| GDPR | EU / EEA | Lawful basis, minimization, processor terms, transfers, DPIA | In-region or on-prem processing, processor agreement, masking, deletion, DPIA input pack |
|---|
| EU AI Act | EU | Risk classification, human oversight, logging, transparency to users | Human approval enforced in configuration, full logs, AI disclosure in user channels, technical documentation |
|---|
| PIPL | China | Localization, cross-border transfer rules, sensitive data | In-country deployment on local models, no calls to foreign APIs, logs and keys in-country |
|---|
| APPI | Japan | Purpose of use, security measures, transfers abroad | Purpose recorded per agent, access control and logs, in-country deployment |
|---|
| PIPA | Korea | Purpose limitation, safety measures, cross-border transfer | On-prem or air-gapped, field-level access, complete access logs |
|---|
| LGPD | Brazil | Legal basis, data-subject rights, impact report | In-country deployment, processing records per use case, deletion on request |
|---|
| Privacy Act & APPs | Australia | Use and disclosure, security, cross-border disclosure | Australian region or on-prem, access control, logs for your privacy impact assessment |
|---|
| CCPA / CPRA | California, US | Notice, consumer rights, service-provider terms, automated decision-making | Service-provider terms, deletion and access support, human review of significant decisions |
|---|
| Sector rules | Health, finance, public sector | Sector-specific confidentiality and record-keeping (e.g. HIPAA-style rules) | Deployment inside your accredited environment, retention and access matched to the rule |
|---|