Chat with us
Privacy · Security · Accountability

Compliance starts
with clarity.

Clear requirements. Defined responsibilities. Thoughtful software.
Explore the privacy, security, and governance considerations behind your next digital product.

  • PrivacyPurposeful data handling
  • SecurityControls shaped by scope
  • AccountabilityClear project ownership
A shared foundation

Make trust part of the project plan.

Compliance requirements depend on your product, users, markets, and operations. Start by identifying what applies, then translate approved requirements into design, development, testing, and handover decisions.

Use this page to explore planning topics and Digittrix’s published policies. Specific controls, reviews, and deliverables are confirmed in your written project scope.

Build for the markets you serve

Important compliance rules,
region by region.

Your launch market shapes your product requirements. Start with the relevant laws, then map them to data flows, user journeys, hosting, and ongoing operations.

Sources reviewed

General project-planning guidance, not legal advice or a compliance certification. Applicability depends on your organisation, users, data, sector, and launch date. Confirm the final requirements with qualified local counsel; this is a starting checklist, not an exhaustive list.

Europe

EU / EEA, with separate UK requirements

  • GDPR: privacy by design

    For in-scope processing, establish a lawful basis, clear notices, data minimisation, retention limits, user-rights workflows, and processor agreements. Assess safeguards for transfers outside the EEA.

    European Commission · GDPR
  • Cookies & tracking

    Obtain prior consent for cookies and similar tracking where required. Keep exempt, necessary technologies separate and make withdrawal easy.

    Your Europe · Cookies
  • European Accessibility Act

    Check whether your product or service is covered, including consumer e-commerce. Requirements apply from 28 June 2025, with exemptions and transition rules; build accessible navigation, forms, and checkout.

    Your Europe · Accessibility
  • AI Act

    Classify AI features and your provider or deployer role. Check prohibited uses, literacy duties, and applicable transparency requirements; high-risk obligations have separate timelines.

    European Commission · AI Act
  • UK projects

    Assess UK GDPR and PECR separately. Review notices, lawful processing, and consent or exemptions for cookies, pixels, and similar technologies.

    ICO · UK tracking rules

India

DPDP readiness, cyber incidents & regulated payments

  • DPDP Act 2023 & Rules 2025

    Commencement is phased. Map each obligation to the official enforcement timeline for your launch date; do not assume all provisions are already in force.

    MeitY · Rules & enforcement timeline
  • Notice, consent & data rights

    Plan clear purpose-specific notices, consent and withdrawal journeys, correction and erasure requests, grievance handling, and security safeguards for the applicable DPDP phase.

    Government of India · DPDP overview
  • Children’s data & verified consent

    For the applicable DPDP phase, plan verifiable parental or lawful-guardian consent for children’s data and check the permitted exemptions before designing onboarding.

    Government of India · Child-data safeguards
  • CERT-In incident reporting

    For covered entities, specified cyber incidents must be reported within six hours of noticing them or being informed. Plan incident escalation and secure retention of ICT logs for 180 days within India.

    CERT-In · Cybersecurity directions (PDF)
  • Payment-system data

    For RBI-regulated payment-system providers, assess India storage requirements and permitted exceptions. Confirm your role with the payment provider before choosing hosting and integrations.

    RBI · Payment-data storage FAQ

Australia

Privacy Act coverage depends on the organisation

  • Privacy Act 1988 & APPs

    Check coverage first: most businesses with turnover of A$3 million or less are exempt, but exceptions include health-service providers. Covered entities need appropriate notices, security, access, and correction processes.

    OAIC · Small-business coverage
  • Overseas disclosure: APP 8

    Before disclosing personal information overseas, take reasonable steps to ensure the recipient meets the APP requirements, unless an exception applies. Assess cloud vendors and overseas support access.

    OAIC · Cross-border disclosure
  • Notifiable Data Breaches scheme

    For covered entities, assess suspected eligible breaches and notify the OAIC and affected people where serious harm is likely and the notification criteria are met.

    OAIC · Data-breach requirements
  • Spam Act 2003

    For covered commercial email and SMS, obtain consent, identify the sender, and provide an unsubscribe option. Honour unsubscribe requests within five working days.

    ACMA · Marketing-message rules

New Zealand

Privacy Act 2020 & electronic marketing

  • Privacy Act 2020

    Apply the information privacy principles to collection, security, access, correction, retention, use, and disclosure. Include a way for people to raise privacy requests.

    Privacy Commissioner · Privacy principles
  • Indirect collection: IPP 3A

    Since 1 May 2026, collecting personal information from another source can require notifying the individual, subject to exceptions. Review imports, partner feeds, and third-party lead sources.

    Privacy Commissioner · Principle 3A
  • Overseas disclosure: IPP 12

    Check comparable protections or another permitted basis before disclosure overseas. Assess whether a vendor acts only as your processing agent, because that affects whether IPP 12 applies.

    Privacy Commissioner · Principle 12
  • Serious privacy breaches

    Notify the Commissioner and affected people as soon as practicable for notifiable breaches, subject to exceptions. The Commissioner’s 72-hour expectation is guidance, not a fixed statutory deadline.

    Privacy Commissioner · Breach guidance
  • Unsolicited Electronic Messages Act 2007

    For commercial messages with a New Zealand link, confirm consent, identify the sender, and provide a working unsubscribe facility.

    Department of Internal Affairs · Spam rules

Gulf countries

Check the country, free zone, sector & data flows

  • United Arab Emirates

    Assess Federal Decree-Law No. 45 of 2021 and applicable exclusions. DIFC has a separate data-protection regime. Confirm the relevant authority and transfer rules for your establishment.

    UAE Government · Data-protection laws
  • Abu Dhabi Global Market (ADGM)

    ADGM has its own Data Protection Regulations 2021. Review controller registration, rights handling, processor duties, breach response, and international-transfer safeguards where that regime applies.

    ADGM · Data-protection guidance
  • Saudi Arabia

    Assess the PDPL, implementing regulations, and overseas-transfer regulation. Plan privacy notices, permitted processing, rights requests, safeguards, and the relevant transfer assessment.

    SDAIA · PDPL guidance
  • Qatar

    Review Law No. 13 of 2016 on Personal Data Privacy Protection and NCSA guidance. Identify any special-category processing approvals relevant to the product.

    NCSA · Privacy principles (PDF)
  • Bahrain

    Assess Law No. 30 of 2018, lawful processing, sensitive-data conditions, and overseas-transfer requirements for the project.

    Bahrain Government · PDPL (PDF)
  • Oman

    Check the Personal Data Protection Law and current executive regulations, including permits for relevant sensitive data and conditions for overseas transfers.

    MTCIT · Personal-data protection
  • Kuwait

    Check whether CITRA’s Data Privacy Protection Regulation, Decision No. 26 of 2024, covers the service or provider. Review the current regulation rather than relying on the superseded 2021 version.

    CITRA · Decision 26/2024 (Arabic)

United States

Review each launch state, audience & industry

  • State privacy laws: CCPA / CPRA

    For covered California businesses, provide privacy notices and rights to access, delete, and correct data, plus applicable sale/sharing opt-outs and Global Privacy Control support. Assess other launch states separately.

    California Attorney General · CCPA
  • Children’s privacy: COPPA

    For covered services directed to under-13s, or with actual knowledge of collecting their data, implement parental notice, verifiable parental consent where required, security, and retention controls.

    FTC · COPPA compliance
  • Healthcare: HIPAA

    HIPAA applies to covered entities and business associates, not every health app. Where it applies, define protected-health-information controls and required business associate agreements.

    HHS · HIPAA applicability
  • Accessibility: ADA

    Assess the obligations for public accommodations and public-sector projects. Build and test keyboard access, readable contrast, form labels, and assistive-technology support against the applicable requirements.

    US Department of Justice · Web accessibility

Turn the rules into a launch checklist.

Document the applicable laws, controller and processor roles, data locations, consent and rights flows, incident owners, and acceptance evidence before development begins.

Discuss Your Launch Market
What to consider

Six areas. One considered approach.

Bring the right questions into the conversation, from the first workshop to the final handover.

Privacy & data handling

Identify the data your product needs, where it moves, who can access it, and how long it should be retained. Build these decisions into the agreed scope.

Access & application security

Plan user roles, authentication, permission checks, and secure integration boundaries around the sensitivity of your product and its data.

Consent & user choice

Define clear notices, consent preferences, account controls, and support journeys so users can understand and manage their choices.

Third-party services

Review the responsibilities, permissions, licences, and data flows associated with hosting, analytics, payments, and external APIs.

Testing & release readiness

Agree acceptance criteria, security testing, issue ownership, and release checks before launch. Record what has been verified and what remains open.

Ownership & handover

Clarify deliverables, source-code access, account ownership, documentation, and post-launch support in the written project agreement.

From requirements to release

A clear path through the details.

Connect business decisions with practical product requirements and a shared definition of done.

STEP 01

Define the context

Share your audience, launch markets, data types, and industry requirements. Identify the people responsible for policy and legal decisions.

STEP 02

Agree the controls

Turn approved requirements into a written scope with owners, acceptance criteria, testing needs, and third-party dependencies.

STEP 03

Review & hand over

Check the agreed controls, document outstanding actions, and establish ownership for updates and ongoing operations.

Good questions, clear answers

A little more clarity.

Have a question about your project?
Talk to our team

Is the personal data you store encrypted?

Digittrix encrypts the personal data it stores to help protect your privacy and reduce the risk of unauthorised access.

Does this page certify my application as compliant?

No. This page outlines topics to address during project planning. Any specific compliance assessment, certification, or independent audit must be separately agreed and supported by evidence.

Can we include industry-specific requirements?

Share the requirements approved by your legal, security, or compliance team during discovery. Their implementation, validation, responsibilities, and any specialist review can then be defined in the project scope.

Where can I read your policies?

Use the policy links below for the published privacy policy, terms and conditions, and refund policy. Your signed project agreement defines the deliverables and responsibilities for your engagement.

How do I raise a privacy or security question?

Use the contact page and describe the affected service and your concern. For an initial enquiry, avoid including passwords, payment information, or private customer records.

Let’s start with your requirements

Build with a clearer picture.

Share your product goals, data needs, and compliance questions.
We’ll help you define the next step.

Contact Our Team