Compliance and Regulatory
Compliance and Regulatory Responsibilities
Which compliance obligations Black Tiger Digital handles, and which remain the client’s responsibility. Read carefully before launch.
Last updated: May 1, 2026
Important: Black Tiger Digital is not your attorney, compliance auditor, or data protection officer. Technical configuration alone does not make a business legally compliant. This page makes the division of responsibility explicit so there are no surprises after launch.
General Division of Responsibility
Black Tiger Digital configures systems and follows industry best practices. The client owns the legal compliance posture of their business.
Black Tiger Digital
- Configuring the website, automations, and integrations as scoped
- Implementing reasonable technical safeguards available within the platforms
- Advising on best practices and flagging known compliance considerations
- Assisting with platform registrations (Twilio Brand and Campaign, and similar)
Client
- Determining which laws and regulations apply to their business
- Retaining qualified legal counsel for policies, agreements, and disclosures
- Obtaining all required user consents (email, SMS, cookies, data processing)
- Funding any third-party audits, penetration testing, or certifications
- Ongoing compliance and monitoring of regulatory changes
HIPAA and Protected Health Information (PHI)
If your business is a Covered Entity or handles PHI, the following applies. HIPAA is the most consequential framework on this page, so please read it in full.
What Black Tiger Digital Provides
- Technical configuration of access controls, user roles, and permissions
- Encrypted document storage and transmission where supported by the platform
- Audit logging where supported by the platform
- Secure form handling and intake configuration
- Reasonable technical safeguards within the limits of the chosen platforms
What Black Tiger Digital Does NOT Provide
Unless separately contracted in writing:
- Penetration testing, vulnerability scanning, or third-party security testing
- Drafting of HIPAA policies and procedures
- Workforce HIPAA training
- Risk analysis or risk management documentation
- Breach notification procedures or incident response planning
- Ongoing HIPAA monitoring or auditing
- Designation of a Privacy Officer or Security Officer
- Legal review of any HIPAA-related documents
What the Client Must Do
- Execute a Business Associate Agreement (BAA) with Black Tiger Digital and every subprocessor that may access PHI
- Retain qualified legal counsel for HIPAA policies, procedures, Notice of Privacy Practices, and patient consent forms
- Conduct workforce training and maintain training records
- Designate a Privacy Officer and a Security Officer
- Conduct and document a HIPAA risk analysis
- Establish breach notification procedures consistent with the HIPAA Breach Notification Rule
- Fund and arrange penetration testing or third-party security audits
Partial Technical Compliance Is Not HIPAA Compliance. A system that meets some technical safeguards but lacks executed BAAs, written policies, training, risk analysis, and breach procedures is not HIPAA compliant, regardless of how strong the technical configuration is. The client acknowledges that proceeding without these elements is the client’s decision and the client’s risk.
SMS, TCPA, and A2P 10DLC Messaging
If your build sends SMS or MMS messages to recipients in the United States, the TCPA, A2P 10DLC, and CTIA standards apply.
What Black Tiger Digital Provides
- Configuration of the SMS sending platform (Twilio or equivalent)
- Assistance with Twilio Brand Registration and Campaign Registration
- Implementation of STOP, HELP, and opt-out keyword handling within the platform
- Configuration of consent capture fields on web forms
What the Client Must Do
- Obtain prior express written consent before sending marketing SMS, as required by the TCPA
- Maintain records of consent for each recipient
- Include required disclosures at point of opt-in (program name, message frequency, message and data rates, HELP and STOP instructions, links to terms and privacy policy)
- Honor opt-out requests immediately
- Respect quiet hours (generally 8:00 AM to 9:00 PM in the recipient’s local time zone) and any state-specific restrictions
- Avoid restricted content categories (SHAFT: Sex, Hate, Alcohol, Firearms, Tobacco) unless properly registered and permitted
Sender of Record: The client is the sender of record for all SMS traffic and is solely liable for TCPA, CTIA, and carrier policy violations.
CAN-SPAM (US Email Marketing)
For commercial email sent to US recipients, the client must ensure:
- Accurate routing: “From,” “To,” and routing information clearly identifies the sender
- No deceptive subject lines
- Ad disclosure: the message clearly identifies itself as an advertisement when applicable
- Physical address: a valid physical postal address is included in every commercial email
- Unsubscribe mechanism: functioning and honored within 10 business days
- Permanent opt-out: opt-outs are honored permanently
- Third-party compliance: any third-party senders the client engages also comply
Sender of Record: Black Tiger Digital can configure these elements within the email platform, but the client is the sender of record and is liable for CAN-SPAM violations.
CASL (Canadian Anti-Spam Legislation)
If you send commercial electronic messages to recipients in Canada, CASL applies. CASL penalties are significantly higher than CAN-SPAM, up to $10 million per violation for businesses.
Client Must Ensure
- Express consent is obtained before sending commercial messages (implied consent has limited applicability and must be documented)
- The sender’s identity and contact information is clearly disclosed
- A working unsubscribe mechanism is provided and honored within 10 business days
- Records of consent are maintained and producible on request
- Software installed on a recipient’s device (including certain cookies and scripts) complies with CASL’s installation provisions
Cross-Border Risk: If your subscriber list includes any Canadian recipients, even unintentionally, CASL may apply to those messages. The client is responsible for list hygiene and consent records.
GDPR and UK GDPR
If you process personal data of individuals in the European Union, European Economic Area, or United Kingdom, GDPR or UK GDPR applies, regardless of where your business is located.
What Black Tiger Digital Provides
- Configuration of cookie consent banners and tracking controls (when in scope)
- Configuration of form fields to capture lawful basis for processing
- Implementation of standard data subject request handling within the platform
What the Client Must Do
- Determine the lawful basis for each processing activity (consent, contract, legitimate interest, and so on)
- Publish a GDPR-compliant Privacy Policy and Cookie Policy
- Execute a Data Processing Agreement (DPA) with Black Tiger Digital and every subprocessor
- Maintain a Record of Processing Activities (ROPA)
- Honor data subject rights: access, rectification, erasure, restriction, portability, objection
- Notify the relevant supervisory authority of breaches within 72 hours where required
- Appoint a Data Protection Officer (DPO) if required by Article 37
- Ensure international data transfers use a valid lawful mechanism (Standard Contractual Clauses, adequacy decision, and similar)
Personal Identifiable Information (PII) and US State Privacy Laws
Most US states now have, or are passing, comprehensive privacy laws, including CCPA/CPRA in California, plus similar laws in Virginia, Colorado, Connecticut, Utah, Texas, and others.
Client Must
- Determine which state laws apply based on customer base and business size
- Publish required privacy disclosures
- Honor consumer rights requests (access, deletion, opt-out of sale or sharing) within statutory deadlines
- Maintain reasonable security practices for PII as required by applicable law
- Provide breach notification as required by each state’s breach notification statute
Note: US state privacy law is evolving rapidly. New states pass legislation each year. The client is responsible for monitoring applicability as the business grows.
PCI-DSS (Payment Card Data)
For builds that process payments, cardholder data is handled by the payment processor, not by Black Tiger Digital systems.
- Cardholder data is handled by the payment processor (Stripe or equivalent)
- Black Tiger Digital does not store, transmit, or process raw cardholder data
- The client is responsible for completing the appropriate Self-Assessment Questionnaire (SAQ) with their payment processor
- The client is responsible for maintaining PCI-DSS compliance for any environments outside the Black Tiger Digital build that handle cardholder data
No Warranty of Compliance
Black Tiger Digital does not warrant or guarantee that any deliverable, configuration, or system makes the client compliant with HIPAA, GDPR, CCPA, TCPA, CAN-SPAM, CASL, PCI-DSS, or any other law or regulation.
Compliance is a function of the client’s full operational, legal, and procedural environment, not the website or automation alone. The client agrees to retain qualified legal counsel to review their compliance posture before launch and on an ongoing basis.
Limitation of Liability: To the maximum extent permitted by law, Black Tiger Digital is not liable for fines, penalties, settlements, judgments, or damages arising from the client’s failure to comply with any law or regulation, including but not limited to those listed on this page.
Client Acknowledgment
By engaging Black Tiger Digital, the client acknowledges and agrees that:
- The client has read and understands this Compliance and Regulatory Responsibilities page
- The client is solely responsible for determining which laws apply to their business
- The client will retain qualified legal counsel for all required policies, agreements, and disclosures
- Black Tiger Digital’s role is technical configuration and advisory, not legal compliance
- Any decision to launch without recommended legal review, agreements, training, or testing is the client’s decision and the client’s risk
Plain Language: We build it right on the technical side. You and your attorney handle the legal side. If you choose to skip the legal side, that is your call, and your risk.
On This Page
Need Clarification?
We are happy to walk through any section in plain language before you sign or pay.
Book a CallQuestions?
Need clarification on your obligations?
Compliance can feel like a maze. We are happy to walk through which frameworks apply to your business and what your next steps look like. No legal jargon, just straight answers.
- Email us[email protected]
- Call us+1-248-205-6977
Other Legal Pages
Ready to Build the Right Way?
We will configure your systems to industry best practices and tell you exactly what to take to your attorney. Let us talk through your project.
- Industry best practices
- Clear handoff to your attorney
- No surprises after launch