Consent & Privacy Service · View 15 of 22 · Runtime
Decisions
- An unregistered purpose is a caller error, not a denial. Answering DENY would let a typo look like a lawful refusal and would hide the fact that something is processing data under a name nobody declared.
- Consent and legitimate interest take the same path and differ only in the default: no processing before a grant, versus processing until objection. The basis is data, not a code branch per purpose.
- Past the staleness ceiling the verdict is UNKNOWN and the purpose's registered posture applies — fail-closed unless explicitly, and rarely, declared otherwise.
Assumptions
- Decision p50 ≤ 2 ms, p99 ≤ 10 ms on cache hit; p99 ≤ 40 ms on remote evaluation.
- False DENY ≤ 1 in 1,000,000 decisions. Zero tolerated ALLOW for a consent withdrawn more than 15 minutes earlier.
Risks
- A caller that treats UNKNOWN as ALLOW defeats the whole design and cannot be prevented from the platform's side. It is a contract test in the client SDK and an audited behaviour, not a guarantee.
- The fail-open subset is a legal judgement stored in a configuration file. It is held in the registry behind two-person approval precisely because it is the most dangerous single field in the system.