From the GDPR to Kenya's Data Protection Act - clear summaries, lawful bases, key principles, enforcement teeth and our point-of-view on how to operationalise each one.
The cornerstone of modern data protection - governs how organisations collect, process and protect personal data of EU residents, anywhere in the world.
Read summaryThe UK's post-Brexit data protection regime - closely mirrors the EU GDPR with UK-specific nuances.
Read summaryGrants California residents broad rights over personal information and creates strict obligations for businesses that meet the revenue or data thresholds.
Read summaryUS federal standard for safeguarding Protected Health Information (PHI) held by covered entities and their business associates.
Read summaryCanada's federal private-sector privacy law - likely to be replaced by the Consumer Privacy Protection Act (CPPA) under Bill C-27.
Read summaryThe international standard for an Information Security Management System (ISMS) - increasingly demanded by enterprise buyers worldwide.
Read summaryExtends ISO/IEC 27001 with privacy-specific controls - the de-facto international certification for a Privacy Information Management System (PIMS).
Read summaryVoluntary, risk-based frameworks from the US National Institute of Standards and Technology - widely adopted globally as the gold standard.
Read summaryMandatory technical and operational standard for any organisation that stores, processes or transmits cardholder data.
Read summaryThe AICPA Trust Services Criteria report demanded by enterprise buyers - a must-have for B2B SaaS.
Read summaryGives effect to the constitutional right of access to information held by the State and by private bodies in certain circumstances.
Read summaryCriminalises cyber-offences and gives effect to investigation, prosecution and international cooperation on cybercrime in Kenya.
Read summaryStrengthens consumer rights in transactions - including disclosures, unfair practices and electronic agreements.
Read summaryKenya's flagship data protection statute, enforced by the Office of the Data Protection Commissioner (ODPC).
Read summaryNigeria's comprehensive privacy law, enforced by the Nigeria Data Protection Commission (NDPC).
Read summarySouth Africa's comprehensive privacy law, enforced by the Information Regulator.
Read summarySingapore's PDPA balances individual rights with the needs of organisations to use data responsibly.
Read summaryBrazil's GDPR-aligned data protection law, enforced by the ANPD.
Read summaryA 30-minute applicability review and a one-page memo on the frameworks that genuinely affect your business - at no cost.