Fides Documentation – Ethyca

Bidirectional consent

This document provides an overview of the Bidirectional consent feature of Fides. Learn more in the following sections:

Prerequisites

For this tutorial you will need:

Introduction to Bidirectional consent

Bidirectional consent is a feature of Fides that acts as a centralized system of record for all consent and privacy preferences. It serves as a universal translator between Fides' standardized privacy concepts and the specific requirements of various third-party consent management systems. This automation enables two crucial functions:

  1. Outbound consent propagation: Any consent preference saved directly in Fides can be automatically propagated to all connected third-party APIs that support consent management.
  2. Inbound consent synchronization (Consent webhooks): Changes to consent preferences made in third-party systems can be posted to Fides, processed, and propagated. Ensuring all connected systems remain up-to-date.

⚠️ The extent of Bidirectional consent functionality in Fides is dependent on the capabilities of the connected consent management APIs. For example:

How Bidirectional consent works

Bidirectional consent in Fides works by acting as a translator between Fides' standardized privacy concepts and the specific requirements of various third-party systems. This process involves three key steps:

Here's an example of how general Fides concepts map to a 3rd-party system to illustrate this process:

Fides terminology 3rd-party system
Marketing privacy notice Email Marketing Channel and Push Marketing Channel
Opt-in consent preference Subscribed
Opt-out consent preference Unsubscribed

In this example:

Fides uses a single Marketing privacy notice to represent consent for marketing communications. The third-party system separates this into two distinct channels: Email Marketing and Push Marketing. Each channel represents a "consentable item" in this system, it could be subscriptions or mailing lists for other systems.

When a user gives consent ( opt-in) in Fides:

When a user revokes consent ( opt-out) in Fides:

Conversely, if the third-party system reports an Unsubscribed status for either channel via consent webhook:

The Bidirectional consent process handles the translation between these two models, ensuring consistency across systems with varying consentable items and consent models.

Configuring Bidirectional consent

Ensure data use overlap between systems and privacy notices

Before mapping consentable items, each system used for bidirectional consent must have at least one privacy declaration whose data_use matches (or is a child of) a data use on the privacy notices you intend to map. Without this overlap, the system will not be considered applicable to those notices, and outbound consent signals will not be sent to it.

For example, if your privacy notice has data_uses: [marketing.advertising], then the system's privacy declaration must also use marketing.advertising (or a child such as marketing.advertising.first_party).

Configuration item Example value
Privacy notice data uses marketing.advertising
System privacy declaration data use marketing.advertising

To add a privacy declaration to your system:

  1. In the Admin UI, navigate to Data map > View Systems and select the system.
  2. Click on the Data uses tab.
  3. Add a privacy declaration with the appropriate data use that matches your privacy notice.
  4. Click Save.

⚠️ If you skip this step, you can still map consentable items in the UI, but outbound consent signals will not be propagated to this system because it will not be considered applicable to the privacy notice.

Map consentable items

  1. In the Admin UI, navigate to Data inventory > Add Systems.
  2. Create a new system, click save.
  3. Navigate to the Integrations tab for this system and select an integration that supports Bidirectional consent (As of Fides v2.68.0: Iterable, Hubspot, Outreach and Bloomreach. Additional integrations can be added on request).
  4. Enter the credentials and click save.
  5. After saving the credentials, the Bidirectional consent accordion will be accessible.
  6. Expand the accordion and map your consentable items to your privacy notices. The list of items is dynamic and will vary between integrations or even within different accounts for the same integration.
  7. Once you're done mapping the items click save.

Setting up the consent webhook

If the 3rd-party API supports posting data to other systems when a consent update occurs, then you can configure a consent webhook in Fides. See Iterable's System Webhooks documentation as an example. This setup will vary between integrations so refer to our integration guides below for more details. Generally speaking, the URL that Fides exposes for an integrations consent webhook will follow the pattern:

/api/v1/plus/connection/{integration_identifier}/consent-webhook

The integration_identifier refers to the Integration identifier of the consent integration. In this case iterable_api

Generating an access token for consent webhooks

In order to secure the payload from external systems, Fides allows users with the Owner role to issue long-lived access tokens for use in the consent webhooks. This is currently done via the API.

GET /api/v1/plus/connection/{{integration_identifier}}/consent-webhook/token
{
  "access_token": "eyJhbGciOiJkaXIiLCJlbmMiOiJBMjU2R0NNIn0..."
}

⚠️ The consent webhook tokens are scoped to an individual integration and expire after 6 months. It is your responsibility to generate a new access token before it expires and update it in your external systems. If you want to change the time-to-live for these settings adjust the value of FIDES__SECURITY__CONSENT_WEBHOOK_ACCESS_TOKEN_EXPIRE_MINUTES

Integration guides

For specific instructions how to set up connectivity to a specific integration or how to setup the consent webhooks, refer to the following integration guides.