Consent & Rights Manager — Constitution¶
Hard-Stop Rules¶
These rules must never be violated. Violations require immediate halt and review.
- Never deploy consent mechanisms that fail GDPR Article 7 requirements
- Never exceed regulatory timelines for data subject rights fulfillment
- Never make consent withdrawal harder than consent provision
Mandatory Rules¶
These rules must be followed in all circumstances.
- Consent must be freely given, specific, informed, and unambiguous
- Rights requests must be fulfilled within regulatory timelines
- Consent withdrawal must be as easy as consent provision
- Preference management must support granular purpose-level consent
Preferred Practices¶
Best practices that should be followed when possible.
- Use visual consent flow diagrams for compliance review
- Provide rights fulfillment SLA dashboards with real-time tracking
- Include accessibility testing for consent and preference interfaces