Consent & Privacy Service  ·  View 12 of 22  ·  Data

Data Model

Twelve entities. What is absent from this view is the argument of the whole package.

Editable source SVG draw.io All views
purpose purpose_id PK parent_id FK -> purpose owner data_categories purpose_version purpose_id PK FK version PK widening bool retention_days lawful_basis purpose_id PK FK version PK FK jurisdiction PK basis notice_version processing_target target_id PK purpose_id FK class first|recipient erasure_window technique subject subject_key PK jurisdiction jurisdiction_version key_arn consent_entry subject_key PK FK captured_at PK purpose_id FK version FK decision surface actor current_state subject_key PK FK purpose_id PK FK jurisdiction PK decision ledger_version identifier identifier_hash PK subject_key FK system linked_at rights_case case_id PK subject_key FK type verification state sla_due target_outcome case_id PK FK target_id PK FK state 4-valued attested_at refusal_reason suppression subject_key_hash PK erased_at case_id FK audit_record record_id PK subject_key FK kind at prev_hash 1 : N 1 : N 1 : N 1 : N N : 1 1 : N 1 : N 1 : N 1 : N 1 : N 1 : 1 1 : N Data Model — Permission, Not People What is missing is the point: no profile, no behaviour, no content. Only a pseudonymous key, what it may be used for, and what was done about it. v 1.0 · owner Security & Identity Architecture

Decisions

  • Lawful basis hangs off purpose version and jurisdiction, not off purpose. The same purpose legitimately has different bases in different places, and a model that cannot express that forces the platform to lie somewhere.
  • consent_entry is keyed on (subject_key, captured_at): append-only, never updated. A grant following a withdrawal is two rows, and current_state is a projection carrying the ledger version it was built from.
  • target_outcome holds a four-valued state per target per case — instructed, acknowledged, attested, verified — rather than a boolean, because collapsing them is how a case closes while data remains.

What is deliberately missing

  • No profile, no behaviour, no content, no contact details. Only a pseudonymous subject key, what it may be used for, and what was done about it.
  • identifier holds hashes rather than identifiers, which limits what a compromise of the index yields — but it still links a person's pseudonyms, and that is why it is the most constrained store in the design.

Assumptions

  • 180,000,000 subjects × 14 average active purposes ≈ 2,500,000,000 current-state records.
  • suppression holds hashed subject keys and erasure dates only, and is retained indefinitely.