Permission belongs in the access path

The documented consent check asks whether a person has an active token for the requested purpose and data categories. The result is allowed or denied, with a matching token identifier when one exists and a status such as active, expired, revoked, blocked, or none.

This makes the permission decision useful at the moment a service requests data. The intended rule is simple: if the request does not match an active permission, access should not proceed.

What still needs operational proof

  • Every relevant service performs the check before access.
  • Unavailable or invalid checks fail closed instead of allowing access.
  • Revocation reaches downstream systems and stops future access.
  • Retention exceptions are disclosed and handled under applicable obligations.