Consent and GDPR engineering

Consent, retention and data subject rights designed into the customer data model rather than bolted on — so an access or deletion request is a query instead of a project.

meeting 1245776 1920

What consent has to look like in the data model

  • Purpose-based consent records

    Consent captured per purpose and per channel, with version, timestamp and the exact wording shown at the time — not a single marketing flag.

  • Withdrawal that propagates

    A withdrawal that reaches the marketing platform, the campaign already scheduled and the analytics export, not only the CRM checkbox.

  • Retention and deletion rules

    Retention periods defined per data category and enforced automatically, with legal holds where a record must be kept despite a request.

  • Subject access and portability

    Access and export requests answered from one place, assembling the record across the systems that hold parts of it.

  • Lawful basis beyond consent

    Contractual necessity and legitimate interest modelled explicitly, so consent is not asked for where it is not the right basis.

  • Audit trail for regulators

    A complete, queryable history of what was consented to, when, and on the basis of which wording.

Don’t see your challenge here? Talk to us about your project

A deletion request should be a query, not a project

Where consent is a flag on a customer row, answering a regulator means a manual search across systems and a written explanation of why parts are missing. Where it is modelled properly, the same question is answered in seconds and with evidence.

The design work is mostly enumeration — every place personal data is held, the lawful basis for each, the retention period, and the propagation path for a withdrawal. It is unglamorous and it is the whole job.

Per purpose
Consent recorded per purpose, channel and version.
Propagating
Withdrawal reaches every downstream consumer.
Enforced retention
Deletion runs on schedule, not on request.
Legal hold
Records preserved where law requires it.
One answer
Access requests assembled from every holding system.
Evidenced
Full audit trail available to regulators.

Consent captured with versioning and a full audit trail

Our work on fertility treatment consent had the strictest version of this problem: what was explained, to whom, in which wording and when, had to be provable years later. The same model — versioned consent, immutable audit, explicit withdrawal — is what we carry into commercial customer platforms.

Common questions

Is this something you retrofit or design in?

Both are possible, but retrofitting costs considerably more and usually leaves gaps. Where an existing platform has to be brought into line, we start with an inventory of where personal data actually sits — which is typically the part nobody has written down.

Does this slow down marketing?

It removes a category of question that currently stops campaigns — whether this segment may be contacted at all. Eligibility resolved from consent data at send time is faster than a manual legal review.

Can you work with our DPO and legal team?

Yes, and we prefer to. Our part is the data model and the enforcement; deciding the lawful basis and the retention periods is theirs, and the design goes faster when both sit in the same session.

Let's talk about your customer platform

Tell us where your customer data sits today and which question you cannot currently answer about it. We will come back with an honest read on the model, the integration work involved, and what a realistic first phase looks like.

Rando Siimon Profile Image

Rando Siimon

Business Development Manager