Balance — Peru Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Peruvian resident covered by this Annex, and the Oficial de Protección de Datos Personales designated under Decreto Supremo 016-2024-JUS Art 38 read with Ley 29733. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to Ley 29733 — Ley de Protección de Datos Personales (the "LPDP"), (b) any amendment to Decreto Supremo 016-2024-JUS (the Reglamento de la Ley 29733, published El Peruano 9 August 2024 with a 180-day vacatio legis; in force since 6 February 2025; superseded Decreto Supremo 003-2013-JUS) or any successor Decreto Supremo of the Ministerio de Justicia y Derechos Humanos (MINJUSDH), (c) any Resolución Directoral of the Autoridad Nacional de Protección de Datos Personales (ANPDP) — particularly Resoluciones on cross-border transfers, breach notification, the Registro Nacional de Protección de Datos Personales (RNPDP), and children's-data — that materially alters the operational rules below, (d) any amendment to Ley 27337 — Código de los Niños y Adolescentes (the "CNA"), (e) any amendment to Ley 30466 (procedural parameters and guarantees for the primordial consideration of the best interest of the child), (f) any amendment to Ley 29571 — Código de Protección y Defensa del Consumidor (the "CDC") or its Reglamento (Decreto Supremo 011-2011-PCM and successors) issued by the Instituto Nacional de Defensa de la Competencia y de la Protección de la Propiedad Intelectual (INDECOPI), (g) any amendment to Ley 30096 — Ley de Delitos Informáticos (as modified by Ley 30171) or to Ley 30838 (which strengthened Código Penal offences for sexual proposals to children and adolescents — Art 183-B), (h) any Sentencia of the Tribunal Constitucional del Perú that materially changes the interpretation of CN Art 2(6) / Art 2(7) (rights to intimacy and protection of personal data) or Art 200(3) (constitutional garantía of habeas data), (i) Peru's accession to Convention 108+ (Peru is invited but accession is pending at the Effective date), (j) the European Commission issuing an adequacy decision in respect of Peru under GDPR Art 45 (none in force at the Effective date), or (k) any change to a sub-processor's Peru data-handling posture under our sub-processor register. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Peru row).
- Children's Privacy Notice § 14 (Country annexes — Peru row).
- Child Safety Standards § 13 (Country annexes — Peru row).
- Terms of Service § 19 (Peru consumer-protection carve-out under Ley 29571).
- Subscription Terms § 20 (Peru consumer-rights overlay — Art 59 derecho de retracto 7-working-day right of retraction; CDC overlays; Ley 28493 anti-spam).
- Data Retention & Deletion Policy § 14 (Peru ANPDP complaint route).
- our breach-notification runbook § 9 (Peru breach-notification route via ANPDP under DS 016-2024-JUS).
- our international-transfer pack § 6 (Ley 29733 Art 15 international-transfer treatment + DS 016-2024-JUS cross-border transfer instruments).
This Annex is the canonical Peru-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Peruvian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Peruvian resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. The authoritative Spanish-language version is republished at Peru annex as part of the Phase-2 locale rollout. In the event of a discrepancy between the English text and the Spanish text, the Spanish text prevails for Peruvian residents.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of Peru ("Peru"), without distinction between the 24 departamentos and the Provincia Constitucional del Callao.
We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies Peru as the country of residence, this Annex applies, even if the other signals are non-Peruvian. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
The LPDP has extraterritorial effect under its Art 3 read with DS 016-2024-JUS Art 4: the LPDP applies whenever the controller is established in Peru, whenever the processing is carried out by means in Peru, or whenever the controller, even without being established in Peru, offers goods or services to Peruvian residents or monitors their behaviour to the extent that the behaviour takes place in Peru. The ANPDP's interpretive practice — expressed in its Resoluciones Directorales and in its published Concept Notes — confirms the GDPR-Art-3(2)-aligned scope. Balance squarely targets Peruvian residents through Google Play and through publication of this Annex at balance.babayagaprogram.com.
2. Statutory framework — what applies
The Peruvian data-protection and online-safety regime sits at the intersection of the Constitución Política del Perú 1993, the Ley 29733 of 2011 and its Reglamento (Decreto Supremo 016-2024-JUS of 2024, which superseded Decreto Supremo 003-2013-JUS), the Código de los Niños y Adolescentes (Ley 27337) read with the procedural best-interest statute (Ley 30466), the Código Penal as modified by Ley 30096 (cybercrime) and Ley 30838 (sexual-offences-against-children strengthening), the Código de Protección y Defensa del Consumidor (Ley 29571), and a body of Resoluciones Directorales issued by the ANPDP.
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| Constitución Política del Perú 1993 | CN, as amended; Art 2(5) (right of access to public information held by State entities); Art 2(6) (right that information services, whether computerised or not, do not provide information that affects personal and family intimacy); Art 2(7) (right to honour and good reputation, to personal and family intimacy, and to the protection of voice and image); Art 200(3) (constitutional acción de habeas data); Art 4 (the community and the State protect the child and the adolescent). | The constitutional anchor for the personal-data-protection regime and for the child-rights regime. The acción de habeas data under Art 200(3) is the principal constitutional remedy available to a Peruvian data subject; the Tribunal Constitucional del Perú has built a body of jurisprudence interpreting Arts 2(6), 2(7), and 200(3) in the digital environment. | Applies in full as the foundational constitutional layer. Treatment in §§ 3, 5, 6, 7, 13 below. |
| Ley 29733 — Ley de Protección de Datos Personales | LPDP — Ley 29733 of 21 June 2011, in force since 22 July 2013 | The principal data-protection regime: definitions (Art 2); principles — legality, consent, purpose, proportionality, quality, security, fitness, level-of-protection, and disposability (Arts 4–12); lawful bases — Art 13 (general rules) + Art 14 (limitations on consent); special-category data — Art 16 + Art 17; rights of the data subject — Arts 18–24 (information, access, update/inclusion/rectification/suppression, opposition, anonymisation, derecho a no ser objeto de decisiones automatizadas, derecho de tutela); international transfers — Art 15; supervisory authority — Arts 32–36 (the Autoridad Nacional de Protección de Datos Personales); sanctions — Arts 37–41; the Registro Nacional de Protección de Datos Personales (RNPDP) — Art 32(c). | Applies in full. Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. |
| Decreto Supremo 016-2024-JUS | Reglamento de la Ley 29733 — published Diario Oficial El Peruano on 9 August 2024 with a 180-day vacatio legis; in force since 6 February 2025; superseded Decreto Supremo 003-2013-JUS of 22 March 2013 | The modernised operational rules for the LPDP, with substantial GDPR-aligned overlays: definitions of controller and processor; Privacy by Design and Privacy by Default; the Oficial de Protección de Datos Personales (OPDP — the LPDP-mandated DPO) regime; the Evaluación de Impacto en la Protección de Datos Personales (EIPDP — Peru's DPIA equivalent) for high-risk processing; the updated cross-border-transfer rules; the breach-notification regime with a 48-hour benchmark to the ANPDP and a 5-working-day data-subject-notification track; the RNPDP registration rules; the Manual de Tratamiento de Datos Personales; the children's-data treatment with reinforced parental-consent and best-interest treatment. | Applies as the principal operational rules layer on top of Ley 29733. Balance's OPDP, EIPDP, and Manual artefacts are cross-referenced in our Records of Processing Activities (Article 30) § 7 and our Data Protection Impact Assessment (the global DPIA satisfies the Peruvian EIPDP). |
| Decreto Supremo 003-2013-JUS | Original Reglamento de la Ley 29733 of 22 March 2013 — superseded by DS 016-2024-JUS | The original operational rules. Not in force at the Effective date except as cited in legacy Resoluciones Directorales of the ANPDP. | Not in force. Listed here for completeness only. |
| ANPDP Resoluciones Directorales | The ANPDP's binding administrative acts. Principal Resoluciones in force at the Effective date include: Resolución Directoral 001-2020-JUS/DGTAIPD (interpretive criteria on consent), the Resoluciones on cross-border transfers (the ANPDP's adequacy-finding mechanism), the Resoluciones on breach-notification operationalisation, the Resoluciones on the RNPDP, and the Resoluciones on children's-data — as published at the ANPDP portal (currently https://www.gob.pe/anpdp and the legacy https://www.minjus.gob.pe/). |
Sets the binding interpretive layer on the LPDP and DS 016-2024-JUS. | Applies. Balance's processing is operationalised consistently with the ANPDP's Resoluciones. |
| Ley 27337 — Código de los Niños y Adolescentes | CNA — Ley 27337 of 21 July 2000, as amended | The principal child-protection statute. Defines niño (under 12) and adolescente (12–17) at Art I of the Título Preliminar. Codifies the interés superior del niño y del adolescente (best-interest principle) at Art IX of the Título Preliminar. Codifies the rights to intimidad (Art 4), to honour and image (Art 4), to opinion (Art 9), and to information (Art 10). Establishes the Sistema Nacional de Atención Integral al Niño y al Adolescente and the Ente Rector (the Ministerio de la Mujer y Poblaciones Vulnerables — MIMP). | Applies in full to every Peruvian kid covered by this Annex. Treatment in §§ 5, 7, 14 below. |
| Ley 30466 | Ley que establece parámetros y garantías procesales para la consideración primordial del interés superior del niño of 17 June 2016 + its Reglamento (Decreto Supremo 002-2018-MIMP) | Codifies the procedural parameters and guarantees for the primordial consideration of the best interest of the child in any administrative or judicial decision that concerns a child. Operationalises the constitutional best-interest principle as a procedural standard. | Applies. Treatment in § 5 below. |
| Ley 30362 | Ley que eleva a rango de ley el Decreto Supremo 001-2012-MIMP and reinforces the protection of children against violence | Reinforces the prevention-of-violence-against-children regime. | Applies. Cross-reference in Child Safety Standards § 5. |
| Ley 30096 — Ley de Delitos Informáticos | Ley 30096 of 22 October 2013, as modified by Ley 30171 of 10 March 2014 | The cybercrime statute, aligned with the Budapest Convention on Cybercrime (to which Peru acceded via Resolución Legislativa 30913 of 12 February 2019, with the instrumento de adhesión deposited 26 August 2019). Codifies illicit access to a computer system (Art 2), illicit interference with a system (Art 3), illicit interference with data (Art 4), illicit interception of data (Art 7), computer fraud (Art 8), identity theft (Art 9), illicit dissemination of CSAM (Art 5), online-grooming proposals to children/adolescents (Art 5 read with Código Penal Art 183-B as strengthened by Ley 30838 of 2018), discrimination via computer means (Art 11), abuse of computer mechanisms for sexual offences against children and adolescents (Art 5). | Applies. Cross-reference in Child Safety Standards § 8 (Peru CSAE routes — see § 14 below). |
| Ley 30838 de 2018 | Ley que modifica el Código Penal y el Código de Ejecución Penal para fortalecer la prevención y sanción de los delitos contra la libertad e indemnidad sexuales of 4 August 2018 | Strengthens the Código Penal offences for sexual offences against children and adolescents. Modified Código Penal Art 183-B (sexual proposals to children and adolescents — the online-grooming offence) and Arts 170-A, 172, 173, 175, 176-A, and 183. | Applies. Cross-reference in Child Safety Standards § 8. |
| Código Penal (Decreto Legislativo 635 de 1991) | Código Penal — relevant articles at the Effective date: Art 154 (violación de la intimidad); Art 154-A (tráfico ilegal de datos personales — inserted by Ley 30171); Art 154-B (difusión de imágenes, materiales audiovisuales o audios con contenido sexual); Art 153 (trata de personas); Art 153-A (formas agravadas de trata de personas); Art 183-A (pornografía infantil); Art 183-B (proposiciones a niños, niñas y adolescentes con fines sexuales por medios tecnológicos — the online-grooming offence as strengthened by Ley 30838); Art 176-A (actos contra el pudor en menores); Art 207-A/B/C/D (delitos informáticos — predating Ley 30096). | The Peruvian criminal-law backbone for CSAM, online grooming, child-sexual-exploitation offences, and personal-data-trafficking offences. | Applies. Cross-reference in Child Safety Standards § 8 (Peru CSAE routes — see § 14 below). |
| Ley 29571 — Código de Protección y Defensa del Consumidor | CDC — Ley 29571 of 1 September 2010, as amended; implementing decree Decreto Supremo 011-2011-PCM | The principal consumer-protection statute. Art 1 (rights of the consumer); Art 2 (information); Art 14 (advertising); Art 19 (advertising directed at children); Art 47 (información mínima — minimum pre-contract information); Art 59 (derecho de retracto — 7-working-day right of retraction for distance contracts); Art 50 (cláusulas abusivas — abusive contract terms); Art 38 (collective interests of consumers). The Peruvian supervisory authority is INDECOPI — Instituto Nacional de Defensa de la Competencia y de la Protección de la Propiedad Intelectual. | Applies to the subscription terms (Subscription Terms) and to the Terms of Service (Terms of Service). Treatment in § 16 below. |
| Ley 28493 — Ley que regula el uso del correo electrónico comercial no solicitado (SPAM) | Ley 28493 of 12 April 2005 + Decreto Supremo 031-2005-MTC of 8 December 2005 | Restricts unsolicited commercial email and electronic communications. Requires the supplier to obtain prior consent (or to provide a free, easy opt-out for the régimen de opt-out), to identify the email as commercial (with the prefix "PUBLICIDAD:" in the subject line), to identify the supplier and a return address, and to provide a free unsubscribe mechanism. | Applies. Balance does NOT send electronic direct marketing to Peruvian residents — § 12.3 below. |
| Decreto Legislativo 1412 de 2018 — Ley de Gobierno Digital | Decreto Legislativo 1412 of 12 September 2018 + its Reglamento (Decreto Supremo 029-2021-PCM) | The Digital Government Act. Anchors the Secretaría de Gobierno y Transformación Digital (SGTD) of the Presidencia del Consejo de Ministros (PCM) as the policy coordinator for digital government. Sets cross-cutting principles for state digital services. | Not directly applicable to Balance (Balance is not a State service), but anchors the policy environment in which the LPDP and its Reglamento operate. |
| Decreto Legislativo 1357 de 2017 | Decreto Legislativo 1357 de 2017 | Modified Ley 29733 in particular respects (Art 15 cross-border transfers and interest-protection updates). | Applies as the substantive overlay on the original LPDP text. |
| Convention 108 + Convention 108+ + Budapest Convention | Peru acceded to the Convention on Cybercrime (Budapest Convention, CETS 185) by Resolución Legislativa 30913 of 12 February 2019, with the instrumento de adhesión deposited on 26 August 2019 (in force for Peru since 1 December 2019). Peru is invited to accede to Convention 108+ (Council of Europe ETS 108 + CETS 223 of 18 May 2018); accession is pending at the Effective date. | The Budapest Convention is in force for Peru and undergirds Ley 30096. Convention 108+ accession is pending. | Relevant as context. Treatment in §§ 8, 13 below. |
| EU adequacy | None as of the Effective date — Peru does not have an EU adequacy decision under GDPR Art 45. | Distinct from Argentina (Decision 2003/490/EC) and Uruguay (Decision 2012/484/EU), Peru does not yet hold an adequacy finding. | Relevant only as context. Balance's transfer mechanism for the PE-to-US leg does not rely on adequacy. Treatment in § 8 below. |
| Tribunal Constitucional del Perú jurisprudence | Principal Sentencias on Arts 2(6) + 2(7) + 200(3): Exp. 1797-2002-HD/TC; Exp. 4739-2007-HD/TC; Exp. 02814-2011-PHD/TC; Exp. 02838-2014-PHD/TC; Exp. 4407-2017-PHD/TC (digital identity); the Tribunal's line on the autodeterminación informativa (informational self-determination) as a constitutional fundamental right. | The Tribunal Constitucional has built a body of jurisprudence on the constitutional right of autodeterminación informativa and the acción de habeas data. | Applies. Treatment in §§ 5, 6, 13 below. |
(Any prospective Peruvian regulation governing automated processing, algorithmic decisions, or related techniques — including any ANPDP Resolución Directoral in that area and any Congressional proyecto de ley on such topics — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Peruvian regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. ANPDP — Supervisory authority
3.1 The ANPDP as supervisory authority
The supervisory authority for the LPDP is the Autoridad Nacional de Protección de Datos Personales ("ANPDP"), a specialised body within the Ministerio de Justicia y Derechos Humanos (MINJUSDH). The ANPDP is established under Ley 29733 Arts 32–36 + DS 016-2024-JUS Title VI. The ANPDP exercises regulatory, supervisory, enforcement, and sanctioning powers in respect of personal-data processing in Peru. The ANPDP is not autonomous in the manner of the AAIP (Argentina), or an EU DPA — it is a Dirección within MINJUSDH. A bill for the conversion of the ANPDP into an autonomous authority has been before the Congreso de la República in successive legislative sessions; the bill is not enacted at the Effective date.
| Field | Value |
|---|---|
| Name | Autoridad Nacional de Protección de Datos Personales (ANPDP) — Dirección de la Autoridad Nacional de Protección de Datos Personales within the Ministerio de Justicia y Derechos Humanos |
| Headquarters | Calle Scipión Llona 350, Miraflores, Lima 15074, Peru |
| General website | https://www.gob.pe/anpdp (the consolidated gob.pe page); the legacy MINJUSDH portal at https://www.minjus.gob.pe/proteccion-de-datos-personales |
| Complaint / claim channel (Procedimientos administrativos — Denuncias y reclamos) | The ANPDP's online intake at https://www.gob.pe/anpdp |
| Incident-notification channel | The ANPDP's online incident-notification form per DS 016-2024-JUS Title VII |
| RNPDP — Registro Nacional de Protección de Datos Personales | The ANPDP's online registry under Ley 29733 Art 32(c) + DS 016-2024-JUS Title VIII. Foreign controllers without permanent Peruvian establishment fall outside the registration scope under the ANPDP's interpretive practice |
| The ANPDP intake email published at the gob.pe page (general); judicial notifications at the MINJUSDH address | |
| Phone | The ANPDP central line published at the gob.pe page; MINJUSDH switchboard +51 1 204-8020 |
| Director | The head of the ANPDP is a Director appointed by the MINJUSDH; the appointment is made under MINJUSDH organisational rules |
The ANPDP is the first-line forum for any LPDP-grounded complaint. A Peruvian resident may petition the ANPDP without first raising the matter with Balance. We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the Oficial de Protección de Datos Personales of Balance) and we will respond within the LPDP + DS 016-2024-JUS timelines (see § 6 below).
A Peruvian resident may also pursue private remedies against Balance via the acción de habeas data (the constitutional remedy under CN Art 200(3) + Código Procesal Constitucional — Ley 31307 de 2021); via the ordinary civil courts; or via the Ministerio Público where criminal offences under Código Penal Arts 154 (violación de la intimidad), 154-A (tráfico ilegal de datos personales), or 183-B (proposiciones a niños, niñas y adolescentes con fines sexuales) are engaged.
3.2 The Oficial de Protección de Datos Personales (OPDP)
DS 016-2024-JUS Art 38 requires the designation, by certain controllers, of an Oficial de Protección de Datos Personales (OPDP) — the LPDP-mandated DPO equivalent. The OPDP must be designated by every controller that, among other criteria, processes large volumes of personal data, processes sensitive personal data, or processes personal data of children and adolescents as a core activity. Balance's processing of children's data engages the OPDP-mandated controller category.
The Balance OPDP is:
- , Director, BabaYaga Program, TOO — .
The OPDP's functions are: (a) inform and advise the controller and its personnel on LPDP and DS 016-2024-JUS obligations; (b) monitor compliance with the LPDP, DS 016-2024-JUS, and the ANPDP's Resoluciones Directorales; (c) cooperate with the ANPDP in any supervisory or investigation activity; (d) act as the contact point for data subjects on rights-exercise matters and for the ANPDP on regulatory matters; (e) lead the children's-data treatment under DS 016-2024-JUS Title V.
3.3 Registro Nacional de Protección de Datos Personales (RNPDP) — non-registration position
Ley 29733 Art 32(c) + DS 016-2024-JUS Title VIII require certain controllers to register their personal-databanks (bancos de datos personales) in the Registro Nacional de Protección de Datos Personales (RNPDP) maintained by the ANPDP. The ANPDP's published interpretive practice — codified in its Resoluciones Directorales and in its Concept Notes — is that foreign controllers without a permanent establishment in Peru are not required to register their databanks in the RNPDP; the obligation applies to controllers having a permanent establishment in Peru (which Balance does not).
Should the ANPDP's interpretive practice change, or should Balance ever establish a permanent presence in Peru, the registration will be filed within the statutory window prescribed by the ANPDP's RNPDP rules.
4. Lawful bases under the LPDP
Balance processes personal data of Peruvian residents on the following LPDP lawful bases. The mapping below is the canonical Balance-side bridge between each processing purpose and the LPDP lawful basis. The full record is in our Records of Processing Activities (Article 30).
| Processing purpose | Lawful basis (LPDP + DS 016-2024-JUS) | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | LPDP Art 13 — express, informed, prior, and free consent of the data subject (here, the parent at sign-up); supplemented by Art 14(5) — data necessary for the performance of a contractual relationship in which the data subject is a party | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal data | LPDP Art 14(6) — read with the protection-of-the-data-subject carve-out; supplemented by the constitutional best-interest principle under CN Art 4 + CNA Art IX Título Preliminar + DS 016-2024-JUS Title V (children's-data); the substantive instrument is the parent's affirmative consent under LPDP Art 13 + CNA patria potestad doctrine | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | LPDP Art 13 + Art 14(5) — consent + contractual relationship | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | LPDP Art 9 (security principle) + Art 14(7) — data necessary for the satisfaction of a legitimate interest of the controller; supplemented by DS 016-2024-JUS security obligations | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations (LPDP Arts 18–24 DSAR responses; DS 016-2024-JUS breach notification; ANPDP information requests; INDECOPI consumer-rights requests; CNA cooperation duties; CSAE-report obligations under Ley 30096 + Ley 30838 + Código Penal) | LPDP Art 14(1) — data collected for the exercise of functions provided in laws | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | LPDP Art 13 — express, informed, prior, and free consent of the parent under the CNA patria potestad doctrine | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | LPDP Art 14(5) — necessary for the performance of the subscription contract | H4; Ley 29571 overlay in § 16 below |
Balance does not rely on the "public-source data" carve-out (LPDP Art 14(2) — data accessible from sources of public access) as a lawful basis for any kid-side processing.
5. CNA + Ley 30466 — children's rights overlay
Ley 27337 (Código de los Niños y Adolescentes — CNA) read with Ley 30466 (procedural parameters for the primordial consideration of the best interest of the child) is the principal Peruvian child-protection framework. The principal Balance-side handshakes are:
5.1 Definitions (CNA Art I Título Preliminar)
Under CNA Art I Título Preliminar, a child (niño) is a person from conception to 12 years of age; an adolescent (adolescente) is a person from 12 to under 18 years of age. The constitutional anchor is CN Art 4 (the community and the State protect the child and the adolescent in situation of abandonment, especially affecting their condition); the international anchor is the UN Convention on the Rights of the Child, internalised in domestic Peruvian law via Resolución Legislativa 25278.
5.2 Best-interest-of-the-child principle (CNA Art IX Título Preliminar + Ley 30466)
CNA Art IX Título Preliminar establishes the interés superior del niño y del adolescente as the controlling principle for any decision that concerns a child. Ley 30466 codifies the procedural parameters and guarantees for the primordial consideration of the best interest of the child in any administrative or judicial decision: (i) due-process safeguards in any decision that affects a child; (ii) the right of the child to be heard in matters that concern them; (iii) the duty of the decision-maker to expressly motivate any decision in light of the child's best interest. Balance's architectural posture is anchored on best interests — see our country classification table § 6 and Child Safety Standards § 5.
5.3 Right to intimacy of the child and adolescent (CNA Art 4)
CNA Art 4 protects the intimidad of children and adolescents — their right to private life, family life, correspondence, communications, honour, and image. Balance does not publish or share any kid's data with any audience outside the kid's own household; the proof-media payload is end-to-end encrypted and is delivered only to the kid's paired parent device(s).
5.4 Right to opinion (CNA Art 9) + Right to information (CNA Art 10)
CNA Art 9 codifies the kid's right to express their opinion freely in any matter that concerns them. CNA Art 10 codifies the kid's right to information appropriate to their age and maturity. Balance's architectural posture preserves both principles: the kid app's UI is designed for the kid; the kid sees their own limits, schedules, tasks, and earned-time ledger in their own kid-app UI; the kid can request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision.
5.5 No advertising directed at children — Ley 29571 Art 19
Ley 29571 Art 19 prohibits commercial advertising directed at children that takes advantage of their credulity or lack of experience, or that promotes behaviours that may harm their physical or mental integrity. Read with CN Art 4, CNA Arts IX + 4 + 9 + 10, and the ANPDP's interpretive practice on children's data, the substantive overlay is that advertising directed at children is a high-risk processing that requires a heightened consent standard and that must not be deceptive. Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.6 Cooperation routes (Sistema Nacional + MIMP)
The principal Peruvian child-protection bodies are: (i) Ministerio de la Mujer y Poblaciones Vulnerables (MIMP) — the cabinet-level child-rights authority and the Ente Rector of the Sistema Nacional de Atención Integral al Niño y al Adolescente; (ii) Demunas — Defensorías Municipales del Niño y del Adolescente — district-level child-defender offices; (iii) Programa Nacional Aurora of the MIMP — for violence against women and children; (iv) Defensoría del Pueblo — Adjuntía para la Niñez y la Adolescencia — the constitutional ombudsperson's child-rights desk; (v) Línea 100 — the MIMP's 24-hour line for violence against children, adolescents, women, and family. Balance cooperates with each on incidents that involve Peruvian kids — see § 14 below.
6. LPDP Articles 18–24 + DS 016-2024-JUS — the rights, the timeline, and how to exercise them
6.1 The rights catalogue
A Peruvian resident has the following rights under the LPDP. The article-list mirrors LPDP Arts 18–24 + DS 016-2024-JUS rights-procedure rules as in force at the Effective date.
- LPDP Art 18 — Right to information. The right to be informed, at the time of collection, of (i) the existence of the personal-databank; (ii) the identity of the controller and (where applicable) the OPDP; (iii) the purposes of the processing; (iv) the recipients of the data; (v) the existence of cross-border transfers; (vi) the data subject's rights and how to exercise them; (vii) the consequences of not providing the data. Satisfied by the global Privacy Policy + this Annex + the in-app consent screen.
- LPDP Art 19 — Right of access. The right to obtain confirmation that personal data are being processed and to receive the data, the purposes, the categories of data, the recipients, and the cross-border transfers. Honored at
and in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a Spanish plain-language summary. - LPDP Art 20 — Right to update, inclusion, and rectification. The right to require the controller to update, complete, or correct personal data. Honored in-app at Settings → Account → Edit and at
. - LPDP Art 20 — Right to suppression (cancelación / supresión). The right to require the controller to delete personal data where the data are inaccurate, incomplete, outdated, or no longer necessary for the purposes for which they were collected. Honored at Settings → "Delete my account" / "Delete this kid"; at Delete-account page; or at
. Cascade per Data Retention & Deletion Policy § 7. - LPDP Art 22 — Right of opposition. The right to oppose the processing where the lawful basis is something other than the data subject's express consent, where the data subject has a legitimate motive that justifies the opposition. Honored at the same channels.
- LPDP Art 23 — Right to anonymisation (tratamiento objetivo). The right to require the anonymisation of the data so that the data subject is no longer identifiable. Honored where technically feasible.
- LPDP Art 23 — Right to not be subject to a decision based solely on automated processing. The right not to be subject to a decision that produces legal effects for, or substantially affects, the data subject and that is based solely on automated processing. Balance's architectural posture is that the earned-time ledger is deterministic (parent-defined rules) and is reviewable by the parent at any time — there is no decision based solely on automated processing that produces legal effects for, or substantially affects, the data subject within the meaning of Art 23.
- LPDP Art 24 — Right of tutela (administrative protection). The right to file a complaint before the ANPDP where the controller has not honored the rights at Arts 19–23. The procedure is set out in DS 016-2024-JUS.
- CN Art 200(3) — Acción de habeas data. The constitutional remedy under the Código Procesal Constitucional (Ley 31307 de 2021). The acción de habeas data is the principal fast-track constitutional remedy. Available at first-instance to any juez constitucional with jurisdiction.
6.2 Timeline
- Information (Art 18): discharged at the time of collection.
- Access (Art 19): the controller must respond within 20 working days of the request (DS 016-2024-JUS rights-exercise rules).
- Update / rectification / suppression / opposition / anonymisation (Arts 20–23): the controller must respond within 10 working days of the request, with the action carried out within an additional 5 working days where the request is well-founded (DS 016-2024-JUS rights-exercise rules).
- ANPDP tutela complaint (Art 24): the ANPDP processes complaints on its own administrative timeline.
- Acción de habeas data (CN Art 200(3)): first-instance decision within the Código Procesal Constitucional timeline; review available on appeal.
Where the request is manifestly unfounded or excessive (in particular because of its repetitive character), Balance may charge a reasonable fee based on administrative cost or refuse to act on the request; the data subject is told the reason and is informed of the right to file a tutela complaint with the ANPDP and to seek constitutional habeas data redress.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity (DS 016-2024-JUS rights-exercise rules). The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification (e.g., a copy of the Peruvian Documento Nacional de Identidad (DNI) or Carné de Extranjería) is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.
6.4 No cost
The exercise of the LPDP Arts 18–24 rights is free of charge for the first request in any 6-month period (DS 016-2024-JUS rights-exercise rules). A fee may only be charged for repeat requests within the same period.
6.5 Language
A request may be submitted in Spanish (preferred for Peruvian residents) or in English.
7. Children's data — LPDP + DS 016-2024-JUS + CNA + patria potestad doctrine
Ley 29733 does not contain an explicit children-specific article equivalent to GDPR Art 8, but DS 016-2024-JUS Title V (the Reglamento's children's-data title) operationalises the protection of children's and adolescents' personal data with the following principal elements:
- Processing of personal data of children (under 12) and adolescents (12–17) is admissible only where (i) it serves the best interest of the child; (ii) it respects the kid's fundamental rights including the right to intimacy and the right to be heard; (iii) the parent or legal guardian has given express, informed, prior, and free consent under the LPDP Art 13 standard, applied under the CNA patria potestad doctrine of the Código Civil Arts 419 et seq.
- The consent must be specific to the categories of data and to the purposes for which they are processed.
- The processing must be subject to enhanced security and confidentiality safeguards (DS 016-2024-JUS).
- The data subject (the kid) has the right to be informed in age-appropriate language and to be heard in matters that concern them (CNA Art 9 + Ley 30466).
For Balance:
- Children and adolescents (under 18). Processing requires the express, informed, prior, and free consent of the parent or legal guardian. Balance obtains this via the VPC mechanism in United States annex § 5 (the same VPC mechanism is engaged for Peruvian residents): email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device, accompanied by a Spanish-language Verifiable Parental Consent screen that itemises the categories of data being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights (cross-reference: LPDP Art 18 + DS 016-2024-JUS Title V).
- No kid-self-serve consent path. Balance's architectural posture is identical regardless of the kid's age — the parent always consents on behalf of the kid; there is no kid-self-serve consent path inside Balance. This is the most-protective reading of CN Art 4 + CNA Arts I + IX + 4 + 9 + 10 + LPDP Arts 13 + 14 + DS 016-2024-JUS Title V + Ley 30466 + the Código Civil patria potestad doctrine.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from Peru
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Peruvian resident's data leaves Peru at the point of being uploaded to the Balance backend.
8.1 Transfer mechanism — LPDP Article 15 + DS 016-2024-JUS
LPDP Art 15 prohibits the transfer of personal data to countries that do not provide an adequate level of protection, except where the data subject has given prior, informed, express, and unequivocal consent OR one of the statutory carve-outs applies. The statutory carve-outs in LPDP Art 15 + DS 016-2024-JUS include: (a) the data subject's prior, informed, express consent; (b) judicial cooperation under international treaty; (c) the transfer is necessary for the performance of a contract between the data subject and the controller, or for pre-contractual measures requested by the data subject; (d) bank or stock-exchange transfers necessary for the processing of the data subject's transactions; (e) the transfer is necessary for the protection of the vital interests of the data subject; (f) the transfer is necessary for medical assistance; (g) the transfer is to an international organisation in the exercise of its functions; (h) the transfer is to a country that the ANPDP has declared to provide an adequate level of protection.
DS 016-2024-JUS modernised the cross-border-transfer regime by introducing GDPR-aligned overlays — adequacy decisions by the ANPDP; Cláusulas Tipo (Peruvian SCCs, to be issued by the ANPDP); Binding Corporate Rules approved by the ANPDP; codes of conduct approved by the ANPDP; specific derogations for explicit consent, contract performance, judicial cooperation, vital interests, public interest, and legal claim.
The ANPDP adequacy list does NOT include the United States as of the Effective date.
Balance relies on the following stack to satisfy Art 15 + DS 016-2024-JUS for the PE → US transfer:
- Express, informed, prior, and unequivocal consent of the parent (LPDP Art 15 first paragraph + DS 016-2024-JUS). The parent's sign-up consent prominently discloses the international transfer (cross-reference: Privacy Policy § 12 + the in-app Spanish-language consent screen, which itemises the country of destination — the United States — and the categories of recipients).
- Contract-performance carve-out (LPDP Art 15 + DS 016-2024-JUS). The transfer is necessary for the performance of the subscription contract between the parent and Balance and for the delivery of the parental-control service the parent contracted for.
- Contractual clauses replicating LPDP standards. Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor DPA that incorporates contractual clauses replicating the LPDP standards, with EU-SCC substance as the substantive overlay. The full transfer pack is in our international-transfer pack § 6. Where the ANPDP publishes its Cláusulas Tipo template, those Cláusulas Tipo will be signed with each US sub-processor as an additional layer.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's DPA forbids onward transfer of Peruvian-resident data to a third country outside the Art 15 framework without the controller's prior written authorisation.
8.2 EU adequacy is not the transfer tool for PE-to-US
The European Commission has not issued an adequacy decision in respect of Peru under GDPR Art 45. The EU position on Peru is under assessment. The EU adequacy path is not available as a transfer tool for any Peru-resident leg at the Effective date or in the short-to-medium term.
8.3 Transfer mechanism — the PE-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan is not on the ANPDP adequacy list, the PE-KZ axis is covered by contractual clauses replicating LPDP standards signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The Kazakhstan personal-data-protection regime (Закон Республики Казахстан "О персональных данных и их защите" № 94-V of 21 May 2013, as amended) is the substantive overlay; the transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
8.4 LPDP Article 15 (b)(d)(e)(f)(g) carve-outs — not relied upon
Balance does not rely on the Art 15 carve-outs for judicial cooperation, bank/stock-exchange transfers, vital interests, medical assistance, or international-organisation transfers as the basis for routine transfers — those carve-outs are reserved for case-by-case scenarios, not for routine flows.
9. Data residency for Peruvian residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Peruvian resident's data held in Peru? | No. Every Peruvian resident's data is held in the United States. The LPDP Art 15 + DS 016-2024-JUS transfer mechanism in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor DPAs and via LPDP-standards contractual clauses in the inverse arrangement in § 8.3. |
| Is there a Peruvian establishment? | No. Balance has no permanent establishment in Peru. |
| Where is the supervisory authority? | Peru — Autoridad Nacional de Protección de Datos Personales (ANPDP), Calle Scipión Llona 350, Miraflores, Lima 15074. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Peru does not impose a comprehensive data-localisation mandate on parental-control services as of the Effective date.
10. Sub-processors touching Peruvian resident data
| Sub-processor | Role | Location of processing | Peruvian transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | Parent's express consent (LPDP Art 15) + contract-performance carve-out + LPDP-standards contractual clauses on file per our international-transfer pack § 6; ANPDP Cláusulas Tipo to be added on publication; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
Parent's express consent + LPDP-standards contractual clauses on file as part of the Google Cloud Data Processing Addendum; ANPDP Cláusulas Tipo to be added on publication; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
Parent's express consent + LPDP-standards contractual clauses on file as part of the Google Cloud Data Processing Addendum; ANPDP Cláusulas Tipo to be added on publication; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Peruvian kid + parent devices | United States | Parent's express consent + LPDP-standards contractual clauses as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | Parent's express consent + LPDP-standards contractual clauses as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | Parent's express consent + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Peruvian parent users | United States | Parent's express consent + LPDP-standards contractual clauses on file. |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + DS 016-2024-JUS security duties. The full sub-processor list, with each row's DPA status and contractual-clause execution date, is at our sub-processor register.
11. Breach notification — DS 016-2024-JUS
DS 016-2024-JUS introduced an explicit breach-notification regime (the original Decreto Supremo 003-2013-JUS did not contain one):
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| ANPDP | A security incident affecting personal data that is reasonably likely to cause damage to data subjects. | Within 48 hours of the controller becoming aware — DS 016-2024-JUS anchors a 48-hour benchmark to the ANPDP. Where the controller cannot provide all the elements within 48 hours, the notification is filed initially and supplemented as the forensic picture develops. | The ANPDP's online incident-notification form per DS 016-2024-JUS, filed in Spanish by the OPDP or by external Peruvian counsel acting on the OPDP's instructions. |
| Affected data subjects | A breach likely to result in a high risk to the rights and freedoms of natural persons. | Within 5 working days of the controller becoming aware — DS 016-2024-JUS. | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in Spanish (or in the language the parent has selected). |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | Línea 100 MIMP + PNP DIVINDAT + Ministerio Público Fiscalía Especializada en Ciberdelincuencia + Demuna + Defensoría del Pueblo Adjuntía para la Niñez. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, ANPDP notification within the 48-hour benchmark, affected-data-subject notification within the 5-working-day window.
11.1 Minimum content of the ANPDP notification (DS 016-2024-JUS)
The ANPDP notification states:
- the nature of the personal data affected;
- the categories and approximate number of data subjects involved;
- the technical and security measures in place at the time of the incident;
- the risks for the data subjects;
- the measures adopted or proposed to mitigate the effects of the incident;
- the OPDP contact point (, named individual: ).
The English-language template lives in our breach-notification runbook § 8.1; the Spanish rendering is produced by external Peruvian counsel on filing.
12. Cookies and electronic direct marketing
Peru does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) LPDP Art 13 consent as the lawful basis for any cookie that processes personal data; (ii) DS 016-2024-JUS Privacy-by-Design and Privacy-by-Default principles; (iii) Ley 28493 (anti-spam) — restricts unsolicited commercial email and requires the supplier to obtain prior consent, identify the email as commercial (with the prefix "PUBLICIDAD:" in the subject line), and provide a free unsubscribe mechanism; (iv) Ley 29571 (CDC) provisions on pre-contract information, deceptive advertising (Art 14), and abusive terms (Art 50).
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent in the Spanish-language consent screen.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send electronic direct marketing to Peruvian residents. The only email Balance sends to Peruvian parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. Ley 28493 + Decreto Supremo 031-2005-MTC require pre-existing consent (or a free, easy opt-out under the régimen de opt-out), the "PUBLICIDAD:" subject-line prefix, supplier identification, and a free unsubscribe mechanism for any commercial communication; if Balance ever introduces a marketing channel, we will comply with the Ley 28493 + DS 031-2005-MTC rules.
13. Lawful-access requests and the encryption posture
Peruvian authorities may serve a lawful-access request on Balance via:
- A judicial order under the Código Procesal Penal (Decreto Legislativo 957 of 2004, in force progressively from 2006).
- A Ministerio Público — Fiscalía de la Nación request under the Ley Orgánica del Ministerio Público (Decreto Legislativo 052 of 1981).
- A judicial intercept order under Ley 27697 de 2002 (interception of telecommunications for crime-prevention investigations) + Código Procesal Penal Arts 230 et seq.
- A juez constitucional order in the acción de habeas data civil procedure (CN Art 200(3) + Código Procesal Constitucional Ley 31307 de 2021).
- A judicial order in the ordinary civil procedure (Código Procesal Civil — Decreto Legislativo 768 of 1992).
- An ANPDP information-request under Ley 29733 + DS 016-2024-JUS.
- An INDECOPI information-request under Ley 29571 + Decreto Legislativo 1033.
- A judicial order under the Convenio sobre la Ciberdelincuencia (Budapest Convention; in force for Peru since 1 December 2019) — channeled via the Punto de Contacto 24/7 under Art 35 Budapest Convention.
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Peruvian counsel to assess the validity of the request and the appropriate response; 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the Policía Nacional del Perú — División de Investigación de Delitos de Alta Tecnología (DIVINDAT), the Ministerio Público — Fiscalías Especializadas en Ciberdelincuencia, and the Fiscalías Especializadas en Delitos de Trata de Personas, on any CSAE-related referral, via the routes in § 14 below.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — Peru
A Peruvian resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in Spanish for Peruvian reporters. - Línea 100 — Ministerio de la Mujer y Poblaciones Vulnerables (MIMP) — the national 24-hour line for violence against children, adolescents, women, and family. Online:
https://www.gob.pe/8487(CHAT 100). Toll-free within Peru: 100. - Demunas — Defensorías Municipales del Niño y del Adolescente — district-level child-defender offices. Located in every municipality; published list at
https://www.gob.pe/mimp. - Policía Nacional del Perú — División de Investigación de Delitos de Alta Tecnología (DIVINDAT) —
https://www.policia.gob.pe/. The principal cybercrime investigation unit. Emergency: 105. - Policía Nacional del Perú — División de Investigación de Trata de Personas y de Tráfico Ilícito de Migrantes (DIRINTRAP) — for CSAE / trafficking matters.
- Ministerio Público — Fiscalía de la Nación — Fiscalías Especializadas en Ciberdelincuencia —
https://www.gob.pe/mpfn. - Ministerio Público — Fiscalías Especializadas en Delitos contra la Trata de Personas y de Tráfico Ilícito de Migrantes —
https://www.gob.pe/mpfn. - Programa Nacional Aurora — MIMP — for violence against women, children, and adolescents.
https://www.gob.pe/aurora. - Defensoría del Pueblo — Adjuntía para la Niñez y la Adolescencia —
https://www.defensoria.gob.pe/. - Te Protejo Perú — the Peruvian arm of the INHOPE-aligned regional hotline network. Online: report intake at
https://www.teprotejo.org/(Latin American regional intake page). - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Peruvian partners include CHS Alternativo (https://chsalternativo.org/) and Save the Children Perú.
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
A Peruvian resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| Autoridad Nacional de Protección de Datos Personales (ANPDP) | LPDP + DS 016-2024-JUS + ANPDP Resoluciones Directorales | Calle Scipión Llona 350, Miraflores, Lima 15074; https://www.gob.pe/anpdp |
| INDECOPI — Instituto Nacional de Defensa de la Competencia y de la Protección de la Propiedad Intelectual | Ley 29571 Código de Protección y Defensa del Consumidor + Ley 28493 anti-spam | Calle de la Prosa 104, San Borja, Lima 41; https://www.gob.pe/indecopi |
| Ministerio Público — Fiscalía de la Nación | Cybercrime + child-sexual-exploitation + criminal LPDP-grounded prosecutions (Código Penal Arts 154, 154-A, 183-A, 183-B) | https://www.gob.pe/mpfn |
| Defensoría del Pueblo — Adjuntía para la Niñez y la Adolescencia | Constitutional human-rights ombudsperson; child-rights complaints | https://www.defensoria.gob.pe/ |
| Demuna — Defensoría Municipal del Niño y del Adolescente | Child-rights first-line forum at the municipal level | Per municipality |
| Poder Judicial — juez constitucional (acción de habeas data) | CN Art 200(3) + Código Procesal Constitucional (Ley 31307 de 2021) | Per jurisdiction |
| Poder Judicial — jueces civiles / jueces de familia | Ordinary civil and family-court actions | Per jurisdiction |
A Peruvian resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the OPDP). We will respond within the DS 016-2024-JUS rights-exercise windows (20 working days for access; 10 working days for rectification / suppression / opposition / anonymisation, plus 5 working days for execution). Raising the matter with us first is not a precondition to filing a tutela complaint with the ANPDP, an acción de habeas data, or any other constitutional, civil, or criminal remedy; the ANPDP accepts complaints directly.
16. Consumer rights — the Ley 29571 overlay
Ley 29571 (the Código de Protección y Defensa del Consumidor, "CDC") is the principal Peruvian consumer-protection statute. Where the parent is acting as a consumidor within the meaning of CDC Art IV, the following overlays apply to the subscription purchase flow and to the Terms of Service.
16.1 Pre-contract information (CDC Arts 2 + 47)
The parent is entitled to información veraz, suficiente, oportuna, accesible, clara y comprensible on the essential characteristics of the service. CDC Art 47 sets the minimum pre-contract information for distance contracts. Implemented in Subscription Terms § 5.
16.2 7-working-day right of retraction — derecho de retracto (CDC Art 59)
CDC Art 59 grants the consumer a 7-working-day right of retraction for distance contracts, computed from the date of the contract. This is the Peruvian equivalent of the Argentine botón de arrepentimiento (AR Annex § 16.2), the Chilean derecho de retracto (CL Annex § 16.2), and the Colombian derecho de retracto (CO Annex § 16.2). Balance's subscription is concluded at a distance (in-app); the 7-working-day right of retraction applies and is implemented in Subscription Terms § 20. The right of retraction is honored regardless of whether the parent has used the service in the 7-working-day window — the parent is entitled to a full refund through the Google Play Billing refund route.
16.3 Abusive contract terms (CDC Art 50)
CDC Art 50 declares null any contract term that (i) limits the supplier's liability for damages contrary to public order; (ii) reverses the burden of proof to the consumer's detriment; (iii) imposes a unilateral right of termination on the supplier; (iv) contains other terms tending to violate the consumer's rights. The Balance Terms of Service (Terms of Service) are drafted to avoid each Art 50 risk.
16.4 Advertising directed at children (CDC Art 19)
CDC Art 19 prohibits commercial advertising directed at children that takes advantage of their credulity or lack of experience, or that promotes behaviours that may harm their physical or mental integrity. Read with CN Art 4, CNA Arts IX + 4 + 9 + 10, and the LPDP children's-data principles, the prohibition operates as the substantive ceiling on any commercial communication that might be directed at a kid. Balance does not display any advertising — see § 5.5 above.
16.5 Forum and INDECOPI procedure
CDC Art 105 + INDECOPI procedural rules operate on a consumer-protective basis. The consumer may file an Asociación de Consumidores claim under CDC Art 70, or seek individual redress at INDECOPI's Comisión de Protección al Consumidor under CDC Arts 105 et seq.; appeal lies to INDECOPI's Tribunal de Defensa de la Competencia y de la Protección Intelectual. The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace Peruvian law to the prejudice of the Peruvian consumer are presumptively null under CDC Art 50.
16.6 Libro de Reclamaciones
CDC Art 150 + Decreto Supremo 011-2011-PCM require the supplier to maintain a Libro de Reclamaciones (physical or virtual book of complaints) accessible to consumers. Balance's online complaint route at + the in-app Settings → Help → "Submit a complaint" affordance + the public-website complaint intake satisfy the Libro de Reclamaciones requirement in its virtual form per Decreto Supremo 006-2014-PCM.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — LPDP-standards contractual clauses on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA).
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the LPDP (Ley 29733) or the enactment of any successor statute triggers an off-cycle rewrite of §§ 2, 4, 6, 7, 8, and 11.
- A material amendment to DS 016-2024-JUS or its replacement by a successor Decreto Supremo triggers an off-cycle rewrite of the affected operational sections.
- A new ANPDP Resolución Directoral that materially affects Balance's posture triggers an off-cycle update to the relevant operational section.
- A material amendment to the CNA (Ley 27337) or Ley 30466 triggers an off-cycle update to § 5 + § 7 + § 14.
- A material amendment to Ley 29571 (CDC) or its implementing decrees (DS 011-2011-PCM; DS 006-2014-PCM) that materially affects the subscription flow triggers an off-cycle update to § 16 + Subscription Terms.
- A material amendment to Ley 30096 (cybercrime), Ley 30838 (sexual offences against children), or Código Penal Arts 154 / 154-A / 183-A / 183-B triggers an off-cycle update to § 13 + § 14.
- A material amendment to Ley 28493 (anti-spam) or DS 031-2005-MTC triggers an off-cycle update to § 12.3.
- A material Sentencia of the Tribunal Constitucional del Perú that materially affects the constitutional interpretation of CN Art 2(6) / Art 2(7) / Art 200(3) triggers an off-cycle update to the relevant operational section.
- The European Commission issuing an adequacy decision in respect of Peru, or Peru acceding to Convention 108+, triggers an off-cycle update to § 8.
- A material change to a sub-processor's Peruvian contractual-clause status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The Privacy Officer signs the review off; the Designated Child Safety Officer co-signs any change to § 5 (CNA / Ley 30466), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The authoritative Spanish-language version is republished at Peru annex.
End of Peru Country Annex.