figma guide

Designing consent records and preference management admin UI in Figma: proof, purposes, and audit trails

Design consent records and preference management admin UI in Figma with purpose-level proof, CMP sync, withdrawal logs, lawful basis linkage, and DSAR evidence for Privacy teams.

Published
Updated
Aug 04, 2026
Read time
9 min
Level
Intermediate

Quick answer

Consent records admin UI is the internal proof layer behind customer-facing banners and preference centers—it stores who consented, to what purpose, when, how, and what changed after withdrawal. Design a consent ledger searchable by user, purpose, and channel; a purpose catalog synced with ROPA activities and cookie consent surfaces; and evidence panels that export regulator-ready bundles for DSAR and audit. Start from the Figma guides hub and pair with notification preferences, privacy settings, DSAR portal, trust center, and Dev Mode handoff.


Who this is for

  • Product designers building privacy ops consoles where Legal needs proof, not screenshots of a CMP dashboard.
  • Design system teams standardizing purpose chips, consent state badges, and evidence export patterns across B2B SaaS.
  • Privacy and Marketing ops reconciling campaign sends with lawful basis and withdrawal timestamps without CSV archaeology.

ConsentHub — Acme Privacy · 4.2M active records · 18 purposes · Last CMP sync 4 min ago
├── Header: Marketing opt-in 312k · Analytics 891k · Product email 1.1M · Withdrawals today 847
├── Actions: [ Search user ] [ Export evidence bundle ] [ Sync CMP ] [ Purpose catalog ]
├── Tabs: Consent ledger · Purpose registry · Withdrawals · CMP mapping · Disputes · Reports
├── Alert: Purpose P-07 "Partner co-marketing" · Missing policy version link · Blocks new capture
├── Filters: Purpose · Channel · Region · Lawful basis · Policy version · Date range
└── Link: [Cookie consent UI](/designing-cookie-consent-and-tracking-preference-ui-in-figma/) · ROPA · DSAR · Trust center
SectionPurpose
Consent ledgerImmutable-style log of grant, update, and withdrawal events
Purpose registryCanonical list of consent purposes tied to ROPA and copy
WithdrawalsMarketing and analytics opt-outs with downstream job status
CMP mappingVendor category ↔ internal purpose ↔ tag firing rules
Disputes”I never opted in” tickets with evidence replay
ReportsRegulator export; consent rate by region and surface

Verdict: Admin consent UI must answer “prove it for this user on this date” in under 30 seconds—or DSAR and Marketing disputes become week-long email chains.


ConsentDetail — user_8f2a · sarah@example.com · Last event Aug 3, 2026 14:22 UTC
├── Identity: User ID · Email hash · Account region EU · Guest: No
├── Current state by purpose:
│   ├── P-01 Essential product · Not consent-based · Contract · Always on
│   ├── P-03 Analytics · Withdrawn Aug 3 · Was granted Jun 12, 2024
│   ├── P-05 Marketing email · Active · Granted Jul 1, 2026 · Double opt-in confirmed
│   └── P-07 Partner co-marketing · Never granted · N/A
├── Event timeline (newest first):
│   ├── Aug 3 14:22 · Withdrawal · P-03 Analytics · Source: preference center
│   ├── Jul 1 09:01 · Grant · P-05 Marketing · Source: signup checkbox · Policy v4.2
│   └── Jun 12 11:44 · Grant · P-03 Analytics · Source: cookie banner · Policy v3.8
├── Evidence:
│   ├── Banner variant B · Screenshot hash · IP country DE · User agent snapshot
│   ├── Policy version v3.8 · Link [privacy notice registry]
│   └── CMP receipt ID cmp_evt_99102 · Vendor webhook delivered
├── Downstream: Segment traits updated · 3 campaigns suppressed · Job status Complete
└── [ Export PDF ] [ Attach to DSAR ] [ Open dispute ]
FieldUI pattern
PurposeControlled vocabulary; color chip matches ROPA lawful basis
Event typeGrant · Update · Withdrawal · Expiry · Admin override
SourceBanner · Preference center · Signup · API · Support override
Policy versionRequired on grant; link to notice management
EvidenceHash + vendor receipt; never editable after write
DownstreamShow sync jobs—Marketing must see “suppression pending”

Withdrawals should feel immediate in UI even if async jobs run—show pending state until CRM and ad platforms confirm.


Purpose registry and ROPA linkage

PurposeRegistry — 18 purposes · 2 missing ROPA link · 1 deprecated
├── P-05 Marketing email · Lawful basis: Consent · ROPA PA-204 · Retention: until withdrawal
├── Capture surfaces: Signup checkbox · Account notification prefs · Re-consent modal
├── Copy blocks: Short label · Full description · Link to privacy notice section 4.2
├── Regions: EU required · UK required · US optional (state rules flag)
├── Double opt-in: Required EU/UK · Confirmation email template ID em_442
├── CMP mapping: OneTrust category C0004 → internal P-05
├── Expiry: None · Re-consent campaign: every 24 months optional
└── [ Edit purpose ] [ Deprecate ] [ Preview capture UI ]
Registry fieldDesign note
ROPA linkBidirectional; changing purpose text flags ROPA review
Capture surfacesThumbnail of each UI; link Figma frames
Regional rulesEU opt-in default; US state toggles for CPRA sell/share
DeprecationCannot delete with historical records—mark Deprecated
Version driftAlert when live banner copy ≠ registry canonical text

Purpose registry is the contract between Legal, Marketing, and Engineering—banner redesigns should pull copy from here, not Slack threads.


CMP sync and tag governance

CMPSyncPanel — OneTrust · Last sync 4 min · 3 mismatches
├── Category map: CMP C0002 Analytics ↔ P-03 · Tags: GA4, Hotjar · Fire when granted
├── Mismatch: Live site fires LinkedIn Insight without mapped purpose · Severity High
├── Webhook log: consent_updated · 12,441 events last 24h · 0 failed
├── Staging vs prod: Prod policy v4.2 · Staging v4.3 draft · Diff viewer
├── Block rules: No P-07 tags until purpose approved + ROPA signed off
└── [ Run tag audit ] [ Pause misfiring tag ] [ Open cookie consent frames ]
Sync concernUI guardrail
Unmapped tagsDaily scan; assign purpose or block
Withdrawal lagShow max SLA; alert if CRM still sending after 24h
Policy previewSide-by-side v4.2 vs v4.3 before publish
Guest consentAnonymous ID merge on login—show merge event in ledger
Children’s dataHard block purposes for under-16 accounts

Connect misfiring tags to third-party app approvals when vendor is a new integration.


Withdrawal queue and Marketing suppression

WithdrawalQueue — 847 today · 12 pending downstream · 0 SLA breach
├── Row: user_8f2a · P-03 Analytics · Aug 3 14:22 · Segment ✓ · Braze ✓ · Ad pixel pending
├── Row: user_991c · P-05 Marketing · Aug 3 13:01 · Mailchimp ✓ · Salesforce ✓
├── Bulk: Import unsubscribe list · Validate against ledger · Reject unknown emails
├── SLA: 95% complete within 15 min · Alert channel #privacy-ops
└── [ Retry failed ] [ Export daily withdrawal report ]

Marketing teams need operational clarity, not legal jargon—show checkmarks per integration, not “Article 7(3) satisfied.”

Failed suppressions should create tickets in the same console as DSAR fulfillment with shared user ID lookup.


Disputes and DSAR evidence bundles

DisputeCase — D-118 · "I never agreed to marketing" · Open · SLA 5 days
├── User timeline: Only withdrawal events for P-05—no grant found in ledger
├── Investigation: Signup checkbox was pre-checked before Jul 2026 fix · Known incident INC-442
├── Remediation: Class correction queued · 2,841 users · Legal approved template
├── Evidence export: PDF timeline + policy v3.1 snapshot + banner variant A screenshot
├── DSAR link: Request REQ-881 · Access package includes consent appendix
└── [ Close with root cause ] [ Escalate to Legal ]
Dispute typeUI workflow
No grant foundSearch alternate IDs (email change, merge)
Dark pattern allegationLink capture surface frame + A/B test metadata
Wrong lawful basisFlag ROPA row; suggest LIA or consent migration
Bulk incidentClass remediation wizard with comms template

Evidence bundles should match compliance audit evidence export formats—hash, timestamp, signer.


Handoff checklist (Dev Mode)

  • Consent event — id, user_id, purpose_id, event_type, timestamp_utc, source_surface, policy_version_id.
  • Purpose — id, name, lawful_basis, ropa_activity_id, regions[], capture_surfaces[], cmp_category_id.
  • Evidence — banner_variant, screenshot_hash, cmp_receipt_id, ip_country, user_agent_truncated.
  • Withdrawal — downstream_jobs[] with status (pending, complete, failed), retry_count.
  • Dispute — case_id, status, linked_dsar_id, incident_id, remediation_batch_id.
  • Accessibility — timeline navigable by keyboard; status not color-only; export available as text.

Common mistakes

MistakeWhy it hurtsFix
Consent stored only in CMP vendorCannot join to product user ID for DSARInternal ledger + webhook sync
Purpose labels differ per surfaceProof breaks in disputesPurpose registry as single copy source
No policy version on grantInvalid consent after notice updateRequire version_id on every grant event
Withdrawal without downstream statusMarketing still emailsSuppression job tracker with SLA
Pre-checked boxes in EUUnlawful consentRegion-aware capture preview in registry
Immutable log that is actually editableAudit failureAppend-only events; admin override as separate type
Guest and logged-in consent silosMissing proof after loginMerge event in timeline
Analytics consent mixed with emailWrong lawful basisSeparate purposes per channel
No dispute workflowPrivacy team in ZendeskDispute tab with evidence export
Export omits banner variantCannot reproduce UI stateStore variant ID + screenshot hash

  1. Design purpose registry with ROPA links and regional capture rules.
  2. Build consent ledger with searchable timeline and evidence attachments.
  3. Wire CMP sync panel with tag audit and mismatch alerts.
  4. Add withdrawal queue showing per-integration suppression status.
  5. Create dispute workspace linked to DSAR and incident records.
  6. Connect cookie consent frames so designers preview capture UI from registry.
  7. Export quarterly consent metrics for trust center and audit packs.

FAQ

Cookie consent is customer-facing capture. Consent admin is internal proof, sync, disputes, and Marketing suppression—both share the purpose registry.

Every consent-based purpose maps to a ROPA activity with matching lawful basis—changing one should flag the other for review.

Double opt-in required?

Design region-aware rules in purpose registry—EU/UK marketing often requires confirmation step with separate ledger event.

DSAR access package?

Include consent timeline appendix auto-generated from ledger—standard export template.

If purpose uses LI, link LIA workflow instead of consent events—do not mix proof types on same purpose row.


Next steps

Share on X

§ Keep reading

Related guides.