Privacy · Data Protection · Consent · Cross-Border Transfers

GDPR. CCPA. PIPL.
36,179 obligations scored.

Comprehensive global data protection and privacy regulations for organisations that collect, process, or transfer personal information. AuditDSS decomposes 71 regulations into 36,179 individually testable obligations across 18 jurisdictions with 4-axis risk scoring.

Privacy enforcement has gone global — and the fines are staggering

European DPAs, California's AG, China's CAC, and Korea's PIPC are all imposing record penalties. Every jurisdiction your users are in is a jurisdiction that can fine you.

€6B

EDPB total fines

441 enforcement actions across EU data protection authorities — GDPR fines are accelerating, not plateauing

$732M

California AG actions

Epic $520M, Google $93M, Zoom $85M — CCPA/CPRA enforcement is producing nine-figure settlements

¥15.2B

China CAC penalties

Didi ¥8B, Ant Group ¥7.1B — China's PIPL enforcement has produced the largest privacy fines in Asia

₩14.4T

Korea PIPC total

South Korea's Personal Information Protection Commission is among the most active privacy regulators in the world

71

Regulations covered

3,951

Rules decomposed

36,179

Obligations scored

18

Jurisdictions

Geographic coverage

18 jurisdictions, 71 regulations

Complete privacy & data protection coverage

From GDPR and CCPA to China's PIPL and Brazil's LGPD, from ePrivacy to sector-specific privacy rules — AuditDSS decomposes every privacy regulation into independently testable obligations so you know exactly where your program stands in every jurisdiction.

Key coverage areas

GDPR & UK GDPR
CCPA / CPRA
China PIPL
Korea PIPA
PDPA (Singapore/Thailand)
Australian Privacy Act
ePrivacy Directive
Brazil LGPD

Purpose-built for privacy compliance

Data-intensive companies

Score your privacy program across GDPR, CCPA, and PIPL in a single assessment. Identify the cross-border transfer gaps, consent failures, and DPIA obligations regulators will target first.

  • Map data processing activities against all lawful bases
  • Validate cross-border transfer mechanisms (SCCs, BCRs, adequacy)
  • Prioritise remediation by enforcement risk

SaaS & cloud providers

Data processor obligations scored at the obligation level. Know exactly which DPA clauses, sub-processor management requirements, and breach notification timelines you need to meet in every jurisdiction.

  • Score Article 28 processor obligations across all DPAs
  • Validate sub-processor management and notification procedures
  • 72-hour breach notification readiness across jurisdictions

Multinationals

Privacy obligations decomposed across 71 regulations in every major jurisdiction. GDPR, CCPA, PIPL, PIPA, LGPD, PDPA — all scored and risk-ranked so your global privacy team knows where to focus.

  • All 42 privacy regulations in one assessment
  • Cross-jurisdiction gap analysis and overlap mapping
  • Risk-scored obligation-level reporting

Regulatory coverage

All 71 regulations applicable to privacy & data protection, grouped by theme. Every regulation links to its detailed obligation breakdown.

Global Privacy Frameworks

🇦🇺
Privacy Act 1988

Office of the Australian Information Commissioner

29 · 203
🇧🇷
LGPD

Autoridade Nacional de Proteção de Dados

19 · 200
🇺🇸
CCPA/CPRA

California Attorney General / California Privacy Protection Agency

46 · 572
🇨🇳
PIPL

Cyberspace Administration of China

15 · 203
🇺🇸
COPPA

Federal Trade Commission

13 · 156
🇦🇪
DIFC Law No. 5/2020

DIFC Commissioner of Data Protection

10 · 65
🇪🇺
ePrivacy Directive

European Parliament and Council

19 · 137
🇪🇺
GDPR

European Data Protection Board

272 · 947
🇺🇸
FCRA Reg V

Consumer Financial Protection Bureau

43 · 751
🇺🇸
FERPA

US Department of Education Student Privacy Policy Office

32 · 353
🇺🇸
GLBA Reg P

Consumer Financial Protection Bureau

17 · 496
🇺🇸
HIPAA

HHS Office for Civil Rights

102 · 1,696
🇭🇰
PDPO

Privacy Commissioner for Personal Data

14 · 155
🇮🇳
DPDP Act 2023

Data Protection Board of India

19 · 183
🇯🇵
APPI

Personal Information Protection Commission

26 · 180
🇰🇷
PIPA

Personal Information Protection Commission

20 · 160
🇲🇽
LFPDPPP

National Institute for Transparency, Access to Information and Protection of Personal Data (INAI)

12 · 158
🇴🇲
Royal Decree 6/2022

Ministry of Transport, Communications and Information Technology

5 · 32
🇸🇦
PDPL

Saudi Data and AI Authority

10 · 135
🇸🇬
PDPA

Personal Data Protection Commission

20 · 184
🇹🇭
PDPA

Personal Data Protection Committee (PDPC)

12 · 180
🇦🇪
Federal Decree-Law 45/2021

UAE Data Office

8 · 31
🇬🇧
UK GDPR

Information Commissioner's Office

53 · 402
🇬🇧
Online Safety Act

Office of Communications

17 · 231
🇿🇦
POPIA

Information Regulator of South Africa

17 · 176

Sector-Specific Privacy

Cybersecurity

Corporate Governance

Saudi Privacy

AI Governance

Employment

Workplace Safety

Audit & Assurance Frameworks

Compliance Program Builder

Generate your privacy & data protection compliance program

Answer a few questions about your business. Get a complete compliance program — policies, procedures, and operational forms — tailored to your risk profile and mapped to every obligation. Ready in minutes.

  • AI-guided questionnaire adapts to your entity type
  • Every clause traces to specific regulatory obligations
  • Export to PDF — ready for board review or audit

Privacy & Data Protection Compliance Policy

Risk-calibrated · 10–15 sections

Policy

Operational Procedures

Step-by-step · Staff-ready

Procedures

Forms & Checklists

Operational forms · Ready to use

Forms

Score your privacy & data protection compliance

Score your existing policies against 36,179 obligations — or generate a complete compliance program tailored to your business in minutes.