> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# One Educated Customer, Ten Laws: Which Regulatory Family Owns Which Customer-Data Gate

> The division of labor across Orbit's three independent regulatory views — outbound-marketing gates (TCPA/quiet hours), data-subject rights requests (GDPR/CCPA/DSAR), and sender-identity registries (10DLC, STIR/SHAKEN, KYC) — with a decision table that maps each control to the law family and the page that owns it.

# One Educated Customer, Ten Laws: Which Regulatory Family Owns Which Customer-Data Gate

The Compliance group holds three concept pages that each answer one
question well: the [posture map](/compliance/posture-overview) says
which controls are yours to toggle, the
[Compliance FAQ](/compliance/faq) routes a first question to the page
that owns it, and the
[GDPR end-to-end guide](/compliance/gdpr-posture-guide) walks one
regulation start to finish. This page answers the question those
three ask back: *when a complaint about "customer data" or a
"regulation" arrives, which of the three independent regulatory
families actually owns the gate — and which page documents it?*

The three families are deliberately independent in Orbit's model. A
tenant who runs outbound voice but no marketing ops sees quiet-hours
gates without ever touching DSAR; a tenant who answers GDPR requests
but never originates a call sees the rights-request pages without a
dialing window. The separation below is the intended division of
labor, not an accidental overlap.

<Warning>
  This page describes Orbit's platform controls. It is **not legal
  advice.** Which laws apply to your traffic, and which family a given
  obligation actually belongs to, depends on where you and your
  recipients are and what you send. Confirm with qualified counsel.
</Warning>

***

## The tenant-owned framing

Same model as the rest of the Compliance group
([posture overview](/compliance/posture-overview)), stated once so
the mapping below reads correctly:

* **Every gate here is yours.** Orbit supplies the control surface and
  enforces what you set; it does not pick a posture for you. Except
  for the one platform-mandated rail (the US TCPA federal voice
  dialing window, called out in the family-1 section), each control
  defaults open or empty and fails open on unresolvable input.
* **The ledger reflects what you did.** Consent rows, suppression
  entries, DSAR clocks, registration filings — the platform keeps the
  record; the decision stays yours.

***

## Family 1 — Outbound-marketing gates: TCPA, quiet hours, deception controls

**What it does: gates calls and sends before they leave.**

This family decides whether an outbound message or call fires at all.
The law families it serves — the US TCPA and its mini-TCPA state
overlays, CAN-SPAM, CASL, the UK PECR/ePrivacy regime, Australia's
Spam Act, CTIA messaging principles — all share one shape: a recipient
must not be contacted at the wrong time, on a list-hygiene miss, or
through deceptive content.

Controls in this family:

* **Quiet hours (tenant gate)** — per-channel sending windows you
  enable under Settings → Quiet hours; fail-open by design until you
  opt in. [Quiet hours configuration](/guides/quiet-hours-configuration)
  and [Send Gates](/compliance/send-gates).
* **The TCPA federal voice window (platform rail)** — campaign and
  dialer voice to US recipients is hard-blocked outside 8 AM–9 PM
  recipient-local, with no tenant toggle; the one platform-owned gate
  in the entire family model. [The TCPA federal voice guard](/concepts/tcpa-federal-voice-guard)
  — the split of federal vs state vs tenant gates is mapped on
  [Federal vs state vs tenant voice gates](/concepts/federal-vs-state-vs-tenant-voice-gates).
* **State mini-TCPA overlays** — stricter state windows and day bans
  intersect on a most-restrictive-wins rule, again with no tenant
  knob. [US state calling windows](/compliance/state-calling-windows).
* **DNC and RND scrubbing** — opt-in list-hygiene checks that fail
  open until you enable them. [DNC Scrubbing](/compliance/dnc-scrub),
  [RND safe-harbor scrub](/compliance/rnd-scrub).
* **Deceptive-marketing screens** — the policy scanner that inspects
  outbound content for deceptive-marketing patterns before dispatch.
  [Policy Scanner](/compliance/policy-scanner).

If the question is "can this send leave at all, and at what time?" —
the answer lives in this family. A voice-only tenant needs it; a data
privacy tenant usually does not.

***

## Family 2 — Data-subject rights: GDPR, CCPA/CPRA, and DSAR intake

**What it does: responds to rights requests — it does not gate sends.**

This family covers the rights a person holds over their own data
under GDPR (EU), CCPA/CPRA (California), LGPD (Brazil), PDPA, and the
equivalent regimes: access, erasure, portability, restriction, and
objection. The controls here are *response* surfaces — intake,
verification, fulfilment, and the evidence trail — not send-time
gates.

Controls in this family:

* **DSAR intake and SLA clock** — operator-filed or through a public
  self-service portal, with a per-jurisdiction deadline (GDPR 30 days,
  CCPA/CPRA 45). [DSAR](/compliance/dsar), and the portal walkthrough
  [Self-service DSAR portal](/guides/self-service-dsar-portal).
* **The records-of-processing register and DPIAs** — Art.30 activities
  and Art.35 screenings for GDPR-scope processing.
  [Privacy Register](/compliance/privacy-register).
* **The processor contract and designations** — the self-serve DPA,
  plus DPO and EU/UK representative records when jurisdictions ask for
  them. [Data Processing Agreement](/compliance/data-processing-agreement),
  [DPO & EU/UK Representative Designation](/compliance/dpo-representative).
* **Retention and erasure policy** — per-domain storage-limitation
  windows and hard-delete schedules.
  [Data Retention Policy](/compliance/data-retention-policy).
* **The evidence binder** — one signed export of DSAR history, breach
  counts, and consent/retention posture for a buyer or authority.
  [Evidence Binder](/compliance/evidence-binder).

The [GDPR end-to-end guide](/compliance/gdpr-posture-guide) is the
worked assembly of this family for EU traffic. If the question is
"someone asked what we hold on them, or asked us to delete it" — the
answer lives here. A GDPR-only tenant wires this family without ever
touching quiet hours.

***

## Family 3 — Sender-identity registries: 10DLC, STIR/SHAKEN, KYC

**What it does: proves who the sender is — fail-closed against
unknown identity.**

This family answers the registries' question: *is the entity
originating this traffic a verified identity?* Unlike families 1 and
2, most gates here are **fail-closed** — a send to a regulated
destination without an approved registration stops at the gate until
the identity is proven.

Controls in this family:

* **10DLC brand and campaign registration (US SMS)** — US long-code
  A2P traffic is blocked until carriers approve the brand and use
  case. [10DLC registration](/guides/10dlc-registration).
* **STIR/SHAKEN attestation (voice)** — the attestation level the
  platform signals per call, and the delegate-certificate registry
  that lifts verified external numbers from C to B.
  [Attestation posture](/compliance/attestation) and
  [STIR/SHAKEN](/channels/voice/stir-shaken).
* **Sender-ID registration (alphabetic senders)** — an approved entry
  per country before A2P SMS to pre-registration destinations
  delivers. [Sender-ID Registration](/compliance/sender-id-registration).
* **KYC documents and compliance profiles** — the documents and
  profiles that unlock numbers and senders in regulated markets;
  gated assets idle at `pending_compliance` until a profile is
  satisfied. [KYC Documents](/compliance/documents-kyc),
  [Compliance Profile Assembly](/compliance/compliance-profile-assembly).
* **RMD filing (US voice)** — the Robocall Mitigation Database record
  you file and recertify before originating US voice.
  [RMD Registration](/compliance/rmd-registration).

If the question is "the send stopped because the sender is unproven"
— the answer lives here. A tenant who never files a rights request
still needs this family before its first send.

***

## Decision table — which control belongs to which law family

Route a "customer data" or "compliance" question by picking the
family first, then the page.

| The situation                                              | Family                  | The control                   | Owning page                                                                         |
| ---------------------------------------------------------- | ----------------------- | ----------------------------- | ----------------------------------------------------------------------------------- |
| A send rejected outside a sending window                   | 1 — outbound marketing  | Tenant quiet hours            | [Quiet hours configuration](/guides/quiet-hours-configuration)                      |
| A dialer/campaign voice call blocked by the federal window | 1 — outbound marketing  | TCPA federal rail (no toggle) | [The TCPA federal voice guard](/concepts/tcpa-federal-voice-guard)                  |
| A state window or day ban blocked the call                 | 1 — outbound marketing  | State mini-TCPA overlay       | [US state calling windows](/compliance/state-calling-windows)                       |
| A recipient on a do-not-call or reassigned list            | 1 — outbound marketing  | DNC / RND scrub               | [DNC Scrubbing](/compliance/dnc-scrub), [RND](/compliance/rnd-scrub)                |
| Outbound content flagged as deceptive                      | 1 — outbound marketing  | Policy scanner                | [Policy Scanner](/compliance/policy-scanner)                                        |
| A customer asks what data you hold, or asks to delete it   | 2 — data-subject rights | DSAR intake + SLA             | [DSAR](/compliance/dsar)                                                            |
| Documenting processing activities or a DPIA                | 2 — data-subject rights | Privacy register              | [Privacy Register](/compliance/privacy-register)                                    |
| A processor contract or a DPO designation                  | 2 — data-subject rights | DPA / DPO-representative      | [DPA](/compliance/data-processing-agreement), [DPO](/compliance/dpo-representative) |
| Retention windows and erasure schedules                    | 2 — data-subject rights | Data retention policy         | [Data Retention Policy](/compliance/data-retention-policy)                          |
| Evidence for a buyer or authority                          | 2 — data-subject rights | Evidence binder               | [Evidence Binder](/compliance/evidence-binder)                                      |
| US SMS blocked pending registration                        | 3 — sender identity     | 10DLC brand/campaign          | [10DLC registration](/guides/10dlc-registration)                                    |
| Calls treated as spam-likely / attestation stuck at C      | 3 — sender identity     | STIR/SHAKEN attestation       | [Attestation posture](/compliance/attestation)                                      |
| An alphabetic sender rejected at the gate                  | 3 — sender identity     | Sender-ID registration        | [Sender-ID Registration](/compliance/sender-id-registration)                        |
| A number idles at `pending_compliance`                     | 3 — sender identity     | KYC documents + profiles      | [KYC Documents](/compliance/documents-kyc)                                          |
| US voice before origination is cleared                     | 3 — sender identity     | RMD filing                    | [RMD Registration](/compliance/rmd-registration)                                    |

The rule of thumb behind the table: family 1 **pre-fires** (can this
send leave), family 2 **responds** (a person exercised a right),
family 3 **proves** (the sender is who it claims). None of them
substitutes for another — registration does not satisfy a rights
request, and a quiet-hours gate does not attest a sender.

***

## How the three existing concept pages split the map

Use this family split together with the three sibling concept pages —
each answers its own question, this one only chooses the family:

* [Posture map](/compliance/posture-overview) — *which toggles exist,
  what defaults open, and which of them you cannot flip.* Read it to
  decide what to change; use this page to decide which family the
  change belongs to.
* [Compliance FAQ](/compliance/faq) — *the first-question router.*
  Each answer ends in the deep page; the family split above tells you
  which section of the FAQ to skim.
* [GDPR end-to-end guide](/compliance/gdpr-posture-guide) — *the
  full walkthrough for family 2 in EU scope.* If your question is EU
  data rights, go straight there and skip family 1 and 3 entirely.

***

## Related references

* [Your Tenant Compliance Posture: The Toggle Map](/compliance/posture-overview)
* [Compliance FAQ: first-question routing](/compliance/faq)
* [Assembling a GDPR Posture End to End](/compliance/gdpr-posture-guide)
* [Send Gates](/compliance/send-gates) — the full gate stack behind
  family 1.
* [DSAR](/compliance/dsar) — the rights-request pipeline behind
  family 2.
* [Attestation posture](/compliance/attestation) — the identity
  registry behind family 3 for voice.
* [API Reference → Compliance](/api-reference/endpoints/compliance) —
  request/response schemas for every endpoint named here.
