Ingestion Layer → Edge Network

Consent Enforcement

Checks the caller's consent state before an event is allowed to proceed — the platform's compliance gate.

High-Level Design

Consent Enforcement is the control point that makes downstream compliance possible.

Data Source
Enrichment
Hands off a geo/device-enriched event
→
Ingestion
Consent Enforcement
Policy check against consent_basis
→
Processing
Queue & Retry
Consented events proceed to Azure Event Hubs
→
Foundation
Governance & Security
Policy table — source of truth
→
Intelligence
Audit Logs
Every consent decision is logged
→
Activation
Compliant Downstream Processing
Only consented events reach analytics/marketing

💼 Business Context

  • Getting consent wrong is a direct legal/regulatory exposure (GDPR, CCPA, DPDP) — this is the control point that prevents that
  • Lets every downstream team build without re-implementing consent logic themselves
  • Owned jointly by Platform Engineering and Legal/Privacy

🔌 Technical Overview

Every event carries a consent_basis field (set by the SDK from the Consent Management Platform's current state, or explicitly by server callers). The Ingestion API checks this against the event's declared purpose (analytics, personalization, marketing) using a policy table maintained by the Governance & Security layer. Events without a valid consent basis for their purpose are either dropped or routed to a restricted-processing path, depending on policy — never silently stored as if consented.

Consent Purposes

analytics personalization marketing essential

💾 Consent Policy Check

{
  "event_id": "9f2c1e6a-...",
  "consent_basis": { "analytics": true, "marketing": false },
  "purpose_requested": "marketing",
  "decision": "blocked",
  "policy_ref": "gdpr-eu-v2"
}

🔗 Integration Points

  • Consent Management Platform (client-side) — supplies real-time consent state to the SDKs
  • Governance & Security policy table — the source of truth for purpose-vs-consent rules
  • .NET Core Ingestion API — enforcement point, before Event Hubs publish
  • Audit Logs (Governance & Security) — every consent decision is logged for compliance review

🧰 Services Consumed

  • Owning microservice — Cxos.Ingestion.Application (see the Full Application Service Map)
  • Database — Azure Cache for Redis (cache only, no system-of-record database)

⚠️ Non-Functional Considerations

  • Scale: policy lookups are cached per consent-basis combination to avoid a database round-trip per event
  • Latency: consent check adds negligible latency — it's a policy-table lookup, not an external call
  • Reliability: on policy-service unavailability, the system fails closed for marketing/personalization and open for essential/legal-basis events
  • Security/Privacy: this is itself a compliance control — its own audit trail is retained longer than standard event data

🎯 Enterprise Example

A customer withdraws marketing consent through the preference center. The very next event they generate is checked against the updated consent basis and blocked from any marketing-purpose processing — with no code change needed in any of the dozens of downstream services that might otherwise have used it.

← Back to Edge Network