Consent Management
Overview
The consent management feature provides a regulatory-compliant, flexible consent management system at the identity level. This process allows customers to determine what information they permit their care providers to access, enabling users to approve or withdraw consent and create personalized experiences.
Benefits
GDPR Compliance
- Support for all GDPR legal bases (consent, contract, legal obligation, vital interests, public authority, legitimate interests)
- Complete audit trail of all consent actions with timestamps
- Data subject rights management (deletion, correction, portability, etc.)
- Processing purpose documentation for transparency
Flexible Consent Models
- Declarative consents: Requested during registration/login flows
- Action-based consents: Requested when specific actions are performed
- Scope consents: Required for THIRD_PARTY OAuth2 clients
- Claim consents: For specific user attributes/claims
User Experience
- Multi-locale support for international deployments
- Version management for regulatory updates
- Skip limits to balance user convenience and compliance
- User self-service portal to view and manage consents
Administrative Control
- Consent groups for organizing multiple consents
- Enable/disable consents without deletion
- Required vs optional consent configuration
- Integration with registration fields and clients
Key Concepts
Consent Hierarchy
The consent management system consists of three hierarchical entities: