Consent & Privacy Service · View 16 of 22 · Operations
Decisions
- Nothing crosses a boundary: no replica, no key, no failover. A region's unavailability makes its subjects' consent-based purposes deny, and that is the correct answer rather than a gap to be engineered away.
- The availability target is set with that behaviour in mind. Buying cross-region failover here would mean replicating consent records out of their jurisdiction, which is the thing the platform exists to prevent.
- Only the signed policy bundle fans out globally, and it carries definitions rather than people.
Assumptions
- 9 regional deployments across 3 jurisdictional boundaries; three AZs per region; per-region customer master key with no cross-region grant.
- RTO 10 minutes in-region for the decision path. No cross-jurisdiction RTO is offered.
Risks
- Duplicated stacks multiply operational cost and configuration drift. The mitigation is that the stack is identical and deployed from one definition, which makes drift a release problem rather than a regional one.
- The jurisdiction router is the single component that can send a subject's request to the wrong boundary. It is a residency control in the data path, and its failure mode is an unlawful transfer.