| GDPR / UK GDPR | Personal data linked to EEA or UK individuals, organisations, processing activities, or transfers. | Analytics, BI, data engineering, AI/ML, cloud data, managed data teams, database and reporting services. | Role, lawful basis, territorial reach, controller/processor status, and transfer mechanism require client and legal confirmation. |
| CCPA / CPRA and US state privacy laws | Personal information of residents covered by applicable state law and qualifying businesses or service relationships. | Customer analytics, CRM data work, marketing data, support operations, data platforms, automation, and managed services. | Thresholds, exemptions, role definitions, contractual restrictions, and consumer-rights workflows vary by law. |
| ISO/IEC 27001 concepts | Clients using information-security management controls in due diligence or contract schedules. | Potentially relevant across all technology and data services. | Alignment with selected concepts is not certification, accreditation, or proof of a complete ISMS. |
| SOC 2 Trust Services Criteria | Supplier assessments that evaluate security, availability, processing integrity, confidentiality, or privacy controls. | Cloud data, managed teams, platform administration, engineering, analytics operations, and support services. | Control awareness is not a SOC 2 examination, attestation, Type I report, or Type II report. |
| HIPAA | US healthcare engagements involving protected health information and a qualifying covered-entity or business-associate relationship. | Healthcare analytics, data engineering, reporting, database, cloud, automation, and AI services involving PHI. | No PHI should be shared until applicability, permitted use, BAA requirements, safeguards, and approved systems are confirmed. |
| PCI DSS | Payment-card data or systems that store, process, transmit, or can affect cardholder-data security. | Ecommerce analytics, payment reporting, platform integration, database, cloud, and automation work. | Scope should be minimised. Direct card-data handling requires explicit review and client-approved controls. |
| Client and sector requirements | Industry rules, internal policies, contractual controls, geographic restrictions, or customer obligations. | Any engagement where the client imposes additional requirements. | Requirements must be supplied, reviewed, accepted, and operationally feasible within the agreed scope. |