The consent management APIs in WSO2 Identity Server collect and manage end user consents when user information is shared with external parties. The following sections guide you through the consent management concepts and the APIs you can invoke.
Definitions for consent management
This section defines and explains commonly used terms in consent management. PII Controller PII Processor
Any information that can be used to identify the PII Principal to whom the information relates to.
The natural person to whom the personally identifiable information (PII) relates to.
A Personally identifiable information (PII) Principal’s freely given, specific and informed agreement to the processing of their PII.
The business, operational or regulatory requirement for the collection, use and/or disclosure of a PII Principal's data. In other words, it is the reason personal information is collected by the entity.
A record of a consent interaction (or consent record summary linked to the record of consent) provided by a PII Principal to a PII Controller to collect, use and disclose the PII Principal’s PII in accordance to an agreed set of terms.
A private stakeholder that determines the purposes and means for processing personally identifiable information (PII) other than the natural persons who use data for personal purposes.
For information on configuring the PII controller, see Configuring the PII controller.
A private stakeholder that processes personally identifiable information (PII) on behalf of and in accordance with the instructions of a PII controller.
For more information about consent management concepts and the use cases of consent management with WSO2 IS, see Consent Management Overview.
Configuring the PII controller
You can configure a default PII controller in one of the following ways:
- Via the management console
- Via the configuration file
Via the management console
- Login to the management console.
- Click Resident under Identity Providers and expand the Consent Management tab.
- Configure the PII controller information.
Via the configuration file
consent-mgt-config.xmlfile found in the
<IS_HOME>/repository/conffolder and configure the following configuration block.
For more information on how to extend or customize this, see Extension points.
APIs and supported operations
For information on the REST APIs, supported operations and sample requests/responses, see Consent Management APIs Swagger Documentation.
You can customize the REST APIs using the following extension points:
- PIIController connector extension - A sample implementation that demonstrates registering a PII controller and providing PII controller information for consent receipts.
- Interceptor extension - A sample implementation that demonstrates registering a consent management interceptor and intercepting consent management related operations.