GDPR Compliance
If any of your recipients are located in the European Union — for example diaspora customers, EU-based staff, or travelers — your messaging falls under the EU General Data Protection Regulation (GDPR), regardless of where your business is based. AfriRoute is built to support GDPR compliance for these flows alongside African data protection laws.
How AfriRoute Supports GDPR
| GDPR Principle | How AfriRoute Helps |
|---|---|
| Lawful basis (Art. 6) | Consent capture and enforcement at send time |
| Data minimization (Art. 5) | Store only the fields needed to deliver; PII redaction in logs |
| Right to access (Art. 15) | Contact + message-history export API |
| Right to erasure (Art. 17) | Hard-delete endpoint for contacts and history |
| Security (Art. 32) | TLS in transit, AES-256 at rest, ISO 27001 / SOC 2 |
| Breach notification (Art. 33) | Customer notification within 72 hours of a confirmed breach |
| International transfers (Ch. V) | EU data region in Frankfurt; SCCs in our DPA |
Controller vs Processor
Under GDPR, you are the data controller and AfriRoute is the data processor. We process EU personal data only on your documented instructions. Our Data Processing Addendum incorporates the European Commission's Standard Contractual Clauses (SCCs) for any transfer of EU data outside the EEA.
Request the signed DPA from [email protected].
Lawful Basis and Consent
For marketing to EU residents you almost always need explicit, opt-in consent under the ePrivacy Directive. Record it and let AfriRoute enforce it:
curl -X POST https://api.afriroute.ai/api/v1/contacts \
-H "Authorization: Bearer $AFRIROUTE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"phone": "+353871234567",
"region": "EU",
"consent": {
"marketing": true,
"source": "double_opt_in_email",
"captured_at": "2026-05-15T12:00:00Z"
}
}'
Promotional sends to EU contacts without recorded consent are rejected with CONSENT_REQUIRED.
Right of Access
Export everything AfriRoute holds about a data subject:
curl "https://api.afriroute.ai/api/v1/contacts/+353871234567/export" \
-H "Authorization: Bearer $AFRIROUTE_API_KEY"
{
"phone": "+353871234567",
"consent": { "marketing": true, "captured_at": "2026-05-15T12:00:00Z" },
"messages": [
{ "message_id": "msg_001", "sent_at": "2026-05-16T09:00:00Z", "status": "delivered" }
],
"generated_at": "2026-05-28T10:00:00Z"
}
Right to Erasure
curl -X DELETE https://api.afriroute.ai/api/v1/contacts/+353871234567/data \
-H "Authorization: Bearer $AFRIROUTE_API_KEY"
PII is hard-deleted; only anonymized aggregate records required for accounting are retained.
Data Residency for EU Subjects
Pin EU personal data to the Frankfurt region so it is stored and processed within the EEA:
curl -X PATCH https://api.afriroute.ai/api/v1/settings/data-residency \
-H "Authorization: Bearer $AFRIROUTE_API_KEY" \
-d '{ "eu_subjects_region": "eu-frankfurt" }'
Sub-processors
AfriRoute uses a limited set of carrier and infrastructure sub-processors. The current list is published at afriroute.ai/legal/subprocessors; customers are notified before any addition.
Your GDPR Checklist
- Sign the AfriRoute DPA (includes SCCs).
- Capture explicit consent for EU marketing and store it.
- Enable EU data residency.
- Wire up access and erasure requests to the export and delete endpoints.
- Maintain your own Record of Processing Activities (RoPA).
Related
GDPR questions? [email protected]
Last Updated: May 2026