Consent & Privacy Service  ·  View 09 of 22  ·  Structure

Interface Catalogue

Three contracts in, three out, and a registration rule: a system that consumes none of the outbound three cannot be named on a purpose.

Editable source SVG draw.io All views
In Capture a decision Evaluate a decision Raise a rights case Consent & Privacy Service Permission & rights plane one contract each way Out Withdrawal events Erasure instruction Suppression feed subjects services portal events targets ingest Interface Catalogue Interface / broker Application we own Queue / topic Data store synchronous event / async batch Three surfaces each way. Two further contracts are drawn where they are decided rather than here: purpose declaration in the release path, evidence export in the failure-class view. v 1.0 · owner Security & Identity Architecture

Decisions

  • One contract per direction per concern. Evaluate and capture are deliberately separate surfaces: they have different callers, different latency budgets and different authorisation.
  • The suppression feed is an outbound contract, not an internal detail. Every ingestion and restore path in the estate is a consumer of it, including paths nobody thinks of as privacy-relevant.
  • Registration against a purpose requires consuming the withdrawal stream or the erasure instruction. A system that cannot be told is a system that will not be told.

Assumptions

  • Batch evaluation of 1,000,000 subject keys completes within 90 s against an immutable projection snapshot, on a path distinct from the per-request one.
  • Capture accepts the unauthenticated device-keyed path and the authenticated path through the same contract, with the actor recorded.

Omissions

  • Two further contracts are drawn where they are decided rather than here: purpose declaration in view 19, evidence export in view 22.
  • This view was cut from four surfaces a side to three; the labels on four converging spokes collided, and the fourth interface was better shown where it is used.