You are here:
Consent Event Stream Control
Streams near real-time events whenever consent-related fields change, providing an auditable feed of consent updates that downstream systems can subscribe to for timely enforcement of privacy choices.
Control Name
Consent Event Stream
Control Overview
Streams near real-time events whenever consent-related fields change, providing an auditable feed of consent updates that downstream systems can subscribe to for timely enforcement of privacy choices.
Description
When enabled, the consent event stream publishes events for creations and updates to consent records and key consent fields, so external platforms, marketing tools, and internal services can react immediately (for example, stop messaging after an opt-out) without relying solely on batch synchronization.
Recommended Configuration
Select 'Use the consent event stream'.
Security Impact
Improves enforcement of consent and data protection policies across integrated systems by making sure that changes to consent are quickly propagated, reducing the window where processing might occur against an individual’s current wants.
Business Impact
Helps keep communication and personalization in sync with customer and patient preferences, reducing regulatory exposure and improving trust by minimizing cases where individuals receive communications after opting out.
Security Risk If Not Configured
Lack of change visibility to consent fields through missing consent event stream setup.
Threat Scenarios
Consent revocations or preference changes are not propagated promptly to downstream or third-party systems, resulting in unauthorized processing or communications that violate regulatory requirements and user expectations.
Estimated CVSS Score Range
Medium (4.0–6.9).
Risk Impact Considerations
Impact increases with the number of integrated systems relying on consent data, the sensitivity of the data being processed (for example, health or financial), and the regulatory regimes applicable to the company.
Higher Risk When
Multiple external marketing, analytics, or engagement platforms consume consent data from Salesforce, consent changes are frequent, or the company operates in highly regulated jurisdictions, such as GDPR or HIPAA-covered environments.
Low Risk When
Salesforce is the primary system of engagement with few or no external processors relying on streamed consent updates, and consent changes are infrequent or handled through tightly controlled manual workflows.
Business and Integration Considerations
N/A
Security Health Review Guidance
Good to have.
Who Is Impacted
Privacy and compliance teams, integration architects, marketing operations, and application owners whose systems rely on timely and accurate consent information from Salesforce.

