Compliance & Service Design · Design Lead
Turning a compliance risk into a simple first step.
Standardising how and when consent is captured, with one pattern that works globally.
Role
Design Lead
Worked with
Product, Legal, Engineering
Started with
Data compliance concerns from L’Oréal US
Outcome
One reusable consent pattern for every journey
Setting the Scene
After L’Oréal US raised concerns about data being stored before people had agreed to the Terms and Conditions, I led a cross-functional review of how consent was captured across SoPost’s feedback journeys.
Working with Product, Legal and Engineering, the goal was to define a single, compliant pattern that worked globally. It had to protect people and brands while keeping the experience fast and intuitive.
Visual coming soon
Consent step before data entry: standard and gifting journeys
The Problem
In the existing flow, responses could be saved before people gave consent. For brands operating under strict data regulations, that was a compliance risk: personal data could be processed by third parties before the Terms were accepted.
We needed to move consent earlier in the flow without adding friction or harming completion rates.
The Trade-Off
Moving consent upfront increases legal confidence, but it often causes a small drop in completions. To balance the two, I simplified the step, cut the copy, and made the nickname field optional or pre-filled, so the legal step felt seamless rather than obstructive.
My Role
I led the audit and redesign end to end. That included:
- · Mapping where and when data was written or saved across systems
- · Working with Engineering to document save events and dependencies
- · Prototyping a new welcome and consent step for both standard and gifting journeys
- · Partnering with Legal to rewrite the consent copy for clarity and brevity
- · Reducing interaction friction through layout, focus order and auto-generation logic
This wasn’t just a visual redesign. It was a compliance and systems change, anchored in design.
Process
With the Product Manager, I analysed historic performance data for the “welcome screen” to understand its effect on conversion, then redefined it as the default consent pattern for every feedback journey. The new design:
- · Adds an upfront welcome step that captures the Terms and required consents before any data entry
- · Simplifies the copy and uses a single primary action to continue
- · Treats the nickname as optional, or auto-generated where possible
- · Includes variants for both standard and gifting journeys
That gives SoPost one reusable consent model across brands, improving compliance and consistency while keeping the effort for the person answering as low as possible.
Visual coming soon
Welcome and consent step: single primary action
Rollout and Measures
The new journeys were designed to roll out first to selected brand partners. After launch, the plan was to track:
- · Step-one drop-off rate
- · Consent acceptance and completion rate
- · Campaign approval time
- · Support impact and qualitative feedback
Those results would inform further optimisation of the copy and layout if completion rates dipped.
Reflection
This was a small but critical piece of work. It set out one way for SoPost to handle consent globally, designed to strengthen legal compliance for enterprise clients, and it showed how micro-level design decisions can de-risk a system without damaging the experience.
It also reinforced how design can act as the link between policy, technology and trust, translating regulatory requirements into clear, usable experiences.