Compliance standards for Government

Curated standards, laws and regulations relevant to Government organizations. Updated continuously, with mapped controls and expert guidance from 6clicks.

85 items

All Government content · 85 items

CybersecurityControl setGuideline

ITSG-33 — IT Security Risk Management: A Lifecycle Approach (ITSG-33)

ITSG-33 is a guideline developed by the Canadian Centre for Cyber Security to help government departments manage IT security risks effectively. It outlines activities at both departmental and project levels, providing a structured process for integrating security considerations into IT environments and maintaining authorization to operate.

Canadian Centre for Cyber Security • Canada

View details
PrivacyLaw

Croatia - Personal Data Protection Act

The Act governs the implementation of the EU General Data Protection Regulation (GDPR) in Croatia. It outlines specific roles such as the responsibilities of the supervisory authority, the Croatian Data Protection Agency (AZOP), and sets additional national measures related to GDPR compliance.

Government of Croatia • Croatia

View details
PrivacyLaw

Law No.59 — Vietnam - Law on Protection of Consumers' Rights

The Vietnam Law on Protection of Consumers' Rights is a consumer protection framework that establishes consumer rights, business obligations, consumer information protection requirements, and mechanisms for resolving disputes between consumers and traders.

Government of Vietnam • Vietnam • vLaw No.59/2010/QH12

View details
CybersecurityLaw

Alabama Data Breach Notification Act of 2018 — Chapter 38 Data Breach Notification Act of 2018

The Alabama Data Breach Notification Act of 2018 is a state data protection law that requires organizations to safeguard sensitive personal information, investigate security breaches, and provide timely notification to affected individuals and regulatory authorities when personal data is compromised.

State of Alabama • Alabama, USA • vPolicy 621-01

View details
PrivacyLaw

Arkansas PIPA — Arkansas Personal Information Protection Act

The Arkansas Personal Information Protection Act (PIPA) is a data privacy and security law that requires organizations to protect personal information, implement reasonable security measures, and notify affected individuals in the event of a qualifying data breach.

State of Arkansas • Arkansas, USA

View details
PrivacyRegulation

Nevada Chapter 603A — Security and Privacy of Personal Information

Nevada Chapter 603A - Security and Privacy of Personal Information is a Nevada privacy and data security law that requires organizations to safeguard personal information, notify individuals of certain data breaches, and comply with consumer privacy requirements relating to the collection, use, and protection of personal data.

State of Nevada • Nevada, USA

View details
PrivacyLaw

Kenya DPA — Kenya Data Protection Act No. 24 OF 2019

The Data Protection Act, 2019 is Kenya’s national data protection law that regulates the processing of personal data, establishes privacy rights for individuals, and sets obligations for organizations to protect personal information through secure and lawful data handling practices.

Government of Kenya • Kenya

View details
PrivacyRegulation

Israel - Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001

The Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 establish Israel's requirements for cross-border transfers of personal data, ensuring that personal information transferred outside Israel remains subject to adequate privacy and data protection safeguards.

Government of Israel • Israel

View details
PrivacyRegulation

PP 82/2012 — Indonesia - Peraturan Pemerintah No.82 Tahun 2012 - Government Regulation - Data Protection Regulation

This regulation specifies the requirements for electronic system and transaction operations in Indonesia, including provisions for electronic agents, signatures, certification, and data management. It aims to ensure security, transparency, and accountability in the use and management of electronic systems and information.

Government of the Republic of Indonesia • Indonesia

View details
PrivacyLaw

Hawaii - Security Breach of Personal Information Chapter 487N

Hawaii Security Breach of Personal Information (Chapter 487N) is a Hawaii state law that requires businesses and government agencies to notify affected individuals of data breaches involving personal information and establishes requirements for protecting and managing sensitive personal data.

State of Hawaii • Hawaii

View details
PrivacyLaw

Greece Law 2472/1997 — Greece Law 2472/1997 on the Protection of Individuals with regard to the Processing of Personal Data

Law 2472/1997 is a legal framework from Greece designed to safeguard individual privacy rights in relation to the processing of personal data. It aligns with principles outlined in the EU Charter of Fundamental Rights, specifically addressing data protection and privacy issues.

Government of Greece • Greece

View details
PrivacyLaw

Ghana Data Protection Act — Ghana Data Protection Act, 2012 (Act 843)

The Data Protection Act, 2012 (Act 843) is Ghana’s data protection law that regulates the processing of personal data, establishes privacy rights for individuals, and sets requirements for organizations to protect and manage personal information responsibly.

Government of Ghana • Ghana

View details
PrivacyLaw

Pakistan EDPA 2005 — Pakistan The Electronic Data Protection Act, 2005

The Electronic Data Protection Act, 2005 is a law enacted in Pakistan to address the processing and protection of electronic data. It aims to ensure the privacy, security, and rights of data subjects, with provisions for data processing, security measures, and penalties for violations.

Government of Pakistan • Pakistan

View details
CybersecurityFramework

DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme

The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information.

Australian Department of Employment and Workplace Relations (DEWR) • Australia

View details
PrivacyLaw

Cyprus - Law 125(I)2018 — Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data of 2018

Law 125(I)/2018 is Cyprus's data protection legislation that implements and supplements the GDPR, establishing requirements for personal data processing, privacy protection, regulatory oversight, and the protection of individuals' data rights.

Government of Cyprus • Cyprus

View details
GRCLaw

Sex Discrimination Act 1984

A federal law enacted by the Australian Government to eliminate discrimination on the basis of sex, gender identity, sexual orientation, marital status, pregnancy, or family responsibilities. It also addresses sexual harassment and outlines protections in employment, education, goods and services, and public programs.

Attorney-General's Department • Australia • v1 January 2014

View details
PrivacyLaw

Brazilian LGPD — Brazilian General Data Protection Law

The LGPD is Brazil’s first comprehensive data protection regulation, aligned with principles of the EU GDPR. It governs the processing, storage, and sharing of personal data of individuals within Brazil, including data security and breach notifications.

Brazilian government • Brazil

View details
GRCLaw

Trade Marks Act 1995

The Trade Marks Act 1995 is an Australian legislation that governs the registration, use, protection, and enforcement of trade marks within the country. It provides rules for registering trade marks, handling disputes, managing trade mark rights, and addressing infringements.

Department of Industry, Science and Resources • Australia • vCompilation No. 38, 24 February 2019

View details
GRCLaw

Racial Discrimination Act 1975

The Racial Discrimination Act 1975 establishes legal protections against racial discrimination in Australia, implementing the International Convention on the Elimination of All Forms of Racial Discrimination. It prohibits racial hatred and discrimination in areas including employment, housing, and public services.

Australian Government • Australia • vCompilation No. 17, 10 December 2015

View details
PrivacyLaw

Korea PIPA — Korea Personal Information Protection Act

The Personal Information Protection Act establishes legal principles and requirements for protecting personal information within South Korea. It defines the rights of individuals regarding their data and sets obligations for organizations handling personal information.

South Korean Government • South Korea

View details
PrivacyLaw

Taiwan PDPA — Taiwan Personal Data Protection Act

The Personal Data Protection Act (PDPA) of Taiwan establishes legal requirements for the collection, processing, and utilization of personal data in order to protect personality rights while enabling appropriate use of such data. It applies to both government and non-government entities, ensuring compliance and safeguarding individuals' privacy and rights.

Personal Data Protection Commission • Taiwan

View details
PrivacyLaw

Thailand PDPA — Thailand Personal Data Protection Act B.E. 2562 (2019)

The Personal Data Protection Act B.E. 2562 (2019) is Thailand's primary law for personal data protection. It establishes rules for data collection, use, and disclosure, and aims to protect individuals' personal information and ensure effective remedies for violations.

Government of Thailand • Thailand • v27 May 2019

View details
PrivacyLaw

Netherlands WBP — Netherlands Personal Data Protection Act

The Personal Data Protection Act (WBP) was the Netherlands' data protection law that governed the processing of personal data and established privacy rights, data protection obligations, and regulatory oversight for organizations handling personal information.

Government of Netherlands • Netherlands

View details
CybersecurityFramework

Spain ENS — Spain - National Security Framework

The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.

Government of Spain • Spain • v5 May 2022

View details
CybersecurityLaw

BDSG — Germany Federal Data Protection Act

The Federal Data Protection Act (BDSG) is Germany's national data protection law that complements the GDPR by establishing rules for personal data processing, privacy protection, regulatory oversight, and compliance obligations for public and private sector organizations.

v23 June 2021

View details
PrivacyLaw

Switzerland FADP — Switzerland Federal Act on Data Protection

The Federal Act on Data Protection (FADP) is Switzerland's data protection law that regulates the processing of personal data and protects the privacy rights of individuals by establishing requirements for lawful, transparent, and secure data handling.

The Federal Assembly of the Swiss Confederation • Switzerland • v3 January 2019

View details
PrivacyLaw

Dubai HDPR — Dubai Health Data Protection Regulation - DHCC Regulation No. 7 of 2013

The Dubai Health Data Protection Regulation is a healthcare privacy regulation that governs the protection, use, disclosure, and management of patient health information within Dubai Healthcare City, ensuring the confidentiality and security of health data.

Dubai Healthcare City Authority (DHCA) • Dubai • v21 October 2013

View details
PrivacyLaw

Finland Data Protection Act — Data Protection Act (1050/2018) - Finland

The Data Protection Act (1050/2018) provides national specifications and supplements the EU GDPR in Finland. It governs the roles and powers of the data protection authority, sets age limits for services to children, and includes rules for special categories of personal data and data processing in public interest contexts.

Government of Finland • Finland • v1050/2018

View details
GRCLaw

Protection of Movable Cultural Heritage Act 1986

The Protection of Movable Cultural Heritage Act 1986 establishes a framework for safeguarding movable cultural heritage in Australia. It provides regulations concerning the export, import, administration, and enforcement related to cultural heritage objects.

Australian Government • Australia • vCompilation No. 18, 21 October 2016

View details
GRCLaw

Patents Act 1990

The Patents Act 1990 establishes the legal framework for patent rights in Australia. It outlines the processes for applying for and granting patents, the exclusive rights conferred by patents, and provisions for examining, opposing, amending, and invalidating patents.

Australian Government • Australia • vCompilation No. 41, 24 February 2017

View details
GRCLaw

Migration Act 1958

The Migration Act 1958 is an Australian legislative framework governing the entry, presence, and departure of non-citizens in Australia. It includes provisions for visas, immigration status, detention, deportation, and migration-related rights and obligations.

Parliament of Australia • Australia • vCompilation No. 150, 22 March 2021

View details
Critical InfrastructureLaw

Independent Contractors Act 2006

The Independent Contractors Act 2006 is Australian legislation that regulates independent contracting arrangements, protects the rights of independent contractors, and provides mechanisms for addressing unfair services contracts.

Australian Government • Australia • vCompilation No. 7, 1 July 2016

View details
Critical InfrastructureLaw

FBTAA 1986 — Fringe Benefits Tax Assessment Act 1986

The Fringe Benefits Tax Assessment Act 1986 is the Australian legislation that governs the taxation of non-cash benefits provided by employers to employees, establishing the rules for identifying, valuing, and taxing fringe benefits.

Australian Government • Australia • vCompilation No. 84, 1 April 2019

View details
Critical InfrastructureLaw

Agricultural and Veterinary Chemicals Code Act 1994

This Australian law establishes the framework for regulating agricultural and veterinary chemical products. It governs approvals, registrations, manufacturing, use, labeling, distribution, and enforcement actions to ensure safety, efficacy, and compliance across the chemicals sector.

Australian Government • Australia • vCompilation No. 29, 21 October 2016

View details
GRCLaw

Age Discrimination Act 2004

The Age Discrimination Act 2004 is an Australian law that aims to eliminate age discrimination across various areas, including employment, education, and access to goods and services. It outlines unlawful discriminatory practices and establishes protections against victimization and related offenses.

Australian Government • Australia • vCompilation No. 35, 12 October 2017

View details
GRCLaw

Aboriginal Heritage Protection Act 1984 — Aboriginal and Torres Strait Islander Heritage Protection Act 1984

The Aboriginal and Torres Strait Islander Heritage Protection Act 1984 provides measures to preserve and protect significant Aboriginal areas and objects with cultural, historical, and spiritual importance. It includes provisions for declarations by the minister or authorized officers, penalties for violations, and procedures for legal assistance and compensation.

Australian Government • Australia • vCompilation No. 17, 21 October 2016

View details
GRCRegulation

Work Health and Safety Regulations 2011

The Work Health and Safety Regulations 2011 establish detailed requirements for workplace health and safety in compliance with the Work Health and Safety Act 2011. They cover topics such as risk management, workplace conditions, hazardous materials, emergency plans, and licensing for high-risk activities.

Australian Government • Australia • vNo. 15, 1 July 2020

View details
GRCLaw

Work Health and Safety Act 2011

The Work Health and Safety Act 2011 is Australian legislation that establishes a framework to ensure workplace safety and health across various industries and occupations. It defines responsibilities for employers, workers, and other parties in maintaining safe conditions and managing risks related to work-related activities.

Australian Government • Australia • vNo. 9, 1 July 2018

View details
GRCLaw

Criminal Code Act 1995

The Criminal Code Act 1995 is an Australian federal law that establishes the legal framework for addressing criminal offenses. It outlines principles of criminal responsibility, specific offenses such as terrorism and espionage, and provisions for external and corporate liabilities.

Attorney-General's Department • Australia • vNo. 137, 17 February 2021

View details
PrivacyLaw

Copyright Act 1968

The Copyright Act 1968 is a foundational law in Australia governing copyrights and intellectual property rights in literary, artistic, dramatic, and musical works, as well as sound recordings, broadcasts, and published editions. It defines the rights and protections for creators and sets out provisions for infringement, fair dealing, and public access in specific scenarios such as education and disabilities.

Australian Government • Australia • vNo. 59, 18 December 2020

View details
PrivacyLaw

Child Support (Registration and Collection) Act 1988

The Child Support (Registration and Collection) Act 1988 sets the legal framework for registering and collecting child maintenance liabilities in Australia. It outlines processes for enforcing payments, managing registrable liabilities, and utilizing computer programs for certain decisions.

Australian Government • Australia • vNo. 61, 17 November 2016

View details
GRCLaw

BCI Act — Building and Construction Industry (Improving Productivity) Act 2016

The Building and Construction Industry (Improving Productivity) Act 2016 establishes a regulatory framework aimed at improving productivity and accountability within the building and construction sector in Australia. It provides for the creation of the Australian Building and Construction Commission and outlines rules governing industrial actions, security of payments, and compliance with workplace safety regulations.

Australian Government • Australia • vNo. 2, 17 February 2017

View details
CybersecurityGuideline

NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.

National Institute of Standards and Technology (NIST) • United States

View details
PrivacyLaw

Spam Act 2003

The Spam Act 2003 is an Australian law designed to regulate the sending of commercial electronic messages to ensure compliance with consent, sender identification, and unsubscribe requirements. It aims to prevent unsolicited messages and address harvesting practices.

Australian Government • Australia • vNo. 10, 10 March 2016

View details
CybersecurityRegulation

Dubai ISR — Dubai Government Information Security Regulation

The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.

Dubai Government • Dubai • v3

View details
PrivacyLaw

Do Not Call Register Act 2006

The Do Not Call Register Act 2006 establishes a framework to prevent unsolicited telemarketing calls and faxes to individuals and organizations who register their numbers on the Do Not Call Register. It includes rules for telemarketers and penalties for violations.

Australian Government • Australia • vNo. 15, 12 December 2019

View details
CybersecurityFramework

DSPF — Defence Security Principles Framework

The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.

Australian Government • Australia • v2 July 2018

View details
GRCLaw

Disability Discrimination Act 1992

The Disability Discrimination Act 1992 is an Australian law prohibiting discrimination based on disability across various areas, including employment, education, access to services, and public spaces. It aims to promote equal opportunity and eliminate unjustifiable hardship for individuals with disabilities.

Australian Government • Australia • vNo. 31, 1 July 2016

View details
PrivacyLaw

Charter of the United Nations Act 1945

The Charter of the United Nations Act 1945 provides a legal framework for implementing United Nations Security Council Resolutions in Australia. It regulates the application of sanctions, the listing and proscription of individuals or entities, and addresses offenses related to UN sanctions.

Australian Government • Australia • vNo. 14, 1 July 2016

View details
GRCLaw

Autonomous Sanctions Act 2011

The Autonomous Sanctions Act 2011 establishes the legal framework for imposing sanctions by the Australian Government as part of its foreign policy objectives. It includes provisions for sanction regulations, offences, and enforcement mechanisms.

Australian Government • Australia • vCompilation No. 4, 9 April 2024

View details
CybersecurityStandard

FedRAMP Controls — FedRAMP Security Controls Baseline rev 5

The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization.

US Government • United States • vrev 5

View details
GRCLaw

ASIC Act — Australian Securities and Investments Commission Act 2001

This Act establishes the legal framework for the operation of the Australian Securities and Investments Commission (ASIC), which is responsible for regulating company, financial services, and consumer protection laws in Australia. It outlines ASIC's powers, functions, and responsibilities while detailing provisions for consumer protection and fair competition in financial services industries.

Australian Government • Australia • vNo. 91, 1 July 2023

View details
CybersecurityGuideline

WA Cyber Security Policy — Western Australian Government Cyber Security Policy

The 2024 WA Government Cyber Security Policy outlines the baseline requirements for cyber security practices within Western Australian Government entities. It aims to reduce cyber security risks through a comprehensive and systematic approach to safeguarding digital information, information systems, and assets.

Department of the Premier and Cabinet - Office of Digital Government • Western Australia • v2024

View details
PrivacyLaw

Anti-Discrimination Act 1991 (Qld) — Queensland Anti-Discrimination Act 1991

The Anti-Discrimination Act 1991 is legislation enacted by the Queensland Government to promote equality of opportunity, prohibit discrimination, and encourage tolerance in the state of Queensland, Australia. It covers areas such as work, education, and the provision of goods and services.

Queensland Government • Queensland, Australia

View details
GRCRegulation

NCCP Regulations — National Consumer Credit Protection Regulations 2010

This regulation provides detailed requirements under the National Consumer Credit Protection Act 2009 to govern the licensing, responsible lending, credit contracts, and compliance monitoring for entities providing credit services in Australia. It aims to ensure transparency and protection for consumers in financial and credit transactions.

Australian Government • Australia • v2021-12

View details
GRCLaw

SIS Act — Superannuation Industry (Supervision) Act 1993

The Superannuation Industry (Supervision) Act 1993 establishes the regulatory framework for superannuation funds in Australia. It defines compliance standards for trustees, funds, and associated entities, aiming to ensure proper administration and protection of member benefits.

Australian Government • Australia • vNo. 78, 1993

View details
PrivacyLaw

NCCP Act 2009 — National Consumer Credit Protection Act 2009

The National Consumer Credit Protection Act 2009 is an Australian law that regulates the provision of consumer credit and financial services in the country. It outlines licensing requirements for entities engaged in credit activities and includes protections for consumers against unsuitable credit agreements.

Australian Government • Australia • vNo. 134

View details
PrivacyLaw

LGOIMA — Local Government Official Information and Meetings Act 1987 - New Zealand

The Local Government Official Information and Meetings Act 1987 (LGOIMA) is a New Zealand law that provides public access to information held by local authorities and council-controlled organizations. It also sets transparency standards for local government meetings, ensuring public notification and accessibility.

New Zealand Government • New Zealand • v23 December 2023

View details
CybersecurityGuideline

WA Digital Security Policy — Western Australia Digital Security Policy

The West Australian Whole of Government Digital Security Policy provides guidelines for adopting and maintaining security controls in digital information and systems. It addresses confidentiality, integrity, and availability, relying on both Australian and international standards.

Australian Government • Australia

View details
PrivacyLaw

Royal Decree 69/2008 — Electronic Transactions Law in Oman

The Electronic Transactions Law in Oman, enacted in 2008 through Royal Decree 69/2008, aims to streamline electronic transactions and ensure their security. It establishes provisions for authentication service providers, e-signature confidentiality, and data integrity.

Government of Oman • Oman

View details
CybersecurityStandardControl set

ASD Essential 8 Maturity Model - 2023 — Australian Signals Directorate (ASD) Essential Eight Maturity Model 2023

The ASD Essential 8 Maturity Model is a framework developed by the Australian Signals Directorate (ASD) to guide organizations in implementing prioritized cyber security mitigation strategies. It provides structured maturity levels to help organizations progressively strengthen their defenses against common cyber threats. The model ensures consistency, accountability, and resilience by aligning practices across all eight strategies.

Australian Signals Directorate (ASD) • Australia • vNovember 2023

View details
CybersecurityStandard

Cyber Essentials Danzell Question Set — Cyber Essentials Question Set v3.3 (Danzell) April 2026

Cyber Essentials: Requirements for IT Infrastructure v3.3 Question Set is a structured self-assessment designed to help organizations evaluate their cyber security practices. It focuses on five key technical control areas—firewalls, secure configuration, user access control, malware protection, and patch management. By completing the question set, organizations can demonstrate compliance with baseline security standards and strengthen resilience against common cyber threats.

National Cyber Security Centre (NCSC) • v3.3

View details
CybersecurityStandard

ISO/IEC 27018:2025 — ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors

ISO/IEC 27018:2025 is the global standard for managing personally identifiable information (PII) in public cloud services. It provides cloud providers with a framework to ensure privacy, security, and compliance when processing customer data.

International Organization for Standardization (ISO) • v2025

View details
CybersecurityStandard

ISM CCM — Information Security Manual Cloud Controls Matrix Template

The Cloud Controls Matrix (CCM) Template is a comprehensive framework for mapping cloud security controls to industry standards and compliance requirements. It helps organizations assess, implement, and demonstrate effective cloud security practices across diverse environments.

Australian Government • Australia • vJune 2026

View details
CybersecurityRegulation

ISM SSP — Information Security Manual System Security Plan Annex Template

The System Security Plan (SSP) Annex Template is a structured document used to capture detailed information about an organization’s cyber security controls and implementation. It supports accreditation processes by providing evidence of compliance, risk management, and system-specific security measures.

Australian Government • Australia • vJune 2026

View details
CybersecurityRegulation

RFFR ISM SoA — Right Fit for Risk Information Security Manual Statement of Applicability

The Right Fit for Risk (RFFR) Statement of Applicability (SoA) is a structured template used to document how organizations meet cyber security accreditation requirements. It outlines applicable controls, their implementation status, and provides assurance of compliance with the RFFR framework.

Australian Government • Australia • vJune 2026

View details
CybersecurityRegulation

ISM — Information Security Manual

The Australian ISM is the nationally recognized cybersecurity framework developed by the Australian Signals Directorate. It provides organizations with structured guidance to safeguard information and operational technology systems against evolving cyber threats.

Australian Government • Australia • vJune 2026

View details
PrivacyLaw

PRIS Act — Privacy and Responsible Information Sharing Act 2024

The Privacy and Responsible Information Sharing Act 2024 (PRIS Act) establishes a privacy framework for the Western Australian public sector. It introduces Information Privacy Principles (IPPs) and provisions for privacy complaints, privacy impact assessments, and a notifiable information breach scheme.

Government of Western Australia • Western Australia

View details
PrivacyRegulation

India - DPDP Rules — India - Digital Personal Data Protection (DPDP) Rules

The Digital Personal Data Protection Rules, 2025 operationalize India’s Digital Personal Data Protection Act, 2023 by establishing detailed requirements for the collection, processing, storage, and protection of digital personal data. The Rules define obligations for organizations handling personal data, including consent management, breach notifications, data retention, and protections for children and vulnerable individuals. They also establish governance mechanisms such as the Data Protection Board and provide a phased implementation timeline for compliance.

Government of India • India • v2025

View details
PrivacyLaw

India - DPDP Act — India - Digital Personal Data Protection (DPDP) Act (Act No. 22 of 2023)

The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) establishes India’s legal framework for processing digital personal data while balancing individuals’ privacy rights with lawful data use. The Act defines obligations for organizations handling personal data, grants rights and duties to individuals, and introduces requirements for consent, data protection, and breach accountability. It also establishes the Data Protection Board of India to oversee compliance, adjudication, and enforcement of penalties for violations.

Government of India • India • v2023

View details
CybersecurityGuideline

Safe & Trusted Internet — Guidelines on Information Security Practices for Government Entities

The Safe & Trusted Internet Guidelines on Information Security Practices for Government Entities, issued by the Indian Computer Emergency Response Team (CERT-In), establish baseline cyber security controls and best practices to help government entities protect ICT infrastructure, systems, networks, and data against evolving cyber threats and strengthen India’s digital security posture.

Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India • India

View details
GRCLaw

CBK Law — Law No. (32) of 1968 Concerning Currency, The Central Bank of Kuwait and The Regulation of Banking

Law No. (32) of 1968 establishes the legal framework for the establishment and operation of the Central Bank of Kuwait (CBK) and governs currency issuance, banking regulations, and financial supervision within Kuwait. It includes amendments to address evolving economic and regulatory needs.

Central Bank of Kuwait • Kuwait • v2021

View details
CybersecurityGuideline

VPDSS PDSP v3.7 — Victorian Protective Data Security Standards Protective Data Security Plan v3.7

Victorian public sector bodies are required to report on their information security practices to the Office of the Victorian Information Commissioner (OVIC). This includes submitting Protective Data Security Plans (PDSPs), annual attestations, and notifying OVIC of security incidents as outlined under the Victorian Protective Data Security Framework and Standards (VPDSF, VPDSS).

Office of the Victorian Information Commissioner (OVIC) • Victoria, Australia • v3.7

View details
Critical InfrastructureLaw

SOCIA 2018 — Security of Critical Infrastructure Act 2018

The Security of Critical Infrastructure Act 2018 (SOCIA) establishes a regulatory framework for managing national security risks to Australia’s critical infrastructure sectors. It introduces statutory obligations, reporting requirements, and oversight mechanisms for critical assets.

Australian Department of Home Affairs • Australia • vNo. 29, 2018

View details
PrivacyLaw

Privacy Act

The Privacy Act of Canada governs the collection, use, retention, and disclosure of personal information by federal government institutions. It ensures that individuals have the right to access and correct their personal information held by the government.

Government of Canada • Canada

View details
GRCLaw

National Greenhouse and Energy Reporting Act 2007

The National Greenhouse and Energy Reporting Act 2007 establishes a national framework for corporations to report their greenhouse gas emissions, energy production, and energy consumption. It aims to improve data transparency and inform government policy on climate change.

Australian Government • Australia

View details
GRCRegulation

Fair Work Regulations 2009

The Fair Work Regulations 2009 provide detailed legislative backing to the Fair Work Act 2009, outlining the operational rules and requirements for employment relationships, industrial agreements, and workplace standards in Australia. It includes rules on employer obligations, employee protections, and compliance mechanisms.

Department of Employment and Workplace Relations (DEWR) • Australia

View details
Critical InfrastructureLaw

Clean Energy Act 2011

The Clean Energy Act 2011 establishes the framework for implementing a carbon pricing mechanism in Australia. It includes provisions for covered entities, emission obligations, and limits on emissions units.

Parliament of Australia • Australia

View details
CybersecurityFramework

C2M2 — Cybersecurity Capability Maturity Model

The Cybersecurity Capability Maturity Model (C2M2) is a tool developed by the U.S. Department of Energy to help organizations evaluate and enhance their cybersecurity capabilities. It focuses on both IT and OT environments, offering a structured framework of over 350 practices organized into 10 domains.

U.S. Department of Energy • United States • v2.1

View details
CybersecurityControl set

ECC 2-2024 — Essential Cybersecurity Controls

The Essential Cybersecurity Controls (ECC 2-2024) aim to enhance cybersecurity at the national level in Saudi Arabia. They provide policies and controls to protect the information and technological assets of national entities.

National Cybersecurity Authority • Kingdom of Saudi Arabia • v2-2024

View details
CybersecurityControl set

DCC-1:2022 — Data Cybersecurity Controls

The Data Cybersecurity Controls (DCC-1:2022) establish minimum cybersecurity requirements to protect data throughout its lifecycle. Issued by the Saudi National Cybersecurity Authority, the controls build on existing cybersecurity frameworks to enhance the Kingdom's overall cybersecurity maturity.

National Cybersecurity Authority (NCA) • Kingdom of Saudi Arabia • v1:2022

View details
CybersecurityGuideline

IS18 — Information and Cyber Security Policy (IS18)

The Information and Cyber Security Policy (IS18) is a policy framework established by the Queensland Government to enhance information security and organizational resilience. It mandates the implementation of ISO 27001-based ISMS, systematic risk management, and compliance with the Australian Signals Directorate's Essential Eight Strategies for all Queensland Government agencies.

Queensland Government • Queensland, Australia • v9.0.0

View details
PrivacyLaw

UAE Personal Data Protection Law — Federal Decree Law No. 45 of 2021 Regarding the Protection of Personal Data

The UAE Personal Data Protection Law establishes an integrated framework to ensure the confidentiality of information and protect individual privacy in the UAE. It governs the processing of personal data, defines the rights of data owners, sets requirements for cross-border data transfer, and outlines obligations for businesses handling personal data.

UAE Data Office • United Arab Emirates • v20 Sep 2021

View details
PrivacyLaw

Privacy and Data Protection Act 2014 — Privacy and Data Protection Act 2014 Version No. 032

The Privacy and Data Protection Act 2014 establishes a framework for protecting personal information and ensuring data security within the State of Victoria, Australia. It sets out responsibilities for Victorian public sector agencies regarding personal data handling and protections.

Victorian Government • Victoria, Australia • version No. 032

View details
CybersecurityStandard

VPDSS 2.0 — Victorian Protective Data Security Standards V2.0

The Victorian Protective Data Security Standards (VPDSS) establish 12 high-level mandatory requirements for the protection of public sector information in Victoria, Australia. These requirements cover governance, information, personnel, ICT, and physical security, focusing on a risk-managed approach tailored to the Victorian government context.

Office of the Victorian Information Commissioner (OVIC) • Victoria, Australia • v2.0

View details

Manage Government compliance with 6clicks

The 6clicks platform maps these regulations to controls, evidence and risks — automatically.