Legal Register
Visual Infographic
I-10 Consent & Notice 👤 Privacy Engineers & Solution Architects

Consent Is an Evidence Chain

Reconstructible Cryptographic Audit Proof: Notice SHA-256 to Ledger Verification

Under Section 6(10), when consent validity is challenged in an adjudication, the legal burden of proof rests entirely on the Data Fiduciary. A simple database boolean flag ('is_consented = true') is legally inadmissible. Compliance requires an immutable, reconstructible evidence chain linking the exact notice version SHA-256, language choice, itemized purpose selection, affirmative timestamp, IP/device telemetry, and signed ledger proof.

Statutory Source: Ch. 9 §4
Archetype: evidence chain
I-10 DiagramArchetype: EVIDENCE CHAIN

Consent Is an Evidence Chain

Sequential Cryptographic Evidence Chain (s.6(10) Burden of Proof)
Immutable Hash
1. Notice Version

SHA-256 of exact notice rendered (s.5(1))

Step 1
Language Code
2. Language Selection

Choice from English or 22 Schedule 8 languages

Step 2
Purpose IDs
3. Itemized Purpose

Explicit purpose codes selected (no bundles)

Step 3
Telemetry Event
4. Affirmative Action

Un-ticked checkbox click event + micro-timestamp

Step 4
Principal Hash
5. Principal Identifier

Pseudonymized principal link (s.6(1))

Step 5
Cryptographic Proof
6. Signed Ledger Proof

HMAC signature in Consent Ledger (SYS-010)

Step 6

💡 Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

In any dispute before the Board, the Fiduciary must prove valid consent was given (s.6(10)).
Notice text changes require a new version hash and re-consent if purposes are altered.
The evidence chain must be retrievable and verifiable years after the initial interaction.

📜 Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Section 5(1) to (3)Section 6(1) to (10)Rule 3Rule 4

🏗️ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) →

⚙️ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix →

🛠️ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Compute and store SHA-256 hashes of all published notice documents in git/CMS.
  2. Deploy SYS-010 Consent Ledger to record full event payloads rather than boolean flags.
  3. Build an automated evidence exporter for DPO audit defense.

Enterprise Traps & Failure Modes

  • ⚠️ Updating privacy policy wording dynamically without creating historical version snapshots.
  • ⚠️ Failing to capture the language in which the notice was displayed to the user.

📁 Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

📄 Notice Version Registry (NOTICE-001-v1.md)
📄 Signed Consent Event Record (consent-events.json)
📄 HMAC Verification Key Manifest