Elaine supports consent-aware customer engagement by connecting acquisition context, recipient permissions, communication status, and activation workflows. These capabilities help organizations implement GDPR-oriented governance, but compliance depends on the complete legal and operational design around the platform.
Consent and permission data in Elaine
A consent process should preserve more than a single yes-or-no value. Depending on the use case, the implementation should make the recipient, purpose, channel, scope, source, time, notice version, confirmation, and later changes traceable. Elaine data sources and Privacy Admission Control (PAC) flags provide technical building blocks for associating recipient data with defined data-use permissions.
Double opt-in and evidence
For subscription workflows that use double opt-in, the initial request and the later confirmation are separate events. The surrounding implementation should preserve the information required by the organization to demonstrate what was requested, which declaration applied, and when confirmation occurred. Forms, transactional messages, recipient data, and connected systems must use a consistent identifier and process.
Withdrawal and permission changes
When a recipient withdraws consent or changes preferences, the change must reach every workflow that relies on the former permission. This can include subscription status, suppression logic, PAC or data-source assignments, automations, audience membership, exports, and downstream systems. Design the process for propagation, retries, reconciliation, and evidence rather than updating only the visible form state.
Governance responsibilities
| Responsibility | Implementation consideration |
|---|---|
| Purpose and legal basis | Define why each data category is processed and which legal basis applies. |
| Transparency | Present accurate, understandable information that matches the configured processing. |
| Permission enforcement | Map collection contexts and permissions to Elaine data sources, PAC flags, and communication rules. |
| Data minimization | Collect and expose only the data needed for the defined purpose. |
| Retention and deletion | Define retention periods and deletion or anonymization workflows across Elaine and connected systems. |
| Access and accountability | Use roles, permissions, operational ownership, and review processes appropriate to the data. |
Validation checklist
- Verify that the wording shown to the recipient matches the actual processing.
- Test acquisition, confirmation, activation, preference change, withdrawal, and deletion paths.
- Confirm that recipient-level profiling is restricted when the relevant PAC permission is absent.
- Check that imports and APIs cannot unintentionally assign a broader data-use level.
- Reconcile consent and suppression state with connected systems.
- Periodically review configuration, access, retention, and evidence requirements.
Warning
Product configuration alone does not establish GDPR compliance. Legal requirements vary by role, jurisdiction, channel, purpose, and implementation. Obtain qualified legal and privacy review for the specific use case.