Regimes
Seven held texts, 51 clauses cited, each linked to the standard itself. A finding cites the clause each placed regime has on the point; it does not mean every regime asks for every finding.
- GDPR (the EU General Data Protection Regulation)Placed for sites in the 27 EU member states and in Iceland, Liechtenstein and Norway (the EEA).
- UK GDPRPlaced for sites in the United Kingdom (England, Scotland, Wales and Northern Ireland).
- EU AI ActPlaced for sites in the 27 EU member states, and only on analytics features that may be AI systems. Its lines on a camera are questions: whether a feature is an AI system, and whether it is high-risk under Art. 6, are for your lawyer.
- Illinois Biometric Information Privacy Act (BIPA)Placed for sites in Illinois. It attaches to biometric identifiers, so its lines appear on face matching cameras only.
- California Consumer Privacy Act (CCPA, as amended by the CPRA)Placed for sites in California, and only when you say the business meets the CCPA thresholds; on "not sure" its lines read as questions.
- Australian Privacy Principles (APPs)Placed for sites in Australia, and only when you say the Australian Privacy Act applies to you (many small businesses are exempt); on "not sure" its lines read as questions.
- ISO/IEC 27001 (information security management)Placed on every site when you tick ISO/IEC 27001 as in scope. It is a management system standard you choose to hold, not a law, and it keys on no place.