The European Union data protection regulation, and the reference point most other modern privacy regimes are drafted against.
Organisations established in the European Union, and organisations outside it that offer goods or services to individuals in the Union or monitor their behaviour. Extraterritorial reach is the part most often misjudged.
Organisations that have completed a serious GDPR programme are usually well positioned for the GCC privacy regimes, because those regimes borrow its structure. The reverse is less reliable: GDPR sets a higher bar on accountability, requiring an organisation to demonstrate compliance rather than simply achieve it.
Supervisory compliance. There is no GDPR certificate; there is documented accountability that survives examination.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.