Research question and scope

Published September 9, 2026.

This study asks whether support-accessible consent records contain the fields needed to establish purpose, notice version, response, timestamp, and source channel. The scope is a defined set of systems and record types during one audit window. It does not judge the legal validity of consent or determine the appropriate lawful basis.

Methodology

Create a field-level specification with privacy and system owners before extraction. Draw a reproducible sample by source system, creation period, and consent purpose. Test required-field presence, valid values, chronological consistency, and links to the governing notice. Keep migrations and legacy records as separate strata. Reviewers should use masked identifiers and record disagreements.

Measures and analysis

Report the eligible population, sample design, missingness by field, internally inconsistent combinations, and results by system and record age. Publish reviewer agreement for judgment-based checks. Investigate clusters at capture and migration points. Treat missing data as a quality finding, not evidence that a customer accepted or declined.

Limitations and inference limits

The study cannot prove what a customer saw or intended. A stored timestamp may be technically complete while the underlying notice or interface was flawed. Sample findings may not generalize to systems, purposes, or periods outside the frame. Legal conclusions require qualified review beyond this descriptive audit.

Sources

  1. NIST Privacy Framework
  2. NIST Privacy Framework Resource Repository
  3. US Government Accountability Office, Assessing Data Reliability
  4. OECD Privacy Guidelines