Skip to content

Compliance · Regional

Regional privacy & compliance regimes

US state privacy, GDPR, and Canadian regimes mapped to cloud findings — in the markets operators actually serve.

Where regional mapping matters

Regional privacy, mapped to your cloud

How state, federal, and cross-border privacy law shows up in your findings across North America and beyond.

Why it matters

Regional privacy law, mapped to your cloud

A cloud posture is judged against two things at once: your industry’s framework stack and the privacy law of the jurisdictions your data subjects live in. The health check carries that overlay — so a finding in a bucket of California residents’ data reads as a CCPA/CPRA exposure, not just a misconfiguration.

US state privacy laws

Comprehensive state statutes in force

StateLawWhat it means for your cloud
CACCPA/CPRACalifornia Consumer Privacy Act (as amended by CPRA) — the strictest US consumer-privacy regime — access, deletion, opt-out, and reasonable-security duties enforced by the CPPA.
COCPAColorado Privacy Act — universal opt-out, data-protection assessments, and duties of care over personal data.
CTCTDPAConnecticut Data Privacy Act — consent, data minimization, and assessment duties for controllers handling Connecticut residents’ data.
DEDPDPADelaware Personal Data Privacy Act — consumer rights and controller obligations over personal data.
IAICDPAIowa Consumer Data Protection Act — controller duties and consumer rights over personal data.
ININCDPAIndiana Consumer Data Protection Act — controller duties and consumer rights over personal data.
KYKCDPAKentucky Consumer Data Protection Act — controller duties and consumer rights over personal data.
MDMODPAMaryland Online Data Privacy Act — strict data-minimization and heightened protections for sensitive data.
MNMCDPAMinnesota Consumer Data Privacy Act — consumer rights plus a documented data-inventory and risk-assessment duty.
MTMCDPAMontana Consumer Data Privacy Act — consent and assessment duties for controllers of Montana residents’ data.
NENDPANebraska Data Privacy Act — controller obligations and consumer rights, broadly applicable to businesses.
NHNHDPANew Hampshire Data Privacy Act — controller security and consumer-rights obligations over personal data.
NJNJDPANew Jersey Data Privacy Act — consent, assessments, and consumer-rights duties for controllers.
OROCPAOregon Consumer Privacy Act — consumer rights and controller duties, with a broad definition of personal data.
RIRIDTPPARhode Island Data Transparency and Privacy Protection Act — transparency, consumer rights, and controller duties over personal data.
TNTIPATennessee Information Protection Act — consumer rights with a NIST-aligned privacy-program affirmative defense.
TXTDPSATexas Data Privacy and Security Act — broad applicability with data-protection assessments and reasonable-security duties.
UTUCPAUtah Consumer Privacy Act — controller security and consumer-rights obligations for personal data.
VAVCDPAVirginia Consumer Data Protection Act — controller/processor duties, data-protection assessments, and consumer rights over personal data.

States not listed fall back to federal and sectoral rules plus your industry’s frameworks. Statutes evolve — this is marketing-accurate framing, not legal advice.

Cross-border & national

GDPR & Canadian regimes

GDPR — EU General Data Protection Regulation

if any of your users or data subjects are in the EU, GDPR’s security-of-processing and breach-notification duties reach your cloud (UK data subjects fall under the parallel UK GDPR and Data Protection Act 2018).

UK GDPR — UK GDPR & Data Protection Act 2018

since Brexit, UK data subjects fall under the UK’s own retained regime (enforced by the ICO), separate from and diverging from EU GDPR — with equivalent security-of-processing and breach-notification duties.

OSFI B-13 — OSFI Guideline B-13 (Canada)

technology and cyber-risk expectations for federally-regulated Canadian financial institutions (governance, technology operations and resilience, and cyber security), in force since January 2024. Third-party and cloud-vendor risk sits in the companion Guideline B-10.

PIPEDA — Personal Information Protection and Electronic Documents Act (Canada)

safeguarding duties over personal information handled in the course of commercial activity.

Law 25 — Quebec Law 25

strengthened consent, breach-reporting, and privacy-by-design duties for organizations handling Quebec residents’ data.

See your regional exposure

A health check finds and prioritizes real exposure. It is not a certification or a promise you will never be breached — closing the findings is what changes your risk.

Take free readiness check