Permission belongs in the access path
The documented consent check asks whether a person has an active token for the requested purpose and data categories. The result is allowed or denied, with a matching token identifier when one exists and a status such as active, expired, revoked, blocked, or none.
This makes the permission decision useful at the moment a service requests data. The intended rule is simple: if the request does not match an active permission, access should not proceed.
What still needs operational proof
- Every relevant service performs the check before access.
- Unavailable or invalid checks fail closed instead of allowing access.
- Revocation reaches downstream systems and stops future access.
- Retention exceptions are disclosed and handled under applicable obligations.