Skip to main content
Adrià García
← Back to the simulators

Experience Platform · Data governance

Can I send this?

A partner permits internal use of its data, but not export or cross-site advertising. Does your configuration enforce that? Try different destinations and policies. The result evaluates only this example’s controls.

Scenario

Try this change

Disable the partner policies. Watch the technical block disappear while the contractual restriction remains.

The data

XDM field and its data usage labels. Location is an event field; the rest are profile attributes.

Where you use it

Destination or channel, each with its marketing actions.

See the full result ↓
More settings (5)
Core policy C2: restrict export to third parties

In Adobe, policies come disabled. Here some start enabled so you can see the effect.

Core policy C5: restrict cross-site targeting
Custom policy: keep health data in-house
Custom policy: precise location on the web only
Shield add-on for consent policies

Healthcare Shield or Privacy & Security Shield. Without them, AJO still applies its native consent checks.

Illustrative scenario ↑ Back to the controls
Example assumptions

Example data, destinations and policies. Which label each field carries is up to each organisation.

Label · policy · marketing action

What these policies block

This example evaluates the configured labels and actions. Finding no block does not guarantee that a send is permitted.

Consent and other controls

What the policy does not tell you

Consent is checked separately, and some destinations apply rules of their own.

The recommendation

Label fields when you design the schema, enable the policies and tag every output with its marketing action

Check labels, enabled policies, marketing actions and integration coverage. A missing piece may leave this restriction unenforced; other controls can still block the operation.

  1. 01

    Labels in the schema, policies enabled

    Label datasets and schema fields according to validated restrictions. Usage policies, including predefined ones, are disabled by default. Enable the relevant policies and test enforcement.

  2. 02

    Marketing actions on every output

    Every Real-Time CDP destination and every AJO channel configuration with its actions: Export to Third Party, Cross Site Targeting, Email Targeting.

  3. 03

    Consent

    Shield enables consent policies that must be configured and activated. AJO retains native controls. Elsewhere, check where each preference is evaluated and how it stays current.

  4. 04

    Event fields in AJO

    DULE in AJO does not cover event context fields. Review data used in messages and custom actions. Add specific controls; moving them into Profile is not always the right solution.

Architecture note · 09 Consent is a chain, not a field It is decided in the CMP, travels through the SDK, is stored in the profile and enforced by each destination. It breaks at the link nobody designed. Read the note →
Try another decision Where consent lives → How much of what Laura decided reaches her profile, and who enforces it at activation?

Explore this decision

DULE and data usage governance