The pattern that ensures consent state travels with the identifier wherever the identifier travels. If a customer revokes consent, every downstream system that holds derived data needs to respect that revocation, not just the system where the revocation was recorded. Foundational to GDPR-defensible architectures and the pattern most often quietly ignored across the multi-system reality of modern stacks.
The pattern that logs not just what happened but why: which model produced the decision, which version, which features contributed, which rules overrode, which consent state applied. The AI Act question coming at everyone with high-risk AI systems, and the defensibility question for any consequential automated decision regardless of the regulation.
The pattern of only capturing what the use case actually requires, rather than collecting everything and figuring out the use case later. Both a compliance posture under GDPR's necessity principle and an architectural discipline that limits the blast radius of any data incident. The hardest pattern to implement because it requires deciding what not to collect.
The pattern that handles the cascading deletion problem: when a customer exercises their right to be forgotten, the deletion has to propagate to every system holding their data, including derived attributes, model training sets, and third-party shares. The composable stack makes this both more important and more complicated than the packaged-suite equivalent.
The pattern that varies decisions by the customer's jurisdiction: which consent regime applies, which retention windows govern, which channel rules dominate, which regulatory carve-outs allow or block specific recipes. Distinct from consent state propagation because jurisdiction is the structural context that determines which consent state is meaningful in the first place. Increasingly required as US state law, EU member state variation, and sectoral regulation create non-uniform compliance terrain.
The pattern that constrains what data a given message, API call, or activation carries to only the fields the communication actually needs, regardless of what the upstream system has available. The architectural counterpart to data minimization at collection, applied at egress rather than ingestion. Especially load-bearing under HIPAA's minimum-necessary rule and under GDPR's purpose-limitation principle.
The pattern that keeps regulated data classes (PHI under HIPAA, sensitive personal data under GDPR Article 9, financial data under GLBA) routed only through systems that are contractually and architecturally permitted to hold them. Boundaries are enforced explicitly at the data layer rather than relying on conventions that drift as the stack composes. Generalizes beyond healthcare to any regulated-class data with a BAA-equivalent contractual perimeter.