7GenEdu

International Compliance Addendum

Last updated: April 2026

Seven Hills Iowa LLC is committed to complying with data protection and privacy laws in all jurisdictions where our users are located. The table below summarizes our compliance posture across applicable regulations worldwide.

This addendum supplements our Privacy Policy and should be read in conjunction with it.

Region / CountryApplicable Law(s)Key RequirementsStatus
United StatesCOPPA (Children's Online Privacy Protection Act)Verifiable parental consent for children under 13; privacy notices; data minimization for child dataCompliant
United States (CA)CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act)Right to know, delete, opt-out of sale; no discrimination; privacy notice at collection; authorized agentsCompliant
EU / EEAGDPR (General Data Protection Regulation)Lawful basis for processing; data subject rights; DPO appointment; DPIAs; 72-hour breach notification; international transfer safeguardsCompliant
EU / EEAePrivacy Directive (2002/58/EC)Cookie consent; electronic communications privacy; prior consent for non-essential cookies/trackingCompliant
United KingdomUK GDPR + Data Protection Act 2018Mirrors EU GDPR with UK-specific provisions; ICO as supervisory authority; UK IDTA for international transfersCompliant
CanadaPIPEDA (Personal Information Protection and Electronic Documents Act)Meaningful consent; purpose limitation; access rights; breach reporting to OPCCompliant
Canada (Quebec)Quebec Law 25 (Act Respecting the Protection of Personal Information in the Private Sector)Privacy impact assessments; consent requirements; de-identification standards; transparency obligationsCompliant
CanadaCASL (Canada's Anti-Spam Legislation)Express or implied consent for commercial electronic messages; unsubscribe mechanism; sender identificationCompliant
AustraliaPrivacy Act 1988 (incl. Australian Privacy Principles)APP compliance; cross-border disclosure rules; notifiable data breaches scheme; consumer guarantees under ACLCompliant
BrazilLGPD (Lei Geral de Proteção de Dados)Lawful basis for processing; data subject rights; DPO appointment; ANPD oversight; international transfer rulesCompliant
IndiaDPDP Act 2023 (Digital Personal Data Protection Act)Consent-based processing; data principal rights; significant data fiduciary obligations; cross-border transfer restrictionsCompliant
SingaporePDPA (Personal Data Protection Act 2012)Consent obligation; purpose limitation; data breach notification to PDPC; data portabilityCompliant
JapanAPPI (Act on the Protection of Personal Information)Consent for sensitive data; cross-border transfer rules; PPC oversight; individual rightsCompliant
South KoreaPIPA (Personal Information Protection Act)Consent requirements; data subject rights; PIPC oversight; mandatory breach notification; pseudonymization standardsCompliant
ArgentinaPDPA (Personal Data Protection Act, Law 25.326)Consent requirements; data subject rights; AAIP registration; adequacy-based cross-border transfersCompliant
South AfricaPOPIA (Protection of Personal Information Act)Lawful processing conditions; data subject rights; Information Regulator oversight; cross-border transfer safeguardsCompliant
PhilippinesDPA 2012 (Data Privacy Act of 2012)Consent and legitimate interest; NPC registration; data subject rights; mandatory breach notificationCompliant
UAEPDPL (Personal Data Protection Law, Federal Decree-Law No. 45/2021)Consent for processing; data subject rights; cross-border transfer restrictions; data protection officer requirementsCompliant
NigeriaNDPR (Nigeria Data Protection Regulation 2019)Consent requirements; data subject rights; NITDA oversight; mandatory DPIAs for high-risk processingCompliant
KenyaDPA 2019 (Data Protection Act 2019)Data subject rights; ODPC registration; cross-border transfer safeguards; mandatory breach notificationCompliant
ColombiaLaw 1581 of 2012 (Statutory Law on Data Protection)Consent requirements; data subject rights (habeas data); SIC oversight; cross-border transfer rulesCompliant
ChileLaw 19.628 (Protection of Private Life)Consent for processing; data subject rights; source-of-data obligations; upcoming reform alignmentCompliant
MexicoLFPDPPP (Federal Law on Protection of Personal Data Held by Private Parties)ARCO rights (Access, Rectification, Cancellation, Opposition); privacy notice requirements; INAI oversight; consent requirementsCompliant

This compliance addendum is reviewed and updated regularly. If you have questions about our compliance with any specific regulation, contact support@7genedu.com.

Contact