A partner permits internal use of its data, but not export or cross-site advertising. Does your configuration enforce that? Try different destinations and policies. The result evaluates only this example’s controls.
Example data, destinations and policies. Which label each field carries is up to each organisation.
Label · policy · marketing action
What these policies block
This example evaluates the configured labels and actions. Finding no block does not guarantee that a send is permitted.
Consent and other controls
What the policy does not tell you
Consent is checked separately, and some destinations apply rules of their own.
The recommendation
Label fields when you design the schema, enable the policies and tag every output with its marketing action
Check labels, enabled policies, marketing actions and integration coverage. A missing piece may leave this restriction unenforced; other controls can still block the operation.
01
Labels in the schema, policies enabled
Label datasets and schema fields according to validated restrictions. Usage policies, including predefined ones, are disabled by default. Enable the relevant policies and test enforcement.
02
Marketing actions on every output
Every Real-Time CDP destination and every AJO channel configuration with its actions: Export to Third Party, Cross Site Targeting, Email Targeting.
03
Consent
Shield enables consent policies that must be configured and activated. AJO retains native controls. Elsewhere, check where each preference is evaluated and how it stays current.
04
Event fields in AJO
DULE in AJO does not cover event context fields. Review data used in messages and custom actions. Add specific controls; moving them into Profile is not always the right solution.
{"dataEmail":"Email","dataPartner":"Travel interest from a partner","dataGeo":"Precise location from the app","dataHealth":"Orthopaedic insole purchase","kindProfile":"Profile attribute","kindSecondParty":"Profile attribute · second-party data","kindEvent":"ExperienceEvent field","kindHealth":"Profile attribute · classified as health data","destMeta":"Audience in Meta","destEmail":"Personalised email","destWeb":"Web personalisation","destSftp":"File for a partner","sysRtcdp":"Real-Time CDP destination","sysAjo":"AJO channel configuration","sysWeb":"Web SDK · Target or AJO web","sysSftp":"Real-Time CDP SFTP destination","polC2":"Restrict export to third parties","polC5":"Restrict cross-site targeting","polRhd":"Keep health data in-house","polS1":"Precise location on the web only","typeCore":"Core","typeCustom":"Custom","labelI1":"Directly identifiable","labelC2":"No export to third parties","labelC5":"No interest-based cross-site targeting","labelS1":"Precise location","labelRhd":"Protected health information","nodeData":"Data","nodePolicy":"Policy","nodePolicyOff":"Disabled policy","nodeDest":"Destination or channel","noPolicy":"None applies","eventGapTitle":"This policy does not cover the event field","eventGapBody":"The field {field} belongs to event context. DULE in AJO does not cover it even with the policy enabled. Other controls may prevent delivery.","blockedTitle":"Blocked: {label} conflicts with {action}","blockedAjo":"AJO will not let you publish the journey or campaign. The channel configuration has {action} and the message uses a field labelled {label}.","blockedRtcdp":"When you activate the audience, Real-Time CDP shows a policy violation with its lineage: dataset, merge policy, audience and destination.","missTitle":"The restriction is not being enforced","missBody":"The field carries {label} and the destination has {action}. The \"{policy}\" policy is disabled. This restriction does not block the operation; others might.","allowedTitle":"No block from the evaluated policies","allowedBody":"The labels on {field} do not match an enabled prohibition in this example. This is not legal authorisation or a complete consent or access check.","tableCaption":"Policies and their effect on this combination","colPolicy":"Policy","colRule":"Rule","colState":"State","prohibits":"prohibits","stateHit":"Blocks","stateMiss":"Would block if enabled","stateOn":"Enabled, does not apply","stateOff":"Disabled, does not apply","i1Title":"I1 blocks nothing on its own","i1Body":"It marks the data as identifiable. Restricting how it is used is a job for a policy.","metaHealthTitle":"Meta applies its own restrictions","metaHealthBody":"Facebook can flag an audience as restricted under its sensitive-data rules. A flagged audience is blocked from activation. This example’s RHD label does not predict that classification on its own.","ajoConsentTitle":"This example uses marketing email","ajoConsentBody":"AJO applies consent controls to marketing email. Transactional messages receive different treatment. Their eligibility and any real person’s consent state are not simulated here.","shieldTitle":"Shield enables consent policies","shieldBody":"Licensing the add-on does not configure policies. Define, enable and associate them with the relevant marketing actions.","noShieldTitle":"Without Shield, review the available controls","noShieldBody":"These custom policies require Shield. AJO retains native controls; other paths may require preference filters and freshness checks before activation.","noNotesTitle":"The result has limited scope","noNotesBody":"Access permissions, individual preferences and the destination’s full controls are not evaluated here. No DULE violation does not mean permission to use the data.","stateGap":"Outside AJO enforcement coverage"} {"data":"partner","dest":"meta","c2":"off","c5":"off","rhd":"on","s1":"off","shield":"no"}