# Compliance DSAR Service

Owns GDPR, CCPA, DSA, and regional data-access export workflows with in-region
storage constraints.

## Launch responsibilities

- GDPR DSAR portability and erasure requests originate in the companion app,
  require identity verification, and carry a 30-day SLA.
- CCPA/CPRA do-not-sell and do-not-share choices are stored at account scope in
  the consent ledger and suppress marketing sharing paths.
- EU/UK moderation reports and appeals expose a DSA human-review path,
  transparency log id, and 72-hour moderation SLA.
- COPPA age-gate requests route under-13 profiles to guardian consent with
  social, voice, workshop, personalized ads, and nonessential telemetry
  disabled.
- EU and CN residency policies pin storage to EU-only and CN-only storage
  regions respectively; cross-region replication is blocked for those accounts.
