Skip to main content
Adrià García
← Back to the simulators

Experience Platform · Consent integration

Where consent lives

Laura makes decisions about her data in three places on the same day. None of them reaches Real-Time Customer Profile on its own. Each needs an integration path, and each field is enforced somewhere different. Turn on the paths and see what is respected.

Scenario

The CMP calls Web SDK setConsent

Banner at 16:00: she accepts analytics and rejects personalisation and advertising.

Preferences and contact centre via streaming

18:00, preference centre: no emails, yes to SMS. 19:00, phone call: no sharing with third parties.

Nightly CRM batch load

At 02:00, with all the preferences of the day.

What enforces share.val in the Meta audience

These policies require Healthcare Shield or Privacy & Security Shield. AJO's native consent checks do not depend on these add-ons.

Illustrative scenario ↑ Back to the controls
Example assumptions

Example customer, times and decisions.

Real-Time Customer Profile · tomorrow, 09:00

What Laura's profile knows

One row per field, from what Laura decided to activation. Cookie choices stay on the ECID; purposes go to the profile. Highlighted, the layer where it breaks.

Web SDK · AJO · destinations

What happens at each activation

Six moments between today and tomorrow. Each one reads a different field, in a different place.

The recommendation

Separate cookies from purposes, integrate each source through its path and enforce each field where it is used

The cookie banner is not the consent system. It is one of its sources, and the only one tied to a device.

  1. 01

    Cookies through the Web SDK

    The CMP calls setConsent on load and when the banner is answered. It stays tied to the ECID, in idSpecific. The Web SDK enforces collect alone; everything else is checked in each rule.

  2. 02

    Purposes via streaming

    Preference centre, contact centre and forms send each change to the profile's general consent straight away: CMP source connector, HTTP API or event forwarding. The batch stays as reconciliation.

  3. 03

    Enforcement at every output

    With Shield, consent policies on each destination's marketing actions. Without Shield, an explicit filter in every activated audience. AJO checks the channel at send time.

  4. 04

    Nothing empty

    An empty consent field does not mean "no": AJO treats an empty email consent as consent by default. Decide the default value and load it for the whole base.

Architecture note · 09 Consent is a chain, not a field It is decided in the CMP, travels through the SDK, is stored in the profile and enforced by each destination. It breaks at the link nobody designed. Read the note →