Independent DPDP educationSWARN is in development · educational, not legal adviceSource status: 30 Aug 2026
P02Record

ARCHITECTURE PATTERN · SYNTHETIC REFERENCE

Consent event and withdrawal propagation

Treat consent and withdrawal as versioned events that downstream systems must acknowledge.

Engineering control

Engineering pattern
not a legal template

WHEN TO USE

Use where consent is the verified basis and multiple systems act on the resulting choice.

Start only after the relevant facts, source status and system boundary are understood.

SOURCE / STATUS BOUNDARY

Verify the legal status before implementation.

Engineering controlPattern verification pointers

These IDs are verification pointers to the primary-source ledger. They are not provision mappings, applicability findings or legal conclusions.

SEQUENCE DIAGRAM

Four accountable hand-offs.

  1. 01Interface

    captures an unambiguous action

    ARTEFACT · choice event
  2. 02Receipt service

    binds purpose and notice version

    ARTEFACT · consent receipt
  3. 03Event bus

    propagates change to subscribers

    ARTEFACT · delivery record
  4. 04Control test

    checks all expected acknowledgements

    ARTEFACT · propagation result

TYPED JSON FIXTURE

Synthetic by design.

This example contains no real person, provider, incident or system data. It demonstrates record boundaries, not a production schema.

{
  "fixture": true,
  "schemaVersion": "1.0-demo",
  "pattern": "consent-event-and-withdrawal-propagation",
  "subjectRef": "synthetic-only",
  "payload": {
    "eventType": "withdrawal",
    "purposeRef": "purpose_demo_01",
    "acknowledgements": [
      "crm_demo",
      "messaging_demo"
    ]
  }
}

EVIDENCE OUTPUTS

  • Consent receipt schema
  • Notice-version reference
  • Subscriber acknowledgement
  • Withdrawal-path test

THREAT CONSIDERATIONS

  • Event replay
  • Identity misbinding
  • Excess personal data in event payloads

FAILURE MODES

  • Consent is reduced to a boolean
  • A failed subscriber is never retried
  • Withdrawal is harder than the original action

RESEARCH / RADAR CONNECTION

Keep implementation context attached.

Interoperability, receipt semantics, revocation reliability and minimised identity binding deserve design attention before integration claims are made.

Read Consent Managers as infrastructure: interfaces, accountability and open questions
Adopt · R-02

Structured consent receipts

Bind each captured choice to purpose, notice version and event context.

Operational pattern · Review 2026-11-20Open radar rationale

LOCAL WORKSPACE NOTE

This browser only

Nothing is sent anywhere. Avoid names, personal data or confidential incident details.

No local note loaded.
NextReturn to pattern discovery