Event-Driven Notification Platform  ·  View 13 of 26  ·  3 · Data

Preference, Consent and Override Policy

Which notifications may ignore a stated preference, and on what authority.

Editable source SVG draw.io All views
Consent basis
Consent basis
Preference respected
Preference respected
Quiet hours
Quiet hours
Frequency cap
Frequency cap
Override rule
Override rule
Security · P0
Security · P0
Legitimate interest
no opt-in needed
Legitimate interest...
Channel order only
cannot disable
Channel order only...
Ignored
sent immediately
Ignored...
None
None
Always overrides
logged as override
Always overrides...
Transactional · P0
Transactional · P0
Contract
service delivery
Contract...
Channel choice
at least one mandatory
Channel choice...
Ignored
Ignored
None
None
Overrides opt-out
reason recorded
Overrides opt-out...
Operational · P1
Operational · P1
Legitimate interest
Legitimate interest
Fully respected
per category
Fully respected...
Deferred
recipient timezone
Deferred...
10 per day
then digested
10 per day...
No override
No override
Marketing · P2
Marketing · P2
Explicit opt-in
timestamp and source
Explicit opt-in...
Fully respected
Fully respected
Deferred
plus local send window
Deferred...
3 per week
hard cap
3 per week...
Never overrides
regulatory breach
Never overrides...
Digest · P2
Digest · P2
Inherits source class
Inherits source class
Digest opt-in
replaces per-event
Digest opt-in...
Scheduled
recipient chosen hour
Scheduled...
1 per window
1 per window
P0 items break out
sent separately
P0 items break out...
Preference, Consent and Override Policy
Preference, Consent and Override Policy
Security / platform
Security / platform
Application we own
Application we own
Decision point
Decision point
Risk / gap
Risk / gap
The override column is the whole point of this view. Anything that overrides a stated preference writes an audit record naming the rule that authorised it, so a regulator can be answered from one query.
The override column is the whole point of this view. Anything that overrides a stated preference writes an audit record naming the rule that authorised it, so a regulator can be answered from one query.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display

The rule this view exists to state

  • Security and transactional notifications override an opt-out; operational and marketing never do
  • Every override writes an audit record naming the rule that authorised it, so a regulator can be answered from one query
  • Classification is set by the rule, not by the producer, so a producer cannot relabel marketing as transactional

Consent basis

  • Marketing requires explicit opt-in with timestamp and source recorded
  • Operational runs on legitimate interest and respects preferences in full
  • Quiet hours and frequency caps apply to everything except security and transactional

Risk

  • Misclassifying marketing as transactional is a regulatory breach, not a bug — drawn in red on the page
  • Controlled by requiring a second approver on any rule that sets a P0 class, and by a weekly report of P0 volume per tenant