bcquality/microsoft/knowledge/privacy/privacy-notice-consent-for-external-data-transfer.md
Jesper Schulz-Wedde 2b5550c346
Some checks failed
Validate knowledge index / validate-index (push) Has been cancelled
Validate AL review fixtures / validate-review-fixtures (push) Has been cancelled
Validate frontmatter and structure / validate (push) Has been cancelled
Improve partner onboarding and documentation navigation (#174)
Lead with a complete plugin quick start and add task-oriented usage, troubleshooting, customization, and contribution guides. Preserve the broader plugin framing, correct conflicting contract guidance, support Agents folder reviews, and align repository validation. Convert existing sample references to clickable links without changing knowledge rules.

Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 17:31:03 +02:00

1.5 KiB

bc-version domain keywords technologies countries application-area
all
privacy
privacy-notice
consent
http-client
outgoing-request
external-service
confirmprivacynoticeapproval
al
w1
all

Check the custom Privacy Notice before external data transfer

Description

Business Central's Codeunit "Privacy Notice" creates notices and records per-integration approval. A custom integration needs its own stable notice ID; it must not borrow the Exchange or another built-in service's consent. ConfirmPrivacyNoticeApproval shows the notice when needed and returns whether the request is approved. GetPrivacyNoticeApprovalState checks an existing notice without showing UI.

Best Practice

Register the custom notice with CreatePrivacyNotice during setup or through OnRegisterPrivacyNotices. Before sending data, call ConfirmPrivacyNoticeApproval(<custom id>) outside a write transaction, or check GetPrivacyNoticeApprovalState(<custom id>) when the flow must not show UI. No path should issue the request without approval.

See sample: privacy-notice-consent-for-external-data-transfer.good.al.

Anti Pattern

A custom integration that posts data without checking its own notice, or that gates the call with a built-in ID such as the Exchange privacy notice ID. Consent for one service does not authorize another.

See sample: privacy-notice-consent-for-external-data-transfer.bad.al.