One framework. Every jurisdiction you answer to.
Each guide explains the law in plain language, maps every obligation to the control that satisfies it, and sets out what implementation actually looks like on the ground. Written for the people who have to act on it, not only for lawyers.
DPDP Act, 2023
Consent and certain legitimate uses, notice, Data Fiduciary duties, Significant Data Fiduciary obligations, breach intimation, and the phased commencement of the DPDP Rules, 2025.
Open guide 🇪🇺European UnionGDPR
Lawful bases, data subject rights, DPIAs, records of processing, international transfers, and the accountability principle that underpins all of it.
Open guide 🇬🇧United KingdomUK GDPR & DPA 2018
Where the UK regime still tracks the EU and where it has diverged, ICO expectations, and the transfer routes available after adequacy.
Open guide 🇺🇸United States · CaliforniaCCPA / CPRA
Notice at collection, opt-out of sale and sharing, limits on sensitive personal information, consumer rights, and the enforcement posture of the CPPA.
Open guide 🇨🇳ChinaPIPL, DSL & CSL
Separate consent, data classification and grading, localisation duties, and the three routes out of the country: security assessment, standard contract, and certification.
Open guide 🇸🇬South East AsiaASEAN privacy laws
Singapore, Malaysia, Indonesia, the Philippines, Thailand and Vietnam, compared side by side so a regional programme stays coherent rather than fragmented.
Open guide 🇯🇵Japan & South KoreaAPPI & PIPA
Two of the most mature regimes in Asia, their consent models, pseudonymised data rules, breach reporting, and how each regulator actually behaves.
Open guide 🇦🇺Australia & New ZealandPrivacy Act 1988 & 2020
The Australian Privacy Principles, the Notifiable Data Breaches scheme, the reform programme in progress, and New Zealand's Privacy Act 2020.
Open guide 🇺🇸United StatesState privacy laws
Virginia, Colorado, Connecticut, Utah, Texas, Oregon and the rest, plus the federal sectoral rules, HIPAA, GLBA and COPPA, that sit underneath them.
Open guide 🇨🇦Canada & Latin AmericaPIPEDA, Law 25 & LGPD
Ten fair-information principles, meaningful consent, Quebec's Law 25, and the Latin American regimes including Brazil's LGPD, Mexico, Chile and Colombia.
Open guide 🇦🇪Middle EastGCC data protection laws
The UAE federal PDPL alongside the DIFC and ADGM regimes, Saudi Arabia's PDPL, and the laws of Qatar, Bahrain, Oman, Kuwait, Israel and Jordan.
Open guide 🇳🇬AfricaNDPA, POPIA & beyond
Nigeria's NDPA 2023 and the NDPC, South Africa's POPIA and its eight conditions, plus Kenya, Ghana, Egypt, Morocco, Rwanda, Uganda and Tanzania.
Open guide 🇨🇭Switzerland & EEARevised FADP
A GDPR-adjacent modernised regime with its own records, impact assessment and transfer requirements, plus how the EEA states adopted the GDPR.
Open guide 🇹🇷Türkiye & wider EuropeKVKK and neighbours
Türkiye's KVKK and its registry duty, alongside the regimes of Serbia, Ukraine and Russia, where localisation rules bite hardest.
Open guide 🤖European UnionEU AI Act
Risk tiers and what each one obliges you to do, the overlap with privacy law on training data and model outputs, and the commencement timetable.
Open guide 🎖StandardsISO/IEC 27001 · 27701 · 42001
The management systems that turn privacy obligations into audit-ready evidence, and how certification readiness actually proceeds.
Certification support In progress🇭🇰Hong Kong, Taiwan & Sri LankaPDPO, PDPA & PDPA 2022
Guides in preparation. Ask us directly in the meantime and we will answer your applicability question without waiting for publication.
Ask about this jurisdiction In progress📊Sector overlaysSectoral obligations
Financial services, healthcare, telecoms and children's data carry duties that sit on top of general privacy law. Guides in preparation.
Ask about your sectorNo guides in that region yet. Ask us about a jurisdiction and we will answer directly.
Also covered on request, without a published guide: Hong Kong SAR, Taiwan, Sri Lanka, Russia, Ukraine, Serbia, Kuwait, Jordan, Rwanda, Uganda, Tanzania, Argentina, Peru and Uruguay. Ask about a jurisdiction.
Guidance that reaches the control, not just the clause
A statute tells you what must be true. It rarely tells you what to build. Every guide here closes that gap.
Plain language
Written to be read by the people who have to act on it, engineers, HR, procurement, not only by lawyers.
Mapped to controls
Each obligation is tied to the notice, consent flow, DPIA, retention rule or record that actually satisfies it.
Compared across regimes
See where jurisdictions align and where they diverge, so a multi-country programme stays one programme.
Get an applicability read in one call
Tell us your footprint and what data you hold, and we will tell you which regimes actually reach you, and what to do first. No obligation, and we will say so if the answer is very little.