Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Consent Event Stream Control

Consent Event Stream Control

Streams near real-time events whenever consent-related fields change, providing an auditable feed of consent updates that downstream systems can subscribe to for timely enforcement of privacy choices.

Control Name

Consent Event Stream

Control Overview

Streams near real-time events whenever consent-related fields change, providing an auditable feed of consent updates that downstream systems can subscribe to for timely enforcement of privacy choices.

Description

When enabled, the consent event stream publishes events for creations and updates to consent records and key consent fields, so external platforms, marketing tools, and internal services can react immediately (for example, stop messaging after an opt-out) without relying solely on batch synchronization.

Recommended Configuration

Select 'Use the consent event stream'.

Security Impact

Improves enforcement of consent and data protection policies across integrated systems by making sure that changes to consent are quickly propagated, reducing the window where processing might occur against an individual’s current wants.

Business Impact

Helps keep communication and personalization in sync with customer and patient preferences, reducing regulatory exposure and improving trust by minimizing cases where individuals receive communications after opting out.

Security Risk If Not Configured

Lack of change visibility to consent fields through missing consent event stream setup.

Threat Scenarios

Consent revocations or preference changes are not propagated promptly to downstream or third-party systems, resulting in unauthorized processing or communications that violate regulatory requirements and user expectations.

Estimated CVSS Score Range

Medium (4.0–6.9).

Risk Impact Considerations

Impact increases with the number of integrated systems relying on consent data, the sensitivity of the data being processed (for example, health or financial), and the regulatory regimes applicable to the company.

Higher Risk When

Multiple external marketing, analytics, or engagement platforms consume consent data from Salesforce, consent changes are frequent, or the company operates in highly regulated jurisdictions, such as GDPR or HIPAA-covered environments.

Low Risk When

Salesforce is the primary system of engagement with few or no external processors relying on streamed consent updates, and consent changes are infrequent or handled through tightly controlled manual workflows.

Business and Integration Considerations

N/A

Security Health Review Guidance

Good to have.

Who Is Impacted

Privacy and compliance teams, integration architects, marketing operations, and application owners whose systems rely on timely and accurate consent information from Salesforce.

 
Loading
Salesforce Help | Article