GDPR — General Data Protection Regulation
What is GDPR?
The GDPR (General Data Protection Regulation) is the European Union's comprehensive data-privacy law, requiring a clear legal basis (often explicit consent) before collecting or processing a person's personal data, giving individuals rights to access, correct, or delete their data, and imposing strict breach-notification and cross-border data-transfer rules. For a CPaaS platform, GDPR shapes how contact data, call recordings, and message content are stored, for how long, and who can be shown or export it.
More detail
GDPR applies to any organization processing the personal data of EU residents, regardless of where the organization itself is based, which is why it affects global platforms handling European customer contacts.
Individual rights under GDPR — access, rectification, erasure ('right to be forgotten'), and data portability — mean a platform storing contact records and call or message history needs a process to fulfill those requests within a statutory time limit.
Frequently asked
- Does GDPR only apply to companies based in the EU?
- No — it applies to any organization processing the personal data of people located in the EU, regardless of where that organization itself is headquartered, which is why global platforms with European customers must comply.
- What does the 'right to be forgotten' require of a messaging platform?
- It requires a documented process to delete an individual's personal data — including contact records, message history, and recordings tied to them — within the statutory time limit once a valid erasure request is received.
See also
Build it on Orbit
Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.