One Educated Customer, Ten Laws: Which Regulatory Family Owns Which Customer-Data Gate
The Compliance group holds three concept pages that each answer one question well: the posture map says which controls are yours to toggle, the Compliance FAQ routes a first question to the page that owns it, and the GDPR end-to-end guide walks one regulation start to finish. This page answers the question those three ask back: when a complaint about “customer data” or a “regulation” arrives, which of the three independent regulatory families actually owns the gate — and which page documents it? The three families are deliberately independent in Orbit’s model. A tenant who runs outbound voice but no marketing ops sees quiet-hours gates without ever touching DSAR; a tenant who answers GDPR requests but never originates a call sees the rights-request pages without a dialing window. The separation below is the intended division of labor, not an accidental overlap.The tenant-owned framing
Same model as the rest of the Compliance group (posture overview), stated once so the mapping below reads correctly:- Every gate here is yours. Orbit supplies the control surface and enforces what you set; it does not pick a posture for you. Except for the one platform-mandated rail (the US TCPA federal voice dialing window, called out in the family-1 section), each control defaults open or empty and fails open on unresolvable input.
- The ledger reflects what you did. Consent rows, suppression entries, DSAR clocks, registration filings — the platform keeps the record; the decision stays yours.
Family 1 — Outbound-marketing gates: TCPA, quiet hours, deception controls
What it does: gates calls and sends before they leave. This family decides whether an outbound message or call fires at all. The law families it serves — the US TCPA and its mini-TCPA state overlays, CAN-SPAM, CASL, the UK PECR/ePrivacy regime, Australia’s Spam Act, CTIA messaging principles — all share one shape: a recipient must not be contacted at the wrong time, on a list-hygiene miss, or through deceptive content. Controls in this family:- Quiet hours (tenant gate) — per-channel sending windows you enable under Settings → Quiet hours; fail-open by design until you opt in. Quiet hours configuration and Send Gates.
- The TCPA federal voice window (platform rail) — campaign and dialer voice to US recipients is hard-blocked outside 8 AM–9 PM recipient-local, with no tenant toggle; the one platform-owned gate in the entire family model. The TCPA federal voice guard — the split of federal vs state vs tenant gates is mapped on Federal vs state vs tenant voice gates.
- State mini-TCPA overlays — stricter state windows and day bans intersect on a most-restrictive-wins rule, again with no tenant knob. US state calling windows.
- DNC and RND scrubbing — opt-in list-hygiene checks that fail open until you enable them. DNC Scrubbing, RND safe-harbor scrub.
- Deceptive-marketing screens — the policy scanner that inspects outbound content for deceptive-marketing patterns before dispatch. Policy Scanner.
Family 2 — Data-subject rights: GDPR, CCPA/CPRA, and DSAR intake
What it does: responds to rights requests — it does not gate sends. This family covers the rights a person holds over their own data under GDPR (EU), CCPA/CPRA (California), LGPD (Brazil), PDPA, and the equivalent regimes: access, erasure, portability, restriction, and objection. The controls here are response surfaces — intake, verification, fulfilment, and the evidence trail — not send-time gates. Controls in this family:- DSAR intake and SLA clock — operator-filed or through a public self-service portal, with a per-jurisdiction deadline (GDPR 30 days, CCPA/CPRA 45). DSAR, and the portal walkthrough Self-service DSAR portal.
- The records-of-processing register and DPIAs — Art.30 activities and Art.35 screenings for GDPR-scope processing. Privacy Register.
- The processor contract and designations — the self-serve DPA, plus DPO and EU/UK representative records when jurisdictions ask for them. Data Processing Agreement, DPO & EU/UK Representative Designation.
- Retention and erasure policy — per-domain storage-limitation windows and hard-delete schedules. Data Retention Policy.
- The evidence binder — one signed export of DSAR history, breach counts, and consent/retention posture for a buyer or authority. Evidence Binder.
Family 3 — Sender-identity registries: 10DLC, STIR/SHAKEN, KYC
What it does: proves who the sender is — fail-closed against unknown identity. This family answers the registries’ question: is the entity originating this traffic a verified identity? Unlike families 1 and 2, most gates here are fail-closed — a send to a regulated destination without an approved registration stops at the gate until the identity is proven. Controls in this family:- 10DLC brand and campaign registration (US SMS) — US long-code A2P traffic is blocked until carriers approve the brand and use case. 10DLC registration.
- STIR/SHAKEN attestation (voice) — the attestation level the platform signals per call, and the delegate-certificate registry that lifts verified external numbers from C to B. Attestation posture and STIR/SHAKEN.
- Sender-ID registration (alphabetic senders) — an approved entry per country before A2P SMS to pre-registration destinations delivers. Sender-ID Registration.
- KYC documents and compliance profiles — the documents and
profiles that unlock numbers and senders in regulated markets;
gated assets idle at
pending_complianceuntil a profile is satisfied. KYC Documents, Compliance Profile Assembly. - RMD filing (US voice) — the Robocall Mitigation Database record you file and recertify before originating US voice. RMD Registration.
Decision table — which control belongs to which law family
Route a “customer data” or “compliance” question by picking the family first, then the page.
The rule of thumb behind the table: family 1 pre-fires (can this
send leave), family 2 responds (a person exercised a right),
family 3 proves (the sender is who it claims). None of them
substitutes for another — registration does not satisfy a rights
request, and a quiet-hours gate does not attest a sender.
How the three existing concept pages split the map
Use this family split together with the three sibling concept pages — each answers its own question, this one only chooses the family:- Posture map — which toggles exist, what defaults open, and which of them you cannot flip. Read it to decide what to change; use this page to decide which family the change belongs to.
- Compliance FAQ — the first-question router. Each answer ends in the deep page; the family split above tells you which section of the FAQ to skim.
- GDPR end-to-end guide — the full walkthrough for family 2 in EU scope. If your question is EU data rights, go straight there and skip family 1 and 3 entirely.
Related references
- Your Tenant Compliance Posture: The Toggle Map
- Compliance FAQ: first-question routing
- Assembling a GDPR Posture End to End
- Send Gates — the full gate stack behind family 1.
- DSAR — the rights-request pipeline behind family 2.
- Attestation posture — the identity registry behind family 3 for voice.
- API Reference → Compliance — request/response schemas for every endpoint named here.