Consent & Privacy Service · View 12 of 22 · Data
Decisions
- Lawful basis hangs off purpose version and jurisdiction, not off purpose. The same purpose legitimately has different bases in different places, and a model that cannot express that forces the platform to lie somewhere.
- consent_entry is keyed on (subject_key, captured_at): append-only, never updated. A grant following a withdrawal is two rows, and current_state is a projection carrying the ledger version it was built from.
- target_outcome holds a four-valued state per target per case — instructed, acknowledged, attested, verified — rather than a boolean, because collapsing them is how a case closes while data remains.
What is deliberately missing
- No profile, no behaviour, no content, no contact details. Only a pseudonymous subject key, what it may be used for, and what was done about it.
- identifier holds hashes rather than identifiers, which limits what a compromise of the index yields — but it still links a person's pseudonyms, and that is why it is the most constrained store in the design.
Assumptions
- 180,000,000 subjects × 14 average active purposes ≈ 2,500,000,000 current-state records.
- suppression holds hashed subject keys and erasure dates only, and is retained indefinitely.