Compliance
Last updated: July 20, 2026
Education consultancies operate under different regulatory expectations depending on where their students and destination institutions are located. This page explains how OBCRM approaches that variation architecturally, and how to get documentation specific to your regulatory environment.
Built for regional variation, not one-size-fits-all
Every organization on OBCRM runs on a logically isolated tenant, which means data handling policies, retention rules, and access controls can be configured per organization rather than applied uniformly across every customer. For details on data residency and GDPR-specific handling, see Data Protection.
Your compliance obligations
As the data controller for your own students and applicants, your organization remains responsible for obtaining appropriate consent and complying with the regulations that apply to your specific markets. OBCRM provides the technical controls — access restriction, audit logging, encryption — that support meeting those obligations; it does not substitute for your own legal review.
Requesting documentation
If your procurement or legal team needs a specific compliance questionnaire completed, a Data Processing Addendum, or architecture documentation under NDA, contact our team directly — we would rather send you an accurate, current answer than have you rely on a static claim on this page that may be out of date by the time you read it.
Reach us at dpo@obcrm.net or visit the Trust Center for the rest of our security and legal documentation.