A receipt per decision, chained so it cannot be edited
28 August 2026
Every consent, withdrawal and notice view as a hash-chained receipt, so the record shown to the Board can be shown to be unaltered.
A consent log answers the question "what does your system currently say?". A consent receipt answers "what did your system say at the time, and can you show it has not been changed since?". Only the second is useful when the record is contested.
What a receipt records
Each receipt covers a single decision — a consent given, a consent withdrawn, a notice viewed — and carries the purpose it applies to, the notice version and language that were shown, the timestamp, and the identifier of the Data Principal. One decision, one record. A consent covering three purposes produces three receipts, which is what makes selective withdrawal expressible.
Why the chain matters
Each receipt includes the digest of the one before it. Altering an earlier record changes its digest, which breaks every digest after it, which is detectable without trusting the operator of the database. This is the difference between a record you assert is accurate and a record whose accuracy can be checked by someone who does not trust you — which describes the Data Protection Board precisely.
What it is for
Under Sec. 8 the Data Fiduciary carries the burden of demonstrating compliance. In a dispute the questions are narrow and factual: was a notice given before consent, what did it say, in which language, and when was the withdrawal acted on. A chained receipt answers all four from a single artefact, and it answers them the same way six months later.