Consent and GDPR engineering
Consent, retention and data subject rights designed into the customer data model rather than bolted on — so an access or deletion request is a query instead of a project.

What consent has to look like in the data model
Purpose-based consent records
Consent captured per purpose and per channel, with version, timestamp and the exact wording shown at the time — not a single marketing flag.
Withdrawal that propagates
A withdrawal that reaches the marketing platform, the campaign already scheduled and the analytics export, not only the CRM checkbox.
Retention and deletion rules
Retention periods defined per data category and enforced automatically, with legal holds where a record must be kept despite a request.
Subject access and portability
Access and export requests answered from one place, assembling the record across the systems that hold parts of it.
Lawful basis beyond consent
Contractual necessity and legitimate interest modelled explicitly, so consent is not asked for where it is not the right basis.
Audit trail for regulators
A complete, queryable history of what was consented to, when, and on the basis of which wording.
Don’t see your challenge here? Talk to us about your project
A deletion request should be a query, not a project
Where consent is a flag on a customer row, answering a regulator means a manual search across systems and a written explanation of why parts are missing. Where it is modelled properly, the same question is answered in seconds and with evidence.
The design work is mostly enumeration — every place personal data is held, the lawful basis for each, the retention period, and the propagation path for a withdrawal. It is unglamorous and it is the whole job.
- Per purpose
- Consent recorded per purpose, channel and version.
- Propagating
- Withdrawal reaches every downstream consumer.
- Enforced retention
- Deletion runs on schedule, not on request.
- Legal hold
- Records preserved where law requires it.
- One answer
- Access requests assembled from every holding system.
- Evidenced
- Full audit trail available to regulators.
Consent captured with versioning and a full audit trail
Our work on fertility treatment consent had the strictest version of this problem: what was explained, to whom, in which wording and when, had to be provable years later. The same model — versioned consent, immutable audit, explicit withdrawal — is what we carry into commercial customer platforms.
Common questions
Is this something you retrofit or design in?
Both are possible, but retrofitting costs considerably more and usually leaves gaps. Where an existing platform has to be brought into line, we start with an inventory of where personal data actually sits — which is typically the part nobody has written down.
Does this slow down marketing?
It removes a category of question that currently stops campaigns — whether this segment may be contacted at all. Eligibility resolved from consent data at send time is faster than a manual legal review.
Can you work with our DPO and legal team?
Yes, and we prefer to. Our part is the data model and the enforcement; deciding the lawful basis and the retention periods is theirs, and the design goes faster when both sit in the same session.
Let's talk about your customer platform
Tell us where your customer data sits today and which question you cannot currently answer about it. We will come back with an honest read on the model, the integration work involved, and what a realistic first phase looks like.
