Privacy regulation as an engineering constraint, not a legal afterthought.
Consent is a lifecycle
Consent should not be reduced to a checkbox. A system needs to record what a person agreed to, for which purpose, when, through which notice and how that choice can be changed.
POPIA compliance depends on context and should be reviewed with qualified legal and information-governance professionals. Architecture can support that work by making purposes, records and responsibilities visible.
Separate purposes and permissions
Avoid one broad flag for unrelated processing. Model distinct purposes and connect each one to the data, channel and retention rule it authorises. Make withdrawal effective across operational systems and downstream processors.
Collect only what is needed for the stated purpose. Access controls and audit records should show who used personal information and under which authority.
Design for accountability
Maintain current notices, processing records, retention schedules and incident procedures. Build ways to locate, correct, export or delete information when an authorised process requires it.
Test consent changes as end-to-end workflows. A preference that changes in the interface but not in messaging, analytics or exports is not an effective control.
