Guide · June 17, 2026
Consent compliance reports for leadership and auditors: what to include
How to build consent compliance reports for leadership/audit: metrics, evidence, and exporting case files for inspections.
Quick answer
What is a consent compliance report for leadership and audit?
This report is a governance dossier showing how the company collects, stores, queries, and presents evidence of consent. Under the Personal Data Protection Law, companies not only need to obtain consent, but must also prove that the consent is valid, retrievable, and can be cross-checked when a competent authority inspects.
In practice at SMEs, many operations teams keep consent scattered across the cookie banner, signup forms, the CRM, email marketing, and the call center system. A good report should consolidate these sources into a single, coherent picture so leadership can see the risks and auditors can see the evidence.
Which metrics should the report track?
A good template should start from risk management, not just counting consents. Metrics to include:
- Opt-in rate by channel: website, app, offline forms, hotline, sales.
- Decline and withdrawal rates: to gauge whether the process is transparent.
- Share of consents with complete evidence: timestamp, content version, processing purpose, source of collection.
- Defective consent rate: missing information, no purpose separation, no logs.
- Response time to retrieve evidence: for example, how long it takes to produce a specific case file.
- Number of DSARs related to consent: access, rectification, withdrawal, deletion.
- Data incidents related to consent or data subject rights.
| Metric | Governance meaning | How to use in the report | |
|---|---|---|---|
| Consent rate | Measure acceptance for each flow | Compare by landing page, campaign, product | |
| Withdrawal rate | Measure withdrawal levels | Detect consent requests that are too broad or unclear | |
| Evidence completeness | Measure evidence quality | Identify which files are audit-ready | |
| Retrieval time | Measure ability to produce files | Test readiness for authority requests | |
| Incident count | Measure operational risk | Prioritize remediation for high-error flows |
What do leadership and audit need to see?
A useful report should not stop at a colorful dashboard. Leadership typically needs four layers of information:
- Current compliance status: how many flows have valid consent, and which flows are not yet compliant.
- Priority risks: which systems use cookies/trackers or collection forms but lack complete evidence.
- Ability to respond to inspections: how quickly files can be produced, who approves, who is accountable.
- Remediation plan: which flows to fix first, SLAs, and required budget.
For internal audit, they usually care about control trails: who created the consent content, who approved it, what changed, which systems keep logs, and whether withdrawal actually stops further processing.
How do you produce evidence when authorities inspect?
When a competent authority requests it, the company should have a standardized “evidence package” that is easy to extract and not dependent on any single individual. According to the regulations, the enforcement authority is the Ministry of Public Security — the Department of Cybersecurity and High-Tech Crime Prevention (A05).
Finalize the scope of the request:
Identify the system(s), timeframe, processing purposes, and data groups involved.
Freeze the content version:
Export the consent content at the time of collection, including the displayed text, language, selection controls, and specific purposes.
Pull technical logs:
Extract timestamp, user/session ID, IP if available, traffic source, and the opt-in/decline/withdrawal status.
Cross-check with CRM/marketing:
Prove that the consent is linked to the correct customer record and used only within the notified scope.
Standardize the handover files:
Consolidate PDFs/CSVs/screenshots/logs into a folder with an index, stating who extracted them, when, and from which system.
Keep the chain of custody:
Record who approved releasing the files to avoid disputes over the integrity of the evidence.
A real example: a SaaS company in Ho Chi Minh City runs a trial form, a cookie banner, and an email nurture. During inspection, they need to produce: the cookie banner text by version; logs of “Agree” clicks; the policy page as of that time; and evidence that anyone who withdrew consent is no longer in the marketing flow.
What report structure works for immediate use?
You can use a one-page format for leadership plus appendices for audit:
- Page 1: summary of status, red/yellow/green risks, notable incidents, actions in the next 30 days.
- Section 2: metric dashboards by channel and by system.
- Section 3: list of critical consent flows, owners, and evidence completeness.
- Section 4: sample case files, storage links, approval process.
- Appendix: sample logs, screenshots, content versions, change records.
If your company has a cookie banner, CRM, CDP, call system, or app, tag each flow with an identifier so auditors can trace quickly. This also reduces reliance on manual spreadsheets.
How to handle missing consent evidence?
Treat it as a control gap, not a one-off technical error. The company should temporarily pause campaigns that rely on consent lacking evidence, review the consent content, and add logging from the next collection onward. If a data incident arises, the company must notify within 72 hours of discovery as required.
Specific penalties will be set by the Government’s implementing decree; serious violations may face criminal liability. Therefore, when reporting to leadership, make the legal risks and remediation roadmap explicit, instead of simply writing “monitoring.”
- Not necessarily. Management reports should be aggregated by flow, system, channel, and risk level; customer-level details are only needed for case-file production or a specific inspection.
- According to regulations and the company’s internal policy, retain it long enough to prove validity and satisfy inspection, dispute, or audit requests.
- Yes, if the cookie/banner generates data or tracking for purposes that require consent. The company should retain the content version, display time, and interaction logs.
- Designate a legal/compliance or security lead to coordinate with IT and data teams for extraction, reconciliation, and handover under the approved process.
If you’d like, consent.vn can help standardize the consent dashboard, store consent evidence, and prepare DSAR bundles for quicker production during inspections.
Source: the Personal Data Protection Law (Law 91/2025/QH15): https://thuvienphapluat.vn ; Decree 13/2023/ND-CP: https://thuvienphapluat.vn ; A05: https://bocongan.gov.vn
Get started — set up in 5 minutes.
Deploy PDPL solutions for your business?