← Back to resources

spec7 min read

PDPA suppression that actually holds up under audit

Why most opt-out implementations are broken — and how ONSET enforces section 43 of PDPA 2010.

Published 15 Apr 2026

PDPA 2010 § 43 requires data users to honour opt-out within 14 days. Most CRMs treat suppression as a soft flag — easy to override. ONSET's pdpa_suppression_list is consulted by every outbound channel (WhatsApp, email, voice, SMS) at send time, not just at queue time. STOP / BERHENTI / UNSUBSCRIBE replies auto-insert. GUARDIAN CRON audits daily.