Resource

The five pillars of
valid consent.

Consent is not a checkbox on a page. It is a state that has to travel with every record, every stream and every downstream partner, and stay provable afterwards.

The pillars

Five conditions, enforced at runtime

Each pillar fails the same way: the intent exists on paper, but the operation ignores it. A runtime closes that gap.

Pillar 1

Freely given

Consent only counts when the person had a real choice. Bundled or pre-ticked permission is not permission, and your runtime should refuse to treat it as such.

Pillar 2

Specific

Each purpose needs its own record. One broad agreement cannot cover marketing, analytics, profiling and data sharing at the same time.

Pillar 3

Informed

People must know who processes their data, why, for how long and with whom it is shared, in language they actually read.

Pillar 4

Unambiguous

A clear, affirmative action. Silence, inactivity and dark patterns leave you with a record you cannot defend.

Pillar 5

Withdrawable

Withdrawing must be as easy as giving. That means consent state has to flow through your operations in real time, not in a monthly export.

From policy to enforcement

In Datastreams, consent state is part of the stream. Rules evaluate it before an action runs, every decision is timestamped, and the trail stays runtime auditable without a separate compliance project.

See it on your own data