Privacy Admission Control (PAC) is Elaine’s technical control layer for recipient-level profiling and data use. A PAC flag enables or restricts a defined category of processing for an individual recipient. A data source records the acquisition context through which a recipient entered Elaine and carries the configured combination of PAC flags for that context.
PAC is an enforcement mechanism inside Elaine. A flag is not, by itself, proof of consent or a legal basis. The organization remains responsible for presenting the appropriate notice, recording the evidence required by its process, mapping that permission to the correct data source and flags, and updating Elaine when the permission changes.
Terms and relationships
- PAC function: A predefined category of recipient-level profiling or data use that Elaine can technically control.
- PAC flag: The technical identifier for a PAC function, such as
pac_link_profiling. - Data source: A configured acquisition context—such as a subscription form, CRM import, or API integration—with a defined set of PAC flags.
- Recipient assignment: The connection between a recipient and the data source whose configured permissions apply.
What PAC controls
When Elaine processes an engagement signal, it can check which personal use is permitted for the recipient concerned. Depending on the assigned PAC flags, a signal such as an open, click, conversion, social interaction, device observation, or location-related event can be used for an allowed recipient-level purpose or restricted accordingly.
PAC therefore separates two questions that are often incorrectly combined:
- Was an event measured?
- May that event be connected to an identifiable recipient and used for a particular profiling purpose?
How PAC flags and data sources work together
Elaine uses data sources as reusable permission profiles. Two recipients can therefore interact with the same message but receive different recipient-level processing because they are assigned to data sources with different PAC flags.
- Define a data source for a collection or import context, such as a subscription form or CRM integration.
- Assign the PAC flags that correspond to the documented permissions for that context.
- Associate recipients with the appropriate data source when they enter Elaine.
- Use the permitted profile and response data in audiences, personalization, analytics, or automations.
- Update the assignment when the applicable permission changes or is withdrawn.
Note
Do not set broad PAC flags merely because data is technically available. Assign only the functions that match the documented acquisition context and permitted purpose.
PAC flag reference
| PAC flag | Purpose represented in Elaine |
|---|---|
pac_user_profiling | Recipient-level storage of message response data such as opens, clicks, and conversions. |
pac_link_profiling | Recipient-level interest profiling based on interactions with categorized links. |
pac_global_user_profiling | Aggregated recipient-level activity values, for example an activity score. |
pac_global_response_profiling | Recipient-level response measurement on connected landing pages or external touchpoints. |
pac_social_activity_profiling | Recipient-level processing of supported social sharing or social interaction signals. |
pac_terminal_device_detection | Detection of supported terminal-device information. |
pac_geo_profiling | Supported location-related profiling based on available signal data. |
pac_advanced_fingerprinting | Supported advanced recognition or fingerprinting use cases. |
Note
The availability and operational effect of individual PAC flags depend on the Elaine edition, enabled features, channels, and project configuration. Confirm the applicable behavior before relying on a flag in a production privacy design.
Example: aggregate statistics without personal history
Assume Elaine measures an email opening, but the recipient does not have the User Profiling flag. The opening can be counted in aggregate campaign statistics, while Elaine does not add it to that recipient’s personal message history. If the appropriate flag is assigned, the permitted recipient-level processing can be used by the corresponding features.
Use PAC in integrations
Recipient data can enter Elaine through forms, APIs, file-based interfaces, and connected platforms. The integration design should transmit or derive the correct data-source assignment instead of silently granting broad profiling permissions. Keep the external record of the notice, permission, timestamp, source, and version aligned with the PAC configuration used in Elaine.
When a permission is withdrawn or replaced, update both the system that holds the authoritative evidence and the Elaine assignment. Define how that change affects existing profile values, future signal processing, active campaigns, and downstream exports.
Implementation checklist
- Inventory every recipient-level profiling and activation purpose.
- Map each purpose to an applicable PAC flag and document any configuration dependency.
- Define data sources for forms, imports, APIs, and connected applications.
- Verify that the presented notice or consent corresponds to the assigned flags.
- Test processing with each relevant flag enabled and disabled.
- Define how changes and withdrawals update Elaine and connected systems.
- Review the design with the responsible privacy and security stakeholders.