Compliance

GDPR and CCPA Compliance for Lead Routing

Lead Router provides the controller-processor split, a public DSR workflow with a 30-day SLA, consent timestamps stored per lead, and Standard Contractual Clauses for EU and UK transfers. A Data Processing Agreement is available on request.

/dsr Form

Data subject requests

30 Days

Response SLA

SCCs

EU and UK transfers

This page is informational, not legal advice. Privacy compliance obligations depend on your business, jurisdiction, and the data you process. Consult qualified privacy counsel for advice on your specific situation.

EU and UK

What GDPR requires

The General Data Protection Regulation applies to any organization that processes personal data of people in the EU, EEA, or UK, no matter where that organization is located.

Lawful basis for processing. Every processing activity needs a legal basis: consent, performance of a contract, legal obligation, vital interests, public task, or legitimate interest. For lead generation, you will mostly use two. The first is consent, from opt-in forms. The second is legitimate interest, in narrow B2B cases with a documented balancing test. You choose and document the basis. Lead Router processes data on your instructions.

Controller versus processor. Under GDPR Article 4, the controller decides why and how personal data is processed. The processor acts on the controller's instructions. When you use Lead Router to route leads, you are the controller of the personal data in your leads, and Lead Router is the processor. Article 28 requires a written agreement between the controller and the processor. It must cover security, sub-processors, breach notification, and return of data at termination. Our Data Processing Agreement covers those duties.

Data subject rights. Articles 15 through 22 give EU and UK residents the right to access their data, correct errors, erase it (the right to be forgotten, Article 17), restrict processing, object, get a copy in a machine-readable format, and withdraw consent. You must respond to a request within one month. That can be extended to three months for complex cases. Our data subject request (DSR) workflow handles intake, identity checks, and completing the request.

International transfers. Chapter V restricts transfers of personal data outside the EEA unless an adequacy decision, Standard Contractual Clauses, or another approved mechanism is in place. Lead Router relies on the 2021 EU SCCs and the UK International Data Transfer Addendum for transfers to the United States.

Breach notification. Article 33 requires controllers to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. As processor, we notify the controller without undue delay so you can meet that clock.

California

What CCPA and CPRA require

The California Consumer Privacy Act (CCPA), amended by the California Privacy Rights Act (CPRA), applies to most businesses processing the personal information of California residents.

  • Right to know. Section 1798.110 grants consumers the right to know what personal information is collected, the sources, the business purpose, and the categories of third parties it is disclosed or sold to.
  • Right to delete. Section 1798.105 grants the right to request deletion of personal information, subject to statutory exceptions (fraud prevention, legal compliance, internal uses aligned with consumer expectations).
  • Right to correct. Added by CPRA, Section 1798.106 grants the right to correct inaccurate personal information a business maintains.
  • Right to opt out of sale or sharing. CCPA Section 1798.135 sets the rules for opt-out links, including Do Not Sell or Share My Personal Information. It also allows certain alternatives, such as a qualifying opt-out preference signal. Check which method applies to your business.
  • Right to limit sensitive personal information. Added by CPRA, Section 1798.121 lets consumers limit the use of sensitive categories (precise geolocation, race, religion, health, biometric) to what is necessary to provide the requested service.
  • Private right of action on breaches. Section 1798.150 gives consumers a private right of action with statutory damages when nonencrypted personal information is exposed in a breach caused by inadequate security.

The response deadline is 45 days. It can be extended another 45 days for complex requests, with written notice to the consumer. Lead Router uses a stricter 30-day target by default.

Beyond California

State privacy laws

More than twenty US states have passed comprehensive privacy laws. Most grant the same core rights as CCPA and follow the same controller-processor model.

Privacy laws now apply in many US states. The rights, deadlines, and business thresholds differ. Check the rules for the states you serve and keep your request process up to date.

These laws share a common core: residents can access, correct, and delete their data, and opt out of sale or targeted advertising. Most also require a way to honor opt-out requests (many recognize the Global Privacy Control signal). Controllers must publish a privacy notice and sign a data processing agreement with service providers.

The Lead Router DSR workflow, consent tracking, and retention controls cover these rights the same way they cover CCPA. The main differences from state to state are who the law covers, the response deadline (usually 30 to 45 days), and whether people can sue directly (a private right of action). Your privacy counsel should confirm which laws apply to your business.

How Lead Router Does It

Lead Router's privacy architecture

Six capabilities that make the platform usable for operators subject to GDPR, CCPA, or any state privacy law.

DSR workflow with 30-day SLA

A public data subject request form lives at /dsr. Anyone who lives in a covered state or region can submit an access, correction, deletion, portability, or opt-out request. We confirm identity by email, send the request to the privacy team, and respond within 30 days. CCPA allows up to 45 days with a documented extension for complex requests. GDPR Article 12 allows a similar extension for complex cases.

Consent tracking per lead

Every lead that comes through a partner form can carry a consent record when the intake supplies it: the exact consent text the subject agreed to, the IP address, user agent, timestamp, and URL where consent was captured. That record stays attached to the lead through every buyer distribution, so when a buyer downstream gets a TCPA or GDPR inquiry, the consent trail is auditable.

Data minimization by contract

Buyer contracts declare the exact fields required for that buyer. Partner posting specs only surface the fields mapped to the offer. We do not silently collect extra fields for future use. If a field is not on the contract, it is not forwarded. This keeps the processing scope aligned with GDPR Article 5 data minimization.

Per-tenant retention controls

Operators configure retention windows per tenant. When the window elapses, lead-subject personal data is purged or pseudonymized according to your policy. The platform does not force a fixed retention; you set the schedule that matches your legal basis and your downstream buyer contracts.

Standard Contractual Clauses

Lead Router is operated from the United States. For personal data originating in the European Economic Area, the United Kingdom, or Switzerland, we rely on the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum as the transfer mechanism. Data processing terms incorporating the SCCs are available to customers on request.

Data Processing Agreement

A Data Processing Agreement (DPA) that reflects GDPR Article 28 processor obligations is available on request. The DPA covers the subject matter and duration of processing, its nature and purpose, the categories of data, notice of sub-processors, security measures, breach notification timing, help with DSRs, audit rights, and return or deletion of data at termination. Matching CPRA language for the controller-to-service-provider relationship is included for California.

DSR Workflow

How a data subject request moves through the system

The same workflow handles GDPR access and erasure requests, CCPA know and delete requests, and the equivalent rights under state privacy laws.

  1. 1Request submitted. The data subject fills out the form at theleadrouter.com/dsr. The form collects the request type (access, correction, deletion, portability, opt-out of sale or sharing, consent withdrawal), identifying information, and the jurisdiction the subject is claiming rights under.
  2. 2Identity verification. We send a verification email to the address on the request. For higher-risk requests, such as deletion or access to sensitive data, we may ask for more confirmation. Identity checks follow the rules for that request, including CCPA Section 1798.130.
  3. 3Routed to the privacy team. Verified requests are assigned to our privacy team, logged, and tracked against the response SLA. If the request concerns data where a customer is the controller and Lead Router is the processor, we coordinate with that customer so the response is consistent across the chain.
  4. 4Response within 30 days. Our privacy team reviews access and deletion requests and aims to respond within 30 days. Deletion follows the retention rules and legal exceptions that apply. Data already sent to a buyer needs separate review by that buyer; a request here does not promise deletion from every outside system.
  5. 5Confirmation and audit trail. The subject receives written confirmation of the action taken. An audit log entry captures who handled the request, when, what action was taken, and what data was returned or purged. That log is retained to demonstrate compliance if a regulator asks.

A request needs a review

A visual guide to the request process described below.

  1. 01

    Request

    Request type

    Contact details

    The person submits a request through the public form.

  2. 02

    Verify and review

    Identity

    Scope of the request

    The privacy team reviews what applies to the request.

  3. 03

    Respond

    Action taken

    Written confirmation

    The response explains the outcome and any limits.

Scope

What this covers and what it does not

Being clear about where Lead Router's obligations end is part of the controller-processor split.

Covered

  • Personal data about your customer account users (admins, operators, agents using the Lead Router platform).
  • Lead-subject data you process through the Lead Router routing engine, while it is in our systems.
  • Consent records and audit logs captured on lead submission and delivery.

Not covered

  • XLead-subject data you store in your own CRM, spreadsheets, or systems outside Lead Router.
  • XData handled by your downstream buyers after delivery. Buyers are separate controllers for the data they receive and they carry their own obligations.
  • XYour partners' consent collection practices. You set the contract requirements; partners execute. Lead Router records what they send.

Frequently Asked

FAQ

The questions privacy officers and compliance leads ask during vendor review.

Is Lead Router GDPR compliant?

Lead Router is built to support GDPR obligations. GDPR compliance itself is the controller’s responsibility. As a processor under Article 28, we provide the controller-processor split, a Data Processing Agreement on request, Standard Contractual Clauses for international data transfers, a data subject request form at /dsr with a 30-day response commitment (SLA), consent timestamps and IP addresses stored on each lead, data minimization tied to the fields mapped in each buyer contract, and deletion controls for your tenant. A customer using Lead Router still needs to establish a lawful basis, publish a privacy notice, and respond to its own data subject requests.

How do I submit a data subject request?

Submit the request at theleadrouter.com/dsr. The form asks for the request type (access, correction, deletion, portability, opt-out, or consent withdrawal), the person’s contact details, and enough detail to find the record. We confirm identity by email, send the request to the privacy team, and respond within 30 days. CCPA allows up to 45 days with a documented extension for complex requests.

Do you sell personal information?

No. Lead Router does not sell personal information as defined by CCPA, CPRA, or any other state privacy statute. We also do not share personal information for cross-context behavioral advertising. The platform distributes leads on the customer’s instructions, with the customer acting as controller. The customer’s own disclosures and opt-out tools decide whether that distribution counts as a sale under the customer’s own privacy notice.

Do you use personal data for AI training?

Our Privacy Policy permits the use of de-identified, aggregated account, usage and lead data to improve the service, including model training. It excludes BAA/HIPAA-covered data, payment data, authentication secrets and sensitive personal information. We do not provide customer data to third parties to train their models. See Privacy Policy section 3 and Terms section 5 for the governing terms.

What about state privacy laws like Virginia VCDPA or Colorado CPA?

State privacy laws have different rights, deadlines, and business thresholds. Lead Router provides data-request, consent, and retention tools to support your process. Your team must check which laws apply and set up the required steps.

Built for Regulated Operators

Route leads with privacy controls built in

DSR workflow, consent tracking, SCCs, and a DPA on request. One set of controls covers every lead your team handles.

This page is informational, not legal advice. Consult qualified privacy counsel.