Salesforce Decode
Salesforcedecode
Back to questions
Data CloudArchitect (Hardest)governanceconsentprivacygdpr

Design data governance and consent management in Data Cloud

Real World Scenario

Legal requires that marketing activations respect opt-out flags stored in three systems with inconsistent consent timestamps and purposes.

Expected Answer

• Harmonize consent into Contact Point Consent DMO with purpose, channel, and effective date • Define survivorship: most restrictive consent wins when sources conflict • Apply consent filters at segment definition layer—not only at activation export • Integrate Privacy Center or CMP webhook updates via streaming ingestion • Audit trail for consent changes with source system reference • Data classification tags on DMO fields: PII, sensitive, anonymizable • Regular compliance reports proving activations excluded opted-out individuals

Follow-Up Questions & Answers

Click to expand — each follow-up includes a direct, interview-ready answer

Direct answer: Harmonize consent into Contact Point Consent DMO with purpose, channel, and effective date Also consider: Define survivorship: most restrictive consent wins when sources conflict In practice: Apply consent filters at segment definition layer—not only at activation export Document the decision in an ADR and align with enterprise standards.

Architect Perspective

Consent is not a checkbox on export—it must be embedded in segment logic. Architects who defer governance to "marketing will filter" inherit regulatory risk.