← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Peru Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Peruvian resident covered by this Annex, and the Oficial de Protección de Datos Personales designated under Decreto Supremo 016-2024-JUS Art 38 read with Ley 29733. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to Ley 29733 — Ley de Protección de Datos Personales (the "LPDP"), (b) any amendment to Decreto Supremo 016-2024-JUS (the Reglamento de la Ley 29733, published El Peruano 9 August 2024 with a 180-day vacatio legis; in force since 6 February 2025; superseded Decreto Supremo 003-2013-JUS) or any successor Decreto Supremo of the Ministerio de Justicia y Derechos Humanos (MINJUSDH), (c) any Resolución Directoral of the Autoridad Nacional de Protección de Datos Personales (ANPDP) — particularly Resoluciones on cross-border transfers, breach notification, the Registro Nacional de Protección de Datos Personales (RNPDP), and children's-data — that materially alters the operational rules below, (d) any amendment to Ley 27337 — Código de los Niños y Adolescentes (the "CNA"), (e) any amendment to Ley 30466 (procedural parameters and guarantees for the primordial consideration of the best interest of the child), (f) any amendment to Ley 29571 — Código de Protección y Defensa del Consumidor (the "CDC") or its Reglamento (Decreto Supremo 011-2011-PCM and successors) issued by the Instituto Nacional de Defensa de la Competencia y de la Protección de la Propiedad Intelectual (INDECOPI), (g) any amendment to Ley 30096 — Ley de Delitos Informáticos (as modified by Ley 30171) or to Ley 30838 (which strengthened Código Penal offences for sexual proposals to children and adolescents — Art 183-B), (h) any Sentencia of the Tribunal Constitucional del Perú that materially changes the interpretation of CN Art 2(6) / Art 2(7) (rights to intimacy and protection of personal data) or Art 200(3) (constitutional garantía of habeas data), (i) Peru's accession to Convention 108+ (Peru is invited but accession is pending at the Effective date), (j) the European Commission issuing an adequacy decision in respect of Peru under GDPR Art 45 (none in force at the Effective date), or (k) any change to a sub-processor's Peru data-handling posture under our sub-processor register. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Peru-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Peruvian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Peruvian resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The authoritative Spanish-language version is republished at Peru annex as part of the Phase-2 locale rollout. In the event of a discrepancy between the English text and the Spanish text, the Spanish text prevails for Peruvian residents.


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of Peru ("Peru"), without distinction between the 24 departamentos and the Provincia Constitucional del Callao.

We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Peru as the country of residence, this Annex applies, even if the other signals are non-Peruvian. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The LPDP has extraterritorial effect under its Art 3 read with DS 016-2024-JUS Art 4: the LPDP applies whenever the controller is established in Peru, whenever the processing is carried out by means in Peru, or whenever the controller, even without being established in Peru, offers goods or services to Peruvian residents or monitors their behaviour to the extent that the behaviour takes place in Peru. The ANPDP's interpretive practice — expressed in its Resoluciones Directorales and in its published Concept Notes — confirms the GDPR-Art-3(2)-aligned scope. Balance squarely targets Peruvian residents through Google Play and through publication of this Annex at balance.babayagaprogram.com.


2. Statutory framework — what applies

The Peruvian data-protection and online-safety regime sits at the intersection of the Constitución Política del Perú 1993, the Ley 29733 of 2011 and its Reglamento (Decreto Supremo 016-2024-JUS of 2024, which superseded Decreto Supremo 003-2013-JUS), the Código de los Niños y Adolescentes (Ley 27337) read with the procedural best-interest statute (Ley 30466), the Código Penal as modified by Ley 30096 (cybercrime) and Ley 30838 (sexual-offences-against-children strengthening), the Código de Protección y Defensa del Consumidor (Ley 29571), and a body of Resoluciones Directorales issued by the ANPDP.

Instrument Short cite What it does Balance's posture
Constitución Política del Perú 1993 CN, as amended; Art 2(5) (right of access to public information held by State entities); Art 2(6) (right that information services, whether computerised or not, do not provide information that affects personal and family intimacy); Art 2(7) (right to honour and good reputation, to personal and family intimacy, and to the protection of voice and image); Art 200(3) (constitutional acción de habeas data); Art 4 (the community and the State protect the child and the adolescent). The constitutional anchor for the personal-data-protection regime and for the child-rights regime. The acción de habeas data under Art 200(3) is the principal constitutional remedy available to a Peruvian data subject; the Tribunal Constitucional del Perú has built a body of jurisprudence interpreting Arts 2(6), 2(7), and 200(3) in the digital environment. Applies in full as the foundational constitutional layer. Treatment in §§ 3, 5, 6, 7, 13 below.
Ley 29733 — Ley de Protección de Datos Personales LPDP — Ley 29733 of 21 June 2011, in force since 22 July 2013 The principal data-protection regime: definitions (Art 2); principles — legality, consent, purpose, proportionality, quality, security, fitness, level-of-protection, and disposability (Arts 4–12); lawful bases — Art 13 (general rules) + Art 14 (limitations on consent); special-category data — Art 16 + Art 17; rights of the data subject — Arts 18–24 (information, access, update/inclusion/rectification/suppression, opposition, anonymisation, derecho a no ser objeto de decisiones automatizadas, derecho de tutela); international transfers — Art 15; supervisory authority — Arts 32–36 (the Autoridad Nacional de Protección de Datos Personales); sanctions — Arts 37–41; the Registro Nacional de Protección de Datos Personales (RNPDP) — Art 32(c). Applies in full. Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Decreto Supremo 016-2024-JUS Reglamento de la Ley 29733 — published Diario Oficial El Peruano on 9 August 2024 with a 180-day vacatio legis; in force since 6 February 2025; superseded Decreto Supremo 003-2013-JUS of 22 March 2013 The modernised operational rules for the LPDP, with substantial GDPR-aligned overlays: definitions of controller and processor; Privacy by Design and Privacy by Default; the Oficial de Protección de Datos Personales (OPDP — the LPDP-mandated DPO) regime; the Evaluación de Impacto en la Protección de Datos Personales (EIPDP — Peru's DPIA equivalent) for high-risk processing; the updated cross-border-transfer rules; the breach-notification regime with a 48-hour benchmark to the ANPDP and a 5-working-day data-subject-notification track; the RNPDP registration rules; the Manual de Tratamiento de Datos Personales; the children's-data treatment with reinforced parental-consent and best-interest treatment. Applies as the principal operational rules layer on top of Ley 29733. Balance's OPDP, EIPDP, and Manual artefacts are cross-referenced in our Records of Processing Activities (Article 30) § 7 and our Data Protection Impact Assessment (the global DPIA satisfies the Peruvian EIPDP).
Decreto Supremo 003-2013-JUS Original Reglamento de la Ley 29733 of 22 March 2013 — superseded by DS 016-2024-JUS The original operational rules. Not in force at the Effective date except as cited in legacy Resoluciones Directorales of the ANPDP. Not in force. Listed here for completeness only.
ANPDP Resoluciones Directorales The ANPDP's binding administrative acts. Principal Resoluciones in force at the Effective date include: Resolución Directoral 001-2020-JUS/DGTAIPD (interpretive criteria on consent), the Resoluciones on cross-border transfers (the ANPDP's adequacy-finding mechanism), the Resoluciones on breach-notification operationalisation, the Resoluciones on the RNPDP, and the Resoluciones on children's-data — as published at the ANPDP portal (currently https://www.gob.pe/anpdp and the legacy https://www.minjus.gob.pe/). Sets the binding interpretive layer on the LPDP and DS 016-2024-JUS. Applies. Balance's processing is operationalised consistently with the ANPDP's Resoluciones.
Ley 27337 — Código de los Niños y Adolescentes CNA — Ley 27337 of 21 July 2000, as amended The principal child-protection statute. Defines niño (under 12) and adolescente (12–17) at Art I of the Título Preliminar. Codifies the interés superior del niño y del adolescente (best-interest principle) at Art IX of the Título Preliminar. Codifies the rights to intimidad (Art 4), to honour and image (Art 4), to opinion (Art 9), and to information (Art 10). Establishes the Sistema Nacional de Atención Integral al Niño y al Adolescente and the Ente Rector (the Ministerio de la Mujer y Poblaciones Vulnerables — MIMP). Applies in full to every Peruvian kid covered by this Annex. Treatment in §§ 5, 7, 14 below.
Ley 30466 Ley que establece parámetros y garantías procesales para la consideración primordial del interés superior del niño of 17 June 2016 + its Reglamento (Decreto Supremo 002-2018-MIMP) Codifies the procedural parameters and guarantees for the primordial consideration of the best interest of the child in any administrative or judicial decision that concerns a child. Operationalises the constitutional best-interest principle as a procedural standard. Applies. Treatment in § 5 below.
Ley 30362 Ley que eleva a rango de ley el Decreto Supremo 001-2012-MIMP and reinforces the protection of children against violence Reinforces the prevention-of-violence-against-children regime. Applies. Cross-reference in Child Safety Standards § 5.
Ley 30096 — Ley de Delitos Informáticos Ley 30096 of 22 October 2013, as modified by Ley 30171 of 10 March 2014 The cybercrime statute, aligned with the Budapest Convention on Cybercrime (to which Peru acceded via Resolución Legislativa 30913 of 12 February 2019, with the instrumento de adhesión deposited 26 August 2019). Codifies illicit access to a computer system (Art 2), illicit interference with a system (Art 3), illicit interference with data (Art 4), illicit interception of data (Art 7), computer fraud (Art 8), identity theft (Art 9), illicit dissemination of CSAM (Art 5), online-grooming proposals to children/adolescents (Art 5 read with Código Penal Art 183-B as strengthened by Ley 30838 of 2018), discrimination via computer means (Art 11), abuse of computer mechanisms for sexual offences against children and adolescents (Art 5). Applies. Cross-reference in Child Safety Standards § 8 (Peru CSAE routes — see § 14 below).
Ley 30838 de 2018 Ley que modifica el Código Penal y el Código de Ejecución Penal para fortalecer la prevención y sanción de los delitos contra la libertad e indemnidad sexuales of 4 August 2018 Strengthens the Código Penal offences for sexual offences against children and adolescents. Modified Código Penal Art 183-B (sexual proposals to children and adolescents — the online-grooming offence) and Arts 170-A, 172, 173, 175, 176-A, and 183. Applies. Cross-reference in Child Safety Standards § 8.
Código Penal (Decreto Legislativo 635 de 1991) Código Penal — relevant articles at the Effective date: Art 154 (violación de la intimidad); Art 154-A (tráfico ilegal de datos personales — inserted by Ley 30171); Art 154-B (difusión de imágenes, materiales audiovisuales o audios con contenido sexual); Art 153 (trata de personas); Art 153-A (formas agravadas de trata de personas); Art 183-A (pornografía infantil); Art 183-B (proposiciones a niños, niñas y adolescentes con fines sexuales por medios tecnológicos — the online-grooming offence as strengthened by Ley 30838); Art 176-A (actos contra el pudor en menores); Art 207-A/B/C/D (delitos informáticos — predating Ley 30096). The Peruvian criminal-law backbone for CSAM, online grooming, child-sexual-exploitation offences, and personal-data-trafficking offences. Applies. Cross-reference in Child Safety Standards § 8 (Peru CSAE routes — see § 14 below).
Ley 29571 — Código de Protección y Defensa del Consumidor CDC — Ley 29571 of 1 September 2010, as amended; implementing decree Decreto Supremo 011-2011-PCM The principal consumer-protection statute. Art 1 (rights of the consumer); Art 2 (information); Art 14 (advertising); Art 19 (advertising directed at children); Art 47 (información mínima — minimum pre-contract information); Art 59 (derecho de retracto — 7-working-day right of retraction for distance contracts); Art 50 (cláusulas abusivas — abusive contract terms); Art 38 (collective interests of consumers). The Peruvian supervisory authority is INDECOPIInstituto Nacional de Defensa de la Competencia y de la Protección de la Propiedad Intelectual. Applies to the subscription terms (Subscription Terms) and to the Terms of Service (Terms of Service). Treatment in § 16 below.
Ley 28493 — Ley que regula el uso del correo electrónico comercial no solicitado (SPAM) Ley 28493 of 12 April 2005 + Decreto Supremo 031-2005-MTC of 8 December 2005 Restricts unsolicited commercial email and electronic communications. Requires the supplier to obtain prior consent (or to provide a free, easy opt-out for the régimen de opt-out), to identify the email as commercial (with the prefix "PUBLICIDAD:" in the subject line), to identify the supplier and a return address, and to provide a free unsubscribe mechanism. Applies. Balance does NOT send electronic direct marketing to Peruvian residents — § 12.3 below.
Decreto Legislativo 1412 de 2018 — Ley de Gobierno Digital Decreto Legislativo 1412 of 12 September 2018 + its Reglamento (Decreto Supremo 029-2021-PCM) The Digital Government Act. Anchors the Secretaría de Gobierno y Transformación Digital (SGTD) of the Presidencia del Consejo de Ministros (PCM) as the policy coordinator for digital government. Sets cross-cutting principles for state digital services. Not directly applicable to Balance (Balance is not a State service), but anchors the policy environment in which the LPDP and its Reglamento operate.
Decreto Legislativo 1357 de 2017 Decreto Legislativo 1357 de 2017 Modified Ley 29733 in particular respects (Art 15 cross-border transfers and interest-protection updates). Applies as the substantive overlay on the original LPDP text.
Convention 108 + Convention 108+ + Budapest Convention Peru acceded to the Convention on Cybercrime (Budapest Convention, CETS 185) by Resolución Legislativa 30913 of 12 February 2019, with the instrumento de adhesión deposited on 26 August 2019 (in force for Peru since 1 December 2019). Peru is invited to accede to Convention 108+ (Council of Europe ETS 108 + CETS 223 of 18 May 2018); accession is pending at the Effective date. The Budapest Convention is in force for Peru and undergirds Ley 30096. Convention 108+ accession is pending. Relevant as context. Treatment in §§ 8, 13 below.
EU adequacy None as of the Effective date — Peru does not have an EU adequacy decision under GDPR Art 45. Distinct from Argentina (Decision 2003/490/EC) and Uruguay (Decision 2012/484/EU), Peru does not yet hold an adequacy finding. Relevant only as context. Balance's transfer mechanism for the PE-to-US leg does not rely on adequacy. Treatment in § 8 below.
Tribunal Constitucional del Perú jurisprudence Principal Sentencias on Arts 2(6) + 2(7) + 200(3): Exp. 1797-2002-HD/TC; Exp. 4739-2007-HD/TC; Exp. 02814-2011-PHD/TC; Exp. 02838-2014-PHD/TC; Exp. 4407-2017-PHD/TC (digital identity); the Tribunal's line on the autodeterminación informativa (informational self-determination) as a constitutional fundamental right. The Tribunal Constitucional has built a body of jurisprudence on the constitutional right of autodeterminación informativa and the acción de habeas data. Applies. Treatment in §§ 5, 6, 13 below.

(Any prospective Peruvian regulation governing automated processing, algorithmic decisions, or related techniques — including any ANPDP Resolución Directoral in that area and any Congressional proyecto de ley on such topics — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Peruvian regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. ANPDP — Supervisory authority

3.1 The ANPDP as supervisory authority

The supervisory authority for the LPDP is the Autoridad Nacional de Protección de Datos Personales ("ANPDP"), a specialised body within the Ministerio de Justicia y Derechos Humanos (MINJUSDH). The ANPDP is established under Ley 29733 Arts 32–36 + DS 016-2024-JUS Title VI. The ANPDP exercises regulatory, supervisory, enforcement, and sanctioning powers in respect of personal-data processing in Peru. The ANPDP is not autonomous in the manner of the AAIP (Argentina), or an EU DPA — it is a Dirección within MINJUSDH. A bill for the conversion of the ANPDP into an autonomous authority has been before the Congreso de la República in successive legislative sessions; the bill is not enacted at the Effective date.

Field Value
Name Autoridad Nacional de Protección de Datos Personales (ANPDP) — Dirección de la Autoridad Nacional de Protección de Datos Personales within the Ministerio de Justicia y Derechos Humanos
Headquarters Calle Scipión Llona 350, Miraflores, Lima 15074, Peru
General website https://www.gob.pe/anpdp (the consolidated gob.pe page); the legacy MINJUSDH portal at https://www.minjus.gob.pe/proteccion-de-datos-personales
Complaint / claim channel (Procedimientos administrativos — Denuncias y reclamos) The ANPDP's online intake at https://www.gob.pe/anpdp
Incident-notification channel The ANPDP's online incident-notification form per DS 016-2024-JUS Title VII
RNPDP — Registro Nacional de Protección de Datos Personales The ANPDP's online registry under Ley 29733 Art 32(c) + DS 016-2024-JUS Title VIII. Foreign controllers without permanent Peruvian establishment fall outside the registration scope under the ANPDP's interpretive practice
Email The ANPDP intake email published at the gob.pe page (general); judicial notifications at the MINJUSDH address
Phone The ANPDP central line published at the gob.pe page; MINJUSDH switchboard +51 1 204-8020
Director The head of the ANPDP is a Director appointed by the MINJUSDH; the appointment is made under MINJUSDH organisational rules

The ANPDP is the first-line forum for any LPDP-grounded complaint. A Peruvian resident may petition the ANPDP without first raising the matter with Balance. We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the Oficial de Protección de Datos Personales of Balance) and we will respond within the LPDP + DS 016-2024-JUS timelines (see § 6 below).

A Peruvian resident may also pursue private remedies against Balance via the acción de habeas data (the constitutional remedy under CN Art 200(3) + Código Procesal ConstitucionalLey 31307 de 2021); via the ordinary civil courts; or via the Ministerio Público where criminal offences under Código Penal Arts 154 (violación de la intimidad), 154-A (tráfico ilegal de datos personales), or 183-B (proposiciones a niños, niñas y adolescentes con fines sexuales) are engaged.

3.2 The Oficial de Protección de Datos Personales (OPDP)

DS 016-2024-JUS Art 38 requires the designation, by certain controllers, of an Oficial de Protección de Datos Personales (OPDP) — the LPDP-mandated DPO equivalent. The OPDP must be designated by every controller that, among other criteria, processes large volumes of personal data, processes sensitive personal data, or processes personal data of children and adolescents as a core activity. Balance's processing of children's data engages the OPDP-mandated controller category.

The Balance OPDP is: - , Director, BabaYaga Program, TOO — .

The OPDP's functions are: (a) inform and advise the controller and its personnel on LPDP and DS 016-2024-JUS obligations; (b) monitor compliance with the LPDP, DS 016-2024-JUS, and the ANPDP's Resoluciones Directorales; (c) cooperate with the ANPDP in any supervisory or investigation activity; (d) act as the contact point for data subjects on rights-exercise matters and for the ANPDP on regulatory matters; (e) lead the children's-data treatment under DS 016-2024-JUS Title V.

3.3 Registro Nacional de Protección de Datos Personales (RNPDP) — non-registration position

Ley 29733 Art 32(c) + DS 016-2024-JUS Title VIII require certain controllers to register their personal-databanks (bancos de datos personales) in the Registro Nacional de Protección de Datos Personales (RNPDP) maintained by the ANPDP. The ANPDP's published interpretive practice — codified in its Resoluciones Directorales and in its Concept Notes — is that foreign controllers without a permanent establishment in Peru are not required to register their databanks in the RNPDP; the obligation applies to controllers having a permanent establishment in Peru (which Balance does not).

Should the ANPDP's interpretive practice change, or should Balance ever establish a permanent presence in Peru, the registration will be filed within the statutory window prescribed by the ANPDP's RNPDP rules.


4. Lawful bases under the LPDP

Balance processes personal data of Peruvian residents on the following LPDP lawful bases. The mapping below is the canonical Balance-side bridge between each processing purpose and the LPDP lawful basis. The full record is in our Records of Processing Activities (Article 30).

Processing purpose Lawful basis (LPDP + DS 016-2024-JUS) Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) LPDP Art 13 — express, informed, prior, and free consent of the data subject (here, the parent at sign-up); supplemented by Art 14(5) — data necessary for the performance of a contractual relationship in which the data subject is a party H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data LPDP Art 14(6) — read with the protection-of-the-data-subject carve-out; supplemented by the constitutional best-interest principle under CN Art 4 + CNA Art IX Título Preliminar + DS 016-2024-JUS Title V (children's-data); the substantive instrument is the parent's affirmative consent under LPDP Art 13 + CNA patria potestad doctrine § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts LPDP Art 13 + Art 14(5) — consent + contractual relationship H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access LPDP Art 9 (security principle) + Art 14(7) — data necessary for the satisfaction of a legitimate interest of the controller; supplemented by DS 016-2024-JUS security obligations H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations (LPDP Arts 18–24 DSAR responses; DS 016-2024-JUS breach notification; ANPDP information requests; INDECOPI consumer-rights requests; CNA cooperation duties; CSAE-report obligations under Ley 30096 + Ley 30838 + Código Penal) LPDP Art 14(1) — data collected for the exercise of functions provided in laws § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data LPDP Art 13 — express, informed, prior, and free consent of the parent under the CNA patria potestad doctrine § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data LPDP Art 14(5) — necessary for the performance of the subscription contract H4; Ley 29571 overlay in § 16 below

Balance does not rely on the "public-source data" carve-out (LPDP Art 14(2) — data accessible from sources of public access) as a lawful basis for any kid-side processing.


5. CNA + Ley 30466 — children's rights overlay

Ley 27337 (Código de los Niños y Adolescentes — CNA) read with Ley 30466 (procedural parameters for the primordial consideration of the best interest of the child) is the principal Peruvian child-protection framework. The principal Balance-side handshakes are:

5.1 Definitions (CNA Art I Título Preliminar)

Under CNA Art I Título Preliminar, a child (niño) is a person from conception to 12 years of age; an adolescent (adolescente) is a person from 12 to under 18 years of age. The constitutional anchor is CN Art 4 (the community and the State protect the child and the adolescent in situation of abandonment, especially affecting their condition); the international anchor is the UN Convention on the Rights of the Child, internalised in domestic Peruvian law via Resolución Legislativa 25278.

5.2 Best-interest-of-the-child principle (CNA Art IX Título Preliminar + Ley 30466)

CNA Art IX Título Preliminar establishes the interés superior del niño y del adolescente as the controlling principle for any decision that concerns a child. Ley 30466 codifies the procedural parameters and guarantees for the primordial consideration of the best interest of the child in any administrative or judicial decision: (i) due-process safeguards in any decision that affects a child; (ii) the right of the child to be heard in matters that concern them; (iii) the duty of the decision-maker to expressly motivate any decision in light of the child's best interest. Balance's architectural posture is anchored on best interests — see our country classification table § 6 and Child Safety Standards § 5.

5.3 Right to intimacy of the child and adolescent (CNA Art 4)

CNA Art 4 protects the intimidad of children and adolescents — their right to private life, family life, correspondence, communications, honour, and image. Balance does not publish or share any kid's data with any audience outside the kid's own household; the proof-media payload is end-to-end encrypted and is delivered only to the kid's paired parent device(s).

5.4 Right to opinion (CNA Art 9) + Right to information (CNA Art 10)

CNA Art 9 codifies the kid's right to express their opinion freely in any matter that concerns them. CNA Art 10 codifies the kid's right to information appropriate to their age and maturity. Balance's architectural posture preserves both principles: the kid app's UI is designed for the kid; the kid sees their own limits, schedules, tasks, and earned-time ledger in their own kid-app UI; the kid can request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision.

5.5 No advertising directed at children — Ley 29571 Art 19

Ley 29571 Art 19 prohibits commercial advertising directed at children that takes advantage of their credulity or lack of experience, or that promotes behaviours that may harm their physical or mental integrity. Read with CN Art 4, CNA Arts IX + 4 + 9 + 10, and the ANPDP's interpretive practice on children's data, the substantive overlay is that advertising directed at children is a high-risk processing that requires a heightened consent standard and that must not be deceptive. Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.6 Cooperation routes (Sistema Nacional + MIMP)

The principal Peruvian child-protection bodies are: (i) Ministerio de la Mujer y Poblaciones Vulnerables (MIMP) — the cabinet-level child-rights authority and the Ente Rector of the Sistema Nacional de Atención Integral al Niño y al Adolescente; (ii) DemunasDefensorías Municipales del Niño y del Adolescente — district-level child-defender offices; (iii) Programa Nacional Aurora of the MIMP — for violence against women and children; (iv) Defensoría del Pueblo — Adjuntía para la Niñez y la Adolescencia — the constitutional ombudsperson's child-rights desk; (v) Línea 100 — the MIMP's 24-hour line for violence against children, adolescents, women, and family. Balance cooperates with each on incidents that involve Peruvian kids — see § 14 below.


6. LPDP Articles 18–24 + DS 016-2024-JUS — the rights, the timeline, and how to exercise them

6.1 The rights catalogue

A Peruvian resident has the following rights under the LPDP. The article-list mirrors LPDP Arts 18–24 + DS 016-2024-JUS rights-procedure rules as in force at the Effective date.

6.2 Timeline

Where the request is manifestly unfounded or excessive (in particular because of its repetitive character), Balance may charge a reasonable fee based on administrative cost or refuse to act on the request; the data subject is told the reason and is informed of the right to file a tutela complaint with the ANPDP and to seek constitutional habeas data redress.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity (DS 016-2024-JUS rights-exercise rules). The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification (e.g., a copy of the Peruvian Documento Nacional de Identidad (DNI) or Carné de Extranjería) is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.

6.4 No cost

The exercise of the LPDP Arts 18–24 rights is free of charge for the first request in any 6-month period (DS 016-2024-JUS rights-exercise rules). A fee may only be charged for repeat requests within the same period.

6.5 Language

A request may be submitted in Spanish (preferred for Peruvian residents) or in English.


7. Children's data — LPDP + DS 016-2024-JUS + CNA + patria potestad doctrine

Ley 29733 does not contain an explicit children-specific article equivalent to GDPR Art 8, but DS 016-2024-JUS Title V (the Reglamento's children's-data title) operationalises the protection of children's and adolescents' personal data with the following principal elements:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from Peru

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Peruvian resident's data leaves Peru at the point of being uploaded to the Balance backend.

8.1 Transfer mechanism — LPDP Article 15 + DS 016-2024-JUS

LPDP Art 15 prohibits the transfer of personal data to countries that do not provide an adequate level of protection, except where the data subject has given prior, informed, express, and unequivocal consent OR one of the statutory carve-outs applies. The statutory carve-outs in LPDP Art 15 + DS 016-2024-JUS include: (a) the data subject's prior, informed, express consent; (b) judicial cooperation under international treaty; (c) the transfer is necessary for the performance of a contract between the data subject and the controller, or for pre-contractual measures requested by the data subject; (d) bank or stock-exchange transfers necessary for the processing of the data subject's transactions; (e) the transfer is necessary for the protection of the vital interests of the data subject; (f) the transfer is necessary for medical assistance; (g) the transfer is to an international organisation in the exercise of its functions; (h) the transfer is to a country that the ANPDP has declared to provide an adequate level of protection.

DS 016-2024-JUS modernised the cross-border-transfer regime by introducing GDPR-aligned overlays — adequacy decisions by the ANPDP; Cláusulas Tipo (Peruvian SCCs, to be issued by the ANPDP); Binding Corporate Rules approved by the ANPDP; codes of conduct approved by the ANPDP; specific derogations for explicit consent, contract performance, judicial cooperation, vital interests, public interest, and legal claim.

The ANPDP adequacy list does NOT include the United States as of the Effective date.

Balance relies on the following stack to satisfy Art 15 + DS 016-2024-JUS for the PE → US transfer:

8.2 EU adequacy is not the transfer tool for PE-to-US

The European Commission has not issued an adequacy decision in respect of Peru under GDPR Art 45. The EU position on Peru is under assessment. The EU adequacy path is not available as a transfer tool for any Peru-resident leg at the Effective date or in the short-to-medium term.

8.3 Transfer mechanism — the PE-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan is not on the ANPDP adequacy list, the PE-KZ axis is covered by contractual clauses replicating LPDP standards signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The Kazakhstan personal-data-protection regime (Закон Республики Казахстан "О персональных данных и их защите" № 94-V of 21 May 2013, as amended) is the substantive overlay; the transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.4 LPDP Article 15 (b)(d)(e)(f)(g) carve-outs — not relied upon

Balance does not rely on the Art 15 carve-outs for judicial cooperation, bank/stock-exchange transfers, vital interests, medical assistance, or international-organisation transfers as the basis for routine transfers — those carve-outs are reserved for case-by-case scenarios, not for routine flows.


9. Data residency for Peruvian residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Peruvian resident's data held in Peru? No. Every Peruvian resident's data is held in the United States. The LPDP Art 15 + DS 016-2024-JUS transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor DPAs and via LPDP-standards contractual clauses in the inverse arrangement in § 8.3.
Is there a Peruvian establishment? No. Balance has no permanent establishment in Peru.
Where is the supervisory authority? Peru — Autoridad Nacional de Protección de Datos Personales (ANPDP), Calle Scipión Llona 350, Miraflores, Lima 15074.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Peru does not impose a comprehensive data-localisation mandate on parental-control services as of the Effective date.


10. Sub-processors touching Peruvian resident data

Sub-processor Role Location of processing Peruvian transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States Parent's express consent (LPDP Art 15) + contract-performance carve-out + LPDP-standards contractual clauses on file per our international-transfer pack § 6; ANPDP Cláusulas Tipo to be added on publication; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) Parent's express consent + LPDP-standards contractual clauses on file as part of the Google Cloud Data Processing Addendum; ANPDP Cláusulas Tipo to be added on publication; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) Parent's express consent + LPDP-standards contractual clauses on file as part of the Google Cloud Data Processing Addendum; ANPDP Cláusulas Tipo to be added on publication; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Peruvian kid + parent devices United States Parent's express consent + LPDP-standards contractual clauses as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States Parent's express consent + LPDP-standards contractual clauses as above.
Google LLC — Google Play Billing Processes subscription purchases United States Parent's express consent + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Peruvian parent users United States Parent's express consent + LPDP-standards contractual clauses on file.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + DS 016-2024-JUS security duties. The full sub-processor list, with each row's DPA status and contractual-clause execution date, is at our sub-processor register.


11. Breach notification — DS 016-2024-JUS

DS 016-2024-JUS introduced an explicit breach-notification regime (the original Decreto Supremo 003-2013-JUS did not contain one):

Audience Trigger Deadline Channel
ANPDP A security incident affecting personal data that is reasonably likely to cause damage to data subjects. Within 48 hours of the controller becoming aware — DS 016-2024-JUS anchors a 48-hour benchmark to the ANPDP. Where the controller cannot provide all the elements within 48 hours, the notification is filed initially and supplemented as the forensic picture develops. The ANPDP's online incident-notification form per DS 016-2024-JUS, filed in Spanish by the OPDP or by external Peruvian counsel acting on the OPDP's instructions.
Affected data subjects A breach likely to result in a high risk to the rights and freedoms of natural persons. Within 5 working days of the controller becoming aware — DS 016-2024-JUS. Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in Spanish (or in the language the parent has selected).
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). Línea 100 MIMP + PNP DIVINDAT + Ministerio Público Fiscalía Especializada en Ciberdelincuencia + Demuna + Defensoría del Pueblo Adjuntía para la Niñez.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, ANPDP notification within the 48-hour benchmark, affected-data-subject notification within the 5-working-day window.

11.1 Minimum content of the ANPDP notification (DS 016-2024-JUS)

The ANPDP notification states: - the nature of the personal data affected; - the categories and approximate number of data subjects involved; - the technical and security measures in place at the time of the incident; - the risks for the data subjects; - the measures adopted or proposed to mitigate the effects of the incident; - the OPDP contact point (, named individual: ).

The English-language template lives in our breach-notification runbook § 8.1; the Spanish rendering is produced by external Peruvian counsel on filing.


12. Cookies and electronic direct marketing

Peru does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) LPDP Art 13 consent as the lawful basis for any cookie that processes personal data; (ii) DS 016-2024-JUS Privacy-by-Design and Privacy-by-Default principles; (iii) Ley 28493 (anti-spam) — restricts unsolicited commercial email and requires the supplier to obtain prior consent, identify the email as commercial (with the prefix "PUBLICIDAD:" in the subject line), and provide a free unsubscribe mechanism; (iv) Ley 29571 (CDC) provisions on pre-contract information, deceptive advertising (Art 14), and abusive terms (Art 50).

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent in the Spanish-language consent screen.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send electronic direct marketing to Peruvian residents. The only email Balance sends to Peruvian parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. Ley 28493 + Decreto Supremo 031-2005-MTC require pre-existing consent (or a free, easy opt-out under the régimen de opt-out), the "PUBLICIDAD:" subject-line prefix, supplier identification, and a free unsubscribe mechanism for any commercial communication; if Balance ever introduces a marketing channel, we will comply with the Ley 28493 + DS 031-2005-MTC rules.


13. Lawful-access requests and the encryption posture

Peruvian authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Peru

A Peruvian resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Peruvian resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Autoridad Nacional de Protección de Datos Personales (ANPDP) LPDP + DS 016-2024-JUS + ANPDP Resoluciones Directorales Calle Scipión Llona 350, Miraflores, Lima 15074; https://www.gob.pe/anpdp
INDECOPI — Instituto Nacional de Defensa de la Competencia y de la Protección de la Propiedad Intelectual Ley 29571 Código de Protección y Defensa del Consumidor + Ley 28493 anti-spam Calle de la Prosa 104, San Borja, Lima 41; https://www.gob.pe/indecopi
Ministerio Público — Fiscalía de la Nación Cybercrime + child-sexual-exploitation + criminal LPDP-grounded prosecutions (Código Penal Arts 154, 154-A, 183-A, 183-B) https://www.gob.pe/mpfn
Defensoría del Pueblo — Adjuntía para la Niñez y la Adolescencia Constitutional human-rights ombudsperson; child-rights complaints https://www.defensoria.gob.pe/
Demuna — Defensoría Municipal del Niño y del Adolescente Child-rights first-line forum at the municipal level Per municipality
Poder Judicial — juez constitucional (acción de habeas data) CN Art 200(3) + Código Procesal Constitucional (Ley 31307 de 2021) Per jurisdiction
Poder Judicial — jueces civiles / jueces de familia Ordinary civil and family-court actions Per jurisdiction

A Peruvian resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the OPDP). We will respond within the DS 016-2024-JUS rights-exercise windows (20 working days for access; 10 working days for rectification / suppression / opposition / anonymisation, plus 5 working days for execution). Raising the matter with us first is not a precondition to filing a tutela complaint with the ANPDP, an acción de habeas data, or any other constitutional, civil, or criminal remedy; the ANPDP accepts complaints directly.


16. Consumer rights — the Ley 29571 overlay

Ley 29571 (the Código de Protección y Defensa del Consumidor, "CDC") is the principal Peruvian consumer-protection statute. Where the parent is acting as a consumidor within the meaning of CDC Art IV, the following overlays apply to the subscription purchase flow and to the Terms of Service.

16.1 Pre-contract information (CDC Arts 2 + 47)

The parent is entitled to información veraz, suficiente, oportuna, accesible, clara y comprensible on the essential characteristics of the service. CDC Art 47 sets the minimum pre-contract information for distance contracts. Implemented in Subscription Terms § 5.

16.2 7-working-day right of retraction — derecho de retracto (CDC Art 59)

CDC Art 59 grants the consumer a 7-working-day right of retraction for distance contracts, computed from the date of the contract. This is the Peruvian equivalent of the Argentine botón de arrepentimiento (AR Annex § 16.2), the Chilean derecho de retracto (CL Annex § 16.2), and the Colombian derecho de retracto (CO Annex § 16.2). Balance's subscription is concluded at a distance (in-app); the 7-working-day right of retraction applies and is implemented in Subscription Terms § 20. The right of retraction is honored regardless of whether the parent has used the service in the 7-working-day window — the parent is entitled to a full refund through the Google Play Billing refund route.

16.3 Abusive contract terms (CDC Art 50)

CDC Art 50 declares null any contract term that (i) limits the supplier's liability for damages contrary to public order; (ii) reverses the burden of proof to the consumer's detriment; (iii) imposes a unilateral right of termination on the supplier; (iv) contains other terms tending to violate the consumer's rights. The Balance Terms of Service (Terms of Service) are drafted to avoid each Art 50 risk.

16.4 Advertising directed at children (CDC Art 19)

CDC Art 19 prohibits commercial advertising directed at children that takes advantage of their credulity or lack of experience, or that promotes behaviours that may harm their physical or mental integrity. Read with CN Art 4, CNA Arts IX + 4 + 9 + 10, and the LPDP children's-data principles, the prohibition operates as the substantive ceiling on any commercial communication that might be directed at a kid. Balance does not display any advertising — see § 5.5 above.

16.5 Forum and INDECOPI procedure

CDC Art 105 + INDECOPI procedural rules operate on a consumer-protective basis. The consumer may file an Asociación de Consumidores claim under CDC Art 70, or seek individual redress at INDECOPI's Comisión de Protección al Consumidor under CDC Arts 105 et seq.; appeal lies to INDECOPI's Tribunal de Defensa de la Competencia y de la Protección Intelectual. The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace Peruvian law to the prejudice of the Peruvian consumer are presumptively null under CDC Art 50.

16.6 Libro de Reclamaciones

CDC Art 150 + Decreto Supremo 011-2011-PCM require the supplier to maintain a Libro de Reclamaciones (physical or virtual book of complaints) accessible to consumers. Balance's online complaint route at + the in-app Settings → Help → "Submit a complaint" affordance + the public-website complaint intake satisfy the Libro de Reclamaciones requirement in its virtual form per Decreto Supremo 006-2014-PCM.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Peru Country Annex.

← Back to Privacy Policy · Children's Privacy Notice