---
title: "What Regulations Does Chatfuel Comply With?"
description: "Chatfuel complies with major international and regional data protection regulations."
canonical_url: https://chatfuel.com/docs/security/what-regulations-does-chatfuel-comply-with
markdown_url: https://chatfuel.com/docs/security/what-regulations-does-chatfuel-comply-with.md
last_updated: 2026-09-09
lang: en
site: https://chatfuel.com/docs
llms_txt: https://chatfuel.com/llms.txt
---

# What Regulations Does Chatfuel Comply With?

Chatfuel complies with major international and regional data protection regulations.

## Overview [#overview]

Chatfuel complies with major international and regional data protection regulations. Whether you operate in Europe, the US, or Latin America, we have the safeguards and documentation to support your compliance requirements.

***

## International Standards [#international-standards]

### GDPR (European Union) [#gdpr-european-union]

Chatfuel is fully compliant with the General Data Protection Regulation. We implement all required technical and organizational measures for lawful data processing, including data minimization, purpose limitation, and full support for data subject rights.

### HIPAA-Aligned Safeguards (United States) [#hipaa-aligned-safeguards-united-states]

While Chatfuel is not a HIPAA-covered entity, we implement technical and administrative safeguards aligned with HIPAA standards — including encryption, access controls, audit logging, and breach notification procedures. Healthcare providers handling US Protected Health Information (PHI) can request a &#x2A;*Business Associate Agreement (BAA)**.

***

## Latin America [#latin-america]

Healthcare data is classified as "sensitive personal data" under all applicable LATAM laws. Chatfuel processes such data strictly as a **Data Processor** under written agreements with healthcare providers (Data Controllers).

| Country   | Regulation                 | Chatfuel Compliance                                                 |
| --------- | -------------------------- | ------------------------------------------------------------------- |
| Brazil    | LGPD (Lei 13.709/2018)     | DPA with controller/processor roles; breach notification procedures |
| Mexico    | LFPDPPP (2025 Edition)     | Updated DPA with retention policies; DSR/ARCO procedures            |
| Colombia  | Ley 1581 + Resolucion 1995 | Security controls; retention policies; cross-border safeguards      |
| Chile     | Ley 19.628 (2024 Reform)   | DSR procedures; data export; deletion protocols                     |
| Argentina | Ley 25.326                 | Standard Contractual Clauses; GDPR-level security                   |
| Peru      | Ley 29733                  | Documented security controls                                        |

***

## Infrastructure Certifications [#infrastructure-certifications]

Our cloud providers hold the following certifications:

* **ISO 27001** — information security management
* **SOC 2 Type II** — security, availability, and confidentiality controls
* **HIPAA-eligible/compliant** infrastructure

***

## Available Documentation [#available-documentation]

We can provide the following documents upon request:

* Privacy Policy (English / Spanish / Portuguese)
* Terms of Use
* Data Processing Agreement (DPA) with Standard Contractual Clauses
* Subprocessor List
* Security Policies (7 comprehensive policies)
* Business Associate Agreement (BAA) for healthcare providers

Contact &#x2A;*[tos@chatfuel.com](mailto:tos@chatfuel.com)** for any compliance documentation.
