Consent, treated seriously, isn’t a single checkbox on a signup form. In a mature organisation, it’s closer to a system — which is what “consent architecture” refers to.
CAPTURE
Record what was agreed, precisely
Across every product surface where consent is collected, not just the main one.
PROPAGATE
Reach every system that uses the data
A withdrawal on one screen has to actually reach every processor and system relying on that data.
PERSIST
Stay accurate as the product changes
New features shouldn’t quietly start relying on consent that was never actually given for them.
Most consent failures aren’t dramatic — nobody sets out to ignore a withdrawal request. They happen because consent was captured once, in one place, and never properly connected to every downstream system that continued using the data anyway. Architecture is what closes that gap between what a person agreed to and what a company’s systems actually do.
Weak consent architecture doesn’t usually fail loudly. It fails quietly, one disconnected system at a time.