8.3 Data Usage Labeling & Enforcement (DULE), Consent, and Privacy

Key Takeaways

  • Data usage labels classify fields or datasets; policies combine those labels with marketing actions to allow or block use.

  • Journey Optimizer performs policy checks during authoring/publication and can block activation when selected profile attributes violate policy.

  • Current journey policy checks apply to profile attributes and do not evaluate event-context fields, so event data needs upstream governance and design review.

  • Consent and subscription preferences are separate from DULE policies and must be configured and tested for each channel and purpose.

  • Privacy Service access/delete requests are rights-management workflows, not a substitute for marketing consent or journey suppression.

Last updated: October 2026

8.3 Data Usage Labeling, Consent, and Privacy

Governance in Adobe Experience Platform has related but distinct controls: data usage labels and policies, consent/subscription preferences, and Privacy Service requests. Choosing the correct control is a frequent scenario skill.

Labels

A data usage label classifies data according to contract, identity, sensitivity, or another governance category. Labels can be applied at appropriate dataset and schema-field levels. A field label follows that field into datasets based on the schema; a dataset-level label classifies the dataset broadly.

Examples include:

  • identity data used to recognize a person or device;
  • sensitive data requiring stronger restrictions;
  • contracted data restricted from certain activation;
  • data prohibited from cross-site targeting.

The exact label alone does not block an action. It supplies classification used by a policy.

Policies and marketing actions

A data usage policy combines labels with a marketing action. Conceptually: “Data carrying label X must not be used for marketing action Y.” Journey Optimizer associates relevant activity with marketing actions and evaluates policy conflicts.

During content/journey authoring and publication, Journey Optimizer can surface violations and block activation until the conflict is resolved. The remedy is not to remove a label casually. Confirm the intended purpose, choose permitted data, change the marketing action where appropriate, or obtain governance review.

Important journey scope limitation

Current Journey Optimizer documentation states that policy checks in journeys apply to profile attributes and not event-context data. Therefore, selecting a sensitive field from an event payload should not be treated as automatically covered by the same preflight check.

This is not permission to misuse event data. Apply labels and controls upstream, minimize event fields exposed to journeys, review expressions and content, and establish organizational authoring controls. The limitation is a reason for more governance, not less.

Consent and subscriptions

Consent answers whether the person permits a purpose or channel. Subscription lists can represent opt-in to a topic or communication program. Suppression lists protect against known undeliverable or blocked destinations. These are not interchangeable with DULE.

A channel design should identify:

  • legal/business purpose;
  • required consent field and unknown-value behavior;
  • subscription list if used;
  • global and channel opt-out;
  • suppression/allow list behavior;
  • transactional versus marketing classification;
  • frequency and fatigue rules.

Journey Optimizer can use standardized consent and preference data, but do not reduce the behavior to one universal field path and one discard name for every implementation. Verify the organization's schema, channel configuration, consent policies, and provider callbacks.

Privacy Service

Privacy Service coordinates consumer data access and deletion requests across supported Adobe Experience Cloud applications. A deletion request is an asynchronous rights workflow with identity, jurisdiction, verification, and status tracking. It is not a real-time unsubscribe mechanism.

Likewise, an email opt-out should not trigger deletion of the customer's entire profile. Update the relevant preference/suppression state so marketing delivery stops while retaining data according to lawful purpose and policy.

Example: governed personalization

A marketer wants to put a sensitive health attribute in an email subject.

  1. The field carries a sensitive label.
  2. The email use maps to a marketing action.
  3. A policy prohibits that label/action combination.
  4. Publication is blocked or a violation is shown.
  5. The marketer removes the attribute and uses permitted content; they do not strip the label.

Even if no policy caught an equivalent event-context field, the team must still prevent the unsafe use through data minimization and review.

Release checklist

  1. Review labels on every profile field used.
  2. Confirm marketing action and policy results.
  3. Inventory event-context fields separately.
  4. Validate consent and subscription states, including unknown.
  5. Test suppressed and missing-address profiles.
  6. Verify unsubscribe and provider feedback.
  7. Confirm privacy notice and retention.
  8. Record approval and monitor discards/violations after launch.

Common traps

  • Treating a label as a policy by itself.
  • Treating consent as DULE.
  • Assuming event context receives the same journey policy checks as profile attributes.
  • Removing a label to make publication pass.
  • Using Privacy Service deletion as an unsubscribe.
  • Assuming audience membership proves permission to contact.

Warning

Technical availability is not authorization. A profile or event field can be visible to an author and still be prohibited by policy, consent, contract, or purpose.

Unknown consent

Define how null or unknown consent is treated; do not silently equate it with permission. The rule may differ by jurisdiction, channel, and purpose, but it must be explicit and tested. Include an unknown-consent profile in release proofs, along with opted-in, opted-out, suppressed, and policy-violating profiles, so the safe default is observable.

Test Your Knowledge

What causes a data usage policy violation?

A

A label alone, with no use

B

A prohibited combination of labeled data and a marketing action

C

Any field used in a draft

D

Every audience import

Test Your Knowledge

Which limitation applies to Journey Optimizer journey policy checks?

A

They evaluate only SMS length.

B

They delete every violating dataset.

C

They evaluate profile attributes but not event-context fields.

D

They replace consent management.

Test Your Knowledge

How should a marketing email opt-out normally be handled?

A

Delete the entire profile through Privacy Service immediately.

B

Remove all data usage labels.

C

Convert the email to a business event.

D

Update the relevant consent/subscription or suppression state and honor it in delivery.

Sections you finish are checked off in the contents.