As of January 1, 2026, California's amended CCPA regulations require businesses to visibly confirm every opt-out request they process, including the ones that never touch a human and instead arrive as a browser-level Global Privacy Control (GPC) signal. Most platforms marketed as "CCPA-compliant" still can't produce that confirmation, or the audit trail behind it, when a regulator asks.
If you're evaluating platforms right now, the real question isn't whether a tool can show a cookie banner. Nearly all of them can. The question is whether it can prove, months later, exactly what a specific California visitor was shown, what they chose, and how that choice was honored across every system that touched their data. That proof is what "consent logging" actually means, and it's the single feature category where CCPA platforms diverge the most once you look past the marketing page.
Key Takeaways
➤ California's Global Privacy Control confirmation rule took effect January 1, 2026 (Cal. Code Regs. tit. 11, § 7025): platforms must now visibly confirm an honored opt-out, not just detect the signal.
➤ The California Attorney General's $2.75 million settlement with Disney/ABC in February 2026 turned on exactly this gap: GPC opt-outs applied per-device instead of per-consumer, so the same person had to opt out up to 10 times.
➤ CPRA record-keeping rules (Cal. Code Regs. tit. 11, § 7101) require businesses to retain consumer-request records for at least 24 months: a floor a consent log has to clear, not a ceiling to design around.
➤ The California Privacy Protection Agency's Audits Division began conducting announced and unannounced CCPA compliance audits in 2026, per Executive Director Tom Kemp, so a defensible log is no longer a hypothetical need.
Why "CCPA-Compliant" and "Audit-Ready" Aren't the Same Claim
Any banner vendor can advertise CCPA compliance. Far fewer can hand you a report, six months from now, that proves what happened on a specific visit.
Consent log: a timestamped record of a consent or opt-out event (who was shown what notice, which choice they made, and through which mechanism, whether a click, a toggle, or a GPC signal), retained and exportable for regulatory review.
The distinction matters because of how CCPA enforcement has actually played out in 2026. The California Attorney General's February 2026 settlement with Disney and ABC is the clearest example: the companies treated a GPC opt-out as applying only to the specific device and service in use, even when the consumer was logged into an account the company could otherwise link across devices. The AG's complaint put it plainly: "if a business can associate a consumer's devices with the consumer for advertising purposes, it can and must associate those devices with the consumer for purposes of honoring the consumer's opt-out rights." Fixing that after the fact required Disney to prove, system by system, what its opt-out logic had actually done, the exact task a shallow consent log can't support.
Ford Motor Company's $375,703 settlement the following month turned on a related failure: requiring consumers to complete an email verification step before an opt-out request would even be processed, which CCPA regulations prohibit as an extra barrier. PlayOn Sports' $1.1 million settlement, also in March 2026, involved third-party tracking pixels (including against ticket-buying students) that kept firing after opt-out signals should have suppressed them. None of these were banner-design failures. Each was a mismatch between what the platform's logs said had happened and what the platform's trackers actually did. If you're not yet current on what changed in the CCPA regulations this year, the full rundown of 2026's new requirements covers the opt-out confirmation rule and the other amendments in detail.
That gap is also why the California Privacy Protection Agency is now checking for it directly. CalPrivacy's Executive Director, Tom Kemp, has confirmed the agency's newly created Audits Division began both announced and unannounced CCPA compliance audits in 2026, with findings that can be referred straight to the Enforcement Division. A consent log is the artifact you hand over when that letter arrives. "We have a banner" and "we can prove what the banner did" are now two different compliance postures, and only one of them survives an audit.
Confused about what qualifies as a valid opt-out signal in the first place? Global Privacy Control's legal status across state laws is worth reading before you shortlist platforms, since a tool that mishandles GPC will produce logs that document its own violation.
The 6 Things a Consent Log Actually Needs to Do
Not every "audit trail" claim on a pricing page means the same thing. Before comparing vendors, use this as your working checklist: a platform that can't do all six isn't giving you a real audit trail, whatever it calls the feature.
Capture every event with full context. Timestamp, the banner version shown, the jurisdiction the platform detected, and the exact choice made, not just "consented: yes/no."
Log GPC and manual opt-outs as distinct events. Since January 1, 2026, California requires visible confirmation specifically when the opt-out arrived via a preference signal like GPC, so the log needs to record which mechanism triggered which outcome, not merge them into one generic "opted out" flag.
Retain records for at least 24 months. This is the CPRA's own floor under Cal. Code Regs. tit. 11, § 7101 for consumer-request records: treat any platform that can't guarantee retention past that window as non-compliant by design, not just under-featured.
Export in a format a regulator or auditor can actually use. A dashboard you can screenshot is not the same as a CSV or API export a legal team can hand to outside counsel or a state agency on short notice.
Tie logs to configuration history. If your banner logic changed in March, the log needs to show which version was live for a consent captured in February. Otherwise you can't reconstruct what a given visitor actually saw.
Hold up across every domain and subdomain, without gaps. A log that's airtight on the main site but silent on a checkout subdomain or a regional microsite is a log with a hole in exactly the place a plaintiff's attorney will look first.
If your business operates outside California too, check whether the same log format extends to Colorado, Connecticut, and the growing list of other states with their own universal opt-out mandates, plus CIPA-adjacent wiretapping exposure from chat widgets and session-replay tools. A platform that only logs CCPA-shaped events will leave you rebuilding the same evaluation for every other state law that reaches your traffic.
Platform Overview
OneTrust is the largest enterprise privacy suite on the market, bundling consent management with data mapping, vendor risk, and DPIAs under one (expensive) roof. TrustArc occupies similar enterprise territory with a strong compliance-reporting layer, built more around consultative deployments than self-serve setup. Osano targets mid-market and SMB buyers with U.S.-law-first positioning and a flat, published pricing page, a rarity in this category. Termly is priced for solo sites and small teams that mainly need a banner and a policy generator, with consent logging as a lighter add-on rather than the product's core. Usercentrics leans toward ad-tech and IAB TCF use cases, with session-metered pricing that scales predictably as traffic grows. Secure Privacy covers the same CCPA/CPRA ground (GPC handling, opt-out logging, DSAR intake) as a self-serve, per-domain product without the enterprise sales process the two largest suites require.
Need context on the wider category before drilling into consent logging specifically? The different types of consent management platforms breaks down how banner-only tools differ from full compliance suites.
Consent Logging Compared
Consent logging is the one feature area where marketing language flattens real differences, so this table isolates it specifically: how deep the audit trail goes, whether GPC gets logged as its own event type, how long records last, and what it costs to get there.
| Platform | Audit-Trail Depth | GPC Signal Logging | Log Retention & Export | Starting Price |
|---|---|---|---|---|
| OneTrust | Consent receipts stored in an audit-ready database with change history; comprehensive but spread across modules, so pulling a single regulator-ready report often needs platform expertise | Supported as part of the broader consent-preference sync across systems | Exportable; retention configurable at the enterprise-contract level | No published pricing; minimum annual contract around $10,000, with mid-market deals commonly $40,000–$120,000 |
| TrustArc | Consent decisions recorded as a "legally defensible audit trail" with exportable reports mapping status to regulatory requirements | GPC and other universal opt-out signals supported at the platform level | Reports exportable; deployment is consultative rather than self-serve | Not published; typical deployments run $15,000–$75,000/year before implementation costs |
| Osano | Logs banner version, device, and timestamp per consent event; historical records preserved even after cookies are cleared | Recognizes GPC as part of its "Do Not Sell" opt-out workflow | CSV export supported for offline audits; built specifically around CPRA and other U.S. state laws | $199/month (Plus plan); flat, published pricing |
| Termly | Document-generation focused; consent logging exists but sits behind banner and policy tools rather than as a dedicated audit-trail product | Not a primary feature of the platform's positioning | Limited compared to compliance-control-focused platforms | $10/site/month (Starter, billed annually); each additional site is billed separately |
| Usercentrics | Stores a consent record per accept/reject decision tied to script blocking; audit trail included across its supported frameworks | Automatically suppresses the banner and shows required visible confirmation when GPC is detected, per California's 2026 rule | Included in all paid plans | Free tier available; self-serve plans scale from roughly $56 to $795/month by session volume |
| Secure Privacy | In-depth audit logs viewable and exportable directly from the dashboard, covering every accepted, declined, and partial consent | GPC handling included starting on the free tier | Exportable from the dashboard; DSAR forms and 55+ jurisdiction templates included from the Business tier up | $15/domain/month (Small); $59/month (Business, adds DSAR forms); $249/month (Advanced, adds audit logs at scale) |
Every table cell above reflects what each vendor states publicly as of this writing; none of these platforms publish an identical definition of "audit-ready," which is exactly why the six-point checklist earlier in this piece matters more than any single column here.
Want the audit trail without the enterprise sales call? Secure Privacy's Cookie & Consent Solution logs every consent decision, honors GPC automatically, and exports the full trail from a dashboard you can set up yourself, no six-figure minimum contract required.
Common Mistakes When Evaluating Consent Logging
Assuming "GDPR-ready" means "CCPA-ready." A platform built primarily for EU opt-in consent can log opt-ins beautifully while still failing to distinguish an opt-out request, a GPC signal, and a Do-Not-Sell click: three separate compliance events under CCPA that a GDPR-first tool sometimes bundles into one.
Confusing "we detect GPC" with "we log and confirm GPC." Detection is the easy half. The Disney settlement happened because detection didn't propagate the opt-out everywhere it needed to, and the same failure mode can exist in a platform whose sales deck says "GPC-supported" without specifying at what depth.
Assuming an opt-out mechanism that worked at setup still works months later. Clothing retailer Todd Snyder paid a $345,178 CPPA fine in May 2025 after its opt-out tool silently stopped functioning for 40 days. A consent log that only records successful opt-outs, with no alerting on a broken opt-out flow, would have hidden that gap for the entire outage window.
Treating a 24-month retention window as optional. Some lower-tier plans cap log retention well below the CPRA's own floor. Ask specifically what happens to consent records older than 24 months on the plan tier you're actually buying, not the enterprise tier in the demo.
Not checking export format until after signing. A screenshot is not a CSV, and a CSV without an API isn't something your legal team can retrieve at 5 p.m. on a Friday when outside counsel asks for it. Confirm the export mechanism during the trial, not during an actual regulatory inquiry. The same scrutiny applies to whatever tool handles the requests on the other side of that log: purpose-built DSAR tooling should show the same audit-ready discipline as the consent log itself.
Skipping the subdomain and multi-brand test. If your organization runs a checkout flow on a separate subdomain or operates multiple brand sites, test consent logging on all of them before committing. Gaps tend to hide exactly where nobody thought to look.
If your organization is also juggling vendor risk assessments, AI system inventories, or DPIAs alongside cookie consent, that's a separate governance layer most CCPA-focused CMPs (including the enterprise suites) sell as a bolt-on module rather than build for. Secure Privacy's companion Privacy & AI Governance Platform handles that layer (vendor management, risk assessments, and AI governance) as its own product rather than a line item inside a bundled enterprise SKU, so you're not paying a six-figure floor to get consent logging plus governance in one relationship.
Choose a Platform Based On Your Actual Buying Situation
Choose OneTrust or TrustArc if you already run a large, multi-entity enterprise with a dedicated privacy engineering team and budget for a five-to-six-figure annual contract plus implementation services: their modular depth pays off at that scale.
Choose Osano if your primary need is CPRA/U.S.-state coverage specifically and you want published, predictable pricing without a sales call.
Choose Termly if you run one or two small sites and mainly need banner and policy generation, with consent logging as a secondary concern.
Choose Usercentrics if ad-tech integration and IAB TCF compatibility matter more to your stack than CCPA-specific depth, and session-based pricing fits your traffic pattern.
Choose Secure Privacy if you want CCPA/CPRA-specific consent logging (including automatic GPC handling and exportable audit logs) self-serve, at a per-domain price that scales with your actual footprint instead of a sales-negotiated enterprise floor, with a straight upgrade path to full privacy and AI governance tooling if your program grows into that need.
FAQ
What counts as "consent logging" under CCPA?
CCPA itself doesn't use the term "consent logging," but its implementing regulations require businesses to retain records of consumer requests, including opt-outs, for at least 24 months (Cal. Code Regs. tit. 11, § 7101). In practice, a consent log is how a platform satisfies that requirement: a timestamped record of what a consumer was shown, what they chose, and how that choice was carried out.
Does my consent platform need to log Global Privacy Control signals separately from manual opt-outs?
Yes, in practice. Since January 1, 2026, California regulations (Cal. Code Regs. tit. 11, § 7025) require businesses to visibly confirm an opt-out that arrived via a preference signal like GPC. A platform that merges GPC opt-outs and manual opt-outs into one generic log entry can't produce that specific confirmation on demand, which is a documented enforcement risk given the 2026 Disney and PlayOn Sports settlements.
How long do I need to keep CCPA consent records?
At least 24 months, per the CPRA's record-keeping rule (Cal. Code Regs. tit. 11, § 7101). That's a regulatory floor, not a target — many businesses retain longer, since the statute of limitations on related claims can extend past that window.
Is a free consent management tool enough for CCPA compliance?
It depends entirely on scale and risk exposure. A free tier can be genuinely compliant for a small site with low traffic and no complex multi-domain setup, but most free tiers cap consent volume and log retention well below what a growing business or a company facing an actual audit would need. Check the specific retention and export limits on the free tier, not just whether GPC is "supported."
What's the difference between a consent log and a cookie scan report?
A cookie scan report tells you what trackers and cookies exist on your site at the time of the scan. A consent log tells you what a specific visitor was shown and chose, and when. Both matter for CCPA compliance, but they answer different questions during an audit. A regulator asking about a specific consumer complaint needs the consent log, not the scan report.
Do enterprise platforms like OneTrust log consent more thoroughly than smaller platforms?
Not necessarily more thoroughly — more broadly. Enterprise suites bundle consent logging with data mapping, vendor risk, and DPIA modules across a much larger surface area, which is genuinely valuable at multi-entity scale but doesn't mean the CCPA-specific consent log itself is deeper than what a CCPA-focused platform provides. Evaluate the six-point checklist above against the specific plan tier you'd actually buy, not the platform's full enterprise capability set.
Can I switch consent platforms without losing my existing consent history?
Most platforms let you export historical consent records before migrating, but the receiving platform generally can't "import" that history into its own active audit trail in a way regulators would treat as continuous. Plan a migration so the old platform's export is archived and retrievable independently, rather than assuming the new platform inherits the old log.
Choosing the wrong platform here doesn't just risk a failed audit — it risks discovering the gap only after a state agency or a plaintiff's attorney finds it first. Secure Privacy's Cookie & Consent Solution builds CCPA-specific consent logging, automatic GPC handling, and exportable audit trails into a self-serve platform priced per domain, with DSAR forms and 55+ jurisdiction templates included as your program grows. Book a demo to see your actual consent log, not a sales deck screenshot of one.




