Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Plivo is a US-based CPaaS (Communications Platform as a Service) competing with Twilio and Vonage. European businesses use Plivo to send transactional and marketing SMS, run voice IVR, deliver one-time passwords, and route phone calls. Although core communications happen server-side, Plivo's browser SDK can load JavaScript for click-to-call, and the platform processes large volumes of phone numbers, call recordings, and message content, falling squarely under the GDPR, the ePrivacy Directive and national telecoms law.
Plivo is a US-headquartered Communications Platform as a Service company providing programmable voice, SMS, MMS, WhatsApp Business and verification APIs. It competes with Twilio, Vonage and MessageBird and is popular in Europe for transactional messaging, two-factor authentication, marketing SMS and call centre voice routing. Most usage is backend (server-to-API), but Plivo also ships a JavaScript SDK for WebRTC click-to-call deployed on websites.
Plivo handles phone numbers (sender and recipient), SMS content, call duration and routing metadata, call recordings (when enabled), voicemail, IVR keypress inputs, WebRTC session identifiers, IP addresses, and operator-level Mobile Network Code information. For verified-by-Plivo flows, identity documents may also be processed. The browser SDK sets a small number of cookies and localStorage entries to manage WebRTC session state.
Phone numbers are personal data. Marketing SMS to EU consumers requires prior, explicit consent under Art. 13 ePrivacy and Art. 6(1)(a) GDPR, with no soft opt-in in most member states for new prospects. Transactional SMS (order confirmation, OTP) can rely on contract or legitimate interest. Call recordings require dual consent (caller and recipient) and clear announcement at the start of the call. Plivo''s DPA sets the controller and processor relationship and includes the 2021 SCCs for transfers to the United States.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Plivo offers EU regional infrastructure (Frankfurt) which keeps voice and SMS termination in the EU. However, Plivo Inc. as a US controller retains access to metadata, billing data, support interactions and call recordings. The transfer is covered by SCCs and, where applicable, by the EU-US Data Privacy Framework. A Transfer Impact Assessment is required: document the data categories, the supplementary measures (encryption, access controls), and any residual risk of US government access.
For marketing SMS, collect granular, freely given consent at the point of phone number collection (a separate unchecked box, not bundled with terms of service). Honour STOP replies and maintain a suppression list. For WebRTC click-to-call, the browser SDK requires consent before establishing a media stream; under the ePrivacy Directive the access to the device''s microphone is itself a regulated event. Gate the SDK behind a CMP category and provide a clear announcement.
1. Sign the Plivo DPA and select the EU region for storage where available. 2. Map all SMS, voice and recording flows in a Record of Processing Activities. 3. Run a DPIA covering call recording and marketing SMS. 4. Configure your sign-up forms to capture granular SMS consent and store proof of consent. 5. Document Plivo in your privacy notice including US transfer disclosure. 6. Build an automated STOP-reply suppression list. 7. Limit call recording retention to the minimum necessary, with role-based access controls.
Websites using Plivo must obtain user consent under GDPR regulations.
DPIA considerations
Plivo processes phone numbers, call detail records, SMS message content (including OTPs and marketing copy), call recordings, voicemail, and customer support interactions. Key DPIA considerations: (1) phone number is a direct identifier under GDPR; (2) call recordings may contain special category data (health, beliefs); (3) marketing SMS triggers ePrivacy Art. 13 prior consent rules with no soft opt-in for B2C in most member states; (4) data transfer to US support and engineering; (5) Plivo's sub-processors include cloud providers (AWS) and global telecoms carriers, expanding the data flow map; (6) law enforcement access risks for stored call recordings. A DPIA is strongly recommended for any deployment involving call recording, marketing campaigns, or sensitive verticals.
Sample consent text
I consent to receive SMS communications from <COMPANY> at the number provided, including marketing messages and product updates. Messages are sent via Plivo Inc. in the United States, under Standard Contractual Clauses. Message frequency varies, message and data rates may apply, and I can opt out at any time by replying STOP.
Third-party domains contacted
plivo.comapi.plivo.comcdn.plivo.comphlo.plivo.comsdk.plivo.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| plivo_session | Functional | Session | Stores the WebRTC session token when the Plivo browser SDK is used for click-to-call. Required to maintain the active media stream. |
| plivo_endpoint | Functional | Session | Identifies the JavaScript SDK endpoint instance for signalling and reconnection during WebRTC calls. |
| plivo_consent (localStorage) | Functional | 1 year | Records whether the visitor has accepted the click-to-call notice and microphone access. |
Plivo uses cookies for user preferences — inform visitors with a consent banner.
Most usage is server-side and sets no cookies on your visitors. The Plivo browser SDK for WebRTC click-to-call may set plivo_session, plivo_endpoint (session identifiers), and store WebRTC media constraints in localStorage. None of these are strictly necessary unless click-to-call is the primary site function.
Yes for marketing SMS. Under Art. 13 ePrivacy and most national implementations, marketing SMS requires prior, explicit, opt-in consent at the moment the phone number is collected. For transactional SMS such as order confirmations or password resets, you can rely on contract performance or legitimate interest, with transparency in your privacy notice.
OTP delivery is generally based on legitimate interest under Art. 6(1)(f) GDPR for security and fraud prevention, or contract performance when the user requested the authenticated service. A balancing test should be documented, especially for SMS-based 2FA which is now considered weaker than authenticator apps.
Yes. Plivo Inc. is headquartered in San Francisco. Even with EU region selection (Frankfurt), Plivo's US team retains access for support, billing, fraud and engineering purposes. The Plivo DPA includes the 2021 SCCs and Plivo participates in the EU-US Data Privacy Framework where applicable. Document the transfer and run a TIA.
A DPIA is recommended for any deployment that records calls, performs marketing campaigns to large audiences, or processes sensitive context (health, legal, financial). The combination of voice content, phone numbers and US transfer typically meets Art. 35(3) GDPR criteria.
Sign the Plivo DPA, select EU region for storage, gate marketing SMS behind granular consent with proof of capture, configure STOP handling and suppression lists, document everything in your Record of Processing Activities, and disclose Plivo and the US transfer in your privacy notice. For voice recording, implement automated retention policies and role-based access.
EU-based or EU-hosted CPaaS alternatives include MessageBird (Netherlands, EU), Sinch (Sweden, EU regional), Infobip (Croatia, EU), Vonage (US but with EU regions), and CM.com (Netherlands). For SMS-only flows, Belgian operator Esendex and German Spryng are EU-native options.
If you use the Plivo browser SDK, list plivo_session and plivo_endpoint in your cookie policy with their purpose and duration. In your privacy notice, identify Plivo Inc. as a data processor, specify the US transfer (EU-US DPF or SCCs), list the categories of personal data processed (phone numbers, message content, call recordings, IP), and describe data subject rights including deletion of recordings.