Methodology
How this check works
Transparency is the point of a compliance tool, so here is exactly how we decide which obligations apply to you, how the readiness score is calculated, where the content comes from, and what the result can and cannot tell you.
5
Jurisdictions
5
Frameworks
40
Obligations
14
Categories
1. Overview
Every obligation we track is an atomic duty drawn from a named law, tagged with the article or section it comes from and the category it belongs to (governance, lawful basis, transparency, data-subject rights, security, breach, transfers, and so on). When you run a check, two things happen: an applicability engine decides which laws and which obligations apply to your organisation, and a severity-weighted score measures how much of what applies you already have in place. Both are described below, and you can inspect the underlying obligations and their citations in the comparison view.
2. What we cover
These are the frameworks currently modelled. Each links to its official source so you can verify any obligation yourself.
| Jurisdiction | Framework | Enacted | Obligations | Maximum exposure |
|---|---|---|---|---|
| πͺπΊEuropean Union / EEA | GDPR General Data Protection Regulation (Regulation (EU) 2016/679) | 2016 | 10 | Up to β¬20m or 4% of annual global turnover, whichever is higher. |
| π¬πGhana | Ghana DPA 2012 Data Protection Act, 2012 (Act 843) | 2012 | 7 | Up to GHS 90,000 or 10 years imprisonment (varies per offence); administrative sanctions. |
| π°πͺKenya | Kenya DPA 2019 The Data Protection Act, 2019 (No. 24 of 2019) | 2019 | 8 | Up to KES 5 million or 1% of annual turnover, whichever is lower. |
| π³π¬Nigeria | Nigeria NDPA 2023 Nigeria Data Protection Act, 2023 | 2023 | 9 | Up to β¦10m or 2% of annual gross revenue for data controllers of major importance. |
| πΊπΈUnited States (California) | CCPA/CPRA California Consumer Privacy Act, as amended by the CPRA | 2018 | 6 | Up to $7,500 per intentional violation; $2,500 per unintentional violation; statutory damages for breaches. |
3. How we decide what applies to you
Applicability is resolved in two layers from the answers you give on the start form β we never assume a law applies just because it is in the list.
Which laws apply (framework level)
- GDPR applies if you process data of people in the EU/EEA, or your organisation is established there.
- Ghana, Kenya and Nigeria Acts each apply if you process data of that country's residents, or you are established in that country.
- CCPA/CPRA applies if you target California residents and cross a statutory threshold β roughly US$25m revenue or 100,000+ consumers. Below the threshold we tell you the duties may still reach you through your contracts.
Which obligations apply (requirement level)
Most obligations apply to everyone a framework covers. Some are switched on only by what you do:
- A DPIA becomes mandatory when you flag high-risk processing β automated decision-making, health, biometric, or children's data.
- A DPO / privacy lead is required for large-scale special-category processing or once you reach ~10,000 data subjects (and stays best practice below that).
- An international-transfer mechanism is required when you indicate cross-border transfers.
- Children's safeguards switch on when you process children's data; the Do-Not-Sell/Share link switches on for California consumers.
Each applicable obligation in your result carries a one-line rationale explaining why it was included, so nothing is a black box.
4. How the readiness score works
For every obligation that applies, you answer Yes (in place), Partial (in progress) or No (not in place). Those map to completion of 100%, 50% and 0%. Anything you leave unanswered counts as No, so the score never flatters you.
Each obligation is weighted by its severity (1β5), and the score is the share of weighted obligations you have met β calculated per jurisdiction, and overall:
score = 100 Γ Ξ£(weight Γ completion) Γ· Ξ£(weight)
Worked example
Say three obligations apply, with severities 5, 3 and 2. You mark them Yes, Partial and No:
5 + 3 + 2 = 10 possible
100 Γ 6.5 Γ· 10 = 65
Weighting means a single critical gap moves the needle more than several minor ones β which is how a regulator would see it too.
5. Severity weighting
Every obligation is assigned a weight from 1 to 5 reflecting its enforcement exposure and how foundational it is. The current distribution across all 40 obligations:
| Weight | What it means | Obligations |
|---|---|---|
| 5 / 5 | Critical β foundational duties; failure typically draws the heaviest penalties | 26 |
| 4 / 5 | High β core obligations regulators expect to see in place | 13 |
| 3 / 5 | Standard β important duties with lower direct exposure | 1 |
| 2 / 5 | Moderate β supporting controls | 0 |
| 1 / 5 | Baseline β good-practice steps | 0 |
6. Keeping it current
Every obligation cites the article or section it is drawn from and links to the official source, so the content is auditable rather than asserted. For each framework we publish when it was last reviewed against that source, the exact edition we checked, and our confidence that the modelled obligations still match the law.
| Framework | Last reviewed | Source version | Confidence |
|---|---|---|---|
| GDPR | 1 Jun 2026 | Consolidated text, OJ L 119, 4.5.2016 | High |
| Ghana DPA 2012 | 1 Jun 2026 | Data Protection Act, 2012 (Act 843) | High |
| Kenya DPA 2019 | 1 Jun 2026 | Act No. 24 of 2019 | High |
| Nigeria NDPA 2023 | 1 Jun 2026 | Nigeria Data Protection Act, 2023 | Medium |
| CCPA/CPRA | 1 Jun 2026 | Cal. Civ. Code Β§1798.100 et seq., as amended by the CPRA | Medium |
Change history
- 2026-06-01 GDPR β Reviewed against the consolidated Regulation; modelled obligations unchanged.
- 2025-05-01 GDPR β Initial modelling of core obligations (Arts. 5, 6, 12β14, 15β22, 30, 32, 33β34, 35, 37β39, 44β50).
- 2026-06-01 Ghana DPA 2012 β Reviewed against Act 843; obligations current.
- 2025-05-01 Ghana DPA 2012 β Initial modelling of registration, principles, consent, notice, security, rights and transfer duties.
- 2026-06-01 Kenya DPA 2019 β Reviewed against the 2019 Act and ODPC guidance; obligations current.
- 2025-05-01 Kenya DPA 2019 β Initial modelling of registration, principles, consent, notice, rights, breach, DPIA and transfer duties.
- 2026-06-01 Nigeria NDPA 2023 β Reviewed against the 2023 Act; held at Medium confidence while NDPC subsidiary regulations continue to develop.
- 2025-05-01 Nigeria NDPA 2023 β Initial modelling of principles, lawful basis, notice, rights, security, breach, DPO, ROPA and transfer duties.
- 2026-06-01 CCPA/CPRA β Reviewed against the CPRA-amended statute; held at Medium confidence while CPPA rulemaking is ongoing.
- 2025-05-01 CCPA/CPRA β Initial modelling of notice, consumer rights, opt-out-of-sale/share, contracts, sensitive-data and security duties.
Reviews are carried out by our content team against the official sources and recorded above. Because data-protection law moves quickly, you can subscribe to law-update notices for any jurisdiction and we will email you when something material changes.
7. What this does not do
- It is not legal advice. The result is informational. Have qualified counsel review anything you rely on for a regulatory decision.
- It is a self-assessment, not an audit or certification. The score reflects only what you report about yourself; nothing is independently verified.
- The legal content is a best-effort paraphrase of public sources, condensed for clarity. The authoritative text is whatever the official source link says.
- Coverage is limited to the frameworks listed above. Sector-specific rules and laws in other countries or US states are not assessed.
- Applicability uses high-level triggers. Genuine edge cases can differ β treat the output as a well-reasoned starting point, not a final determination.
Questions about the method? Email support@spatialsusty.com.