Customer consent: structuring data access in a regulated environment


Every loyalty program sign-up, every order placed, and every user action on a website, in an app, or in-store is accompanied by customer consent. This consent determines what a brand can do with the collected data: use it in a marketing campaign to send emails or SMS, use it to personalize a customer journey, or share it with a partner.
This subject has long been viewed as a legal constraint. It is now becoming a full-fledged management issue: when handled well, customer consent becomes the foundation for relevant marketing activation and a lasting, trusting relationship. When handled poorly, it undermines both compliance and the ability to leverage data. The 3.5 million euro fine issued by the CNIL in January 2026 against a major sports retailer for sharing data with a social network without valid consent illustrates the authority's increased vigilance on these matters.
How can you move from a checkbox-based approach to comprehensive governance of customer data access?
According to the CNIL, customer consent refers to the agreement given by a user for a brand to collect, process, or share their personal data within a defined framework.
This concept was already present in the Data Protection Act and was strengthened under the GDPR. It is one of the six legal bases provided by the GDPR to justify data processing, and it is the condition required for that data to truly serve the commercial relationship. To be valid, this agreement must meet 4 conditions. It must be:
Two principles complete this framework and have a direct impact on how retailers must organize their consent management:
In practice, the term covers three distinct realities that are useful to distinguish.
1. Consent for cookies and tracking
This is the most visible aspect: the pop-up that appears when arriving on a site, which conditions the placement of cookies and the execution of third-party scripts (Google Analytics, Microsoft Clarity, Meta Pixel, etc.). These mechanisms collect so-called third-party data, meaning data not linked to an identified user. This management is handled on the front-end via dedicated tools (CMP, or Consent Management Platform). While essential for site compliance, it does not directly involve the customer account. This is a scope that CIAM (Customer Identity and Access Management) does not cover.
2. Consent related to customer preferences
This is the core of the matter for B2C brands. We are talking here about first-partyconsent, meaning data collected directly by the brand from its customer without an intermediary. It occurs at every moment the customer interacts with the brand: signing up on a site, joining a loyalty program, creating an in-store account, or making an online purchase. This scope covers three main categories of consent:
It is within this scope that data capture is key and the quality of the long-term customer relationship is determined.
3. Consent for sharing in a social login journey
More marginal, this occurs when a customer logs into a site using, for example, their Google, Apple, or Facebook account, or any other third-party identity provider. The identity provider then asks the user to authorize the sharing of specific information (name, email, profile picture, etc.) with the brand in question.
CIAM applies to categories 2 and 3. These are the two categories we will discuss in this article.
Effectively managing customer consent means turning it into an asset for marketing activation and compliance. This requires access governance that goes beyond simple data capture: a system capable of linking each consent to a unique identity, structuring complex choices, and enriching customer insight throughout their interactions. Three levers form the foundation of robust management.
The foundation of solid governance is to bring customer identity and consents together within a single repository. This is where a CIAM provider like Purse makes a difference: every consent is directly linked to a unique and reliable customer identifier (email, phone, etc.). Each customer corresponds to a single identity, and associated with this identity are their login methods, communication channels (email, phone, postal address), active consents (with their history), and preferences. The CIAM platform acts as the single source of truth.
This uniqueness makes all the difference compared to an organization where multiple solutions coexist. The brand gains operational consistency and peace of mind during audits. Without a direct link between identity and consents, discrepancies inevitably arise, and the difficulty of synchronizing databases has direct consequences: for example, a customer who has unsubscribed but continues to receive communications because the information did not propagate between systems.
Many retailers today operate under a multi-brand or multi-sector structure. A group may bring several brands under one banner, expand its activities across various consumer sectors, or form commercial partnerships. Each brand, sector, and partner represents a distinct purpose in the eyes of the customer and requires specific consent.
The solution to managing this seemingly complex consent landscape lies in a hierarchical structure of consents, which combines two levels:
The customer first provides global consent, then refines their choices.
The case of the E.Leclerc group clearly illustrates this mechanism. The retailer covers a wide range of consumer sectors: grocery, drive-thru, parapharmacy, DIY, travel, and optics. A customer who creates an account for the drive-thru service does not necessarily want to receive offers from the parapharmacy or travel agencies. A parent consent opens up global communication ("I agree to receive offers from E.Leclerc"), and child consents then specify the relevant domains, channels, or partners.
This approach captures maximum consent while maintaining the granularity required by GDPR. If a customer clicks "unsubscribe" in an email, they are offered the choice to withdraw specific sub-consents rather than opting out of everything.
Beyond consent, which defines what a brand is allowed to do, customer preferences specify what is relevant to do. The two concepts are complementary and should be clearly distinguished:
A CIAM platform allows you to store both types of information alongside the customer's identity. This proximity enhances the quality of marketing activation.
Let's take an example. A customer creates an account on a home improvement retailer's website. They agree to receive the newsletter (consent) and indicate, during registration or through their browsing behavior, that they are interested in gardening and renovation (preferences). Based on these two pieces of information, the retailer can send them targeted offers relevant to their interests, without overwhelming them with content that doesn't apply to them.
Communication is doubly justified: the customer has given their agreement and expressed an interest. Three benefits are combined:
Beyond the mechanics of capture and structuring, consent management requires true governance : an organized framework that defines how consent is collected, stored, updated, and used, ensuring the consistency of the system over time.
The GDPR remains the benchmark for consent in Europe, and the CNIL ensures its enforcement in France. For a brand, compliance goes beyond the risk of fines. Three consequences deserve the attention of business leaders:
Solid governance is based on the criteria regularly reiterated by the CNIL: consent must be free, specific, informed, and unambiguous, with clear information provided at the time of collection and a simple way to change one's mind. The principles outlined at the beginning of this article remain the most reliable framework for evaluating your own practices.
A customer does not exist in a single channel. They sign up in-store, buy online, download the mobile app, and click on a link in a newsletter. With every interaction, their consent may change, and the brand must track these changes in real time to remain compliant and relevant.
The case of Micromania, supported by Purse on this subject, perfectly illustrates this logic. A customer might buy a game in-store and agree to receive communications from the brand. A few weeks later, they create an online account: the CIAM platform automatically links this new identity to their existing profile. Later still, they click "unsubscribe" in an email. The information flows from the marketing automation tool back to the CIAM, which updates the account. A single identity, continuous history of consent, and up-to-date preferences regardless of the entry point.
This consistency also relies on the ability for customers to manage their own consent. From their personal account, they can view the permissions they have granted, modify communication preferences, or withdraw consent at any time. This consent self-service meets a GDPR requirement (withdrawal must be as simple as collection) and acts as a powerful trust-building tool: the customer feels in control of the relationship rather than a passive recipient.
For brands operating outside of Europe, consent management becomes significantly more complex. Regulatory frameworks and local expectations vary greatly from one country to another, imposing specific rules on how customer data is collected, stored, and used.
A few examples illustrate these discrepancies:
For a brand operating in multiple markets, the challenge is twofold: complying with local requirements while maintaining a seamless, global experience for its customers.
A CIAM platform designed for international operations allows for the adaptation of consent collection, storage, and formatting to meet each country's rules, while maintaining a unified view of customer preferences at the group level. The customer enjoys a consistent experience from one market to the next, and the brand retains control over its data repository.
This is the area where Purse currently supports brands like LVMH in territories with high regulatory and cultural complexity, helping them serve a highly international clientele.
Local expertise, combined with a single platform, makes the difference between a brand that manages its own governance and one with fragmented governance country by country.
CIAM acts as a conductor. Based on the consent collected, it centralizes and distributes data to enable all use cases:
The Purse Identity differentiator lies in the native integration of these functions. Authentication, consent management, and the customer repository are brought together in a single platform, where consent is at the heart of identity governance by design.
Customer consent has long been viewed as a constraint to be managed. Brands that have shifted this perspective are winning on three fronts: strengthened regulatory compliance, more relevant marketing activation, and consolidated customer trust.
Structuring data access in a regulated environment requires governance built around three principles: a single repository that unites identity, consent, and preferences; a structure capable of managing multi-brand, multi-channel, and multi-country complexity; and a system that manages all data usage, from the customer journey to sharing with third-party systems.
CIAM is the foundation that transforms a burdensome regulatory obligation into a controlled infrastructure, giving business departments the means to build a lasting customer relationship while respecting individual choices with a regulation-compliant solution.

Find answers to the most common questions.
Cookie consent concerns the placement of trackers on a browser (Google Analytics, Meta Pixel, etc.) and is managed via a front-end banner called a CMP (Consent Management Platform). Customer consent, on the other hand, covers all agreements given by an identified customer when interacting with a brand.
OAuth 2.0 is an authorization protocol that allows an application to access user data in a limited and revocable way, without sharing login credentials.
By relying on a hierarchical structure of consent: a parent consent that opens global communication, and child consents that specify the brands, segments, or channels involved. This logic allows for capturing consent in a way that is simple for the customer, while maintaining the granularity required for compliance.
Regulations vary significantly from one country to another, and the applicable rule is often that of the customer's residence, rather than the location of the service or the company. A CIAM platform adapts the collection and storage of consent to local requirements. In complex scenarios, guidance from an expert partner remains essential.
GDPR requires that withdrawing consent be as simple as giving it. A self-service consent portal allows customers to view their authorizations, update their preferences, or withdraw consent at any time from their personal account.