Skip to content

Compliance reference

Every rule that might bind you.

Ten frameworks, split by what actually pulls you into scope. Seven apply by law because of the data you hold. Two are adopted because a buyer asked. One sits on top of another. Knowing which is which is most of the work.

7
Apply by law, whether or not anyone asks
3
Adopted to unblock enterprise deals
1 programme
Can satisfy most of them at once

Start here

What pulls you into scope.

Each row is one factual condition about your data or your users. If it's true for you, that framework applies, regardless of your size, your revenue or where your company is registered.

Conditions that bring a company into scope for each compliance framework
If this is true of youThen this applies
You have any users, customers or staff in the EU or UK.GDPR
You touch protected health information for a US covered entity.HIPAA
Your service is directed at under-13s, or you know they use it.COPPA
You do business with California residents above the revenue or data thresholds.CCPA / CPRA
You store, process or transmit cardholder data, including via an embedded payment form.PCI DSS
You are ISO 27001 certified and want a certifiable privacy posture too.ISO 27701
You handle student education records for US schools or districts.FERPA
You are an EU cloud, managed service or other in-scope essential entity.NIS2
A customer, investor or procurement gate asks for it, most often outside the US.ISO 27001
A US enterprise buyer asks for a report, usually Type II, during procurement.SOC 2

This table is a starting point, not a legal determination. Thresholds and definitions vary, and some frameworks turn on details, how a payment form embeds, whether you have actual knowledge of under-13 users. That need looking at properly.

Data protection & privacy

Personal data, wherever it comes from.

GDPR

EU & UKBy law

General Data Protection Regulation

Who it binds
Any company processing personal data of people in the EU or UK, regardless of where your company is based.
What teams get wrong
Most teams write a privacy policy and stop. The regulation asks for a Record of Processing Activities, a lawful basis per purpose, a DPIA for high-risk processing, and a documented process for answering a data subject request in 30 days.
What we do
  • Data mapping and Record of Processing Activities (Article 30)
  • Lawful basis assessment and consent mechanics
  • DPIAs for high-risk processing
  • Data subject request workflow, tested end to end
  • International transfer assessments and Standard Contractual Clauses
  • Processor agreements and sub-processor register
  • 72-hour breach notification runbook

CCPA / CPRA

California, USBy law

California Consumer Privacy Act, as amended

Who it binds
Companies over defined revenue or data-volume thresholds doing business with California residents.
What teams get wrong
"Sale" and "share" are defined far more broadly than money changing hands. Running third-party advertising or analytics pixels usually triggers opt-out obligations you may not realise you have.
What we do
  • Threshold assessment, whether you're actually in scope
  • Consumer rights workflows: know, delete, correct, opt out
  • "Do Not Sell or Share My Personal Information" implementation
  • Global Privacy Control signal handling
  • Service provider contract terms and vendor review
  • Annual privacy policy disclosures

NIS2

European UnionBy law

Network and Information Security Directive 2

Who it binds
Essential and important entities in the EU, including many cloud and managed service providers, with personal liability for management bodies.
What teams get wrong
Cloud computing and managed service providers are named in scope. Incident reporting runs on a 24-hour early-warning clock, which is far shorter than most teams have planned for.
What we do
  • Scope and entity classification assessment
  • Risk management measures under Article 21
  • 24-hour / 72-hour / one-month incident reporting runbook
  • Supply chain security requirements
  • Management body accountability and training
  • Mapping onto an existing ISO 27001 ISMS to avoid duplicate work

Sector-specific

Rules attached to who your users are.

HIPAA

United StatesBy law

Health Insurance Portability and Accountability Act

Who it binds
SaaS handling protected health information for US covered entities, which makes you a Business Associate with direct liability.
What teams get wrong
Signing a BAA does not make you compliant; it makes you liable. The Security Rule requires a documented risk analysis, and that analysis is the first thing requested after any incident.
What we do
  • Security Rule administrative, physical and technical safeguards
  • Documented risk analysis and risk management plan (§164.308)
  • Business Associate Agreement review and sub-processor flow-down
  • Audit controls, encryption and access management for PHI
  • Breach notification procedures and the 60-day clock
  • Workforce training with retained records

COPPA

United StatesBy law

Children's Online Privacy Protection Act

Who it binds
Any service directed at children under 13, or that knowingly collects data from them. Edtech, gaming and social products most often.
What teams get wrong
"We don't target kids" is not a defence if you have actual knowledge they use it. Verifiable parental consent is a specific legal standard, and a checkbox saying "I am over 13" does not meet it.
What we do
  • Age-gating design and actual-knowledge assessment
  • Verifiable parental consent mechanism selection
  • Data minimisation review, collect only what the activity needs
  • Third-party SDK and advertising audit for child-directed traffic
  • Parental access, review and deletion workflows
  • Direct-notice and privacy policy drafting support

FERPA

United StatesBy law

Family Educational Rights and Privacy Act

Who it binds
Edtech vendors handling student education records on behalf of US schools and districts.
What teams get wrong
You'll usually operate under the 'school official' exception, which carries hard constraints: direct institutional control, a legitimate educational interest, and no secondary use of the data. Ever.
What we do
  • School official exception analysis and contract terms
  • Student data inventory and retention schedule
  • Directory information handling and parental rights
  • State student-privacy law overlay (SOPIPA and equivalents)
  • Vendor and sub-processor review

Payments

Anything touching card data.

PCI DSS

GlobalBy law

Payment Card Industry Data Security Standard

Who it binds
Anyone who stores, processes or transmits cardholder data, including via a hosted payment page you embed.
What teams get wrong
Using Stripe or Adyen reduces your scope; it does not remove it. Which Self-Assessment Questionnaire applies depends on exactly how the payment form touches your page, and getting that wrong invalidates the whole assessment.
What we do
  • Scope definition and correct SAQ type selection
  • Cardholder data flow mapping
  • Network segmentation review to keep scope small
  • Control implementation against the applicable requirements
  • Evidence pack and SAQ completion support
  • Coordination with your acquirer or QSA

Security certification

Chosen, not imposed.

ISO 27701

GlobalBy choice

Privacy Information Management System

Who it binds
Companies already certified to ISO 27001 that want a certifiable privacy posture on top of it.
What teams get wrong
It is an extension, not a standalone standard. You cannot certify to it without ISO 27001. Done alongside a 27001 programme it costs a fraction of doing it later.
What we do
  • PIMS scope extension over your existing ISMS
  • Controller and processor control mapping (Annexes A and B)
  • GDPR Article mapping for demonstrable accountability
  • Privacy risk assessment integrated with your risk register
  • Internal audit and certification support

ISO 27001

GlobalBy choice

Information Security Management System

Who it binds
Nobody by law. You adopt it because buyers ask, and because it is the most widely recognised security certification outside North America.
What teams get wrong
It certifies a management system, not a product. Auditors assess whether you can identify and treat risk over time, which is why a tool full of green checkmarks does not get you through Stage 2.
What we do
  • Gap analysis against all 93 Annex A controls and Clauses 4–10
  • ISMS scope and Statement of Applicability
  • Risk methodology, register and treatment plan
  • Internal audit and management review
  • Stage 1 and Stage 2 audit support

SOC 2

United StatesBy choice

Service Organization Control 2

Who it binds
Nobody by law. It is an attestation US buyers ask for, issued by a licensed CPA firm rather than a certification body.
What teams get wrong
Type I says your controls are designed well on one day. Type II says they actually operated over months. Teams write impressive controls, never run them, and get a qualified opinion at the end of the observation window.
What we do
  • Trust Services Criteria scoping
  • Control design with owners, frequencies and evidence sources
  • Readiness assessment before the CPA firm looks
  • Evidence pipeline for the observation window
  • Auditor selection and coordination

Questions

About scope.

Or take the free readiness assessment . It maps your gaps to named controls in about four minutes.

Work through the trigger table above, each row is a single factual condition about your data or your users. If a row is true for you, that framework binds you. If you're unsure about a threshold, that is exactly what a scoping call is for, and the honest answer is often that fewer apply than a vendor questionnaire implies.

GDPR, HIPAA, COPPA, CCPA, PCI DSS, FERPA and NIS2 apply because of the data you hold and the people you hold it about. They applied from the day you started, whether or not anyone raised it. ISO 27001 and SOC 2 apply because a buyer asked, no regulator will ever fine you for not having them.

Largely, yes. Access control, vendor review, incident response, retention, logging and encryption serve nearly all of them. The efficient path is one control set with a crosswalk showing which obligation each control satisfies, rather than separate projects that rebuild the same evidence.

No. We are security and compliance consultants, not a law firm. We build the technical and organisational measures, evidence and processes these frameworks require, and we work alongside your counsel on legal interpretation. Nothing on this page is legal advice.

Some of it does regardless of revenue, GDPR and COPPA have no revenue threshold, so if you have EU users or under-13 users you are in scope from your first signup. CCPA does have thresholds. ISO 27001 and SOC 2 are almost always premature pre-revenue, and we will say so.

Find out which of these actually bind you.

Bring your product, your users and your markets. We'll tell you what applies, what doesn't, and what it takes, including when the answer is that you're not in scope at all.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.