For the complete documentation index, see llms.txt. This page is also available as Markdown.

GDPR, CCPA and DSAR

How iCustomer Platform supports GDPR and CCPA compliance, and how data subject requests are handled.

The platform is built to operate inside privacy regulation, not around it.

What that means in practice

  • Opt-outs are honored. Consent and suppression flags travel with records and are enforced before any activation reaches a destination.

  • PII is protected at ingestion. Hash, mask, encrypt, or exclude sensitive fields per your policy. See the Security model.

  • Deletion and access requests are supported. When a data subject exercises their rights, the corresponding records can be exported or removed across the platform.

Data subject requests (DSARs)

Route data subject requests through your own privacy process as the controller. As a processor, iCustomer supports fulfillment: locating the subject's records, exporting them, and deleting them on instruction. Contact your iCustomer administrator or reach us through the Privacy Policy channels to initiate a request.

Documentation

Our sub-processor list, Data Processing Agreement, and data-handling policies are available on request from your iCustomer contact. Deletion requests propagate at the OneSource ID level, which is what keeps provenance clean across every source that contributed to a record.

Last updated