Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 20 of 52
Taiwan PDPA — Taiwan Personal Data Protection Act
The Personal Data Protection Act (PDPA) of Taiwan establishes legal requirements for the collection, processing, and utilization of personal data in order to protect personality rights while enabling appropriate use of such data. It applies to both government and non-government entities, ensuring compliance and safeguarding individuals' privacy and rights.
Personal Data Protection Commission • Taiwan
Thailand PDPA — Thailand Personal Data Protection Act B.E. 2562 (2019)
The Personal Data Protection Act B.E. 2562 (2019) is Thailand's primary law for personal data protection. It establishes rules for data collection, use, and disclosure, and aims to protect individuals' personal information and ensure effective remedies for violations.
Government of Thailand • Thailand • v27 May 2019
Netherlands WBP — Netherlands Personal Data Protection Act
The Personal Data Protection Act (WBP) was the Netherlands' data protection law that governed the processing of personal data and established privacy rights, data protection obligations, and regulatory oversight for organizations handling personal information.
Government of Netherlands • Netherlands
New York Privacy Act
The New York Privacy Act aims to provide state-level consumer privacy protections similar to California’s CCPA. It introduces rights like access, correction, and challenging automated decision-making, while requiring businesses to implement security measures and obtain consent for specific practices.
New York State Legislature • New York, United States
Mauritius DPA — Mauritius Data Protection Act 2017
The Data Protection Act 2017 establishes legal protections for privacy rights in Mauritius, regulating the collection, processing, storage, and use of personal information. It aims to safeguard privacy amid technical advancements while balancing the needs of government, businesses, and individuals.
Government of Mauritius • Mauritius
BDSG — Germany Federal Data Protection Act
The Federal Data Protection Act (BDSG) is Germany's national data protection law that complements the GDPR by establishing rules for personal data processing, privacy protection, regulatory oversight, and compliance obligations for public and private sector organizations.
v23 June 2021
Switzerland FADP — Switzerland Federal Act on Data Protection
The Federal Act on Data Protection (FADP) is Switzerland's data protection law that regulates the processing of personal data and protects the privacy rights of individuals by establishing requirements for lawful, transparent, and secure data handling.
The Federal Assembly of the Swiss Confederation • Switzerland • v3 January 2019
Estonia PDPA — Estonia - Personal Data Protection Act
The Estonia Personal Data Protection Act (IKS) is Estonia's data protection law that implements and supplements the GDPR, establishing requirements for personal data processing, privacy protection, and regulatory oversight.
Government of Estonia • Estonia • v15 January 2019
Dubai HDPR — Dubai Health Data Protection Regulation - DHCC Regulation No. 7 of 2013
The Dubai Health Data Protection Regulation is a healthcare privacy regulation that governs the protection, use, disclosure, and management of patient health information within Dubai Healthcare City, ensuring the confidentiality and security of health data.
Dubai Healthcare City Authority (DHCA) • Dubai • v21 October 2013
Finland Data Protection Act — Data Protection Act (1050/2018) - Finland
The Data Protection Act (1050/2018) provides national specifications and supplements the EU GDPR in Finland. It governs the roles and powers of the data protection authority, sets age limits for services to children, and includes rules for special categories of personal data and data processing in public interest contexts.
Government of Finland • Finland • v1050/2018
Do Not Call Register Act 2006
The Do Not Call Register Act 2006 establishes a framework to prevent unsolicited telemarketing calls and faxes to individuals and organizations who register their numbers on the Do Not Call Register. It includes rules for telemarketers and penalties for violations.
Australian Government • Australia • vNo. 15, 12 December 2019
CR code v2.1 — Privacy (Credit Reporting) Code 2014 (Version 2.1)
The Privacy (Credit Reporting) Code 2014 (Version 2.1) provides a framework for credit reporting practices under Australia's Privacy Act. It outlines obligations for Credit Reporting Bodies (CRBs), Credit Providers (CPs), and other affected entities to ensure compliance with privacy regulations.
Australian Government • Australia • v2.1
LGOIMA — Local Government Official Information and Meetings Act 1987 - New Zealand
The Local Government Official Information and Meetings Act 1987 (LGOIMA) is a New Zealand law that provides public access to information held by local authorities and council-controlled organizations. It also sets transparency standards for local government meetings, ensuring public notification and accessibility.
New Zealand Government • New Zealand • v23 December 2023
CCM v4.1 — Cloud Controls Matrix v4.1
The Cloud Controls Matrix (CCM) v4.1 is a cybersecurity control framework that consists of 207 controls across 17 security domains, specifically tailored for cloud security and privacy. The Consensus Assessment Initiative Questionnaire (CAIQ) accompanies the CCM, offering a set of assessment questions to evaluate security controls.
Cloud Security Alliance (CSA) • v4.1
ISO/IEC 27018:2025 — ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors
ISO/IEC 27018:2025 is the global standard for managing personally identifiable information (PII) in public cloud services. It provides cloud providers with a framework to ensure privacy, security, and compliance when processing customer data.
International Organization for Standardization (ISO) • v2025
PRIS Act — Privacy and Responsible Information Sharing Act 2024
The Privacy and Responsible Information Sharing Act 2024 (PRIS Act) establishes a privacy framework for the Western Australian public sector. It introduces Information Privacy Principles (IPPs) and provisions for privacy complaints, privacy impact assessments, and a notifiable information breach scheme.
Government of Western Australia • Western Australia
NIST SP 800-53 Rev. 5.2 — Security and Privacy Controls for Information Systems and Organizations
NIST Special Publication 800-53 Rev. 5 provides a comprehensive catalog of security and privacy controls designed to safeguard organizational operations, assets, and individuals from a broad spectrum of risks including cyberattacks, human mistakes, and natural disasters. It is widely used for implementing security measures as part of risk management frameworks.
NIST (National Institute of Standards and Technology) • United States • v5.2.0
India - DPDP Rules — India - Digital Personal Data Protection (DPDP) Rules
The Digital Personal Data Protection Rules, 2025 operationalize India’s Digital Personal Data Protection Act, 2023 by establishing detailed requirements for the collection, processing, storage, and protection of digital personal data. The Rules define obligations for organizations handling personal data, including consent management, breach notifications, data retention, and protections for children and vulnerable individuals. They also establish governance mechanisms such as the Data Protection Board and provide a phased implementation timeline for compliance.
Government of India • India • v2025
India - DPDP Act — India - Digital Personal Data Protection (DPDP) Act (Act No. 22 of 2023)
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) establishes India’s legal framework for processing digital personal data while balancing individuals’ privacy rights with lawful data use. The Act defines obligations for organizations handling personal data, grants rights and duties to individuals, and introduces requirements for consent, data protection, and breach accountability. It also establishes the Data Protection Board of India to oversee compliance, adjudication, and enforcement of penalties for violations.
Government of India • India • v2023
Privacy Act
The Privacy Act of Canada governs the collection, use, retention, and disclosure of personal information by federal government institutions. It ensures that individuals have the right to access and correct their personal information held by the government.
Government of Canada • Canada
Partner directory
Certified resellers, integrators and advisors to help you implement and manage your GRC program.

1886 Consulting
- Region
- Australia
Tap into our knowledge of wealth.
Governance • Risk Management • Compliance Management • GRC Advisory

19eighty Advisory
- Region
- Australia
Business ownership is the most powerful calling.

3 Lights
- Region
- 4001, Brisbane, Australia
Finance & Professional Services, Healthcare, Technology & Telecommunications Energy & Utilities
ISO27001 • NIST • SMB1001

3Quotes
- Region
- Canada
Your IT Procurement Partner

A1 Hrvatska d.o.o.
- Region
- Croatia
Croatia's leading telecommunications provider offering mobile, internet, TV, and managed security services.
Managed Security Services • Security Operations • Cloud Security

Accenture
- Region
- Australia
De-risk tomorrow by infusing cybersecurity into strategy, resilience, and protection at global scale.
GRC Advisory • Risk Management • Compliance Management • Security Operations

AfterDark Technology
- Region
- Australia
ISO 27001-certified managed IT services provider keeping Australian businesses secure, reliable, and running.
IT Managed Services • Managed Security Services • Essential Eight • ISO 27001

Archer & Round
- Region
- Australia
Cybersecurity that keeps you one step ahead with 24/7 managed SOC, vCISO, and GRC services.
Managed Security Services • Governance • Risk Management • Incident Response
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.