figma guide
Designing consent records and preference management admin UI in Figma: proof, purposes, and audit trails
Design consent records and preference management admin UI in Figma with purpose-level proof, CMP sync, withdrawal logs, lawful basis linkage, and DSAR evidence for Privacy teams.
- Published
- Updated
- Aug 04, 2026
- Read time
- 9 min
- Level
- Intermediate
Quick answer
Consent records admin UI is the internal proof layer behind customer-facing banners and preference centers—it stores who consented, to what purpose, when, how, and what changed after withdrawal. Design a consent ledger searchable by user, purpose, and channel; a purpose catalog synced with ROPA activities and cookie consent surfaces; and evidence panels that export regulator-ready bundles for DSAR and audit. Start from the Figma guides hub and pair with notification preferences, privacy settings, DSAR portal, trust center, and Dev Mode handoff.
Who this is for
- Product designers building privacy ops consoles where Legal needs proof, not screenshots of a CMP dashboard.
- Design system teams standardizing purpose chips, consent state badges, and evidence export patterns across B2B SaaS.
- Privacy and Marketing ops reconciling campaign sends with lawful basis and withdrawal timestamps without CSV archaeology.
Consent admin hub (internal overview)
ConsentHub — Acme Privacy · 4.2M active records · 18 purposes · Last CMP sync 4 min ago
├── Header: Marketing opt-in 312k · Analytics 891k · Product email 1.1M · Withdrawals today 847
├── Actions: [ Search user ] [ Export evidence bundle ] [ Sync CMP ] [ Purpose catalog ]
├── Tabs: Consent ledger · Purpose registry · Withdrawals · CMP mapping · Disputes · Reports
├── Alert: Purpose P-07 "Partner co-marketing" · Missing policy version link · Blocks new capture
├── Filters: Purpose · Channel · Region · Lawful basis · Policy version · Date range
└── Link: [Cookie consent UI](/designing-cookie-consent-and-tracking-preference-ui-in-figma/) · ROPA · DSAR · Trust center
| Section | Purpose |
|---|---|
| Consent ledger | Immutable-style log of grant, update, and withdrawal events |
| Purpose registry | Canonical list of consent purposes tied to ROPA and copy |
| Withdrawals | Marketing and analytics opt-outs with downstream job status |
| CMP mapping | Vendor category ↔ internal purpose ↔ tag firing rules |
| Disputes | ”I never opted in” tickets with evidence replay |
| Reports | Regulator export; consent rate by region and surface |
Verdict: Admin consent UI must answer “prove it for this user on this date” in under 30 seconds—or DSAR and Marketing disputes become week-long email chains.
Consent ledger record (user detail)
ConsentDetail — user_8f2a · sarah@example.com · Last event Aug 3, 2026 14:22 UTC
├── Identity: User ID · Email hash · Account region EU · Guest: No
├── Current state by purpose:
│ ├── P-01 Essential product · Not consent-based · Contract · Always on
│ ├── P-03 Analytics · Withdrawn Aug 3 · Was granted Jun 12, 2024
│ ├── P-05 Marketing email · Active · Granted Jul 1, 2026 · Double opt-in confirmed
│ └── P-07 Partner co-marketing · Never granted · N/A
├── Event timeline (newest first):
│ ├── Aug 3 14:22 · Withdrawal · P-03 Analytics · Source: preference center
│ ├── Jul 1 09:01 · Grant · P-05 Marketing · Source: signup checkbox · Policy v4.2
│ └── Jun 12 11:44 · Grant · P-03 Analytics · Source: cookie banner · Policy v3.8
├── Evidence:
│ ├── Banner variant B · Screenshot hash · IP country DE · User agent snapshot
│ ├── Policy version v3.8 · Link [privacy notice registry]
│ └── CMP receipt ID cmp_evt_99102 · Vendor webhook delivered
├── Downstream: Segment traits updated · 3 campaigns suppressed · Job status Complete
└── [ Export PDF ] [ Attach to DSAR ] [ Open dispute ]
| Field | UI pattern |
|---|---|
| Purpose | Controlled vocabulary; color chip matches ROPA lawful basis |
| Event type | Grant · Update · Withdrawal · Expiry · Admin override |
| Source | Banner · Preference center · Signup · API · Support override |
| Policy version | Required on grant; link to notice management |
| Evidence | Hash + vendor receipt; never editable after write |
| Downstream | Show sync jobs—Marketing must see “suppression pending” |
Withdrawals should feel immediate in UI even if async jobs run—show pending state until CRM and ad platforms confirm.
Purpose registry and ROPA linkage
PurposeRegistry — 18 purposes · 2 missing ROPA link · 1 deprecated
├── P-05 Marketing email · Lawful basis: Consent · ROPA PA-204 · Retention: until withdrawal
├── Capture surfaces: Signup checkbox · Account notification prefs · Re-consent modal
├── Copy blocks: Short label · Full description · Link to privacy notice section 4.2
├── Regions: EU required · UK required · US optional (state rules flag)
├── Double opt-in: Required EU/UK · Confirmation email template ID em_442
├── CMP mapping: OneTrust category C0004 → internal P-05
├── Expiry: None · Re-consent campaign: every 24 months optional
└── [ Edit purpose ] [ Deprecate ] [ Preview capture UI ]
| Registry field | Design note |
|---|---|
| ROPA link | Bidirectional; changing purpose text flags ROPA review |
| Capture surfaces | Thumbnail of each UI; link Figma frames |
| Regional rules | EU opt-in default; US state toggles for CPRA sell/share |
| Deprecation | Cannot delete with historical records—mark Deprecated |
| Version drift | Alert when live banner copy ≠ registry canonical text |
Purpose registry is the contract between Legal, Marketing, and Engineering—banner redesigns should pull copy from here, not Slack threads.
CMP sync and tag governance
CMPSyncPanel — OneTrust · Last sync 4 min · 3 mismatches
├── Category map: CMP C0002 Analytics ↔ P-03 · Tags: GA4, Hotjar · Fire when granted
├── Mismatch: Live site fires LinkedIn Insight without mapped purpose · Severity High
├── Webhook log: consent_updated · 12,441 events last 24h · 0 failed
├── Staging vs prod: Prod policy v4.2 · Staging v4.3 draft · Diff viewer
├── Block rules: No P-07 tags until purpose approved + ROPA signed off
└── [ Run tag audit ] [ Pause misfiring tag ] [ Open cookie consent frames ]
| Sync concern | UI guardrail |
|---|---|
| Unmapped tags | Daily scan; assign purpose or block |
| Withdrawal lag | Show max SLA; alert if CRM still sending after 24h |
| Policy preview | Side-by-side v4.2 vs v4.3 before publish |
| Guest consent | Anonymous ID merge on login—show merge event in ledger |
| Children’s data | Hard block purposes for under-16 accounts |
Connect misfiring tags to third-party app approvals when vendor is a new integration.
Withdrawal queue and Marketing suppression
WithdrawalQueue — 847 today · 12 pending downstream · 0 SLA breach
├── Row: user_8f2a · P-03 Analytics · Aug 3 14:22 · Segment ✓ · Braze ✓ · Ad pixel pending
├── Row: user_991c · P-05 Marketing · Aug 3 13:01 · Mailchimp ✓ · Salesforce ✓
├── Bulk: Import unsubscribe list · Validate against ledger · Reject unknown emails
├── SLA: 95% complete within 15 min · Alert channel #privacy-ops
└── [ Retry failed ] [ Export daily withdrawal report ]
Marketing teams need operational clarity, not legal jargon—show checkmarks per integration, not “Article 7(3) satisfied.”
Failed suppressions should create tickets in the same console as DSAR fulfillment with shared user ID lookup.
Disputes and DSAR evidence bundles
DisputeCase — D-118 · "I never agreed to marketing" · Open · SLA 5 days
├── User timeline: Only withdrawal events for P-05—no grant found in ledger
├── Investigation: Signup checkbox was pre-checked before Jul 2026 fix · Known incident INC-442
├── Remediation: Class correction queued · 2,841 users · Legal approved template
├── Evidence export: PDF timeline + policy v3.1 snapshot + banner variant A screenshot
├── DSAR link: Request REQ-881 · Access package includes consent appendix
└── [ Close with root cause ] [ Escalate to Legal ]
| Dispute type | UI workflow |
|---|---|
| No grant found | Search alternate IDs (email change, merge) |
| Dark pattern allegation | Link capture surface frame + A/B test metadata |
| Wrong lawful basis | Flag ROPA row; suggest LIA or consent migration |
| Bulk incident | Class remediation wizard with comms template |
Evidence bundles should match compliance audit evidence export formats—hash, timestamp, signer.
Handoff checklist (Dev Mode)
- Consent event — id, user_id, purpose_id, event_type, timestamp_utc, source_surface, policy_version_id.
- Purpose — id, name, lawful_basis, ropa_activity_id, regions[], capture_surfaces[], cmp_category_id.
- Evidence — banner_variant, screenshot_hash, cmp_receipt_id, ip_country, user_agent_truncated.
- Withdrawal — downstream_jobs[] with status (pending, complete, failed), retry_count.
- Dispute — case_id, status, linked_dsar_id, incident_id, remediation_batch_id.
- Accessibility — timeline navigable by keyboard; status not color-only; export available as text.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Consent stored only in CMP vendor | Cannot join to product user ID for DSAR | Internal ledger + webhook sync |
| Purpose labels differ per surface | Proof breaks in disputes | Purpose registry as single copy source |
| No policy version on grant | Invalid consent after notice update | Require version_id on every grant event |
| Withdrawal without downstream status | Marketing still emails | Suppression job tracker with SLA |
| Pre-checked boxes in EU | Unlawful consent | Region-aware capture preview in registry |
| Immutable log that is actually editable | Audit failure | Append-only events; admin override as separate type |
| Guest and logged-in consent silos | Missing proof after login | Merge event in timeline |
| Analytics consent mixed with email | Wrong lawful basis | Separate purposes per channel |
| No dispute workflow | Privacy team in Zendesk | Dispute tab with evidence export |
| Export omits banner variant | Cannot reproduce UI state | Store variant ID + screenshot hash |
Recommended workflow
- Design purpose registry with ROPA links and regional capture rules.
- Build consent ledger with searchable timeline and evidence attachments.
- Wire CMP sync panel with tag audit and mismatch alerts.
- Add withdrawal queue showing per-integration suppression status.
- Create dispute workspace linked to DSAR and incident records.
- Connect cookie consent frames so designers preview capture UI from registry.
- Export quarterly consent metrics for trust center and audit packs.
FAQ
Admin UI vs cookie consent UI?
Cookie consent is customer-facing capture. Consent admin is internal proof, sync, disputes, and Marketing suppression—both share the purpose registry.
Link to ROPA?
Every consent-based purpose maps to a ROPA activity with matching lawful basis—changing one should flag the other for review.
Double opt-in required?
Design region-aware rules in purpose registry—EU/UK marketing often requires confirmation step with separate ledger event.
DSAR access package?
Include consent timeline appendix auto-generated from ledger—standard export template.
Legitimate interest instead of consent?
If purpose uses LI, link LIA workflow instead of consent events—do not mix proof types on same purpose row.
Next steps
- Design cookie consent and tracking preference UI in Figma — customer-facing capture surfaces
- Design records of processing activities and data mapping UI in Figma — lawful basis and purpose linkage
- Design data subject access request and GDPR portal UI in Figma — access packages with consent evidence
- Design notification preferences and communication settings UI in Figma — user-facing preference center
- Design privacy settings and data management UI in Figma — account-level privacy controls
§ Keep reading