Lead Router provides the controller-processor split, a public DSR workflow with a 30-day SLA, consent timestamps stored per lead, and Standard Contractual Clauses for EU and UK transfers. A Data Processing Agreement is available on request.
/dsr Form
Data subject requests
30 Days
Response SLA
SCCs
EU and UK transfers
This page is informational, not legal advice. Privacy compliance obligations depend on your business, jurisdiction, and the data you process. Consult qualified privacy counsel for advice on your specific situation.
EU and UK
The General Data Protection Regulation applies to any organization that processes personal data of people in the EU, EEA, or UK, no matter where that organization is located.
Lawful basis for processing. Every processing activity needs a legal basis: consent, performance of a contract, legal obligation, vital interests, public task, or legitimate interest. For lead generation, you will mostly use two. The first is consent, from opt-in forms. The second is legitimate interest, in narrow B2B cases with a documented balancing test. You choose and document the basis. Lead Router processes data on your instructions.
Controller versus processor. Under GDPR Article 4, the controller decides why and how personal data is processed. The processor acts on the controller's instructions. When you use Lead Router to route leads, you are the controller of the personal data in your leads, and Lead Router is the processor. Article 28 requires a written agreement between the controller and the processor. It must cover security, sub-processors, breach notification, and return of data at termination. Our Data Processing Agreement covers those duties.
Data subject rights. Articles 15 through 22 give EU and UK residents the right to access their data, correct errors, erase it (the right to be forgotten, Article 17), restrict processing, object, get a copy in a machine-readable format, and withdraw consent. You must respond to a request within one month. That can be extended to three months for complex cases. Our data subject request (DSR) workflow handles intake, identity checks, and completing the request.
International transfers. Chapter V restricts transfers of personal data outside the EEA unless an adequacy decision, Standard Contractual Clauses, or another approved mechanism is in place. Lead Router relies on the 2021 EU SCCs and the UK International Data Transfer Addendum for transfers to the United States.
Breach notification. Article 33 requires controllers to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. As processor, we notify the controller without undue delay so you can meet that clock.
California
The California Consumer Privacy Act (CCPA), amended by the California Privacy Rights Act (CPRA), applies to most businesses processing the personal information of California residents.
The response deadline is 45 days. It can be extended another 45 days for complex requests, with written notice to the consumer. Lead Router uses a stricter 30-day target by default.
Beyond California
More than twenty US states have passed comprehensive privacy laws. Most grant the same core rights as CCPA and follow the same controller-processor model.
Privacy laws now apply in many US states. The rights, deadlines, and business thresholds differ. Check the rules for the states you serve and keep your request process up to date.
These laws share a common core: residents can access, correct, and delete their data, and opt out of sale or targeted advertising. Most also require a way to honor opt-out requests (many recognize the Global Privacy Control signal). Controllers must publish a privacy notice and sign a data processing agreement with service providers.
The Lead Router DSR workflow, consent tracking, and retention controls cover these rights the same way they cover CCPA. The main differences from state to state are who the law covers, the response deadline (usually 30 to 45 days), and whether people can sue directly (a private right of action). Your privacy counsel should confirm which laws apply to your business.
How Lead Router Does It
Six capabilities that make the platform usable for operators subject to GDPR, CCPA, or any state privacy law.
A public data subject request form lives at /dsr. Anyone who lives in a covered state or region can submit an access, correction, deletion, portability, or opt-out request. We confirm identity by email, send the request to the privacy team, and respond within 30 days. CCPA allows up to 45 days with a documented extension for complex requests. GDPR Article 12 allows a similar extension for complex cases.
Every lead that comes through a partner form can carry a consent record when the intake supplies it: the exact consent text the subject agreed to, the IP address, user agent, timestamp, and URL where consent was captured. That record stays attached to the lead through every buyer distribution, so when a buyer downstream gets a TCPA or GDPR inquiry, the consent trail is auditable.
Buyer contracts declare the exact fields required for that buyer. Partner posting specs only surface the fields mapped to the offer. We do not silently collect extra fields for future use. If a field is not on the contract, it is not forwarded. This keeps the processing scope aligned with GDPR Article 5 data minimization.
Operators configure retention windows per tenant. When the window elapses, lead-subject personal data is purged or pseudonymized according to your policy. The platform does not force a fixed retention; you set the schedule that matches your legal basis and your downstream buyer contracts.
Lead Router is operated from the United States. For personal data originating in the European Economic Area, the United Kingdom, or Switzerland, we rely on the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum as the transfer mechanism. Data processing terms incorporating the SCCs are available to customers on request.
A Data Processing Agreement (DPA) that reflects GDPR Article 28 processor obligations is available on request. The DPA covers the subject matter and duration of processing, its nature and purpose, the categories of data, notice of sub-processors, security measures, breach notification timing, help with DSRs, audit rights, and return or deletion of data at termination. Matching CPRA language for the controller-to-service-provider relationship is included for California.
DSR Workflow
The same workflow handles GDPR access and erasure requests, CCPA know and delete requests, and the equivalent rights under state privacy laws.
A visual guide to the request process described below.
Request
Request type
Contact details
The person submits a request through the public form.
Verify and review
Identity
Scope of the request
The privacy team reviews what applies to the request.
Respond
Action taken
Written confirmation
The response explains the outcome and any limits.
Scope
Being clear about where Lead Router's obligations end is part of the controller-processor split.
Frequently Asked
The questions privacy officers and compliance leads ask during vendor review.
Lead Router is built to support GDPR obligations. GDPR compliance itself is the controller’s responsibility. As a processor under Article 28, we provide the controller-processor split, a Data Processing Agreement on request, Standard Contractual Clauses for international data transfers, a data subject request form at /dsr with a 30-day response commitment (SLA), consent timestamps and IP addresses stored on each lead, data minimization tied to the fields mapped in each buyer contract, and deletion controls for your tenant. A customer using Lead Router still needs to establish a lawful basis, publish a privacy notice, and respond to its own data subject requests.
Submit the request at theleadrouter.com/dsr. The form asks for the request type (access, correction, deletion, portability, opt-out, or consent withdrawal), the person’s contact details, and enough detail to find the record. We confirm identity by email, send the request to the privacy team, and respond within 30 days. CCPA allows up to 45 days with a documented extension for complex requests.
No. Lead Router does not sell personal information as defined by CCPA, CPRA, or any other state privacy statute. We also do not share personal information for cross-context behavioral advertising. The platform distributes leads on the customer’s instructions, with the customer acting as controller. The customer’s own disclosures and opt-out tools decide whether that distribution counts as a sale under the customer’s own privacy notice.
Our Privacy Policy permits the use of de-identified, aggregated account, usage and lead data to improve the service, including model training. It excludes BAA/HIPAA-covered data, payment data, authentication secrets and sensitive personal information. We do not provide customer data to third parties to train their models. See Privacy Policy section 3 and Terms section 5 for the governing terms.
State privacy laws have different rights, deadlines, and business thresholds. Lead Router provides data-request, consent, and retention tools to support your process. Your team must check which laws apply and set up the required steps.
Built for Regulated Operators
DSR workflow, consent tracking, SCCs, and a DPA on request. One set of controls covers every lead your team handles.
This page is informational, not legal advice. Consult qualified privacy counsel.