# 1. Regulatory Compliance

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 1. Regulatory Compliance

### 1.1 GDPR (Europe)
**What it does:** Complies with the GDPR: the compliance of the GDPR (the compliance, the rule, the data, the date) is done for the European users, so the platform is compliant (the compliance is the adherence). The Super Administrator complies with the GDPR (the compliance, the rule, the data, the date) so the compliance is structured and the adherence is explicit.

**Sub-features:**
- Compliance: the compliance (the compliance, the rule, the data, the date)
- Rule: the rule (the rule of the GDPR, the requirement, the date)
- Data: the data (the data of the users, the type, the date)
- Consent: the consent (the consent of the user, the date, the scope)
- Compliance status: the status (the compliant, the non-compliant)
- Compliance count: the count (the count of the rules by status)
- Compliance view: the view (the compliances, the rules, the data, the dates)
- Audit logging of the GDPR compliance

**Super Administrator User Journey:**
1. Super Admin complies with the GDPR: the compliance (the compliance, the rule, the data, the date), the rule (the rule of the GDPR, the requirement, the date), and the data (the data of the users, the type, the date); the compliance is explicit.
2. Selects the rule: the rule (the rule of the GDPR, the requirement, the date); the rule is the requirement.
3. Selects the data: the data (the data of the users, the type, the date); the data is the subject.
4. Sets the consent: the consent (the consent of the user, the date, the scope); the consent is the permission.
5. Views the compliance status: the status (the compliant, the non-compliant); the status is the state.
6. Views the compliance count: the count (the count of the rules by status); the count is the measure.
7. The GDPR is compliant: the compliances, the rules, the data, the dates, so the adherence is complete.
8. The GDPR compliance is audit-logged with the compliance, the rule, and the timestamp.

**Rules & Edge Cases:**
- The compliance is the adherence (the compliance, the rule, the data, the date); the compliance is the conformity.
- The rule is the requirement (the rule of the GDPR, the requirement, the date); the rule is the law.
- The data is the subject (the data of the users, the type, the date); the data is the personal data.
- The consent is the permission (the consent of the user, the date, the scope); the consent is the agreement.
- The GDPR is compliant (the compliances, the rules, the data, the dates); the adherence is managed.
- GDPR compliance is audit-logged with the compliance, rule, and timestamp.

### 1.2 POPIA (South Africa)
**What it does:** Complies with the POPIA: the compliance of the POPIA (the compliance, the rule, the data, the date) is done for the South African users, so the platform is compliant (the compliance is the adherence). The Super Administrator complies with the POPIA (the compliance, the rule, the data, the date) so the compliance is structured and the adherence is explicit.

**Sub-features:**
- Compliance: the compliance (the compliance, the rule, the data, the date)
- Rule: the rule (the rule of the POPIA, the requirement, the date)
- Data: the data (the data of the users, the type, the date)
- Consent: the consent (the consent of the user, the date, the scope)
- Compliance status: the status (the compliant, the non-compliant)
- Compliance count: the count (the count of the rules by status)
- Compliance view: the view (the compliances, the rules, the data, the dates)
- Audit logging of the POPIA compliance

**Super Administrator User Journey:**
1. Super Admin complies with the POPIA: the compliance (the compliance, the rule, the data, the date), the rule (the rule of the POPIA, the requirement, the date), and the data (the data of the users, the type, the date); the compliance is explicit.
2. Selects the rule: the rule (the rule of the POPIA, the requirement, the date); the rule is the requirement.
3. Selects the data: the data (the data of the users, the type, the date); the data is the subject.
4. Sets the consent: the consent (the consent of the user, the date, the scope); the consent is the permission.
5. Views the compliance status: the status (the compliant, the non-compliant); the status is the state.
6. Views the compliance count: the count (the count of the rules by status); the count is the measure.
7. The POPIA is compliant: the compliances, the rules, the data, the dates, so the adherence is complete.
8. The POPIA compliance is audit-logged with the compliance, the rule, and the timestamp.

**Rules & Edge Cases:**
- The compliance is the adherence (the compliance, the rule, the data, the date); the compliance is the conformity.
- The rule is the requirement (the rule of the POPIA, the requirement, the date); the rule is the law.
- The data is the subject (the data of the users, the type, the date); the data is the personal data.
- The consent is the permission (the consent of the user, the date, the scope); the consent is the agreement.
- The POPIA is compliant (the compliances, the rules, the data, the dates); the adherence is managed.
- POPIA compliance is audit-logged with the compliance, rule, and timestamp.

### 1.3 COPPA (Children's Online Privacy)
**What it does:** Complies with the COPPA: the compliance of the COPPA (the compliance, the rule, the child, the date) is done for the children's data, so the platform is compliant (the compliance is the adherence). The Super Administrator complies with the COPPA (the compliance, the rule, the child, the date) so the compliance is structured and the adherence is explicit.

**Sub-features:**
- Compliance: the compliance (the compliance, the rule, the child, the date)
- Rule: the rule (the rule of the COPPA, the requirement, the date)
- Child: the child (the child, the age, the date)
- Parental consent: the consent (the consent of the parent, the date, the scope)
- Compliance status: the status (the compliant, the non-compliant)
- Compliance count: the count (the count of the rules by status)
- Compliance view: the view (the compliances, the rules, the children, the dates)
- Audit logging of the COPPA compliance

**Super Administrator User Journey:**
1. Super Admin complies with the COPPA: the compliance (the compliance, the rule, the child, the date), the rule (the rule of the COPPA, the requirement, the date), and the child (the child, the age, the date); the compliance is explicit.
2. Selects the rule: the rule (the rule of the COPPA, the requirement, the date); the rule is the requirement.
3. Selects the child: the child (the child, the age, the date); the child is the minor.
4. Sets the parental consent: the consent (the consent of the parent, the date, the scope); the consent is the permission.
5. Views the compliance status: the status (the compliant, the non-compliant); the status is the state.
6. Views the compliance count: the count (the count of the rules by status); the count is the measure.
7. The COPPA is compliant: the compliances, the rules, the children, the dates, so the adherence is complete.
8. The COPPA compliance is audit-logged with the compliance, the rule, and the timestamp.

**Rules & Edge Cases:**
- The compliance is the adherence (the compliance, the rule, the child, the date); the compliance is the conformity.
- The rule is the requirement (the rule of the COPPA, the requirement, the date); the rule is the law.
- The child is the minor (the child, the age, the date); the child is the protected user.
- The parental consent is the permission (the consent of the parent, the date, the scope); the consent is the agreement.
- The COPPA is compliant (the compliances, the rules, the children, the dates); the adherence is managed.
- COPPA compliance is audit-logged with the compliance, rule, and timestamp.

### 1.4 FERPA (Educational Records)
**What it does:** Complies with the FERPA: the compliance of the FERPA (the compliance, the rule, the record, the date) is done for the educational records, so the platform is compliant (the compliance is the adherence). The Super Administrator complies with the FERPA (the compliance, the rule, the record, the date) so the compliance is structured and the adherence is explicit.

**Sub-features:**
- Compliance: the compliance (the compliance, the rule, the record, the date)
- Rule: the rule (the rule of the FERPA, the requirement, the date)
- Record: the record (the record of the student, the type, the date)
- Access: the access (the access to the record, the role, the date)
- Compliance status: the status (the compliant, the non-compliant)
- Compliance count: the count (the count of the rules by status)
- Compliance view: the view (the compliances, the rules, the records, the dates)
- Audit logging of the FERPA compliance

**Super Administrator User Journey:**
1. Super Admin complies with the FERPA: the compliance (the compliance, the rule, the record, the date), the rule (the rule of the FERPA, the requirement, the date), and the record (the record of the student, the type, the date); the compliance is explicit.
2. Selects the rule: the rule (the rule of the FERPA, the requirement, the date); the rule is the requirement.
3. Selects the record: the record (the record of the student, the type, the date); the record is the educational record.
4. Sets the access: the access (the access to the record, the role, the date); the access is the permission.
5. Views the compliance status: the status (the compliant, the non-compliant); the status is the state.
6. Views the compliance count: the count (the count of the rules by status); the count is the measure.
7. The FERPA is compliant: the compliances, the rules, the records, the dates, so the adherence is complete.
8. The FERPA compliance is audit-logged with the compliance, the rule, and the timestamp.

**Rules & Edge Cases:**
- The compliance is the adherence (the compliance, the rule, the record, the date); the compliance is the conformity.
- The rule is the requirement (the rule of the FERPA, the requirement, the date); the rule is the law.
- The record is the educational record (the record of the student, the type, the date); the record is the data.
- The access is the permission (the access to the record, the role, the date); the access is the control.
- The FERPA is compliant (the compliances, the rules, the records, the dates); the adherence is managed.
- FERPA compliance is audit-logged with the compliance, rule, and timestamp.
