Skip to main content
← Back to glossary
Compliance & consent

GDPR — General Data Protection Regulation

What is GDPR?

The GDPR (General Data Protection Regulation — Regulation (EU) 2016/679) is the EU's data-privacy law: it requires a lawful basis (often explicit consent) before processing personal data, grants individuals rights to access, correct, export, or erase their data, and imposes breach-notification and cross-border transfer rules. For a CPaaS platform, GDPR governs every flow that touches personal data — contact records, message and call content, recordings and transcripts, delivery metadata — and splits responsibility between the tenant (the controller) and the platform (the processor acting on the tenant's documented instructions).

More detail

GDPR's in-scope data flows on a CPaaS platform are wider than most teams assume: contact fields (names, numbers, email) and free-form message bodies are personal data, but so are call recordings and transcripts, delivery receipts and timestamps, routing metadata, and device or IP identifiers captured at signup. Erasure and access requests have to reach all of those surfaces, not just the contact table.

GDPR splits responsibility along a controller/processor line that maps directly onto a CPaaS relationship: the tenant is the controller — it decides why contacts are messaged or called, what content is sent, and how long data is retained — while the platform acts as the processor, storing and transmitting that data strictly on the tenant's documented instructions under a Data Processing Agreement. The data-protection controls are therefore tenant-owned: retention windows, consent capture, DSAR fulfilment, and the privacy register each sit in the tenant's configuration rather than being imposed by the platform.

Individual rights under GDPR — access, rectification, erasure (the 'right to be forgotten'), and portability — carry a statutory clock (one calendar month, extendable once for complex requests), so fulfilment needs an intake path, identity verification, and an auditable export or deletion. Orbit's DSAR pipeline queues those requests against the regime's deadline under the tenant's authority, with the evidence trail the regulation demands.

Orbit ships four tenant-side GDPR surfaces: the GDPR Posture Guide (how the regulation maps onto sensitive-data handling on the platform), the DSAR pipeline (intake + SLA fulfilment), the Privacy Register (the Article 30-style record of processing a tenant maintains for audits), and the Data Processing Agreement (the Article 28 contract executed between the tenant and Devotel that authorises the processor relationship and, where used, its sub-processors).

Frequently asked

Does GDPR only apply to companies based in the EU?
No — it applies to any organization processing the personal data of people located in the EU or EEA, regardless of where that organization is headquartered. A CPaaS tenant in the US messaging European contacts is in scope for those contacts' data even with no EU office.
What does 'controller versus processor' mean on a CPaaS platform?
The controller decides why and how personal data is processed — on Orbit that is you, the tenant: you choose who to message, what to send, and how long to keep it. The processor acts only on the controller's documented instructions — Orbit stores and transmits that data under a Data Processing Agreement rather than determining its own purposes for it.
What does the 'right to be forgotten' require of a messaging platform?
A documented, timely process to locate and delete a person's personal data across every surface that holds it — contact records, message history, recordings and transcripts, and metadata — once a valid erasure request arrives. Orbit's DSAR pipeline enforces that fulfilment SLA and keeps the evidence trail the regulation requires.
Do I need a DPA with my CPaaS provider?
Yes — GDPR Article 28 requires a contract between controller and processor whenever a processor handles personal data on your behalf. Orbit executes a Data Processing Agreement from the Trust Center that covers exactly this processor relationship, including the sub-processor disclosures it relies on.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.