Legal & Trust · framework register

Frameworks with their sources visible.

This register preserves framework names, jurisdictions, authorities, scope summaries, review context, and source links from the migrated legal data.

India · Law

Digital Personal Data Protection Act, 2023

India’s digital personal-data framework. Applicability, commencement, notices, rights, transfers, and obligations depend on the facts, notified provisions, and applicable rules.

Ministry of Electronics and Information Technology / Parliament of India

Review: Monitor · Aug 2026

India · Regulator Guidance

Digital Personal Data Protection Rules, 2025

Rules and implementation detail should be reviewed with the Act and the organization’s processing activities before relying on them.

Ministry of Electronics and Information Technology

Review: Monitor · Aug 2026

India · Regulator Guidance

CERT-In Directions and incident-response guidance

Cybersecurity incident handling, reporting, logging, and technical controls may apply according to the organization, system, incident, and current CERT-In directions.

Indian Computer Emergency Response Team

Review: Reference · Aug 2026

United Kingdom · Law

UK GDPR and Data Protection Act 2018

UK personal-data processing requires a scoped assessment of lawful basis, transparency, minimisation, rights, security, retention, processors, and international transfers.

Information Commissioner’s Office / UK Parliament

Review: Monitor · Aug 2026

United Kingdom · Law

Privacy and Electronic Communications Regulations (PECR)

Cookies, similar technologies, electronic marketing, and communications require a fact-specific review of notice, consent, exemptions, and record keeping.

Information Commissioner’s Office

Review: Monitor · Aug 2026

United States · Regulator Guidance

FTC privacy and data-security principles

Businesses should substantiate privacy and security representations and maintain safeguards appropriate to the nature of the data they hold. US requirements also vary by sector, state, and activity.

Federal Trade Commission

Review: Reference · Aug 2026

United States — California · Law

California Consumer Privacy Act / California Privacy Rights Act

California privacy rights and business obligations depend on thresholds, data categories, purposes, consumer status, and the organization’s role.

California Privacy Protection Agency

Review: Monitor · Aug 2026

United States / Global · Standards Framework

AI Risk Management Framework

NIST AI RMF is voluntary guidance for managing AI risks and incorporating trustworthiness into AI design, development, use, and evaluation. It is not a legal certification.

National Institute of Standards and Technology

Review: Reference · Aug 2026

Global · Principles

UN Global Compact Ten Principles

Principles-based guidance covering human rights, labour, environment, and anti-corruption. It is not a CloudAlls legal certification or a substitute for local law.

United Nations Global Compact

Review: Reference · Aug 2026

Global · Principles

Guiding Principles on Business and Human Rights

The Protect, Respect and Remedy framework is a global reference for preventing and addressing adverse human-rights impacts involving business activity.

United Nations Office of the High Commissioner for Human Rights

Review: Reference · Aug 2026

Global · Principles

Recommendation on the Ethics of Artificial Intelligence

A global normative reference for human dignity, human rights, fairness, transparency, environmental responsibility, and accountable AI governance.

UNESCO

Review: Reference · Aug 2026

Legal & Trust

Interpret references with the surrounding policy context.

External framework references are source material, not a claim of certification or legal advice.