Compare jurisdictions
Side-by-side view of the obligations each covered law imposes, grouped by category. Use this to spot where requirements overlap (one well-written control often satisfies multiple jurisdictions).
| Category |
πͺπΊEuropean Union / EEA
|
π¬πGhana
|
π°πͺKenya
|
π³π¬Nigeria
|
πΊπΈUnited States (California)
|
|---|---|---|---|---|---|
| Governance & Accountability |
|
|
|
|
β |
| Lawful basis & consent |
|
|
|
|
β |
| Transparency & notices |
|
|
|
|
|
| Data subject rights |
|
|
|
|
|
| Security of processing |
|
|
β |
|
|
| Breach notification |
|
β |
|
|
β |
| International transfers |
|
|
|
|
β |
| DPIA / Risk assessment |
|
β |
|
β | β |
| Processors & sub-processors | β | β | β | β |
|
| Record of processing |
|
β | β |
|
β |
| Special categories / children | β | β | β | β |
|
| Regulator registration | β |
|
|
β | β |
Each obligation links to the official law text or the regulator that imposes it, with the precise article/section shown beside it. Sourced from the same content engine that powers the assessment. Cells marked "β" mean the law in that column has no specific requirement in that category β not that anything is exempt. Each framework's last-reviewed date, source version and change history are on the methodology page.