Skip to main content
20% off — first 20 customers. See the offer →

International data protection

Any jurisdiction. One privacy programme

Sentinel42 turns the data protection law of the countries you operate in into the same registers, clocks and evidence. UK and EU GDPR are automated in the core at every tier. Other jurisdictions are built on the same engine on request, from primary sources, by a qualified lead auditor and DPO — no second tool, no second team.

218

jurisdictions in the reference catalogue

135

with a comprehensive law

158

with a law in force today

2

regimes automated in the product now

Start free trialTalk to us about a jurisdiction

Where your data lives

EU-hosted by default, a dedicated region on request

Every customer, today

Your workspace, database, evidence storage and backups sit in the EU region, with encryption in transit and at rest, tenant isolation enforced at the database and a standard Article 28 DPA. Full detail is on the security page.

Enterprise, by arrangement

Enterprise customers can request a dedicated instance in a chosen region — for example London or São Paulo — following a scoping call. It is arranged with us rather than self-serve, is priced per deal, and comes with a security review and a custom DPA. We will also tell you plainly which of your obligations a region change actually answers and which it does not.

Why one programme matters

The same incident, eleven different clocks

One breach in a company with customers in five countries starts five timers. Your breach register should show who has to be told, by when, and whether the threshold is even met — not send you back to eleven statutes.

  • 72 h

    EU and UK GDPR

    to the regulator; people if high risk

  • 3 working days

    Brazil LGPD

    ANPD Resolution 15/2024

  • 48 h

    Peru

    regulation in force March 2025

  • 72 h

    Vietnam PDPL

    Law 91/2025, from January 2026

  • 72 h

    South Korea PIPA

    and affected individuals

  • 3 days

    Singapore PDPA

    calendar days after assessment

  • 72 h

    India DPDP

    detailed report to the Board

  • 72 h

    Saudi PDPL

    to SDAIA

  • Immediately

    China PIPL

    remedial measures and notice

  • 30 days

    Australia

    to assess a suspected breach

  • Most expedient

    California

    without unreasonable delay

How it works

Add a country. The registers know what changed

  1. 01

    Tell us where you operate

    The countries, states and free zones you sell into, employ in or host in. Free zones count separately — DIFC and ADGM are not the UAE federal law.

  2. 02

    The rules are applied as requirements

    Lawful bases, individual rights and their deadlines, breach clocks, DPO and representative duties, transfer mechanisms and retention rules, mapped to controls you already run.

  3. 03

    Your registers adapt

    One ROPA, one request queue, one breach log, one transfer register. Each row knows which law applies and what that changes — the deadline, the notice, the mechanism.

  4. 04

    Evidence per regulator

    Reports and audit packs cut by jurisdiction, so each regulator gets its own view of the same programme.

What is written per jurisdiction

Eight things every law has

Not a PDF of the statute — the law decomposed into the parts a compliance programme runs on, each wired to the register that uses it.

Scope and who it applies to

Territorial reach, thresholds and any small-business carve-outs.

Lawful bases

Including where consent is the only realistic route and where legitimate interests do not exist.

Individual rights and deadlines

Access, correction, deletion, portability and objection, each with its own statutory clock.

Breach notification

The regulator deadline, the threshold, and whether affected people must be told.

DPO and representative duties

Whether one is required, who they must be, and whether they must be published or registered.

Transfers

Adequacy, standard clauses, local approval or localisation requirements.

Retention and records

What must be kept, for how long, and what has to be produced on demand.

Penalties

The maximum exposure, so the risk register carries a real number.

Availability

Automated today, built on request for everywhere else

In the product now

Included in the core at every tier and maintained by the Sentinel42 team.

  • UK GDPR, Data Protection Act 2018 and PECR
  • EU GDPR, with the ePrivacy overlay
  • ISO 27701 privacy information management, as a certifiable module

Built on request

Any other jurisdiction in the catalogue below — a country, a US state, a free zone or a regional framework — is scoped with you and built on the same engine. Until it is built, treat the catalogue as reference information rather than product behaviour.

  • Tell us where you sell, employ and host, and we scope the jurisdictions with you
  • Built from primary sources and reviewed by a qualified lead auditor and DPO
  • Sectoral overlays such as HIPAA are available as modules today

Reference catalogue

218 jurisdictions, including the ones with no law yet

This is published reference information, not a list of regimes the product enforces. Only UK and EU GDPR are automated today; anything else here is built on request. Search by country, law or acronym, and open a row for the regulator, breach rule, DPO duty, transfer regime and penalties.

218 of 218 shown

JurisdictionStatusDetail
European Union / EEAPan-European (EU + EEA)GDPRIn force
United KingdomWestern EuropeUK GDPR / DPA 2018 / DUAA / PECRIn force
SwitzerlandWestern EuropeFADPIn force
EEA EFTA states (Norway, Iceland, Liechtenstein)Northern / Western Europe (EEA EFTA)GDPR (EEA) + national DP actsIn force
JerseyCrown DependenciesDPJLIn force
GuernseyCrown DependenciesDPL 2017In force
Isle of ManCrown DependenciesApplied GDPR (IoM)In force
GibraltarBritish Overseas Territory (Southern Europe)Gibraltar GDPR / DPA 2004In force
TurkeyAnatolia / South-Eastern EuropeKVKKIn force
RussiaEastern Europe / Eurasia152-FZIn force
UkraineEastern EuropeLaw 2297-VI / Draft 8153In force
SerbiaBalkansZZPL / PDPA 2018In force
Bosnia and HerzegovinaBalkansLPPD 2025 (BiH)In force
MontenegroBalkansZZPL (Montenegro)In force
North MacedoniaBalkansLPDP 2020In force
AlbaniaBalkansLaw 124/2024Enacted, phasing in
KosovoBalkansLPPD (Kosovo)In force
MoldovaEastern EuropeLaw 195/2024Enacted, phasing in
GeorgiaCaucasusLaw 3144/2023In force
ArmeniaCaucasusLaw HO-49-N (2015)In force
AzerbaijanCaucasusLaw on Personal Data (2010)In force
BelarusEastern EuropeLaw 99-ZIn force
AndorraMicrostates (Western Europe)LQPDIn force
MonacoMicrostates (Western Europe)Law 1.565Enacted, phasing in
San MarinoMicrostates (Southern Europe)Law 171/2018In force
Faroe IslandsNorthern Europe (Danish Realm, outside EU)Faroese DPA 2020In force
Vatican City StateMicrostates (Southern Europe)Vatican GDPR (Decree DCLVII)In force
KazakhstanCentral AsiaLaw 94-VIn force
UzbekistanCentral AsiaLaw ZRU-547In force
KyrgyzstanCentral AsiaLaw No. 58 (2008)In force
TajikistanCentral AsiaLaw 1537In force
TurkmenistanCentral AsiaLaw 519-VIn force
Council of Europe Convention 108 / 108+Pan-European treaty frameworkConvention 108 / 108+In force
United States (federal)US federal / sectoralUS sectoral frameworkIn force
United States — HIPAAUS federal / sectoralHIPAA/HITECHIn force
United States — GLBAUS federal / sectoralGLBAIn force
United States — COPPAUS federal / sectoralCOPPAIn force
United States — CaliforniaUS statesCCPA/CPRAIn force
United States — VirginiaUS statesVCDPAIn force
United States — ColoradoUS statesCPAIn force
United States — ConnecticutUS statesCTDPAIn force
United States — UtahUS statesUCPAIn force
United States — IowaUS statesICDPAIn force
United States — IndianaUS statesINCDPAIn force
United States — TennesseeUS statesTIPAIn force
United States — MontanaUS statesMCDPAIn force
United States — TexasUS statesTDPSAIn force
United States — OregonUS statesOCPAIn force
United States — DelawareUS statesDPDPAIn force
United States — New JerseyUS statesNJDPAIn force
United States — New HampshireUS statesNHPAIn force
United States — KentuckyUS statesKCDPAIn force
United States — NebraskaUS statesNDPAIn force
United States — MarylandUS statesMODPAIn force
United States — MinnesotaUS statesMCDPAIn force
United States — Rhode IslandUS statesRIDTPPAIn force
United States — OklahomaUS statesOCDPAEnacted, phasing in
United States — AlabamaUS statesALPDPAEnacted, phasing in
United States — LouisianaUS statesLDPAEnacted, phasing in
United States — VermontUS statesVDPOSAEnacted, phasing in
United States — FloridaUS statesFDBRIn force
United States — Illinois (BIPA)US statesBIPAIn force
United States — Washington (My Health My Data Act)US statesMHMDAIn force
United States — New York (SHIELD Act)US statesNY SHIELD ActIn force
Canada (federal)North AmericaPIPEDAIn force
Canada — QuebecNorth AmericaQuebec Law 25In force
Canada — AlbertaNorth AmericaAlberta PIPAIn force
Canada — British ColumbiaNorth AmericaBC PIPAIn force
MexicoNorth AmericaLFPDPPP (2025)In force
GuatemalaCentral AmericaGuatemala (bill 6572)Bill
BelizeCentral AmericaBelize DPA 2021Enacted, phasing in
HondurasCentral AmericaHonduras (draft law)Bill
El SalvadorCentral AmericaEl Salvador LPDP 2024In force
NicaraguaCentral AmericaLaw 787In force
Costa RicaCentral AmericaLaw 8968In force
PanamaCentral AmericaLaw 81In force
BahamasCaribbeanBahamas DPA 2025Enacted, phasing in
BarbadosCaribbeanBarbados DPAIn force
BermudaCaribbeanBermuda PIPAIn force
Cayman IslandsCaribbeanCayman DPAIn force
JamaicaCaribbeanJamaica DPAIn force
Trinidad and TobagoCaribbeanT&T DPA 2011Enacted, phasing in
Dominican RepublicCaribbeanLaw 172-13In force
CubaCaribbeanLaw 149/2022In force
HaitiCaribbeanHaiti (none)No law yet
Puerto RicoCaribbeanPuerto Rico (US law + Act 111-2005)In force
British Virgin IslandsCaribbeanBVI DPAIn force
CuracaoCaribbeanCuracao LBPIn force
ArubaCaribbeanAruba LPRIn force
Antigua and BarbudaCaribbeanAntigua DPA 2013In force
Saint LuciaCaribbeanSt Lucia DPAEnacted, phasing in
Saint Kitts and NevisCaribbeanSt Kitts DPA 2018Enacted, phasing in
GrenadaCaribbeanGrenada DPA 2023Enacted, phasing in
Saint Vincent and the GrenadinesCaribbeanSVG Privacy Act 2003Enacted, phasing in
DominicaCaribbeanDominica (none)No law yet
BrazilSouth AmericaLGPDIn force
ArgentinaSouth AmericaLaw 25,326In force
ChileSouth AmericaLaw 21.719Enacted, phasing in
ColombiaSouth AmericaLaw 1581In force
PeruSouth AmericaLaw 29733In force
UruguaySouth AmericaLaw 18.331In force
EcuadorSouth AmericaLOPDPIn force
BoliviaSouth AmericaBolivia (draft law)Bill
ParaguaySouth AmericaLaw 7593/2025Enacted, phasing in
VenezuelaSouth AmericaVenezuela (none)No law yet
GuyanaSouth AmericaGuyana DPA 2023Enacted, phasing in
SurinameSouth AmericaSuriname (draft bill)Bill
Ibero-American / OAS regional frameworksRegional frameworkRIPD Standards / OAS PrinciplesIn force
EgyptNorth AfricaPDPLIn force
MoroccoNorth AfricaLaw 09-08In force
TunisiaNorth AfricaOrganic Law 2004-63In force
AlgeriaNorth AfricaLaw 18-07In force
LibyaNorth AfricaCybercrime/E-Transactions Laws 2022In force
SudanNorth AfricaNo law yet
NigeriaWest AfricaNDPAIn force
GhanaWest AfricaAct 843In force
SenegalWest AfricaAct 2008-12In force
Côte d'IvoireWest AfricaLaw 2013-450In force
BeninWest AfricaDigital CodeIn force
Burkina FasoWest AfricaLaw 001-2021In force
MaliWest AfricaLaw 2013-015In force
NigerWest AfricaLaw 2022-59In force
TogoWest AfricaLaw 2019-014In force
GuineaWest AfricaLaw L/2016/037Enacted, phasing in
Guinea-BissauWest AfricaNo law yet
Sierra LeoneWest AfricaData Protection BillBill
LiberiaWest AfricaNo law yet
GambiaWest AfricaBill
MauritaniaWest AfricaLaw 2017-020In force
Cabo VerdeWest AfricaLaw 133/V/2001In force
KenyaEast AfricaDPA 2019In force
UgandaEast AfricaDPPA 2019In force
RwandaEast AfricaLaw 058/2021In force
TanzaniaEast AfricaPDPA 2022In force
EthiopiaEast AfricaProclamation 1321/2024Enacted, phasing in
SomaliaEast AfricaDPA 2023In force
DjiboutiEast AfricaNo law yet
EritreaEast AfricaNo law yet
South SudanEast AfricaNo law yet
BurundiEast AfricaSectoral lawsIn force
CameroonCentral AfricaLaw 2024/017Enacted, phasing in
GabonCentral AfricaAct 001/2011In force
Congo-BrazzavilleCentral AfricaLaw 29-2019Enacted, phasing in
DR CongoCentral AfricaDigital CodeEnacted, phasing in
ChadCentral AfricaAct 007/PR/2015In force
Equatorial GuineaCentral AfricaLaw 1/2016In force
Central African RepublicCentral AfricaNo law yet
São Tomé and PríncipeCentral AfricaLaw 3/2016In force
South AfricaSouthern AfricaPOPIAIn force
BotswanaSouthern AfricaDPA 2024In force
ZambiaSouthern AfricaDPA 2021In force
ZimbabweSouthern AfricaCyber and Data Protection ActIn force
MalawiSouthern AfricaData Protection Act 2024In force
MozambiqueSouthern AfricaElectronic Transactions LawIn force
AngolaSouthern AfricaLaw 22/11In force
NamibiaSouthern AfricaDraft Data Protection BillBill
EswatiniSouthern AfricaData Protection Act 2022Enacted, phasing in
LesothoSouthern AfricaDPA 2013In force
MauritiusIndian OceanDPA 2017In force
MadagascarIndian OceanLaw 2014-038Enacted, phasing in
SeychellesIndian OceanDPA 2023In force
ComorosIndian OceanLaw 21-005Enacted, phasing in
African Union (Malabo Convention)Regional frameworkMalabo ConventionIn force
ECOWAS Supplementary ActRegional frameworkECOWAS Supplementary ActIn force
United Arab EmiratesGulfUAE PDPLEnacted, phasing in
UAE — DIFCGulfDIFC DP Law 2020In force
UAE — ADGMGulfADGM DPR 2021In force
Saudi ArabiaGulfSaudi PDPLIn force
QatarGulfLaw 13/2016In force
Qatar — QFCGulfQFC DPR 2021In force
BahrainGulfBahrain PDPLIn force
OmanGulfOman PDPLIn force
KuwaitGulfKuwait DPR 2024In force
IsraelLevantPPL / Amendment 13In force
JordanLevantLaw 24/2023In force
LebanonLevantLaw 81/2018In force
IraqGulfDraft PDP BillBill
IranGulfSectoral cyber lawsIn force
SyriaLevantNo law yet
YemenGulfNo law yet
PalestineLevantNo law yet
ChinaEast AsiaPIPLIn force
Hong KongEast AsiaPDPOIn force
MacauEast AsiaMacau PDPLIn force
TaiwanEast AsiaTaiwan PDPAIn force
JapanEast AsiaAPPIIn force
South KoreaEast AsiaPIPAIn force
MongoliaEast AsiaMongolia PDPLIn force
IndiaSouth AsiaDPDP ActEnacted, phasing in
PakistanSouth AsiaPECA / draft PDPBIn force
Sri LankaSouth AsiaSri Lanka PDPAEnacted, phasing in
BangladeshSouth AsiaCyber Security Act 2023In force
NepalSouth AsiaIndividual Privacy ActIn force
BhutanSouth AsiaNoneNo law yet
MaldivesSouth AsiaNoneNo law yet
AfghanistanSouth AsiaNoneNo law yet
SingaporeSouth-East AsiaPDPAIn force
MalaysiaSouth-East AsiaMalaysia PDPAIn force
ThailandSouth-East AsiaThailand PDPAIn force
IndonesiaSouth-East AsiaPDP LawIn force
PhilippinesSouth-East AsiaData Privacy ActIn force
VietnamSouth-East AsiaPDPLIn force
CambodiaSouth-East AsiaDraft PDP LawBill
LaosSouth-East AsiaElectronic Data Protection LawIn force
MyanmarSouth-East AsiaSectoral (Cybersecurity Law 2025)In force
BruneiSouth-East AsiaBrunei PDPOIn force
Timor-LesteSouth-East AsiaNoneNo law yet
AustraliaOceaniaPrivacy Act 1988In force
New ZealandOceaniaPrivacy Act 2020In force
Papua New GuineaOceaniaNoneNo law yet
FijiOceaniaNone (sectoral only)In force
SamoaOceaniaNoneNo law yet
TongaOceaniaNoneNo law yet
VanuatuOceaniaNoneNo law yet
Solomon IslandsOceaniaNoneNo law yet
Other Pacific Islands (Kiribati, Micronesia, Palau, Marshall Islands, Nauru, Tuvalu)OceaniaNoneNo law yet
APEC CBPR / Global CBPR ForumRegional frameworkGlobal CBPR ForumIn force
ASEAN Framework on Personal Data ProtectionRegional frameworkASEAN PDP FrameworkIn force

Catalogue compiled 5 September 2026 from primary legislation, regulator publications and the DLA Piper Data Protection Laws of the World handbook. Information, not legal advice — your DPO or counsel owns interpretation. Entries marked “verify” rest on secondary sources and are confirmed before anything is built on them.

Who it is for

Small teams with customers in more countries than they have lawyers

UK → US

A UK SaaS company selling into the United States

Twenty-three state privacy laws with different thresholds, opt-out rights and cure periods. One request queue that knows which state a requester is in and what that state gives them.

EU → BR · IN · ZA

A European company with teams in Brazil, India or South Africa

HR data under three regimes: the LGPD encarregado, India's phased DPDP rules and POPIA's information officer, each mapped back to the GDPR controls already in place.

AE · DIFC · ADGM

A group with entities in the Gulf

The UAE federal PDPL, the DIFC law and the ADGM regulations are three separate regimes. Each entity sees its own obligations; the group sees all three in one register.

What people ask before adding a jurisdiction

Is this legal advice?

No. What we build is a configuration taken from the published law and regulator guidance, so your registers apply the right rules and deadlines. Interpreting the law for your situation stays with your DPO or counsel — and Sentinel42's consultancy can act as your DPO if you need one.

Which laws does the product automate today?

UK GDPR with the Data Protection Act 2018 and PECR, EU GDPR with the ePrivacy overlay, and ISO 27701 as a certifiable privacy management module. Everything else in the catalogue below is reference information until we build it with you.

How current is the catalogue?

It was compiled on 5 September 2026 and is reviewed quarterly against primary sources. Entries that rest on secondary sources are marked "verify" and are confirmed before anything is built on them.

Can our data be held in a particular country?

The platform runs in the EU region by default. Enterprise customers can request a dedicated instance in a chosen region — for example London or São Paulo — by arrangement, following a scoping call. It is not self-serve, and we will tell you honestly what a region change does and does not solve.

Does this replace ISO 27701?

No, they do different jobs. ISO 27701 is a management system you can be certified against; a jurisdiction configuration is the legal requirement set for one country. They map onto each other, so neither duplicates the other.

Start with the countries you are in. Add the rest as you grow

14-day free trial, no card. UK or EU GDPR on day one, and ask us about the next jurisdiction whenever you need it.

Start free trialPricingModules