Peru Annex: Processing Contract and Cross-Border Flow Clauses

ANX-PE · Draft of October 6, 2026 · revision 1 · version 1.0

Final draft for counsel's review. It is not in effect, and no clinic has accepted it. Items still to be confirmed are highlighted in the text.

Convenience translation: the Español text controls.

Read in: English · Español

SHA-256 of this text: b3f7eaf0d3bb31dbcc5b9d16183e757428c12a47a2ede3a9aa00005fbab626e5

Peru — ANX-PE: Processing Contract and Cross-Border Flow Clauses

Document ID: ANX-PE · Version: 1.0 · Effective date: [[TO CONFIRM: publication date]] Language: Spanish controls (es/annex-pe.md: "Contrato de Encargo y Cláusulas de Flujo Transfronterizo"). This English text is a convenience translation. Applies to: Clinics established in the Republic of Peru. Part of the Master Data Processing Agreement (the "MDPA"). Terms defined in the MDPA have the same meaning here.


1. Legal framework and roles

1.1 Roles. This Annex governs the processing of Clinic Data by:

  • VstreamX, as encargado del tratamiento (processor); and
  • the Clinic, as titular del banco de datos personales and responsable del tratamiento (controller).

1.2 The law. It is made under Law 29733, the Personal Data Protection Law ("Law 29733"), and its Regulation approved by Supreme Decree 016-2024-JUS (the "Regulation").

1.3 VstreamX is bound directly. Under Article VI of the Preliminary Title of the Regulation, VstreamX is directly subject to Law 29733 and the Regulation for the processing it performs on behalf of the Clinic.

2. Processing on the Clinic's behalf (encargo)

2.1 Scope. VstreamX processes the Clinic Data only:

  • to provide DentalX to the Clinic as MDPA Schedule 1 describes; and
  • on the Clinic's documented instructions (MDPA clause 3).

2.2 No other purpose. It does not process the data for any other purpose, and does not communicate it to third parties other than the Sub-processors under clause 4.

3. Cloud computing services

In accordance with Articles 28 to 30 of the Regulation, VstreamX, as provider of the processing through cloud computing services:

  • (a) informs the Clinic of the location of the processing and of each Sub-processor (MDPA clause 13.1 and Schedule 3);
  • (b) applies the security measures in MDPA Schedule 2;
  • (c) does not use the Clinic Data for its own purposes (MDPA clause 4);
  • (d) guarantees the return and deletion of the Clinic Data at the end of the service (clause 6);
  • (e) allows the Clinic to verify compliance (MDPA clause 12); and
  • (f) informs the Clinic of any request from an authority (MDPA clause 16).

4. Sub-processors

4.1 Authorisation. In accordance with Articles 32 and 33 of the Regulation, the Clinic authorises the Sub-processors listed in MDPA Schedule 3.

4.2 Obligations. Each Sub-processor is bound by obligations equivalent to those of VstreamX. VstreamX remains responsible to the Clinic for them.

4.3 Changes. Changes follow MDPA clause 7.

5. Cross-border data flow

5.1 The flow. The processing of the Clinic Data by VstreamX in Canada, and by the Sub-processors in the United States and other countries, is a cross-border flow of personal data under Law 29733 and the Regulation.

5.2 Contractual guarantees. In accordance with Articles 18 to 20 of the Regulation, VstreamX guarantees to the Clinic, as recipient of the flow, a level of protection at least comparable to that of Law 29733. In particular, VstreamX:

  • (a) processes the data only for the purposes in MDPA Schedule 1;
  • (b) applies the security measures in MDPA Schedule 2;
  • (c) keeps confidentiality (MDPA clause 5);
  • (d) allows data subjects to exercise their rights through the Clinic (clause 9);
  • (e) does not make onward flows except to the Sub-processors in MDPA Schedule 3, under obligations equivalent to these; and
  • (f) submits to the supervision of the National Authority for Personal Data Protection ("ANPD") for the processing of the Clinic Data, and cooperates with it.

5.3 Communication to the ANPD.

  • The Clinic's duty. Under Article 21.2 of the Regulation, the Clinic communicates the cross-border flow to the ANPD.
  • VstreamX's help. VstreamX provides a pre-filled communication in the Service with the identity of the recipient, the destination countries, the Sub-processors and the purposes.
  • The attestation. The Clinic attests in the Service, within 30 days of acceptance, that it has made the communication and that its database is registered in the National Registry for Personal Data Protection.
  • Effect. The Service reminds the Clinic until then, but does not block it.

5.4 Model clauses. If the ANPD approves model clauses for cross-border flows, VstreamX will adopt them as MDPA clause 18.4 provides. [[TO CONFIRM: whether the ANPD has published model clauses or a position on the United States]]

6. Return and deletion: two-year cap

6.1 Return first. At the end of the service, the complete export under MDPA clause 14 is the return of the Clinic Data.

6.2 The two-year cap. In accordance with Article 31.2 of the Regulation, VstreamX does not keep personal data of the Clinic for more than two years after the end of the service. In particular:

  • (a) the Patient Data is deleted as MDPA clause 14 provides (within 30 days of the 90th day after the end);
  • (b) the audit trail is returned in the export, and VstreamX deletes or anonymises its copy on the deletion date (MDPA clause 14.5(c)), well within the two-year cap;
  • (c) backups expire within seven days of deletion; and
  • (d) the record of WhatsApp opt-outs is deleted with the Clinic Data on the deletion date (MDPA clause 14.5(d)).

7. Security

7.1 Measures. VstreamX applies the measures in MDPA Schedule 2, which correspond to the processing of sensitive data. In addition, in accordance with Article 46 of the Regulation and the applicable security provisions, VstreamX:

  • (a) keeps the access logs of the Service for at least two years while the Clinic is active;
  • (b) reviews the access privileges of its own personnel to the production environment every six months; and
  • (c) makes backups at least weekly and verifies their restoration periodically. DentalX's backups are daily. [[TO CONFIRM: the restore-test frequency VstreamX performs]]

7.2 The audit trail. The audit trail described in MDPA Schedule 2 is retained for seven years while the Clinic's account is active, and after the end as clause 6.2(b) provides.

8. Security incidents

8.1 Notice to the Clinic. VstreamX notifies the Clinic immediately upon establishing an incident that affects the Clinic Data, and in any event within 24 hours, in accordance with Article 36 of the Regulation and MDPA clause 9.

8.2 What the Clinic must do. This allows the Clinic to notify:

  • the ANPD and the affected data subjects within 48 hours; and
  • where it is a digital incident, the National Centre for Digital Security.

8.3 Assistance. VstreamX provides the information it holds for those notices.

9. Rights of data subjects

VstreamX assists the Clinic within 5 business days (MDPA clause 8) to answer the rights of information, access, rectification, cancellation, opposition and the others under Law 29733 within the statutory periods.

10. Electronic clinical records (SIHCE)

10.1 Not accredited. DentalX is not a Sistema de Información de Historias Clínicas Electrónicas accredited by the Ministry of Health. It does not use the accredited digital signature, the RENIEC identity checks or the connection to the RENHICE that Law 30024 and its regulations require for an electronic clinical record to be legally valid.

10.2 Effect. DentalX therefore does not replace a legally valid electronic clinical record. The Clinic remains responsible for keeping its clinical record in a legally valid form. [[TO CONFIRM: whether Directiva 373-MINSA/OGTI-2025 evaluates private dental offices]]

11. Retention of clinical records

11.1 The Clinic's duty. The Clinic must keep its clinical records for at least 20 years (5 in the active archive and 15 in the passive archive), as the Ministry of Health's technical standard provides. DentalX does not auto-delete clinical records.

11.2 At the end of the service. At the end of the service, the export allows the Clinic to keep them after the deletion under clause 6.

12. The Clinic's obligations

The Clinic is responsible for:

  • informing its patients under Article 18 of Law 29733, including of the cross-border flow, the recipient and the purposes;
  • obtaining the written consent of each patient to the processing of their health data, where no exception applies. DentalX provides a template;
  • registering its database; and
  • communicating the cross-border flow (clause 5.3).

13. Data protection officer

13.1 VstreamX. VstreamX will appoint a personal data officer (Oficial de Datos Personales) as Article 37 of the Regulation requires, on the timetable that applies to its size. It is expected to apply from 30 November 2028, and an external officer is allowed. [[TO CONFIRM: VstreamX's size classification and appointment date]]

13.2 The Clinic. The Clinic records its own officer in the Service where it must appoint one.

13.3 Representative in Peru. Where the Regulation requires a controller that is not established in Peru, and that offers services to persons in Peru, to designate a representative in or for Peru, VstreamX designates one for the processing in which it is itself a controller (Account Data), and names it in its Privacy Policy and here: [[TO CONFIRM: Peruvian counsel's confirmation of the representative duty under D.S. 016-2024-JUS (article number) and its timing, and the representative's name and address]].

14. Applicable law

Law 29733 and the Regulation apply to the processing of the Clinic Data whatever law governs the commercial relationship under MDPA clause 23.


Items to confirm before publication (Peru)

  1. Publication date.
  2. Whether the ANPD has published model clauses for cross-border flows, or a position on the United States (§5.4).
  3. Product implementation of the deletion or anonymisation of the audit trail at the deletion date (§6.2(b); MDPA clause 14.5(c)).
  4. Product implementation of the clinic-scoped WhatsApp opt-out list (§6.2(d); MDPA clause 14.5(d)).
  5. The restore-test frequency VstreamX performs (§7.1(c)).
  6. Whether Directiva 373-MINSA/OGTI-2025 evaluates private dental offices (§10).
  7. VstreamX's size classification and the date it must appoint its personal data officer (§13.1).
  8. The duty to designate a representative in Peru, and the representative's name and address (§13.3).