01 · 13 artifacts
Governance and accountability
Who owns privacy and how decisions get made.
- MGDPRTUK GDPRTPIPEDAMLaw 25MPOPIAMCCPAO
- GDPR · T
Art 37public authority; large-scale regular and systematic monitoring; or large-scale special category / criminal data- UK GDPR · T
Art 37public authority; large-scale regular and systematic monitoring; or large-scale special category / criminal data- PIPEDA · M
Principle 4.1designate an individual accountable for compliance- Law 25 · M
s. 3.1the person with the highest authority is the person in charge by default, and can delegate in writing- POPIA · M
s. 55the head of the organisation is the Information Officer by default; s. 56 deputies designated in writing- CCPA · O
- No statutory role; someone still has to own request handling and §7100 training
- MGDPRMUK GDPRMPIPEDAALaw 25MPOPIAM
- GDPR · M
Art 37(7), once a DPO is appointedpublish contact details and notify the SA- UK GDPR · M
Art 37(7), once a DPO is appointedpublish contact details and tell the ICO- PIPEDA · A
Principle 4.1.2identity made known on request; put the contact in the privacy policy- Law 25 · M
s. 3.1publish the title and contact details on the website- POPIA · M
s. 55(2)register the Information Officer with the Information Regulator before they take up duties
- AGDPRAUK GDPRA
- GDPR · A
Art 5(2)record the decision even when no DPO is required- UK GDPR · A
Art 5(2)record the decision even when no DPO is required
- TGDPRTUK GDPRT
- GDPR · T
Art 27no EU establishment, but targeting or monitoring people in the EU; exemption for occasional, low-risk processing- UK GDPR · T
Art 27no UK establishment, but targeting or monitoring people in the UK; exemption for occasional, low-risk processing
- TGDPR onlyT
- GDPR · T
Art 56establishments in more than one member state (one-stop shop)
- MUK GDPR onlyM
- UK GDPR · M
- Data Protection (Charges and Information) Regulations 2018, unless exempt
- MGDPRAUK GDPRAPIPEDAMLaw 25MPOPIAACCPAA
- GDPR · A
Art 24(2)"where proportionate", which in practice means always- UK GDPR · A
Art 24(2)"where proportionate", which in practice means always- PIPEDA · M
Principle 4.1.4(a)implement policies and practices to protect personal information- Law 25 · M
s. 3.2governance policies and practices, approved by the person in charge- POPIA · A
- s. 8 accountability; Reg 4(1)(a) compliance framework
- CCPA · A
- Needed to evidence request handling, contracts and reasonable security (§1798.100(e))
- MGDPRAUK GDPRAPIPEDAALaw 25APOPIAMCCPAO
- GDPR · A
Art 24, Art 5(2)scope, ownership, reporting lines, review cycle- UK GDPR · A
Art 24, Art 5(2)scope, ownership, reporting lines, review cycle- PIPEDA · A
- Principle 4.1; the OPC's accountability guidance expects a documented program
- Law 25 · A
- s. 3.2
- POPIA · M
Reg 4(1)(a)develop, implement, monitor and continuously improve a compliance framework- CCPA · O
- Good practice
- MGDPRAUK GDPRAPIPEDAALaw 25MPOPIAACCPAO
- GDPR · A
- Art 24, Art 5(2)
- UK GDPR · A
- Art 24, Art 5(2)
- PIPEDA · A
Principle 4.1others can handle day-to-day work, but accountability stays with the designated individual- Law 25 · M
s. 3.2roles and responsibilities of staff through the information life cycle- POPIA · A
- s. 8; ss. 55–56
- CCPA · O
- Good practice
- MGDPRAUK GDPRAPIPEDAMLaw 25APOPIAMCCPAM
- GDPR · A
- Art 39(1)(b), Art 32(4)
- UK GDPR · A
- Art 39(1)(b), Art 32(4)
- PIPEDA · M
Principle 4.1.4(c)train staff on policies and practices- Law 25 · A
- s. 3.2; the CAI expects staff awareness activities
- POPIA · M
Reg 4(1)(e)internal awareness sessions- CCPA · M
§1798.130(a)(6); Regs §7100staff handling consumer requests must know the rules
- TGDPR onlyT
- GDPR · T
AI Act Art 4 (as amended by the AI Omnibus)providers and deployers of AI systems take measures to support staff AI literacy
- OAll 6 lawsO
- GDPR · O
- Supports review evidence under Art 24(1)
- UK GDPR · O
- Supports review evidence under Art 24(1)
- PIPEDA · O
- Supports the review cycle
- Law 25 · O
- Supports the review cycle
- POPIA · O
- Supports continuous improvement under Reg 4(1)(a)
- CCPA · O
- Supports the annual privacy policy update
- OAll 6 lawsO
- GDPR · O
- Shows oversight at the top
- UK GDPR · O
- Shows oversight at the top
- PIPEDA · O
- Shows oversight at the top
- Law 25 · O
- Shows oversight at the top
- POPIA · O
- Shows oversight at the top
- CCPA · O
- Risk assessments and cybersecurity audits are certified by an executive
02 · 10 artifacts
Inventory, purposes and retention
What you hold, why you hold it, and for how long.
- MGDPRMUK GDPRMPIPEDAALaw 25APOPIAMCCPAA
- GDPR · M
- Art 30(1) controller; Art 30(2) processor. The Art 30(5) under-250-employee exemption is narrow enough to ignore in practice
- UK GDPR · M
- Art 30(1) controller; Art 30(2) processor. The under-250-employee exemption is narrow enough to ignore in practice
- PIPEDA · A
- Principle 4.1; the OPC's accountability guidance expects a personal information inventory
- Law 25 · A
- s. 3.2; an inventory is the practical basis for PIAs, access requests and retention
- POPIA · M
s. 17keep documentation of all processing operations (as referred to in PAIA ss. 14 and 51)- CCPA · A
- The privacy policy must list categories, sources, purposes and recipients (§1798.110, Regs §7011); an inventory is how you get that right
- OAll 6 lawsO
- GDPR · O
- Makes the RoPA and TIAs defensible
- UK GDPR · O
- Makes the RoPA and TIAs defensible
- PIPEDA · O
- Makes the inventory and cross-border disclosures defensible
- Law 25 · O
- Makes PIAs and s. 17 assessments defensible
- POPIA · O
- Makes the documentation and transfer analysis defensible
- CCPA · O
- Shows where sale or sharing happens
- MGDPRAUK GDPRAPIPEDAMLaw 25APOPIAACCPAA
- GDPR · A
- Art 6, per purpose; can sit in the RoPA
- UK GDPR · A
- Art 6, per purpose; can sit in the RoPA
- PIPEDA · M
Principle 4.2.1document the purposes for which information is collected- Law 25 · A
ss. 4–5determine purposes before collecting; collect only what's necessary- POPIA · A
s. 11a justification for every processing operation- CCPA · A
§1798.100(c)collection and use reasonably necessary and proportionate to the disclosed purposes
- TGDPRTUK GDPRTPOPIAT
- GDPR · T
- Reliance on Art 6(1)(f)
- UK GDPR · T
- Reliance on Art 6(1)(f); record reliance on a DUAA "recognised legitimate interest" (Annex 1) instead where one applies
- POPIA · T
s. 11(1)(f)relying on legitimate interests
- AGDPRTUK GDPRTPIPEDAALaw 25APOPIATCCPAT
- GDPR · T
Art 7(1)consent must be demonstrable- UK GDPR · T
Art 7(1)consent must be demonstrable- PIPEDA · A
- Principle 4.3; OPC Guidelines for obtaining meaningful consent
- Law 25 · A
ss. 12–14consent must be manifest, free, enlightened and specific, and requested separately- POPIA · T
s. 11(2)(a)you carry the burden of proving consent- CCPA · T
- Opt-in consent for financial incentives, selling minors' data, or re-opting in after an opt-out (Regs §7004)
- TAll 6 lawsT
- GDPR · T
- Art 9 / Art 10 processing
- UK GDPR · T
- Art 9 / Art 10 processing
- PIPEDA · T
Principle 4.3.6sensitive information generally needs express consent- Law 25 · T
s. 12sensitive information needs express consent- POPIA · T
ss. 26–33special personal information needs a listed authorisation- CCPA · T
§1798.121sensitive personal information used beyond permitted purposes triggers the right to limit
- TUK GDPR onlyT
- UK GDPR · T
- DPA 2018 Sch 1 Pt 4, when relying on most Sch 1 conditions such as employment or substantial public interest
- TAll 6 lawsT
- GDPR · T
- Art 6(4)
- UK GDPR · T
- Art 6(4) and the DUAA's Annex 2 list of compatible purposes
- PIPEDA · T
Principle 4.2.4identify a new purpose before use, and get consent unless an exception applies- Law 25 · T
s. 12a new purpose needs consent unless a listed exception applies- POPIA · T
s. 15further processing must be compatible with the original purpose- CCPA · T
§1798.100(c), Regs §7002new purposes must be compatible with the context of collection
- MGDPRAUK GDPRAPIPEDAALaw 25MPOPIAACCPAA
- GDPR · A
- Art 5(1)(e); Art 13(2)(a) puts periods in notices, so effectively mandatory
- UK GDPR · A
- Art 5(1)(e); Art 13(2)(a) puts periods in notices, so effectively mandatory
- PIPEDA · A
Principles 4.5.2–4.5.3retention guidelines with minimum and maximum periods; destroy or anonymise when no longer needed- Law 25 · M
s. 3.2governance policies must cover retention and destruction; s. 23 destroy or anonymise- POPIA · A
s. 14keep no longer than necessary; destroy, delete or de-identify- CCPA · A
§1798.100(a)(3)notices must state how long you keep each category, so you need the schedule behind them
- TLaw 25 onlyT
- Law 25 · T
- s. 23 and the Regulation respecting the anonymization of personal information: when anonymising instead of destroying
03 · 12 artifacts
Transparency
Several notices, one per audience.
- MAll 6 lawsM
- GDPR · M
- Art 13 / 14
- UK GDPR · M
- Art 13 / 14
- PIPEDA · M
Principle 4.8make policies and practices readily available, in practice a website privacy policy- Law 25 · M
ss. 7–8.2inform at collection; publish a privacy policy when collecting by technological means- POPIA · M
s. 18tell people what you collect, why, and their rights- CCPA · M
§1798.130(a)(5), Regs §7011privacy policy updated every 12 months; CalOPPA for any commercial website
- MGDPROUK GDPROPIPEDAALaw 25OPOPIAOCCPAM
- GDPR · O
- Improves clarity at the point of collection
- UK GDPR · O
- Improves clarity at the point of collection
- PIPEDA · A
OPC meaningful consent guidelinesemphasise key elements at the point of collection- Law 25 · O
s. 8clear and simple terms at the point of collection- POPIA · O
- Improves clarity at the point of collection
- CCPA · M
§1798.100(a), Regs §7012notice at collection, at or before the point of collection
- MGDPRMUK GDPRMPIPEDATLaw 25MPOPIAMCCPAM
- GDPR · M
Art 13any staff or recruitment- UK GDPR · M
Art 13any staff or recruitment- PIPEDA · T
- Federally regulated employers only (s. 4(1)(b)); other employers follow provincial law
- Law 25 · M
s. 8applies to employee and candidate information- POPIA · M
s. 18any staff or recruitment- CCPA · M
Regs §7012employees, applicants and contractors are consumers (since 1 January 2023)
- MGDPRMUK GDPRMPOPIAMCCPAM
- GDPR · M
Art 13 / 14processing business contact data- UK GDPR · M
Art 13 / 14processing business contact data- POPIA · M
s. 18companies and their staff are data subjects under POPIA too- CCPA · M
- B2B contacts are consumers (since 1 January 2023)
- TGDPRTUK GDPRTPOPIAT
- GDPR · T
Art 14data obtained from third parties or public sources- UK GDPR · T
Art 14data obtained from third parties or public sources- POPIA · T
s. 18(1)–(2)information collected from other sources
- MLaw 25 onlyM
- Law 25 · M
s. 3.2publish detailed information about the governance policies in clear and simple terms
- MPOPIA onlyM
- POPIA · M
PAIA s. 51compile, publish and update a manual (all private bodies since 1 January 2022)
- TCCPA onlyT
- CCPA · T
§1798.125(b), Regs §7016loyalty programs, discounts or other incentives tied to personal information
- TAll 6 lawsT
- GDPR · T
ePrivacy Art 5(3) and national implementationsconsent for non-essential storage and access- UK GDPR · T
PECR reg 6consent for non-essential cookies; the DUAA added exemptions for some analytics and functionality cookies- PIPEDA · T
Online tracking and behavioural advertisingOPC guidance expects clear notice and an easy opt-out, and express consent for sensitive tracking- Law 25 · T
s. 8.1technology that identifies, locates or profiles people must be off by default and disclosed- POPIA · T
- Online tracking needs a s. 11 justification and s. 18 notice; there's no cookie-specific rule
- CCPA · T
- Ad and cross-site tracking can be "sharing" (§1798.140(ah)); disclose it and honour opt-outs
- TGDPR onlyT
- GDPR · T
AI Act Art 50tell people they're interacting with AI and label deepfakes (from 2 August 2026); machine-readable marking of generated content from 2 December 2026
- TGDPRTUK GDPRTPIPEDATLaw 25TPOPIAT
- GDPR · T
- Video surveillance; EDPB Guidelines 3/2019
- UK GDPR · T
- Video surveillance; ICO video surveillance guidance
- PIPEDA · T
- Video surveillance; OPC guidance on overt video surveillance
- Law 25 · T
- Video surveillance; CAI guidance
- POPIA · T
Video surveillances. 18 notice
- TGDPRTUK GDPRT
- GDPR · T
- Art 26(2)
- UK GDPR · T
- Art 26(2)
04 · 9 artifacts
Individual rights
Requests answered on time and on the record.
- MGDPRAUK GDPRAPIPEDAALaw 25APOPIAMCCPAM
- GDPR · A
Art 12(3)facilitate rights, respond within one month- UK GDPR · A
Art 12(3)respond within one month; the DUAA limits searches to what's reasonable and proportionate- PIPEDA · A
s. 8respond to access requests within 30 days; Principle 4.9- Law 25 · A
ss. 27–32respond within 30 days; includes portability (s. 27) and de-indexing (s. 28.1)- POPIA · M
Reg 4(1)(d)internal measures and systems to process requests; ss. 23–25- CCPA · M
§1798.130(a)(1)–(2)two or more request methods; respond within 45 days
- MGDPRAUK GDPRAPIPEDAALaw 25APOPIAACCPAM
- GDPR · A
Art 5(2)evidence of timeliness and outcomes- UK GDPR · A
Art 5(2)evidence of timeliness and outcomes- PIPEDA · A
- Evidence of timeliness and outcomes
- Law 25 · A
- Evidence of timeliness and outcomes
- POPIA · A
- Evidence of timeliness and outcomes
- CCPA · M
Regs §7101keep request records for 24 months
- MGDPRAUK GDPRAPIPEDAALaw 25APOPIAACCPAM
- GDPR · A
- Art 12(6)
- UK GDPR · A
- Art 12(6)
- PIPEDA · A
Principle 4.9confirm identity before giving access- Law 25 · A
ss. 30–32confirm the requester is entitled to the information- POPIA · A
s. 23(1)adequate proof of identity- CCPA · M
Regs §§7060–7062a documented, reasonable verification method
- OAll 6 lawsO
- GDPR · O
- Consistency; supports defensible refusals
- UK GDPR · O
- Consistency; supports defensible refusals
- PIPEDA · O
- Consistency; supports defensible refusals
- Law 25 · O
- Consistency; supports defensible refusals
- POPIA · O
- Consistency; supports defensible refusals
- CCPA · O
- Consistency; supports defensible refusals
- APOPIA onlyA
- POPIA · A
PAIA ss. 53–56requests on the prescribed form, decided within 30 days
- MUK GDPRMPIPEDAMLaw 25MPOPIAO
- UK GDPR · M
DPA 2018 s. 164A (DUAA, from 19 June 2026)make it easy to complain, acknowledge within 30 days, respond without undue delay- PIPEDA · M
Principle 4.10.2procedures to receive and respond to complaints and inquiries- Law 25 · M
s. 3.2governance policies must include a complaints process- POPIA · O
- Complaints go to the Regulator under s. 74; resolving them internally first is good practice
- TCCPA onlyT
- CCPA · T
§§1798.120, 1798.121, 1798.135selling or sharing personal information, or using sensitive information beyond permitted purposes
- TCCPA onlyT
- CCPA · T
Regs §7025honour opt-out preference signals such as Global Privacy Control where you sell or share
- TGDPRTUK GDPRTLaw 25TPOPIATCCPAT
- GDPR · T
Art 22decisions based solely on automated processing with legal or similarly significant effects- UK GDPR · T
Arts 22A–22D (DUAA)significant decisions based solely on automated processing need information, human intervention and a way to contest- Law 25 · T
s. 12.1tell the person about decisions based exclusively on automated processing, and let them submit observations- POPIA · T
s. 71decisions based solely on automated processing with legal or substantial effects- CCPA · T
Regs §§7200–7222pre-use notice, opt-out and access for ADMT used in significant decisions, from 1 January 2027
05 · 10 artifacts
Privacy by design and risk
Assess new processing before it goes live.
- AGDPRAUK GDPRAPIPEDAOLaw 25APOPIAACCPAA
- GDPR · A
- Art 35
- UK GDPR · A
- Art 35
- PIPEDA · O
- The OPC recommends privacy impact assessments; not a statutory duty for the private sector
- Law 25 · A
- s. 3.3
- POPIA · A
- Reg 4(1)(b)
- CCPA · A
Regs §7150you need a way to spot processing that triggers a risk assessment
- MGDPRTUK GDPRTPIPEDAOLaw 25TPOPIAMCCPAT
- GDPR · T
Art 35likely high risk; check the relevant SA's mandatory list- UK GDPR · T
Art 35likely high risk; check the ICO's mandatory list- PIPEDA · O
- The OPC recommends PIAs for new or high-risk initiatives; not a statutory duty for the private sector
- Law 25 · T
s. 3.3acquiring, developing or overhauling an information system or electronic service delivery involving personal information- POPIA · M
Reg 4(1)(b)a personal information impact assessment to confirm the conditions for lawful processing are met- CCPA · T
Regs §§7150–7157risk assessment before selling or sharing, processing sensitive information, ADMT for significant decisions, and certain profiling or AI training. Processing ongoing at 1 January 2026 must be assessed by 31 December 2027
- TGDPRTUK GDPRT
- GDPR · T
Art 36residual risk remains high after mitigation- UK GDPR · T
Art 36residual risk remains high after mitigation
- TPOPIA onlyT
- POPIA · T
ss. 57–58unique identifiers used for new purposes, criminal or credit information processed for third parties, special or children's information sent to countries without adequate protection. Apply before processing
- TCCPA onlyT
- CCPA · T
Regs §7157annual submission of risk assessment information to the CPPA; first due 1 April 2028
- AGDPRAUK GDPRAPIPEDAOLaw 25APOPIAOCCPAO
- GDPR · A
- Art 25
- UK GDPR · A
- Art 25
- PIPEDA · O
- Good practice; supports Principles 4.4 (limiting collection) and 4.7
- Law 25 · A
s. 3.3privacy built into system projects from the start- POPIA · O
- Good practice; supports s. 19
- CCPA · O
- Good practice
- TLaw 25 onlyT
- Law 25 · T
s. 9.1technology products and services offered to the public default to the highest level of confidentiality (cookies excluded)
- AAll 6 lawsA
- GDPR · A
- Art 24, Art 32
- UK GDPR · A
- Art 24, Art 32
- PIPEDA · A
- Principles 4.1 and 4.7
- Law 25 · A
s. 10measures reasonable given sensitivity, purpose, quantity, distribution and medium- POPIA · A
- s. 19(2)(a)
- CCPA · A
- Supports risk assessments and reasonable security
- OAll 6 lawsO
- GDPR · O
- Prerequisite for AI Act risk classification
- UK GDPR · O
- Supports DPIAs and ADM safeguards for AI tools
- PIPEDA · O
- Supports consent, transparency and safeguards for AI tools
- Law 25 · O
- Supports s. 12.1 automated decision notices
- POPIA · O
- Supports s. 71 automated decision safeguards
- CCPA · O
- Prerequisite for identifying ADMT in significant decisions
- TGDPR onlyT
- GDPR · T
AI Act Art 27certain deployers of high-risk AI (public services, credit scoring, life and health insurance); Annex III obligations apply from 2 December 2027
06 · 7 artifacts
Vendors and third parties
Every vendor gets a contract and a check.
- MAll 6 lawsM
- GDPR · M
- Art 28(3), whenever a processor is used
- UK GDPR · M
- Art 28(3), whenever a processor is used
- PIPEDA · M
Principle 4.1.3contractual or other means to give comparable protection when a third party processes information for you- Law 25 · M
s. 18.3written contract with anyone receiving information to perform a mandate or service- POPIA · M
s. 21(1)written contract requiring operators to maintain security measures- CCPA · M
§1798.100(d), Regs §§7051, 7053contracts with service providers, contractors and third parties
- AAll 6 lawsA
- GDPR · A
Art 28(1)"sufficient guarantees"- UK GDPR · A
Art 28(1)"sufficient guarantees"- PIPEDA · A
- Principle 4.1.3
- Law 25 · A
- s. 18.3
- POPIA · A
- s. 21
- CCPA · A
Regs §7051(e)due diligence affects whether you can rely on the contract
- AAll 6 lawsA
- GDPR · A
- Supports RoPA recipients and transfer mapping
- UK GDPR · A
- Supports RoPA recipients and transfer mapping
- PIPEDA · A
- Supports Principle 4.1.3 and cross-border transparency
- Law 25 · A
- Supports s. 18.3 contracts and s. 17 transfer assessments
- POPIA · A
- Supports s. 21 contracts and s. 72 transfer analysis
- CCPA · A
- Supports the privacy policy's recipient categories
- TGDPRTUK GDPRT
- GDPR · T
Art 26two or more controllers jointly determine purposes and means- UK GDPR · T
Art 26two or more controllers jointly determine purposes and means
- AGDPROUK GDPRA
- GDPR · O
- Good practice
- UK GDPR · A
- The ICO Data Sharing Code is a statutory code
- TAll 6 lawsT
- GDPR · T
- Organisation acts as a processor
- UK GDPR · T
- Organisation acts as a processor
- PIPEDA · T
- Organisation processes information on behalf of clients
- Law 25 · T
- Organisation performs mandates or services for clients
- POPIA · T
- Organisation acts as an operator (s. 20)
- CCPA · T
- Organisation acts as a service provider or contractor
- TGDPRTUK GDPRTPIPEDAOLaw 25OPOPIAOCCPAO
- GDPR · T
- Organisation acts as a processor; Art 28(2)
- UK GDPR · T
- Organisation acts as a processor; Art 28(2)
- PIPEDA · O
- Customers will ask; no statutory duty
- Law 25 · O
- Customers will ask; no statutory duty
- POPIA · O
- Customers will ask; no statutory duty
- CCPA · O
- Customers will ask; CCPA contracts restrict onward engagement
07 · 9 artifacts
International transfers
A mechanism and an assessment for each route.
- MGDPRMUK GDPRMPIPEDAALaw 25APOPIAA
- GDPR · M
Art 30(1)(e)transfers must be recorded in the RoPA- UK GDPR · M
Art 30(1)(e)transfers must be recorded in the RoPA- PIPEDA · A
OPC cross-border processing guidelinestell people their information may be processed outside Canada- Law 25 · A
- s. 17
- POPIA · A
- s. 72
- TGDPRTUK GDPRT
- GDPR · T
- Art 45; check EU-US DPF certification per recipient. The UK (renewed to 2031) and Canada (PIPEDA-covered data) hold adequacy
- UK GDPR · T
- UK adequacy regulations; check UK Extension to the EU-US DPF certification per recipient
- TGDPR onlyT
- GDPR · T
- Art 46(2)(c), no adequacy
- TUK GDPR onlyT
- UK GDPR · T
- Art 46, no UK adequacy regulations
- TLaw 25TPOPIAT
- Law 25 · T
s. 17written agreement taking the assessment's results into account- POPIA · T
s. 72(1)(a)binding agreement with adequate protection
- TGDPRTUK GDPRTLaw 25TPOPIAT
- GDPR · T
- Reliance on an Art 46 tool
- UK GDPR · T
- Reliance on an Art 46 tool; applies the DUAA "data protection test" (not materially lower)
- Law 25 · T
s. 17assess privacy before communicating information outside Quebec; the information must be adequately protected- POPIA · T
s. 72(1)(a)the recipient must be bound by law, binding corporate rules or an agreement giving adequate protection
- TGDPRTUK GDPRT
- GDPR · T
- Groups transferring between entities; contractual wrapper for SCCs, can carry Art 28 / 26 terms
- UK GDPR · T
- Groups transferring between entities; contractual wrapper for the IDTA or Addendum, can carry Art 28 / 26 terms
- OGDPROUK GDPROPOPIAO
- GDPR · O
Art 47large groups with high intragroup transfer volume- UK GDPR · O
Art 47large groups with high intragroup transfer volume- POPIA · O
s. 72(1)(a)binding corporate rules
- TGDPRTUK GDPRTPOPIAT
- GDPR · T
Art 49occasional transfers with no Art 45 / 46 basis- UK GDPR · T
Art 49occasional transfers with no Art 45 / 46 basis- POPIA · T
s. 72(1)(b)–(e)consent, contract necessity or the data subject's benefit
08 · 7 artifacts
Security
Appropriate to the risk, with testing evidence.
- AAll 6 lawsA
- GDPR · A
- Art 32
- UK GDPR · A
- Art 32
- PIPEDA · A
- Principle 4.7
- Law 25 · A
- s. 10
- POPIA · A
- s. 19
- CCPA · A
§1798.100(e); Civ. Code §1798.81.5reasonable security procedures
- MGDPRMUK GDPRM
- GDPR · M
Art 30(1)(g)general description in the RoPA- UK GDPR · M
Art 30(1)(g)general description in the RoPA
- AAll 6 lawsA
- GDPR · A
- Art 32(1)
- UK GDPR · A
- Art 32(1)
- PIPEDA · A
Principle 4.7.3physical, organisational and technological measures- Law 25 · A
- s. 10
- POPIA · A
- s. 19(1)
- CCPA · A
- §1798.81.5
- MGDPRAUK GDPRAPIPEDAALaw 25APOPIAMCCPAA
- GDPR · A
- Art 32(2)
- UK GDPR · A
- Art 32(2)
- PIPEDA · A
Principle 4.7safeguards appropriate to sensitivity- Law 25 · A
- s. 10
- POPIA · M
s. 19(2)(a)identify all reasonably foreseeable internal and external risks- CCPA · A
- §1798.81.5
- AAll 6 lawsA
- GDPR · A
- Art 32(1)(a)–(b)
- UK GDPR · A
- Art 32(1)(a)–(b)
- PIPEDA · A
- Principle 4.7.3
- Law 25 · A
- s. 10
- POPIA · A
- s. 19(2)(b)
- CCPA · A
- §1798.81.5
- AGDPRAUK GDPRAPIPEDAOLaw 25OPOPIAOCCPAO
- GDPR · A
Art 32(1)(c)ability to restore availability- UK GDPR · A
Art 32(1)(c)ability to restore availability- PIPEDA · O
- Good practice
- Law 25 · O
- Good practice
- POPIA · O
- Good practice
- CCPA · O
- Good practice
- MGDPRAUK GDPRAPIPEDAALaw 25APOPIAMCCPAA
- GDPR · A
Art 32(1)(d)regularly test and evaluate- UK GDPR · A
Art 32(1)(d)regularly test and evaluate- PIPEDA · A
- Principle 4.7
- Law 25 · A
- s. 10
- POPIA · M
s. 19(2)(c)regularly verify that safeguards are effectively implemented- CCPA · A
- §1798.81.5; also evidence for a cybersecurity audit
09 · 7 artifacts
Breach management
Log every incident and know each regulator's clock.
- AAll 6 lawsA
- GDPR · A
- Arts 33–34
- UK GDPR · A
- Arts 33–34
- PIPEDA · A
- ss. 10.1–10.3
- Law 25 · A
- ss. 3.5–3.8
- POPIA · A
- s. 22
- CCPA · A
- §1798.82
- MGDPRMUK GDPRMPIPEDAMLaw 25MPOPIAA
- GDPR · M
Art 33(5)all breaches, facts, effects and remedial action- UK GDPR · M
Art 33(5)all breaches, facts, effects and remedial action- PIPEDA · M
s. 10.3record every breach of security safeguards; keep records 24 months (Breach of Security Safeguards Regulations s. 6)- Law 25 · M
s. 3.8register every confidentiality incident; keep entries five years (Regulation respecting confidentiality incidents)- POPIA · A
- Supports s. 22 notifications and Regulator queries
- TAll 6 lawsT
- GDPR · T
Art 33within 72 hours, unless unlikely to result in risk- UK GDPR · T
Art 33within 72 hours, unless unlikely to result in risk- PIPEDA · T
s. 10.1(1)real risk of significant harm; report to the OPC as soon as feasible- Law 25 · T
s. 3.5risk of serious injury; notify the CAI promptly- POPIA · T
s. 22notify the Regulator as soon as reasonably possible, through the eServices portal- CCPA · T
§1798.82(f)sample notice to the Attorney General within 15 days of notifying residents, when more than 500 are affected
- TAll 6 lawsT
- GDPR · T
Art 34high risk to individuals- UK GDPR · T
Art 34high risk to individuals- PIPEDA · T
s. 10.1(3)real risk of significant harm- Law 25 · T
s. 3.5risk of serious injury- POPIA · T
s. 22notify affected data subjects unless their identity can't be established- CCPA · T
§1798.82notify affected residents within 30 calendar days of discovery (since 1 January 2026)
- TPIPEDATLaw 25O
- PIPEDA · T
s. 10.2notify organisations that can reduce the risk of harm- Law 25 · O
- s. 3.5 allows notifying anyone able to reduce the risk
- MGDPRMUK GDPRMPIPEDAALaw 25MPOPIAMCCPAM
- GDPR · M
- Art 28(3)(f) / Art 33(2), inside the DPA
- UK GDPR · M
- Art 28(3)(f) / Art 33(2), inside the DPA
- PIPEDA · A
Principle 4.1.3contracts should require processors to report breaches- Law 25 · M
s. 18.3the contract must require notice of any confidentiality breach without delay- POPIA · M
s. 21(2)operators must notify you immediately of a compromise- CCPA · M
§1798.82(b)anyone maintaining data for you must notify you immediately
- TUK GDPR onlyT
- UK GDPR · T
PECR reg 5Atelecom and internet service providers notify the ICO within 24 hours
10 · 5 artifacts
Monitoring and assurance
Review on a cycle and keep the evidence.
- AGDPRAUK GDPRAPIPEDAALaw 25APOPIAACCPAO
- GDPR · A
Art 24(1)review and update measures- UK GDPR · A
Art 24(1)review and update measures- PIPEDA · A
- Principle 4.1; the OPC's accountability guidance expects ongoing assessment
- Law 25 · A
- s. 3.2
- POPIA · A
Reg 4(1)(a)monitor and continuously improve- CCPA · O
- Good practice
- AGDPRAUK GDPRAPIPEDAOLaw 25OPOPIAO
- GDPR · A
- Art 38(3), where a DPO exists
- UK GDPR · A
- Art 38(3), where a DPO exists
- PIPEDA · O
- Shows the accountable individual is informed
- Law 25 · O
- Shows the person in charge is informed
- POPIA · O
- Shows the Information Officer is informed
- TCCPA onlyT
- CCPA · T
Regs §§7120–7124annual independent audit where processing presents significant security risk; first certifications due 1 April 2028, 2029 or 2030 by revenue
- OAll 6 lawsO
- GDPR · O
- Tracks regulator interactions and commitments
- UK GDPR · O
- Tracks regulator interactions and commitments
- PIPEDA · O
- Tracks regulator interactions and commitments
- Law 25 · O
- Tracks regulator interactions and commitments
- POPIA · O
- Tracks regulator interactions and commitments
- CCPA · O
- Tracks regulator interactions and commitments
- OAll 6 lawsO
- GDPR · O
- Art 40 / 42
- UK GDPR · O
- Art 40 / 42
- PIPEDA · O
- Voluntary
- Law 25 · O
- Voluntary
- POPIA · O
- Chapter 7 codes of conduct
- CCPA · O
- Voluntary
11 · 9 artifacts
Situational triggers
Scope each one in or out, in writing.
- TAll 6 lawsT
- GDPR · T
ePrivacy Art 13opt-in for electronic marketing, with a soft opt-in for existing customers in most member states- UK GDPR · T
PECR regs 22–23consent for electronic marketing, soft opt-in for existing customers (extended to charities by the DUAA)- PIPEDA · T
CASL ss. 6 and 11consent before sending commercial electronic messages; unsubscribe honoured within 10 business days; s. 13 puts the onus of proving consent on you- Law 25 · T
s. 22when using information for commercial prospecting, identify yourself and offer withdrawal; CASL also applies to electronic messages- POPIA · T
s. 69electronic direct marketing needs opt-in consent (asked once) or the existing-customer exception; every message carries an opt-out- CCPA · T
15 U.S.C. §7704working unsubscribe honoured within 10 business days, a postal address, no deceptive headers
- OPIPEDAOLaw 25O
- PIPEDA · O
- CASL s. 33 due diligence defence; CRTC Compliance and Enforcement Bulletin 2014-326
- Law 25 · O
- CASL s. 33 due diligence defence; CRTC Compliance and Enforcement Bulletin 2014-326
- TPIPEDATLaw 25T
- PIPEDA · T
CASL s. 8installing software on someone else's device in the course of commercial activity- Law 25 · T
CASL s. 8installing software on someone else's device in the course of commercial activity
- TAll 6 lawsT
- GDPR · T
Art 8information society services offered to children; age 13 to 16 depending on the member state- UK GDPR · T
Art 8information society services offered to children under 13- PIPEDA · T
Services directed at childrenthe OPC's position is parental consent under 13- Law 25 · T
s. 4.1under-14s need consent from a parent or tutor- POPIA · T
s. 35children under 18 need a competent person's consent- CCPA · T
§1798.120(c)opt-in before selling or sharing data of under-16s, with a parent's consent for under-13s
- TCCPA onlyT
- CCPA · T
16 CFR Part 312verifiable parental consent for under-13s on child-directed services or with actual knowledge
- TUK GDPR onlyT
- UK GDPR · T
DPA 2018 s. 123online services likely to be accessed by children
- TAll 6 lawsT
- GDPR · T
Monitoring staffDPIA, notice, proportionality; Art 88 national rules- UK GDPR · T
Monitoring staffDPIA, notice, proportionality; ICO monitoring workers guidance- PIPEDA · T
- Federally regulated employers only; otherwise provincial law
- Law 25 · T
Monitoring staffs. 3.3 assessment for new systems; s. 8.1 for tracking tools- POPIA · T
Monitoring staffs. 18 notice, s. 11 justification, proportionality- CCPA · T
- Employee data is fully covered; monitoring may need a risk assessment (Regs §7150)
- TGDPRTUK GDPRTLaw 25TPOPIAT
- GDPR · T
- Art 89
- UK GDPR · T
- Art 89; the DUAA clarified scientific research purposes
- Law 25 · T
ss. 21–21.0.2research use without consent needs an assessment and a written agreement- POPIA · T
s. 27(1)(d) and s. 15(3)(e)research safeguards
- TCCPA onlyT
- CCPA · T
Civ. Code §1798.99.80 and followingregister annually with the CPPA; from 1 August 2026, process DROP deletion requests at least every 45 days