Consent is not a tick in a database. It is a person, a moment, a form of words they were actually shown, and a way of taking it back that is as easy as giving it. When somebody asks what they agreed to, the answer has to be the wording from that day, not the wording on the site now. This keeps that record, including the part everyone forgets: what happened when somebody changed their mind.
A record of consent is worth nothing without the words that were agreed to. Keep each version here; entries point at the version in force when they were taken, so changing the wording later cannot quietly rewrite what somebody agreed.
The wording is the record. Nobody consents to a database column. They consent to a sentence on a screen, and the only answer to "what did I agree to?" is that sentence as it stood on that day. Wordings are versioned here and entries point at a version, so changing the site later cannot quietly change what somebody agreed to two years ago.
A pre-ticked box is not consent, and the page says so. Nor is continuing to browse, nor is silence, nor is a condition of service that has nothing to do with the service. Entries recorded that way are marked as weakly evidenced rather than accepted quietly, because the moment they are relied on is the moment somebody looks closely at them.
Withdrawal is part of the record, not the end of it. Deleting the row when somebody unsubscribes destroys the evidence that they were ever on the list and the evidence that you stopped when asked. Withdrawals are recorded here alongside the consent, with the date and how it was made, and the entry stays.
Consent goes stale even when nobody withdraws it. Something agreed to four years ago, for a thing somebody has not engaged with since, is not obviously still agreed to. There is no fixed period in law and there is a practical one: the page marks entries older than the period you set, so a stale list is visible rather than assumed.
It stays on this machine. A consent register is a list of people with their contact details and what they agreed to. Keeping it on a service in order to demonstrate good data practice would be an odd way round. Export it and keep it where your other records live.
No, and reaching for it by default is a common mistake. Most processing runs on another basis: performing a contract, complying with an obligation, a legitimate interest that has been assessed and written down. Consent is the right basis when the person genuinely has a free choice, and the wrong one when they do not, because consent that cannot be refused is not consent.
Freely given, specific, informed and unambiguous, by a clear affirmative act. In practice that means an unticked box they ticked, wording that says who and what for, a real option to say no, and a record of all of it. Bundling several purposes into one tick fails the specific part.
There is no fixed period. It lasts until it is withdrawn or until it is no longer reasonable to rely on it, which is a judgement about the context. Setting a period here and reviewing what goes past it is the practical version of that judgement.
Stop, promptly, and record that you stopped. Withdrawal must be as easy as giving it was. Keep the record of both: the consent, and the withdrawal. What you must not keep is the processing.
It helps a great deal, and it is not enough on its own, because it does not tie a person to a moment. What you want is the wording, the person, the timestamp and the mechanism together. This page keeps those four things in one row and points the row at the wording.