Global coverage

Where we operate and what we comply with

We advise organizations across 5 regions against 22 named regimes. This page sets out each one, what it asks of a firm like ours, what we do about it for ourselves, and the work we do for clients under it. Our own position is generated from the control register, so it changes when the practice changes.

What we claim, and what we do not

  • We can be lawful and defensible in every country where we trade, and we are.
  • No firm can hold every certification in every country, and any provider claiming otherwise should be checked.
  • We hold no SOC 2 report, no ISO 27001 certificate, and no CMMC certification today. Each has a written program and a date.
  • Where a country requires a local entity, local representation, or data that cannot leave its borders, we say so and work with local counsel rather than pretending the problem away.
  • Every claim on a buyer page is generated from our control register, so it changes when the practice changes rather than when the marketing changes.

North America

Our home market and the source of most federal and state contracting work. Registration and contract clauses drive most of the obligation.

Federal contracting requirements, including FAR and DFARS clauses

in place

United States federal and subcontract work

What it requires
Accurate registration and representations, safeguarding of any federal contract information, and flow down of clauses to subcontractors.
Our own position
Registration facts are held in one approved record and written into every bid automatically. Subcontractor terms carry the same confidentiality and handling obligations we accept.
What we do for clients
Readiness assessment, control implementation, and evidence preparation for contract obligations.

NIST SP 800-171 and CMMC Level 2

triggered by contract

Contracts involving controlled unclassified information

What it requires
Implementation of the practice set and an assessment before award.
Our own position
Practices are mapped and scheduled. The program is deliberately held until a contract actually brings controlled information to us, and we hold no certification today.
What we do for clients
Gap assessment, system security plan, and assessment preparation.

State privacy and breach notification laws

in place

All fifty states, with California, Virginia, Colorado, Texas, and others leading

What it requires
Notification inside a defined window and honouring individual rights.
Our own position
Our own notification route and timing is written down and rehearsed, and we hold a very small amount of personal data by design.
What we do for clients
Multi state notification playbooks and rights handling procedures.

Sector rules, including HIPAA, GLBA, and the Safeguards Rule

in place

Health, financial services, and higher education clients

What it requires
A written program, a named responsible individual, vendor oversight, and incident response.
Our own position
We act as a service provider and sign the appropriate agreements. We do not hold health records.
What we do for clients
Written programs, qualified individual support, vendor oversight, and incident response.

Canadian federal privacy law, PIPEDA and provincial equivalents

in place

Canada

What it requires
Accountability, consent, and breach reporting to the regulator and individuals.
Our own position
Handled under the same data minimization and notification approach.
What we do for clients
Privacy program design and cross border transfer assessment.

Europe, the United Kingdom, and the wider EMEA region

The densest regulatory environment we work in, and the one clients most often need help translating into practice.

GDPR and the UK GDPR

in place

European Union and the United Kingdom

What it requires
Lawful basis, records of processing, data subject rights, transfer safeguards, and seventy two hour breach notification.
Our own position
We process a small, documented set of personal data, act as a processor on engagements, offer the standard contractual clauses with a transfer assessment, and can meet the notification window.
What we do for clients
Program build, records of processing, impact assessments, and transfer work.

NIS2

in place

European Union essential and important entities, and their suppliers

What it requires
Risk management measures, supply chain security, incident reporting inside twenty four and seventy two hour stages, and management accountability.
Our own position
We are not an in scope entity, and we answer supplier security requirements from in scope clients directly from our control register.
What we do for clients
Scoping, measure implementation, reporting playbooks, and board briefing.

DORA

in place

European financial entities and their information technology providers

What it requires
Resilience testing, register of information, incident classification, and contractual terms for providers.
Our own position
Where we serve a financial entity we accept the required contractual terms and appear in the client register of information.
What we do for clients
Resilience program, register support, and third party contract remediation.

The EU AI Act

in place

European Union, phased obligations

What it requires
Transparency, risk classification, and human oversight where a system is higher risk.
Our own position
Our own automated jobs are inventoried with their purpose, their limits, and the decisions a person keeps. No automated job makes a decision about a person.
What we do for clients
System inventory, classification, and governance design.

POPIA and the NDPR, with the African Union Malabo Convention as context

in place

South Africa, Nigeria, and the wider continent

What it requires
Lawful processing, an information officer or equivalent, and regulator notification.
Our own position
Treated on the same basis as other privacy regimes we are subject to.
What we do for clients
Program build and regulator engagement support.

Regional data localization and sector rules across the Gulf and the Levant

in place

Saudi Arabia, the United Arab Emirates, and neighbouring markets

What it requires
National cyber security controls, hosting location rules, and sector regulator approval.
Our own position
We deliver remotely and never require client data to leave the client tenancy, which avoids most localization conflict outright.
What we do for clients
Control mapping to national frameworks and localization assessment.

Asia Pacific

Fast moving privacy law and strong sector supervision, especially in financial services.

Australian Privacy Act, the notifiable data breaches scheme, and the Essential Eight

in place

Australia

What it requires
Notification of eligible breaches and recognized hardening expectations.
Our own position
Notification route documented. Hardening measured against the same maturity model.
What we do for clients
Maturity uplift and notification readiness.

Singapore PDPA and the Monetary Authority technology risk guidelines

in place

Singapore

What it requires
Consent, protection obligations, and third party risk expectations.
Our own position
Met through the same processor terms and control register.
What we do for clients
Technology risk management and outsourcing assessment.

Japan APPI, Korea PIPA, and India DPDP

in place

Japan, South Korea, and India

What it requires
Consent, cross border transfer conditions, and breach reporting.
Our own position
Transfer positions are documented per engagement before any data is touched.
What we do for clients
Transfer assessment and local program alignment.

China PIPL, the Data Security Law, and the Cybersecurity Law

in place

Mainland China

What it requires
Localization for some data, a security assessment for export, and local representation.
Our own position
We do not export personal data out of mainland China, and any engagement touching it is scoped so that analysis stays inside the client environment.
What we do for clients
Scoping and export assessment support with local counsel in the lead.

Latin America

Privacy law modeled closely on the European approach, with active regulators.

LGPD

in place

Brazil

What it requires
Lawful basis, a data protection officer contact, and incident reporting.
Our own position
Handled under the same privacy program and contact route.
What we do for clients
Program build and reporting readiness.

Mexican federal privacy law and other national regimes

in place

Mexico, Chile, Colombia, Argentina, and neighbors

What it requires
Notice, rights handling, and security measures proportionate to the data.
Our own position
Same processor terms and notification route.
What we do for clients
Notice and rights handling design, plus security measure implementation.

Cross border and framework wide

What we hold for ourselves, everywhere, regardless of where a client sits.

ISO 27001 and ISO 27701

being strengthened

International

What it requires
A management system, a risk process, and audited controls.
Our own position
Our management system artifacts are being built to the clause structure on a written timeline. We hold no certificate and we say so on every buyer page.
What we do for clients
Management system build and certification readiness.

SOC 2

being strengthened

Buyer assurance, chiefly North America

What it requires
Controls operating over a period, examined by a licensed firm.
Our own position
Readiness program underway with a month by month plan. We hold no report and offer a signed management attestation in its place.
What we do for clients
Readiness, control implementation, and audit preparation.

NIST Cybersecurity Framework and NIST 800-53

in place

International, used as our translation layer

What it requires
A common control language across regimes.
Our own position
One control set is mapped outward to every framework we report against.
What we do for clients
Cross framework mapping so a client implements once and reports many times.

Export control, sanctions screening, and anti bribery law

in place

International, including the Foreign Corrupt Practices Act and the UK Bribery Act

What it requires
Screening of counterparties, refusal of restricted engagements, and no facilitation payments.
Our own position
Counterparty screening happens before engagement acceptance, and the refusal rule is absolute.
What we do for clients
Not applicable. This governs who we will work with.

Accessibility law, including the European Accessibility Act, Section 508, and WCAG

in place

International

What it requires
Digital services usable by people with disabilities.
Our own position
Public pages are built to the recognized guidance, a statement is published, and reduced motion and right to left reading are supported.
What we do for clients
Reviewing client facing security tooling for accessibility barriers.

Ask us about your own jurisdictions

Tell us where you operate and which regulators supervise you, and we will map the overlap so you implement one control set and report against all of them.

Reviewed by a Dephiant advisor on