Every framework, explained plainly — with a direct line to the source.
Praeferre's GRC engine monitors against all of these frameworks and more, including your own internal policies. Each page below gives you the plain-English version — what it is, who it applies to, what it requires, what it costs to get wrong — and links straight through to the official regulator or standards body for the authoritative text.
Everything Praeferre monitors, in one map
Click any node to jump straight to that framework's page. GDPR, PIPA, SOC 2, POPIA and DPDP — Praeferre's five most-requested frameworks — are highlighted in blue.
Privacy & Data Protection
GDPR
The EU's foundational data protection law, giving individuals rights over their personal data and requiring…
View frameworkUK GDPR
The UK's version of the GDPR, retained in domestic law after Brexit and read alongside the Data Protection Act 2018.…
View frameworkDPDP Act
India's first comprehensive digital data protection law, built around plain-language principles (consent, purpose…
View frameworkPOPIA
South Africa's principal data protection law, similar in structure to the GDPR. It sets eight conditions for lawful…
View frameworkPIPA
South Korea's comprehensive data protection law, enforced by an independent regulator with strong investigative and…
View frameworkCCPA / CPRA
The first comprehensive consumer privacy law in the United States, giving California residents rights to know,…
View frameworkLGPD
Brazil's general data protection law, closely modelled on the GDPR. It sets out lawful bases for processing, data…
View frameworkPIPEDA
Canada's federal private-sector privacy law, governing how organisations collect, use and disclose personal…
View frameworkAPPI
Japan's core data protection law, overseen by the independent Personal Information Protection Commission. It combines…
View frameworkPDPA
Singapore's data protection law, balancing individual rights with the country's data-driven economy. It's enforced by…
View frameworkPrivacy Act 1988
Australia's principal privacy law, built around 13 Australian Privacy Principles covering collection, use, disclosure…
View frameworkUAE PDPL
The UAE's federal personal data protection law, applying across the mainland alongside separate data protection…
View frameworkSaudi PDPL
Saudi Arabia's first comprehensive data protection law, administered by SDAIA. It sets out consent, purpose…
View frameworkSecurity, Resilience & Assurance
NIS2
The EU's updated cybersecurity directive, widening the scope of the original NIS Directive to cover more sectors and…
View frameworkUK Cyber Security & Resilience Bill
The UK's post-Brexit update to the NIS Regulations 2018, broadly mirroring the EU's NIS2 while reflecting UK-specific…
View frameworkCAF 4.0
An outcome-based framework from the UK's National Cyber Security Centre, used to assess cyber resilience across four…
View frameworkISO/IEC 27001
The leading international standard for information security management systems (ISMS). Certification is voluntary but…
View frameworkSOC 2
An attestation framework built on the AICPA's Trust Services Criteria, used overwhelmingly by SaaS and technology…
View frameworkPCI DSS
A global contractual security standard mandated by the major card networks for any organisation that stores,…
View frameworkDORA
An EU regulation requiring financial entities and their critical ICT providers to build and prove digital operational…
View frameworkHIPAA
The US federal law governing protected health information (PHI). Its Privacy and Security Rules set standards for how…
View frameworkWe model custom and internal frameworks too
Every organisation has policies beyond the standard list. Praeferre's GRC engine maps your own internal frameworks with the same rigour as GDPR or ISO 27001.