Compliance · Regional
Regional privacy & compliance regimes
US state privacy, GDPR, and Canadian regimes mapped to cloud findings — in the markets operators actually serve.
Where regional mapping matters
Regional privacy, mapped to your cloud
How state, federal, and cross-border privacy law shows up in your findings across North America and beyond.
Why it matters
Regional privacy law, mapped to your cloud
A cloud posture is judged against two things at once: your industry’s framework stack and the privacy law of the jurisdictions your data subjects live in. The health check carries that overlay — so a finding in a bucket of California residents’ data reads as a CCPA/CPRA exposure, not just a misconfiguration.
US state privacy laws
Comprehensive state statutes in force
| State | Law | What it means for your cloud |
|---|---|---|
| CA | CCPA/CPRA | California Consumer Privacy Act (as amended by CPRA) — the strictest US consumer-privacy regime — access, deletion, opt-out, and reasonable-security duties enforced by the CPPA. |
| CO | CPA | Colorado Privacy Act — universal opt-out, data-protection assessments, and duties of care over personal data. |
| CT | CTDPA | Connecticut Data Privacy Act — consent, data minimization, and assessment duties for controllers handling Connecticut residents’ data. |
| DE | DPDPA | Delaware Personal Data Privacy Act — consumer rights and controller obligations over personal data. |
| IA | ICDPA | Iowa Consumer Data Protection Act — controller duties and consumer rights over personal data. |
| IN | INCDPA | Indiana Consumer Data Protection Act — controller duties and consumer rights over personal data. |
| KY | KCDPA | Kentucky Consumer Data Protection Act — controller duties and consumer rights over personal data. |
| MD | MODPA | Maryland Online Data Privacy Act — strict data-minimization and heightened protections for sensitive data. |
| MN | MCDPA | Minnesota Consumer Data Privacy Act — consumer rights plus a documented data-inventory and risk-assessment duty. |
| MT | MCDPA | Montana Consumer Data Privacy Act — consent and assessment duties for controllers of Montana residents’ data. |
| NE | NDPA | Nebraska Data Privacy Act — controller obligations and consumer rights, broadly applicable to businesses. |
| NH | NHDPA | New Hampshire Data Privacy Act — controller security and consumer-rights obligations over personal data. |
| NJ | NJDPA | New Jersey Data Privacy Act — consent, assessments, and consumer-rights duties for controllers. |
| OR | OCPA | Oregon Consumer Privacy Act — consumer rights and controller duties, with a broad definition of personal data. |
| RI | RIDTPPA | Rhode Island Data Transparency and Privacy Protection Act — transparency, consumer rights, and controller duties over personal data. |
| TN | TIPA | Tennessee Information Protection Act — consumer rights with a NIST-aligned privacy-program affirmative defense. |
| TX | TDPSA | Texas Data Privacy and Security Act — broad applicability with data-protection assessments and reasonable-security duties. |
| UT | UCPA | Utah Consumer Privacy Act — controller security and consumer-rights obligations for personal data. |
| VA | VCDPA | Virginia Consumer Data Protection Act — controller/processor duties, data-protection assessments, and consumer rights over personal data. |
States not listed fall back to federal and sectoral rules plus your industry’s frameworks. Statutes evolve — this is marketing-accurate framing, not legal advice.
Cross-border & national
GDPR & Canadian regimes
GDPR — EU General Data Protection Regulation
if any of your users or data subjects are in the EU, GDPR’s security-of-processing and breach-notification duties reach your cloud (UK data subjects fall under the parallel UK GDPR and Data Protection Act 2018).
UK GDPR — UK GDPR & Data Protection Act 2018
since Brexit, UK data subjects fall under the UK’s own retained regime (enforced by the ICO), separate from and diverging from EU GDPR — with equivalent security-of-processing and breach-notification duties.
OSFI B-13 — OSFI Guideline B-13 (Canada)
technology and cyber-risk expectations for federally-regulated Canadian financial institutions (governance, technology operations and resilience, and cyber security), in force since January 2024. Third-party and cloud-vendor risk sits in the companion Guideline B-10.
PIPEDA — Personal Information Protection and Electronic Documents Act (Canada)
safeguarding duties over personal information handled in the course of commercial activity.
Law 25 — Quebec Law 25
strengthened consent, breach-reporting, and privacy-by-design duties for organizations handling Quebec residents’ data.
See your regional exposure
A health check finds and prioritizes real exposure. It is not a certification or a promise you will never be breached — closing the findings is what changes your risk.





