Skip to main content
Adrià García
← Back to the simulators

Web SDK · consent and datastreams

The journey of an event

Laura opens the product page for a pair of trainers and the cookie banner appears. What happens to her events depends on the Web SDK defaultConsent before she answers, and on what the CMP passes to setConsent afterwards. Once an event goes out, the datastream decides which services it reaches.

Scenario

Web SDK defaultConsent

What the SDK does before the CMP calls setConsent.

Laura on the banner
Services in the datastream

Every event sent reaches all enabled services. The table shows which ones.

IP obfuscation

Illustrative scenario ↑ Back to the controls
Example assumptions

Example visit, events and set-up. Datastream changes can take up to 35 minutes to apply across the Edge Network.

The visit

What happens to each event

The visit's events in order, with Laura's decision in between and the services that receive each event sent.

Reading

What to check

The consequences of the chosen set-up, for Laura's privacy and for the services.

Architecture

Where it fits in the platform

One request brings back the Journey Optimizer proposition and the ECID. The Edge Network sends the event to Experience Platform, where CJA reads it, and forwards it to Meta. With consent set to out, the event never leaves the browser.

Sequence diagram of one Web SDK request, with seven participants: the page, a product page; the Web SDK, alloy.js; the Edge Network with its datastream; Journey Optimizer, deciding at the Edge Network; Experience Platform, with a dataset and Profile; Customer Journey Analytics with its connection; and event forwarding to the Meta Conversions API. Out: the page passes consent in from the CMP to the Web SDK with setConsent, then calls sendEvent with commerce.productViews. The Web SDK sends a POST to the interact endpoint with the XDM event. Decision: the Edge Network requests propositions from Journey Optimizer, which returns a banner. The Edge Network responds to the Web SDK with the propositions and the ECID, which the Web SDK reuses, and the Web SDK renders the banner without a second call. Only the Journey Optimizer proposition travels in that response, and it needs an Active-On-Edge merge policy. Fan-out: the Edge Network sends the XDM event to the dataset and Profile, the Customer Journey Analytics connection reads that dataset, and the Edge Network applies the product view rule to forward it to CAPI. Measurement: after rendering, the Web SDK sends the display notification. With consent set to out, the event never leaves the browser, and with no event at the Edge Network there is nothing to forward.

The recommendation

defaultConsent set to pending where the law requires it, setConsent as early as possible and a lean datastream

The Web SDK does what it is configured to do. The problems come from not deciding what happens before the user answers and from connecting services just in case.

  1. 01

    defaultConsent set to pending where consent is required

    No ECID or identity cookies are created until the user decides, and events wait in a queue. With in as the default, data is collected before asking.

  2. 02

    setConsent as soon as it is known

    On page load with the decision stored in the CMP, and right when the banner is answered. The pending queue lives in memory: if the user changes page first, those events are lost.

  3. 03

    A lean datastream

    Every enabled service receives the events. Adding Target, Analytics or event forwarding just in case sends data where it is not needed. One datastream per environment.

  4. 04

    Consent in the profile too

    With a profile dataset in the datastream and the consent field group in the schema, the preference reaches Real-Time Customer Profile and AJO can respect it.

Architecture note · 09 Consent is a chain, not a field It is decided in the CMP, travels through the SDK, is stored in the profile and enforced by each destination. It breaks at the link nobody designed. Read the note →