Articles

Regulations

Krete Paal
CEO · 30.10.2025

Core Regulations Supported by GDPR Register

General Data Protection Regulation (GDPR)

The foundation of our platform. Full support for Article 30 records, DPIAs, LIAs, data subject requests (DSRs), processor management, and accountability principles.

UK GDPR and Data Protection Act 2018

The post-Brexit framework of the GDPR. GDPR Register enables organisations to maintain parallel compliance with both EU and UK requirements.

United States Privacy Laws

GDPR Register supports mapping of data subject rights, vendor contracts, and opt-out procedures to align with major state-level privacy acts, helping organisations avoid fragmented compliance efforts and harmonise assessments for multi-jurisdiction operations.

Supported US frameworks include:

  • California – California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • Virginia – Consumer Data Protection Act (CDPA)
  • Colorado – Colorado Privacy Act (CPA)
  • Connecticut – Data Privacy Act (CTDPA)
  • Utah – Consumer Privacy Act (UCPA)
  • Texas – Data Privacy and Security Act (TDPSA)
  • Florida – Digital Bill of Rights (FDBR)
  • Oregon – Consumer Privacy Act (OCPA)
  • Montana – Consumer Data Privacy Act (MCDPA)
  • Iowa – Consumer Data Protection Act (ICDPA)
  • Delaware – Personal Data Privacy Act (DPDPA)
  • Nebraska – Data Privacy Act (NDPA)
  • New Hampshire – Privacy Act (NHPA)
  • New Jersey – Data Privacy Law (NJDPL)
  • Tennessee – Information Protection Act (TIPA)
  • Minnesota – Consumer Data Privacy Act (MCDPA)
  • Maryland – Online Data Privacy Act (MODPA)

South Africa – POPIA (Protection of Personal Information Act)

GDPR Register helps organisations comply with POPIA by enabling records of processing, risk assessments, operator management, and data subject rights handling — all aligned with South Africa’s lawful processing principles.

Brazil – LGPD (Lei Geral de Proteção de Dados)

Supports data mapping, risk assessments, and processor oversight in line with Brazilian requirements.

Canada – PIPEDA

Facilitates data accountability, breach logging, and documentation of cross-border data transfers.

Switzerland – FADP (rev. 2023)

Helps Swiss companies — and EU organisations processing Swiss data — comply with local record-keeping and transparency obligations.

Other Emerging Frameworks (e.g. India’s DPDP Act, APAC privacy laws)

Flexible fields and templates enable you to adapt your privacy programme to new or hybrid regulatory requirements as they evolve globally.


Tags:
case study
gdpr
gutenberg
interesting
Krete Paal
Ex erat referrentur vis. Vim ad consul molestie, eu malorum aliquando referrentur pro, erroribus gloriatur sed at.!
PREVIOUS
What is a Data Processing Agreement (DPA) Playbook
Data flow between subjects and partners
NEXT
Records of Processing Activities (RoPA): 9 Things You Need to Know