← All case studies
Professional services · Customer Insights – Journeys, Dataverse · consent architecture

Consent that survives a lawyer.

A per-address consent model, with the dates the platform doesn’t keep.

~145,000dated consent entries in the production ledger
1consent holder per unique email address — however many roles and records use it
5markets, each with its own channel rules held in configuration

The situation

Consent, legally, is specific: it belongs to an email address, it has a source, and it has dates. Platforms are looser. The system of record kept one consent at a time per record — when it neared expiry, staff were notified ahead of anonymisation and extensions were collected by phone. And the modern marketing engine’s native consent carries no validity dates at all, which for a business that must know until what date it may write to someone is not a detail.

On a Dynamics 365 platform spanning five European markets, DynaVerto designed and built a consent model that satisfies both worlds — the marketing engine’s mechanics and the legal department’s questions.

What we did

The anchor is the email address: one consent holder per unique address, regardless of how many roles or records use it. Every consent lives as its own dated row — typed by source, never deleted, expiring by date rather than by overwrite. From those rows the model computes two answers: the strongest active consent (what a user sees and edits) and the longest-valid one (what actually governs contactability), and the longest is propagated to every record using that address.

Directionality is the heart of it. Contributions flowing in — from the system of record, from imports, from linked records — can only ever extend consent; nothing on the feeding side can silently shorten it. Shortening happens only through explicit, auditable acts: a manual edit on the consent holder, natural expiry, or the unsubscribe. Propagation writes carry a marker so the feeding logic recognises them and stands down — the loop closes by design, not by luck. One market’s separate phone-call consent deliberately stays per person, because that is what it legally is. The platform’s native consent points are still created alongside, so segmentation and journey gating work out of the box.

One caveat is accepted and written down: because the feeding side can only extend, a manual shortening can later be out-extended by a genuinely longer contribution. That is precisely why the unsubscribe is the one true withdrawal lever — and the model treats it as such.

In five lines

  • One consent holder per unique email address — consent survives changes to the records that use it
  • Every consent is a dated, typed row that is never deleted — expiry happens by date, history stays
  • Strict directionality: inbound contributions extend only; shortening is always an explicit, audited act
  • Succession on expiry: when one consent lapses, the next-longest active one takes over automatically
  • Native consent points maintained in parallel, so the marketing engine’s own mechanics keep working

Results

  • A dated consent ledger of roughly 145,000 entries in production
  • Expiry stopped being a phone-call process — where staff once chased end dates manually, the next-longest consent now takes over on its own
  • Consent survives the record lifecycle: removing a role or record no longer erases what the address had granted
  • In daily use under the client’s data-protection regime across five markets, with per-market channel rules intact
“The platform doesn’t keep validity dates and the lawyers keep asking for them — so we ended up keeping our own ledger.”

All engagements are anonymised. References available on request, subject to client approval.

Would your consent model survive the second question?

Bring your consent questions. If the model can’t answer them, we’ll say so.

Request a 30-minute call