How should consent and authority be documented?¶
Consent and authority should be documented clearly enough to show who permitted access, what they permitted and the limits of that permission.
Avoid this assumption: A willing person handing over a device or account gives unlimited authority to search, copy or retain everything connected with it. Consent may be limited by ownership, account control, employment, shared use, privacy, capacity or the purpose explained.
Record the person’s identity, relationship to the device or account and how they claim authority over it.
Document what they were asked, what they agreed to and whether the consent covered access, copying, retention, disclosure, account action or specialist examination.
Record the date, time, location and people present.
Use the organisation’s approved form or process where one exists, but do not rely on a signature alone. The surrounding explanation and scope still matter.
Record any condition, restriction, withdrawal or uncertainty.
If another person may own, manage or use the system, note that separately.
Do not pressure a victim or witness into agreeing to actions they do not understand.
Where the person lacks clear authority, the device is shared, or the material belongs to an employer or third party, seek legal or supervisory advice.
If urgent safeguarding or preservation action is taken without consent, document the separate lawful basis and why delay was not reasonable.
Keep consent separate from evidential interpretation. Permission to access does not prove who created or controlled the material.
Operational takeaway¶
Document who gave permission, their relationship to the system, the exact scope and limits of consent, and any separate authority relied upon for actions beyond it.