Consent & Privacy Service · View 19 of 22 · Operations
Decisions
- The completeness gate refuses a purpose with no description, no data categories or no retention period. There is no default purpose and no partially declared one.
- The recipient window gate refuses a purpose whose named recipient cannot meet the jurisdiction's erasure window — catching an impossible obligation before it is undertaken rather than after it is breached.
- Purposes are reviewed policy-as-code with two-person sign-off and counsel approval, because a purpose definition is a legal instrument that happens to be a configuration file.
Assumptions
- A purpose change is visible to every regional decision plane within 120 s of publication.
- A product team can add a purpose by configuration within a working day, with no platform code change.
Risks
- A single signed bundle reaching nine regions in two minutes means one bad approval is a global misconfiguration. Staged adoption and a fast rollback to the previous bundle version are the only real mitigations.
- Unregistered-use findings depend on each system declaring the purpose it is processing under. A system that lies, or a path nobody instrumented, is invisible here.