Blog
Consent management for user research
June 24, 2026 · 6 min read
Consent is where research ethics and the law meet the day-to-day. Done well, it protects participants, keeps you compliant, and builds the trust that makes people open up. Done poorly, it is a liability waiting to surface.
What good consent looks like
- Informed — the participant understands what you will collect and why.
- Specific — it covers this study and purpose, not everything forever.
- Recorded — you can show what each person agreed to, and when.
- Revocable — withdrawing is easy, and you can actually act on it.
What to track per participant
- Consent status — granted, pending, expired, or withdrawn.
- Scope — what it covers (interview, recording, use of quotes).
- Recording permission and any NDA, tracked separately from general consent.
- Expiry and retention — when consent lapses, and when data should be removed.
Practices that hold up
- Capture consent before the session, not after.
- Make status visible at a glance across your participants.
- Handle expiry and withdrawal by anonymizing or deleting, on a schedule.
- Tie consent to retention, so lapsed consent triggers cleanup.
How Lens helps
Lens tracks consent status, recording permission, and NDA per participant, and pairs them with anonymize, export, and erasure — with GDPR settings that gate consent and retention policy. For the bigger picture, see GDPR-compliant user research.
This article is general guidance, not legal advice — validate against your own policies and obligations.
See Lens on your own research
Request access