1. Scope and requests
A person’s nationality or the presence of a country in a case record does not alone determine every applicable privacy law. Relevant factors can include where an organization operates, which services it offers, the people and processing involved, and its role in that processing. The information below does not establish that a particular regime applies to HQL Solutions or a customer, or that a filing, assessment, representative appointment, or transfer agreement has been completed.
For customer-managed immigration or other case records, contact the customer organization that collected or manages your information. It determines the processing purposes and handles the substantive response; the service provider assists according to lawful instructions and applicable duties. For HQL Solutions’s own business-account or administration processing, use the business contact identified in your customer agreement. See the Privacy Notice for more information about these roles and request handling.
Rights are subject to applicable conditions, verification, exemptions, and retention requirements. You may also complain to the competent authority where the relevant law permits. A customer’s operational or contractual review remains necessary for its own workflow.
2. Morocco
Where Morocco’s Law 09-08 applies, people have rights to information, access, rectification, and objection under its conditions, and may contact the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP). Notices must describe the actual controller and processing, including applicable declaration or authorization particulars.
Processing declarations or authorizations and foreign-transfer requirements depend on the data, purposes, parties, and destinations. Sensitive information and some identifiers or criminal-record information require particular assessment. Foreign hosting or access must be evaluated before use; a cloud contract or general privacy consent does not by itself establish CNDP authorization.
Official sources: Law 09-08; CNDP information for individuals; CNDP processing and transfer formalities.
3. Canada and Quebec
Where Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) applies, relevant protections include information about handling practices, meaningful consent where required, access, correction, withdrawal of consent subject to legal or contractual restrictions, and complaints. Applicable provincial laws may add or replace requirements. The organization remains accountable for outsourced processing and must explain relevant foreign processing and potential foreign-authority access.
Where Quebec’s private-sector privacy law applies, additional requirements include governance and a responsible privacy person, privacy impact assessments for covered systems projects and processing outside Quebec, and appropriate written service arrangements. Rights can include access, rectification, and portability of qualifying computerized information collected from you. Sensitive information, children’s information, and consent require particular care. A configured Canadian database does not establish that a Quebec cross-border assessment or agreement has been completed.
Official sources: Office of the Privacy Commissioner of Canada; PIPEDA; Quebec private-sector Act; Commission d’accès à l’information guidance on Law 25.
4. European Economic Area
Where the EU General Data Protection Regulation (GDPR) applies, rights can include access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority. Its scope depends on establishment or relevant offering of services or monitoring, rather than citizenship alone. The controller must identify its lawful basis, provide required notices, and establish additional conditions for special-category or criminal-record information.
Customer case processing can require a binding processor agreement and separate lawful international-transfer arrangements. Transfers outside the EEA need an applicable legal mechanism and any required assessment or supplementary safeguards. This page does not execute standard contractual clauses, designate a representative, or establish a particular transfer’s legality.
Official sources: European Data Protection Board rights guidance; Controller and processor guidance; European Commission transfer adequacy decisions.
5. United Kingdom
Where UK GDPR and the Data Protection Act 2018, as amended, apply, additional rights can include access, correction, erasure, restriction, objection, portability, withdrawal of consent, and complaint to the Information Commissioner’s Office (ICO), subject to applicable conditions. The Data (Use and Access) Act 2025 amended this framework; UK requirements must be assessed separately from EU law.
Applicable organizations must provide a privacy complaint route, acknowledge complaints within 30 days, and investigate and respond without undue delay. Restricted international transfers require an applicable UK mechanism and assessment. An EU transfer agreement alone does not necessarily meet UK requirements; this information does not execute a UK IDTA or Addendum or establish a UK representative.
Official sources: ICO guidance on the amended framework; Privacy complaints; International transfers.
6. India
India’s Digital Personal Data Protection framework has staged commencement. At this page’s revision date, its core processing duties and individual-rights provisions have not yet commenced: the notification provides for these provisions to begin eighteen months after publication in the Official Gazette. When those provisions commence and apply, notice, consent withdrawal, access, correction, erasure, grievance, and nomination rights must be addressed under the applicable framework.
Existing Indian privacy, security, and other legal duties require separate assessment during the transition, including the Information Technology Act and sensitive personal data rules where applicable. Applicable duties can include an accessible privacy policy, appropriate safeguards, review or correction, withdrawal, and grievance handling. The processing role and contractual arrangement matter; customer-controlled case processing and the provider’s own administration processing require separate consideration.
Official sources: MeitY commencement notification; Digital Personal Data Protection Rules; Rules corrigenda; Sensitive personal data rules.
7. United States
Additional rights may apply according to the relevant state, processing, and the organization’s role. Where applicable, these may include access or knowledge, correction, deletion, portability, and appeal. Opt-outs of sale, sharing, targeted advertising, or certain profiling, and limits on sensitive-information use apply when the relevant activity and law require them. These rights and procedures are not identical across states.
California’s CCPA has its own scope and business thresholds, while qualifying service-provider or contractor obligations can also apply to processing for covered customers. Publishing this information does not establish CCPA business status or an executed service-provider contract. Other state privacy, security, breach, and online-notice laws may apply separately. Requests about customer-managed case data should first go to that organization.
Official sources: California Privacy Protection Agency FAQs; Current CCPA statute; California regulations.
8. International processing and contracts
The provider list describes confirmed service providers and configured components. International processing must be evaluated across hosting, application runtime, access, integrations, and onward processing. Depending on the applicable law, contracts, assessments, notices, consents, or regulatory authorizations may be required.
The proposed Data Processing Addendum is available for customer and counsel review. It binds only when expressly agreed with a factual processing schedule and does not supply a missing transfer instrument or approval. Use the existing business contact in your customer agreement to discuss the actual arrangement.
