Consent & Privacy Service  ·  View 08 of 22  ·  Structure

Platform Components

Two planes drawn as two boxes, because they fail independently and only one of them may be global.

Editable source SVG draw.io All views
Global control plane — no personal data Registry Purpose registry Aurora Global Notice text & translations Change control Approval workflow two-person Signed policy bundle S3 + CloudFront Regional plane — eu-west-1 (repeated per jurisdiction) Capture & ledger Capture service Consent ledger DynamoDB Projection builder Current state Decision Decision API Withdrawal stream Batch evaluator Rights & propagation Case orchestrator Step Functions Identity index per-subject keys Target adapters 100 Suppression list Evidence Audit store Object Lock Per-subject keys KMS Product services 40, in-process cache Processors 60 policy withdrawal erasure Platform Components — Regional Plane and Global Control Plane Security / platform Data store Application we own Interface / broker Queue / topic External / third party batch event / async The regional plane serves its jurisdiction with the global plane unreachable. There is no cross-jurisdiction failover, by design. v 1.0 · owner Security & Identity Architecture

Decisions

  • The global control plane holds definitions, notice text, approvals and a signed policy bundle. It is strongly consistent and contains no personal data, which is the only reason it is permitted to be global.
  • Each regional plane serves its jurisdiction with the global plane unreachable, running on its last-known-good bundle: new purposes cannot be registered, existing decisions continue.
  • Per-subject keys live in the regional trust boundary with the audit store, so crypto-shredding is available wherever hard deletion is not.

Assumptions

  • Decision path ≥ 99.99% monthly per region; global control plane ≥ 99.9% monthly.
  • Capture, decision and orchestration run on Fargate across three AZs; ledger and projection on DynamoDB with synchronous in-region replication.

Risks

  • A single signed bundle distributed globally is a single point of catastrophic misconfiguration: one bad publish reaches every region in 120 seconds. Hence the two-person approval and the staged adoption in view 19.
  • Forty in-process caches in systems this platform does not own means the real enforcement behaviour is only as good as the least-updated client library.