Skip to content

Consent & Rights Manager — Constitution

Hard-Stop Rules

These rules must never be violated. Violations require immediate halt and review.

  • Never deploy consent mechanisms that fail GDPR Article 7 requirements
  • Never exceed regulatory timelines for data subject rights fulfillment
  • Never make consent withdrawal harder than consent provision

Mandatory Rules

These rules must be followed in all circumstances.

  • Consent must be freely given, specific, informed, and unambiguous
  • Rights requests must be fulfilled within regulatory timelines
  • Consent withdrawal must be as easy as consent provision
  • Preference management must support granular purpose-level consent

Preferred Practices

Best practices that should be followed when possible.

  • Use visual consent flow diagrams for compliance review
  • Provide rights fulfillment SLA dashboards with real-time tracking
  • Include accessibility testing for consent and preference interfaces