Every client record in Colib carries a consent register: a dated, unalterable list of what your client agreed to, refused or withdrew.
Part of that register fills itself as your clients book appointments and sign forms. The rest is up to you: when a consent is given verbally, on paper, by a parent or through a third party, you record it yourself in one short form.
Privacy law does not only require you to obtain consent. It requires you to be able to show, later, that you obtained it: from whom, for what, and when. That is exactly what the register is for.
Where to find it. Open a client record and scroll to the Consents section, between the communications history and the client's portal access.
In this article
- Reading the register: current state and history
- What Colib records on its own
- How to record a consent yourself
- Recording a refusal or a withdrawal
- Consent for a minor, given by a parent or guardian
- Information you collected from someone else
- What to write, and what not to write
- What your client sees
- How long consents are kept
1. Reading the register: current state and history
The section opens with a row of small badges: one per type of consent, showing what applies today. A green check means the consent stands, a red cross means it was refused or withdrawn. The date beside each badge is the date the client gave that answer.
Below the badges, the table lists every entry ever recorded, newest first: date, type, where it came from, whether it was accepted, the version of the text that was accepted, and the details. Nothing is ever overwritten — a consent that changes adds a line, it does not replace the previous one. Use Show all to unfold the full history.
Reading tip. The badges answer "what is true right now"; the table answers "what happened, and when". In a complaint or an audit, it is the table that carries the proof.
2. What Colib records on its own
Four situations write to the register without any action from you:
- Terms of service and cancellation policy — when a client books online and accepts your terms. The exact version of the text is kept with the entry.
- Appointment reminders by text message — the box your client ticks, or leaves unticked, during online booking. If it is left unticked, Colib records a refusal and switches that appointment to email reminders only.
- Form signature attestation — the text your client signed at the bottom of a form, stored exactly as it was shown to them.
- Parent or legal guardian consent — when a booking is made for a dependant under 14.
Each of these entries carries its source, so you can always tell an answer given online from one you entered yourself.
3. How to record a consent yourself
Most consents are not given through a screen. They are given out loud, in the room, or on a paper form. Record them the same day, while the wording is fresh:
- Open the client record and click Record a consent in the Consents section.
- Choose the type of consent.
- Choose the answer: consent obtained, or consent refused or withdrawn.
- Set the date obtained if the client gave it on an earlier day. Leave it empty for today.
- Add details: who may receive the information, what it covers, anything that makes the entry unambiguous a year from now.
- Tick the attestation, then save.
The attestation is the heart of the entry. By ticking it you declare that the consent was given by the person concerned, or by the holder of parental authority. Colib records your name and the date beside it — that is what makes the entry hold up later.
Three types are available for consents obtained outside a screen:
- Consent to collect and use personal information — the general consent, given verbally or on paper when the file is opened.
- Consent to share information with a third party — a physician, an insurer, a school, a family member. Name the recipient in the details.
- Information collected from a third party — see section 6.
4. Recording a refusal or a withdrawal
A client can change their mind at any time, and that withdrawal is as important to record as the original consent. Record it the same way, choosing Consent refused or withdrawn, and say in the details what the client asked for.
The badge at the top of the section turns red immediately, so anyone opening the record afterwards sees the current position at a glance rather than having to read the whole history.
Text message reminders. A withdrawal recorded here does not change the reminder settings by itself. If your client asks to stop receiving text messages, also set their communication preference to email on the appointment or on the record.
5. Consent for a minor, given by a parent or guardian
For a client under 14, consent comes from the holder of parental authority. Online booking captures it when the appointment is made for a dependant. When the parent consents in person or by phone instead, record it yourself with the type Parent or legal guardian consent, and name the parent in the details.
6. Information you collected from someone else
Sometimes the information does not come from the client: a referring professional sends a summary, a parent fills in a history, an employer provides a form. When that happens, the law expects you to be able to say where it came from and why it could not be collected directly from the person.
Use the type Information collected from a third party. The details field is mandatory here: write the source and the reason, in one sentence each.
7. What to write, and what not to write
The details field is stored encrypted, like the rest of the record, and it is meant for one thing: making the consent unambiguous. A few lines are enough.
- Do write the scope: "may share the assessment report with Dr. Tremblay, referring physician, for this episode of care".
- Do write how it was given: verbally at the first session, on the paper form signed on 12 May.
- Do not write clinical observations. The register proves a consent; it is not a place for notes.
- Do not paste a whole document. Reference it instead.
8. What your client sees
Clients do not browse the register in their portal. They do receive it, in full, when they ask for a copy of their data: the export includes a consents file per clinic, with the date, the type, the decision, the source and the version of the text they accepted.
That is one more reason to keep the details factual and free of clinical content — your client may read them one day.
9. How long consents are kept
The register lives with the client record: it follows the file if you merge two records, and it is deleted with the file when the record is deleted or purged. It is never edited and never partially erased — that is what gives it its value as proof.
Questions about consents? Write to support@colib.io. This article is updated whenever the register changes.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article