “do you have a cookie banner” but “show me the consent record for this visitor on this date”. If your answer is that the banner was definitely displayed, you have no evidence, and under Article 7(1) of the GDPR the burden of demonstrating consent sits with you.

Consent logging is the least glamorous feature in this whole category and the one that decides how an enquiry goes. It is also poorly compared, because every vendor lists it and almost nobody describes what their log actually contains. This article covers what a defensible record needs, how long to keep it, and which plugins produce something you could hand over.

Verified August 2026. This is a practical guide, not legal advice.


What a defensible record contains

Demonstrating consent means showing that a specific person agreed to a specific thing at a specific moment, having been shown specific information. Four elements do that work, and a log missing any of them is weaker than it looks.

  • Who, to the extent you can say. Usually a pseudonymous consent identifier rather than a name, which is correct: building an identity database to prove consent creates the very processing you were trying to justify.
  • What, per category. “Accepted” is not a record. “Analytics granted, marketing denied, preferences granted” is, because the whole point of granular categories is that they are answered separately.
  • When, with a timestamp. Including withdrawals. A record showing consent granted in March and withdrawn in July is more useful than one showing only the grant.
  • What they were shown. The version of the banner, its text, and the category descriptions in force at that moment. This is the element most logs omit and the one that turns a record into evidence, because consent to a description you have since rewritten proves nothing about the current one.

Two supporting details matter almost as much. The record should note the method of collection, meaning which banner interaction or signal produced it, and it should be exportable in a format somebody else can read. A log you can only view inside a plugin’s dashboard is an operational tool, not a disclosure.


The 6 options compared

1. Complianz

The best value in this specific area at $59 a year for a single site, flat, because consent records are bundled into a licence you were buying for the banner and blocking anyway. Nobody should pay separately for logging.

Its records cover the essentials, including which categories were granted, and it keeps the surrounding documentation, the policies and the processing information, in the same place. That colocation is worth more than it sounds during an enquiry, because the awkward questions arrive together: show me the consent, show me the notice they saw, show me what you do with the data. Being able to answer all three from one admin screen is the difference between a morning’s work and a fortnight’s.

  • Price: From $59 a year, single site, flat
  • Log: Per-category records alongside policies and documentation
  • Best for: Most sites, as part of one licence
  • Watch out for: Records live in your database, so include them in backups

2. WebToffee GDPR Cookie Consent

The most explicit about this feature of anything here, and priced to suit sites with volume: $69 a year for a single site with unlimited pageviews, then $199 for five, $399 for twenty-five and $1,199 for a hundred.

It maintains a detailed record of every visitor’s consent and exports to CSV, which is the format an auditor or lawyer can actually work with. It also issues each visitor a consent ID they can quote back to you, which is a genuinely well-designed touch: it gives you a lookup key for individual enquiries without requiring you to hold anything identifying. If logging is the reason you are shopping, this is the product built around it, and the unlimited-pageview pricing means a busy site is not penalised for generating more records.

  • Price: $69/yr single site, unlimited pageviews; $199 for 5
  • Log: Detailed per-visitor records, CSV export, visitor consent IDs
  • Best for: Sites where proving consent is the priority
  • Watch out for: Record volume grows fast; plan database retention

3. Cookiebot by Usercentrics

Records held on the vendor’s infrastructure rather than yours, priced by page count at roughly €12 a month under 500 pages, €28 under 5,000, and €49 above.

Off-site storage is a real structural advantage for evidence. A consent log in your own database is only as durable as your hosting, your backups, and your next migration, and “we moved servers and lost the records” is a poor answer to a regulator. A hosted log survives all of that independently. The trade is that you are relying on a third party for evidence about your own compliance, and that your page count rather than your traffic sets the bill, which puts a large catalogue on the top tier at €588 a year regardless of visitors.

  • Price: ~€12, €28, or €49 a month by page count
  • Log: Hosted off-site, surviving migrations and hosting changes
  • Best for: Sites where record durability matters most
  • Watch out for: Evidence held by a vendor; page-count meter

4. Real Cookie Banner

Worth shortlisting specifically for the quality of what it records, because its underlying model is unusually well suited to producing defensible evidence. It treats every third-party service as a defined entity with known cookies, purposes and blocking rules.

That structure means a consent record can reference exactly which services were permitted rather than which broad category was ticked, which is a meaningfully stronger statement. It also keeps the record of what the visitor was shown alongside the decision, addressing the element most logs omit. There is a free version, and paid pricing should be confirmed with the vendor. If a regulator’s question is likely to be specific, this and WebToffee are the two to compare closely.

  • Price: Free version available; confirm paid tiers with vendor
  • Log: Service-level records with the presented text retained
  • Best for: Precise, itemised evidence
  • Watch out for: Confirm current pricing directly

5. Borlabs Cookie

From €49 a year, flat, with logging built to German expectations, which in this area is a compliment. The German regulatory environment has been demanding about consent evidence for longer than most, and products built for it tend to record more rather than less.

Its conservative defaults extend to record-keeping: it stores consents with the detail needed to reconstruct what happened rather than a simple accepted flag. Combined with the best embed blocking in the category and flat pricing, it makes a strong overall case for a European site. The caveat is the same one that applies to every self-hosted log: the records are in your database, so your backup strategy is now part of your compliance posture, and a restore that silently rolls back three weeks of consent records is a problem nobody notices until it matters.

  • Price: From €49 a year, single site, flat
  • Log: Detailed, built to German evidentiary expectations
  • Best for: European sites wanting depth at a flat price
  • Watch out for: Self-hosted records depend on your backups

6. Osano and Usercentrics

The enterprise platforms, with Osano’s paid plans from around $199 a month. At roughly $2,400 a year they are not competing with a $59 plugin on features but on organisational assurance.

What they sell here is a consent record maintained as a compliance artefact: retained to a stated policy, produced in a defined format, backed by contractual commitments, and reportable across a portfolio of properties rather than one site. If a legal team has to sign something off, or if consent records may end up in litigation rather than in a routine enquiry, those commitments are what the money buys. For a single WordPress site with a marketing team of one, they are considerably more assurance than the risk warrants.

  • Price: Free tiers; Osano paid from around $199 a month
  • Log: Contractual retention, defined formats, portfolio reporting
  • Best for: Legal sign-off and multi-property organisations
  • Watch out for: Enterprise pricing against plugin-level need

Comparison table

OptionPriceWhere records liveExportRecord detail
ComplianzFrom $59/yr flatYour databaseYesPer category, with policies
WebToffee$69/yr, unlimited viewsYour databaseCSVPer visitor, with consent IDs
Cookiebot€12 to €49/moVendor infrastructureYesPer category, hosted
Real Cookie BannerFree tier; confirm paidYour databaseYesPer service, text retained
Borlabs CookieFrom €49/yr flatYour databaseYesDetailed, German standard
Osano / UsercentricsFrom ~$199/moVendor infrastructureYes, defined formatsContractual retention

How long to keep records

The GDPR sets no fixed retention period for consent evidence, which is unhelpful in practice and leads sites to either delete too early or keep everything forever. Both are wrong, because the log itself is personal data and indefinite retention of it is its own problem.

The workable principle is to keep a consent record for as long as you rely on that consent, plus a reasonable margin for a complaint or enquiry about the period it covered. In practice that means records outlive the consent by a year or two rather than a decade. Write your chosen period down and apply it, because a stated policy consistently followed is far more defensible than an accidental archive.

Two related habits are worth adopting:

  • Re-ask periodically. Several European authorities expect consent to be refreshed at reasonable intervals, with six to twelve months commonly cited. Consent captured three years ago against a banner you have since rewritten is thin evidence for what you are doing today.
  • Version your banner. When you change categories or wording, record that as a new version so every log entry points at the text actually shown. This single practice does more for evidential quality than any feature in the comparison above.

Finally, test the export before you need it. Generate the file, open it somewhere other than the plugin, and confirm a colleague could understand what it says. An export that only makes sense to the software that produced it will not survive contact with a lawyer.



Related guides

Frequently asked questions

Is a consent log legally required?

The obligation is to be able to demonstrate that consent was given. No specific format is mandated, but in practice a log is how you meet it, and automatic consent logging appears in the 2026 requirement sets that vendors and regulators alike now treat as baseline.

Does logging consent create a new privacy problem?

It can, which is why good implementations use pseudonymous identifiers rather than names or full IP addresses. Record enough to prove the decision, not enough to identify the person, and set a retention period so the log does not become a permanent archive.

What about visitors who reject everything?

Log those too. A record showing consent was declined is exactly what you want if someone later alleges you tracked them, and a log containing only acceptances looks selective.

Do I need a log for US state laws?

The US model is opt-out, so what you generally need to evidence is that opt-out requests and Global Privacy Control signals were honoured, rather than that consent was obtained. Different record, same principle: keep proof of what you did.

Where should the records physically live?

Hosted storage survives migrations and hosting failures; self-hosted storage keeps the evidence under your control and costs nothing recurring. If you self-host, confirm the consent tables are inside your backup set and that a restore does not quietly discard recent entries.

How big does the log get?

One row per visitor decision, so a busy site accumulates quickly. This is a further argument for a defined retention period and, on high-traffic sites, for checking that the plugin prunes rather than growing a table indefinitely.


The verdict

For most sites: Complianz at $59 a year, flat. The records come bundled with the banner, the blocking, and the policies, and nobody should buy logging as a separate product.

If proving consent is the actual reason you are shopping: WebToffee at $69 a year, for detailed per-visitor records, CSV export, and visitor-facing consent IDs, with unlimited pageviews so volume does not raise the bill.

If your records must survive a migration or a hosting failure: Cookiebot, storing evidence off your infrastructure, budgeted by page count.

Then do the two free things. Version your banner so each record points at the text actually shown, and write down a retention period and apply it. Those cost nothing and improve your position more than upgrading a licence.