Identity
28/5/2026
9 min

Customer consent: structuring data access in a regulated environment

Consentement client : structurer l'accès aux données avec Purse Identity
Table of contents
Section Content 1

Every loyalty program sign-up, every order placed, and every user action on a website, in an app, or in-store is accompanied by customer consent. This consent determines what a brand can do with the collected data: use it in a marketing campaign to send emails or SMS, use it to personalize a customer journey, or share it with a partner.

This subject has long been viewed as a legal constraint. It is now becoming a full-fledged management issue: when handled well, customer consent becomes the foundation for relevant marketing activation and a lasting, trusting relationship. When handled poorly, it undermines both compliance and the ability to leverage data. The 3.5 million euro fine issued by the CNIL in January 2026 against a major sports retailer for sharing data with a social network without valid consent illustrates the authority's increased vigilance on these matters.

How can you move from a checkbox-based approach to comprehensive governance of customer data access?

What is customer consent?

According to the CNIL, customer consent refers to the agreement given by a user for a brand to collect, process, or share their personal data within a defined framework.
This concept was already present in the Data Protection Act and was strengthened under the GDPR. It is one of the six legal bases provided by the GDPR to justify data processing, and it is the condition required for that data to truly serve the commercial relationship. To be valid, this agreement must meet 4 conditions. It must be:

  • freely given : the customer must be able to choose without coercion and/or without suffering negative consequences for refusing.
  • specific : each consent corresponds to a precise purpose; if there are multiple purposes, there must be multiple consents.
  • informed: the customer must have access to clear and transparent information about the processing of their data before consenting.
  • unambiguous. consent is expressed through a clear, affirmative action; pre-checked boxes, inaction, or bundled consents are not considered valid.

Two principles complete this framework and have a direct impact on how retailers must organize their consent management:

  • The right to withdraw : the customer must be able to withdraw their consent at any time, using a method as simple as the one used to give it. Consent collected online must be able to be withdrawn online.
  • Proof of consent : in the event of an audit, the brand must be able to demonstrate at any time that the customer has indeed consented under valid conditions.

In practice, the term covers three distinct realities that are useful to distinguish.

1. Consent for cookies and tracking

This is the most visible aspect: the pop-up that appears when arriving on a site, which conditions the placement of cookies and the execution of third-party scripts (Google Analytics, Microsoft Clarity, Meta Pixel, etc.). These mechanisms collect so-called third-party data, meaning data not linked to an identified user. This management is handled on the front-end via dedicated tools (CMP, or Consent Management Platform). While essential for site compliance, it does not directly involve the customer account. This is a scope that CIAM (Customer Identity and Access Management) does not cover.

2. Consent related to customer preferences

This is the core of the matter for B2C brands. We are talking here about first-partyconsent, meaning data collected directly by the brand from its customer without an intermediary. It occurs at every moment the customer interacts with the brand: signing up on a site, joining a loyalty program, creating an in-store account, or making an online purchase. This scope covers three main categories of consent:

  • Acceptance of general terms and conditions (Terms of Use, Terms of Sale, Terms of Service) : This is a prerequisite for accessing the service. It is often integrated into the registration or checkout process in the form of explicit opt-in consent.
  • Promotional communications : Opt-in and opt-out choices provided for receiving newsletters, commercial SMS, or promotional mail. These three models follow distinct frameworks: opt-in for B2C in Europe, opt-out currently permitted in B2B, and double opt-in required by certain national regulations, such as in Germany.
  • Data sharing with third-party brands or partners : Authorization for a brand to transmit customer data to another partner entity.

It is within this scope that data capture is key and the quality of the long-term customer relationship is determined.

3. Consent for sharing in a social login journey

More marginal, this occurs when a customer logs into a site using, for example, their Google, Apple, or Facebook account, or any other third-party identity provider. The identity provider then asks the user to authorize the sharing of specific information (name, email, profile picture, etc.) with the brand in question.

CIAM applies to categories 2 and 3. These are the two categories we will discuss in this article.

How can you effectively manage your customers' consent?

Effectively managing customer consent means turning it into an asset for marketing activation and compliance. This requires access governance that goes beyond simple data capture: a system capable of linking each consent to a unique identity, structuring complex choices, and enriching customer insight throughout their interactions. Three levers form the foundation of robust management.

Link customer identity to their consents to avoid desynchronization

The foundation of solid governance is to bring customer identity and consents together within a single repository. This is where a CIAM provider like Purse makes a difference: every consent is directly linked to a unique and reliable customer identifier (email, phone, etc.). Each customer corresponds to a single identity, and associated with this identity are their login methods, communication channels (email, phone, postal address), active consents (with their history), and preferences. The CIAM platform acts as the single source of truth.

This uniqueness makes all the difference compared to an organization where multiple solutions coexist. The brand gains operational consistency and peace of mind during audits. Without a direct link between identity and consents, discrepancies inevitably arise, and the difficulty of synchronizing databases has direct consequences: for example, a customer who has unsubscribed but continues to receive communications because the information did not propagate between systems.

Structuring customer consents in multi-brand and omnichannel environments

Many retailers today operate under a multi-brand or multi-sector structure. A group may bring several brands under one banner, expand its activities across various consumer sectors, or form commercial partnerships. Each brand, sector, and partner represents a distinct purpose in the eyes of the customer and requires specific consent.

The solution to managing this seemingly complex consent landscape lies in a hierarchical structure of consents, which combines two levels:

  • group consents (also known as parent consents)
  • and stand-alone (child) consents.

The customer first provides global consent, then refines their choices.

The case of the E.Leclerc group clearly illustrates this mechanism. The retailer covers a wide range of consumer sectors: grocery, drive-thru, parapharmacy, DIY, travel, and optics. A customer who creates an account for the drive-thru service does not necessarily want to receive offers from the parapharmacy or travel agencies. A parent consent opens up global communication ("I agree to receive offers from E.Leclerc"), and child consents then specify the relevant domains, channels, or partners.

This approach captures maximum consent while maintaining the granularity required by GDPR. If a customer clicks "unsubscribe" in an email, they are offered the choice to withdraw specific sub-consents rather than opting out of everything.

Enriching consent with customer preferences

Beyond consent, which defines what a brand is allowed to do, customer preferences specify what is relevant to do. The two concepts are complementary and should be clearly distinguished:

  • The consent is a legal act. It grants or revokes a right: sending a newsletter, sharing data with a partner, or using an identifier for marketing purposes.
  • The preference is usage information. It describes the customer's interests, habits, and tastes: product categories followed, favorite brands, or events of interest.

A CIAM platform allows you to store both types of information alongside the customer's identity. This proximity enhances the quality of marketing activation.

Let's take an example. A customer creates an account on a home improvement retailer's website. They agree to receive the newsletter (consent) and indicate, during registration or through their browsing behavior, that they are interested in gardening and renovation (preferences). Based on these two pieces of information, the retailer can send them targeted offers relevant to their interests, without overwhelming them with content that doesn't apply to them.

Communication is doubly justified: the customer has given their agreement and expressed an interest. Three benefits are combined:

  • Increased relevance of communications, leading to higher engagement rates
  • Personalization at scale, without relying on third-party cookies
  • Strengthened trust, because the customer feels understood rather than solicited

Consent management: key challenges for B2C retailers

Beyond the mechanics of capture and structuring, consent management requires true governance : an organized framework that defines how consent is collected, stored, updated, and used, ensuring the consistency of the system over time.

GDPR compliance: three risks to anticipate

The GDPR remains the benchmark for consent in Europe, and the CNIL ensures its enforcement in France. For a brand, compliance goes beyond the risk of fines. Three consequences deserve the attention of business leaders:

  • Financial risk. The GDPR provides for sanctions of up to 20 million euros or 4% of total worldwide annual turnover, whichever is higher. Beyond this ceiling, it is primarily the increasing frequency and media coverage of sanctions that demand vigilance.
  • Risk to activation capacity. A sanction from the CNIL can, beyond the fine itself, limit a brand's right to communicate with its database. The commercial impact can then far exceed the financial amount of the sanction.
  • Risk to customer trust. When a customer receives solicitations from parties with whom they have no direct relationship, they quickly identify the source. Their perception of the brand is durably, and sometimes irreversibly, affected.

Solid governance is based on the criteria regularly reiterated by the CNIL: consent must be free, specific, informed, and unambiguous, with clear information provided at the time of collection and a simple way to change one's mind. The principles outlined at the beginning of this article remain the most reliable framework for evaluating your own practices.

Consent consistency across all touchpoints

A customer does not exist in a single channel. They sign up in-store, buy online, download the mobile app, and click on a link in a newsletter. With every interaction, their consent may change, and the brand must track these changes in real time to remain compliant and relevant.

The case of Micromania, supported by Purse on this subject, perfectly illustrates this logic. A customer might buy a game in-store and agree to receive communications from the brand. A few weeks later, they create an online account: the CIAM platform automatically links this new identity to their existing profile. Later still, they click "unsubscribe" in an email. The information flows from the marketing automation tool back to the CIAM, which updates the account. A single identity, continuous history of consent, and up-to-date preferences regardless of the entry point.

This consistency also relies on the ability for customers to manage their own consent. From their personal account, they can view the permissions they have granted, modify communication preferences, or withdraw consent at any time. This consent self-service meets a GDPR requirement (withdrawal must be as simple as collection) and acts as a powerful trust-building tool: the customer feels in control of the relationship rather than a passive recipient.

International customer consent management: adapting without fragmenting

For brands operating outside of Europe, consent management becomes significantly more complex. Regulatory frameworks and local expectations vary greatly from one country to another, imposing specific rules on how customer data is collected, stored, and used.

A few examples illustrate these discrepancies:

  • In Europe, the GDPR governs all personal data processing with high standards for consent. This covers, for example, hosting data within the territory where the service is provided, as well as the principle of data minimization: only data strictly necessary for the execution of the service or order may be collected.
  • In China, South Korea, and Russia, regulations require explicit consent and often mandate local data storage. (This therefore requires having servers hosted in the relevant regions that comply with local regulations.)

For a brand operating in multiple markets, the challenge is twofold: complying with local requirements while maintaining a seamless, global experience for its customers.
A CIAM platform designed for international operations allows for the adaptation of consent collection, storage, and formatting to meet each country's rules, while maintaining a unified view of customer preferences at the group level. The customer enjoys a consistent experience from one market to the next, and the brand retains control over its data repository.

This is the area where Purse currently supports brands like LVMH in territories with high regulatory and cultural complexity, helping them serve a highly international clientele.
Local expertise, combined with a single platform, makes the difference between a brand that manages its own governance and one with fragmented governance country by country.

CIAM and access governance: the foundation of your compliance and customer activation

CIAM acts as a conductor. Based on the consent collected, it centralizes and distributes data to enable all use cases:

  • Access to services. Application of terms and conditions, account opening, and access to loyalty programs or exclusive features.
  • Communications. Triggering (or blocking) newsletters, SMS, and notifications based on active opt-ins and their granularity.
  • Personalized experience. Making customer preferences available to personalization and recommendation tools, within the limits of their consent.
  • Data sharing with third-party systems. Controlled transmission of customer information to the CRM, marketing automation tools, and business partners via proven standards such as OAuth 2.0, the standard authorization protocol for this type of data flow.

The Purse Identity differentiator lies in the native integration of these functions. Authentication, consent management, and the customer repository are brought together in a single platform, where consent is at the heart of identity governance by design.

Conclusion

Customer consent has long been viewed as a constraint to be managed. Brands that have shifted this perspective are winning on three fronts: strengthened regulatory compliance, more relevant marketing activation, and consolidated customer trust.

Structuring data access in a regulated environment requires governance built around three principles: a single repository that unites identity, consent, and preferences; a structure capable of managing multi-brand, multi-channel, and multi-country complexity; and a system that manages all data usage, from the customer journey to sharing with third-party systems.

CIAM is the foundation that transforms a burdensome regulatory obligation into a controlled infrastructure, giving business departments the means to build a lasting customer relationship while respecting individual choices with a regulation-compliant solution.  

Homme portant des lunettes, tenant une carte bancaire d'une main, un smartphone de l'autre, concentré.

Frequently asked questions about customer consent and access governance

Find answers to the most common questions.

What is the difference between cookie consent and customer consent?

Cookie consent concerns the placement of trackers on a browser (Google Analytics, Meta Pixel, etc.) and is managed via a front-end banner called a CMP (Consent Management Platform). Customer consent, on the other hand, covers all agreements given by an identified customer when interacting with a brand.

What is OAuth 2.0 in the context of consent management?

OAuth 2.0 is an authorization protocol that allows an application to access user data in a limited and revocable way, without sharing login credentials.

How do you manage customer consent in a multi-brand or multi-channel environment?

By relying on a hierarchical structure of consent: a parent consent that opens global communication, and child consents that specify the brands, segments, or channels involved. This logic allows for capturing consent in a way that is simple for the customer, while maintaining the granularity required for compliance.

How do you manage customer consent internationally?

Regulations vary significantly from one country to another, and the applicable rule is often that of the customer's residence, rather than the location of the service or the company. A CIAM platform adapts the collection and storage of consent to local requirements. In complex scenarios, guidance from an expert partner remains essential.

How can a customer withdraw or modify their consent?

GDPR requires that withdrawing consent be as simple as giving it. A self-service consent portal allows customers to view their authorizations, update their preferences, or withdraw consent at any time from their personal account.