Compliance glossary

14 compliance frameworks, defined

HIPAA, BAA, PHI, GDPR, SOC 2, ISO 27001, UPL, FERPA — each framework defined in plain English alongside SLAtech's compliance posture per framework. Complements the security controls inventory and sub-processor list.

A–Z

14 entries

BAA (Business Associate Agreement)

A HIPAA-mandated contract between a covered entity (typically a healthcare provider) and a vendor that processes PHI on their behalf. The BAA enumerates permitted uses, security controls, breach-notification SLA and subcontractor flow-down requirements. Signing a BAA without supporting controls is a federal compliance violation.

SLAtech: SLAtech executes BAAs only on the Enterprise tier where SLA-backed single-tenant infrastructure can support the underlying control requirements. Request via security@slatech.ai.

COPPA

Children's Online Privacy Protection Act (US, 1998). Restricts collection of personal information from children under 13 without verifiable parental consent. Applies to operators of websites or online services directed to children, or those with actual knowledge of collecting from children.

SLAtech: SLAtech products are not directed to children under 13. SLAtech Education customers serving primary-school audiences must ensure COPPA-compliant parental-consent workflows upstream of the chatbot — typically handled by the school's existing SIS.

DPA (Data Processing Agreement)

Contract required by GDPR Article 28 between a data controller and a data processor. Specifies the nature and purpose of processing, types of personal data, duration, processor obligations (confidentiality, security, sub-processors, breach notification, audit cooperation) and data return / deletion on contract end.

SLAtech: DPA template available on signup. Custom DPAs negotiated for Enterprise tier. Standard DPA references SCC 2021/914 for transfers and enumerates all current sub-processors.

FERPA

Family Educational Rights and Privacy Act (US, 1974). Restricts disclosure of student education records by federally-funded educational institutions. Key exception: "school officials with legitimate educational interest" — under which a chatbot vendor can be covered if the contract designates them a school official.

SLAtech: SLAtech Education contracts include FERPA school-official designation language where applicable. Detected structured identifiers (email, phone, payment card, Israeli national-ID, medical-record number) are redacted from visitor messages and tokenised in opt-in document uploads before LLM calls; free-text student names and grades are not auto-detected. Transcripts logged only with aggregate metadata.

GDPR

General Data Protection Regulation (EU 2016/679). Regulates processing of personal data of EU residents regardless of where the controller or processor is located. Articles 6 (lawful basis), 7 (consent), 17 (right to erasure), 28 (processor obligations) and 32 (security of processing) are most relevant to chatbot vendors.

SLAtech: GDPR-compliant by default: DPA executed on signup for Enterprise, DSR portal in the admin platform, sub-processor list at /en/sub-processors/, SCC 2021/914 for transfers outside EEA. Hosting in your own jurisdiction is available on request (Enterprise deployments).

HIPAA

Health Insurance Portability and Accountability Act (US, 1996). Regulates handling of protected health information (PHI) by covered entities and their business associates. Requires administrative, physical and technical safeguards: access control, audit trails, encryption at rest and in transit, breach notification within 60 days.

SLAtech: SLAtech Medical is BAA-eligible on the Enterprise tier with a single-tenant deployment option. Multi-tenant tiers (Starter/Pro) are not BAA-covered — these are appropriate for non-PHI workloads such as appointment intake before clinical context is captured.

ISO 27001

International standard for an Information Security Management System (ISMS). Annex A enumerates 93 controls across organisational, people, physical and technological domains. Certification involves a Stage 1 documentation audit + Stage 2 controls audit + annual surveillance audits. Often paired with ISO 27017 (cloud-specific) and ISO 27018 (PII in the cloud).

SLAtech: ISO 27001 certification targeted Q4 2026. ISMS scope = production infrastructure + customer-data processing systems. Statement of Applicability (SoA) available to Enterprise buyers under NDA.

NIS2

Network and Information Security Directive 2 (EU 2022/2555). Expands cybersecurity obligations to a broader set of "essential" and "important" entities including digital infrastructure and managed services. Member-state transposition deadline was October 2024; enforcement is ramping in 2026.

SLAtech: SLAtech is classified as a managed service provider under NIS2 for several Enterprise customers. Incident-notification SLA (within 24 hours for significant incidents) is reflected in the standard MSA. NIS2 risk-management documentation available to designated essential-entity customers.

PCI-DSS

Payment Card Industry Data Security Standard. Mandatory for any organisation that stores, processes or transmits cardholder data. PCI-DSS 4.0 (effective March 2025) introduces customised approach for compensating controls. SAQ-A applies to merchants that fully outsource card handling to a PCI-compliant processor.

SLAtech: SLAtech does not store, process or transmit cardholder data — payments are handled exclusively by an external PCI-DSS Level 1 payment provider. SAQ-A applies; SLAtech operates as a merchant, not a PCI entity.

PHI (Protected Health Information)

Any individually identifiable health information held or transmitted by a HIPAA covered entity or business associate. Includes 18 specific identifiers — name, address, date of birth, medical record number, biometric identifiers, photographs of face, and more. PHI redaction is a common compliance pattern for AI workloads that must run on multi-tenant infrastructure.

SLAtech: SLAtech applies opt-in, ingest-time identifier tokenisation: detected structured identifiers (email, phone, payment card, Israeli national-ID, medical-record number) in uploaded documents are replaced with tokens before any text is embedded or sent to an AI sub-processor. The original values stay encrypted at rest in our own vault and are never sent to those providers, recoverable only by authorised admins. The same identifiers are redacted from visitor chat messages before the LLM call. Free-text names, dates of birth and addresses are not auto-detected; masking is opt-in per upload (public website content is left as-is).

SCC (Standard Contractual Clauses)

Pre-approved contract template published by the European Commission for transferring personal data from the EEA to third countries lacking an adequacy decision. The current version is 2021/914 (effective June 2021), replacing the earlier 2010/87 clauses. Schrems II ruling (CJEU C-311/18) requires supplementary transfer-impact assessments alongside SCCs.

SLAtech: Every SLAtech sub-processor transfer outside EEA (our model provider in the US, a re-ranking provider in Canada, error monitoring in the US) is governed by SCC 2021/914 with transfer-impact assessment available on request.

SOC 2

Service Organization Control 2 — AICPA audit framework that evaluates a service organisation's controls against five trust services criteria: security, availability, processing integrity, confidentiality, and privacy. Type I = controls designed appropriately at a point in time; Type II = controls operating effectively over a 6-12 month period.

SLAtech: Type I report targeted Q3 2026; Type II Q2 2027. Until then, the operational controls listed at /en/security/ are independently auditable on request. Customers can request Trust Service Criteria mapping as a pre-audit gap-analysis artefact.

UPL (Unauthorized Practice of Law)

Common-law and statutory restriction limiting the practice of law to licensed attorneys. Defined narrowly varies by jurisdiction but typically includes giving legal advice, drafting legal documents and representing parties in proceedings. AI chatbots in the legal vertical face acute UPL exposure if they answer substantive legal questions without attorney review.

SLAtech: SLAtech Legal ships a UPL safeguard that routes every substantive legal question to "an attorney will follow up" rather than letting the bot answer. The bot handles intake, qualifying questions and appointment scheduling — never legal positions.

ePHI (Electronic PHI)

PHI in electronic form — what HIPAA's Security Rule actually regulates. The Security Rule mandates technical safeguards (access control, audit controls, integrity controls, transmission security) specifically for ePHI. Paper PHI falls under the Privacy Rule only.

SLAtech: All SLAtech-handled health-context data is ePHI by definition. AES-256-GCM at rest, TLS 1.2+ in transit, audit log of admin actions, role-based access control — all baseline controls implemented.

Need compliance artefacts?

DPA, BAA, SoA mapping, sub-processor list, SCC transfer-impact assessment — all available on request.