Skip to main content

One Educated Customer, Ten Laws: Which Regulatory Family Owns Which Customer-Data Gate

The Compliance group holds three concept pages that each answer one question well: the posture map says which controls are yours to toggle, the Compliance FAQ routes a first question to the page that owns it, and the GDPR end-to-end guide walks one regulation start to finish. This page answers the question those three ask back: when a complaint about “customer data” or a “regulation” arrives, which of the three independent regulatory families actually owns the gate — and which page documents it? The three families are deliberately independent in Orbit’s model. A tenant who runs outbound voice but no marketing ops sees quiet-hours gates without ever touching DSAR; a tenant who answers GDPR requests but never originates a call sees the rights-request pages without a dialing window. The separation below is the intended division of labor, not an accidental overlap.
This page describes Orbit’s platform controls. It is not legal advice. Which laws apply to your traffic, and which family a given obligation actually belongs to, depends on where you and your recipients are and what you send. Confirm with qualified counsel.

The tenant-owned framing

Same model as the rest of the Compliance group (posture overview), stated once so the mapping below reads correctly:
  • Every gate here is yours. Orbit supplies the control surface and enforces what you set; it does not pick a posture for you. Except for the one platform-mandated rail (the US TCPA federal voice dialing window, called out in the family-1 section), each control defaults open or empty and fails open on unresolvable input.
  • The ledger reflects what you did. Consent rows, suppression entries, DSAR clocks, registration filings — the platform keeps the record; the decision stays yours.

Family 1 — Outbound-marketing gates: TCPA, quiet hours, deception controls

What it does: gates calls and sends before they leave. This family decides whether an outbound message or call fires at all. The law families it serves — the US TCPA and its mini-TCPA state overlays, CAN-SPAM, CASL, the UK PECR/ePrivacy regime, Australia’s Spam Act, CTIA messaging principles — all share one shape: a recipient must not be contacted at the wrong time, on a list-hygiene miss, or through deceptive content. Controls in this family:
  • Quiet hours (tenant gate) — per-channel sending windows you enable under Settings → Quiet hours; fail-open by design until you opt in. Quiet hours configuration and Send Gates.
  • The TCPA federal voice window (platform rail) — campaign and dialer voice to US recipients is hard-blocked outside 8 AM–9 PM recipient-local, with no tenant toggle; the one platform-owned gate in the entire family model. The TCPA federal voice guard — the split of federal vs state vs tenant gates is mapped on Federal vs state vs tenant voice gates.
  • State mini-TCPA overlays — stricter state windows and day bans intersect on a most-restrictive-wins rule, again with no tenant knob. US state calling windows.
  • DNC and RND scrubbing — opt-in list-hygiene checks that fail open until you enable them. DNC Scrubbing, RND safe-harbor scrub.
  • Deceptive-marketing screens — the policy scanner that inspects outbound content for deceptive-marketing patterns before dispatch. Policy Scanner.
If the question is “can this send leave at all, and at what time?” — the answer lives in this family. A voice-only tenant needs it; a data privacy tenant usually does not.

Family 2 — Data-subject rights: GDPR, CCPA/CPRA, and DSAR intake

What it does: responds to rights requests — it does not gate sends. This family covers the rights a person holds over their own data under GDPR (EU), CCPA/CPRA (California), LGPD (Brazil), PDPA, and the equivalent regimes: access, erasure, portability, restriction, and objection. The controls here are response surfaces — intake, verification, fulfilment, and the evidence trail — not send-time gates. Controls in this family:
  • DSAR intake and SLA clock — operator-filed or through a public self-service portal, with a per-jurisdiction deadline (GDPR 30 days, CCPA/CPRA 45). DSAR, and the portal walkthrough Self-service DSAR portal.
  • The records-of-processing register and DPIAs — Art.30 activities and Art.35 screenings for GDPR-scope processing. Privacy Register.
  • The processor contract and designations — the self-serve DPA, plus DPO and EU/UK representative records when jurisdictions ask for them. Data Processing Agreement, DPO & EU/UK Representative Designation.
  • Retention and erasure policy — per-domain storage-limitation windows and hard-delete schedules. Data Retention Policy.
  • The evidence binder — one signed export of DSAR history, breach counts, and consent/retention posture for a buyer or authority. Evidence Binder.
The GDPR end-to-end guide is the worked assembly of this family for EU traffic. If the question is “someone asked what we hold on them, or asked us to delete it” — the answer lives here. A GDPR-only tenant wires this family without ever touching quiet hours.

Family 3 — Sender-identity registries: 10DLC, STIR/SHAKEN, KYC

What it does: proves who the sender is — fail-closed against unknown identity. This family answers the registries’ question: is the entity originating this traffic a verified identity? Unlike families 1 and 2, most gates here are fail-closed — a send to a regulated destination without an approved registration stops at the gate until the identity is proven. Controls in this family:
  • 10DLC brand and campaign registration (US SMS) — US long-code A2P traffic is blocked until carriers approve the brand and use case. 10DLC registration.
  • STIR/SHAKEN attestation (voice) — the attestation level the platform signals per call, and the delegate-certificate registry that lifts verified external numbers from C to B. Attestation posture and STIR/SHAKEN.
  • Sender-ID registration (alphabetic senders) — an approved entry per country before A2P SMS to pre-registration destinations delivers. Sender-ID Registration.
  • KYC documents and compliance profiles — the documents and profiles that unlock numbers and senders in regulated markets; gated assets idle at pending_compliance until a profile is satisfied. KYC Documents, Compliance Profile Assembly.
  • RMD filing (US voice) — the Robocall Mitigation Database record you file and recertify before originating US voice. RMD Registration.
If the question is “the send stopped because the sender is unproven” — the answer lives here. A tenant who never files a rights request still needs this family before its first send.

Decision table — which control belongs to which law family

Route a “customer data” or “compliance” question by picking the family first, then the page. The rule of thumb behind the table: family 1 pre-fires (can this send leave), family 2 responds (a person exercised a right), family 3 proves (the sender is who it claims). None of them substitutes for another — registration does not satisfy a rights request, and a quiet-hours gate does not attest a sender.

How the three existing concept pages split the map

Use this family split together with the three sibling concept pages — each answers its own question, this one only chooses the family:
  • Posture mapwhich toggles exist, what defaults open, and which of them you cannot flip. Read it to decide what to change; use this page to decide which family the change belongs to.
  • Compliance FAQthe first-question router. Each answer ends in the deep page; the family split above tells you which section of the FAQ to skim.
  • GDPR end-to-end guidethe full walkthrough for family 2 in EU scope. If your question is EU data rights, go straight there and skip family 1 and 3 entirely.