Track, analyze, and manage your organization's compliance posture across all regulatory frameworks from a single dashboard.
Fully Compliant
Partially Compliant
Non-Compliant
Overall Compliance
| Regulation / Framework | Category | Region | Status | Compliance Score | Last Audit | Next Review | |
|---|---|---|---|---|---|---|---|
GDPRGeneral Data Protection Regulation |
Data Privacy | European Union | Compliant |
94%
|
2025-01-15 | 2025-07-15 | |
π Key RequirementsData Subject Rightsβ Met
Lawful Basis Processingβ Met
DPO Appointedβ Met
Data Breach Notificationβ Met
Privacy by Designβ Partial
DPIA Completedβ Met
π Compliance DetailsTotal Requirements54
Fully Met51
Partially Met3
Not Met0
Responsible TeamLegal & IT
Assigned OfficerMaria Santos
β οΈ Identified Gapsβ’ Privacy by Design β documentation incomplete for 2 systems
β’ Cookie consent banner β updated (resolved 2025-01-10)
β’ Data retention schedule β finalized (resolved 2024-12-20)
|
|||||||
HIPAAHealth Insurance Portability & Accountability Act |
Healthcare | United States | Compliant |
91%
|
2025-02-01 | 2025-08-01 | |
π Key RequirementsPrivacy Ruleβ Met
Security Ruleβ Met
Breach Notificationβ Met
BAAs in Placeβ Met
Risk Assessmentβ Met
π Compliance DetailsTotal Requirements42
Fully Met38
Partially Met4
Not Met0
Assigned OfficerDr. Alan Park
β οΈ Identified Gapsβ’ Workforce training β 3 employees pending recertification
β’ Incident response plan β updated (resolved 2025-01-28)
|
|||||||
SOXSarbanes-Oxley Act |
Financial | United States | Compliant |
88%
|
2025-01-20 | 2025-07-20 | |
π Key RequirementsSection 302 β Certificationsβ Met
Section 404 β Internal Controlsβ Met
Section 409 β Disclosuresβ Met
Section 802 β Record Retentionβ Met
π Compliance DetailsTotal Requirements36
Fully Met32
Partially Met4
Responsible TeamFinance & Audit
β οΈ Identified Gapsβ’ Access controls β review pending for 2 legacy systems
β’ Change management log β updated (resolved 2025-01-22)
|
|||||||
CCPA / CPRACalifornia Consumer Privacy Act |
Data Privacy | United States (CA) | Partial |
72%
|
2025-02-10 | 2025-05-10 | |
π Key RequirementsRight to Knowβ Met
Right to Deleteβ Met
Right to Opt-Outβ Partial
Service Agreement Updatesβ Not Met
Privacy Notice Updatesβ Met
π Compliance DetailsTotal Requirements48
Fully Met30
Partially Met12
Not Met6
Assigned OfficerJames Carter
β οΈ Identified Gapsβ’ Opt-out mechanism β needs global coverage implementation
β’ Service agreements β 4 vendor contracts need CPRA addenda
β’ Privacy notice β updated for CPRA (resolved 2025-01-15)
|
|||||||
ISO 27001Information Security Management System |
Info Security | Global | Compliant |
96%
|
2025-01-08 | 2025-07-08 | |
π Key RequirementsRisk Assessment Processβ Met
Access Control Policyβ Met
Incident Managementβ Met
Business Continuityβ Met
Supplier Securityβ Met
π Compliance DetailsTotal Controls93
Implemented89
Partially4
Certification Valid Until2026-03-15
β οΈ Identified Gapsβ’ Cryptographic key management β review needed
β’ Physical security β updated after office move (resolved 2024-12-10)
|
|||||||
PCI DSSPayment Card Industry Data Security Standard |
Info Security | Global | In Progress |
65%
|
2025-02-20 | 2025-06-20 | |
π Key RequirementsNetwork Securityβ Met
Data Protectionβ Partial
Vulnerability Mgmtβ Met
Access Controlβ Partial
Monitoring & Testingβ Met
π Compliance DetailsTotal Requirements12
Fully Met7
In Progress5
Target Completion2025-06-20
β οΈ Identified Gapsβ’ Cardholder data encryption β key rotation needed
β’ Access control β least privilege review pending
β’ Network segmentation β implemented (resolved 2025-02-01)
|
|||||||
OCC / EEOCEmployment & Anti-Discrimination Guidelines |
Employment | United States | Non-Compliant |
45%
|
2025-02-05 | 2025-04-05 | |
π Key RequirementsAnti-Discrimination Policyβ Not Met
Harassment Preventionβ Not Met
Reasonable Accommodationβ Met
Pay Equity Analysisβ Partial
Complaint Proceduresβ Not Met
π Compliance DetailsTotal Requirements30
Fully Met10
Partially Met4
Not Met16
Urgencyπ΄ Critical
β οΈ Identified Gapsβ’ Anti-discrimination policy β not yet drafted
β’ Harassment prevention β training program missing
β’ Complaint procedures β formal process needed
β’ Pay equity β annual analysis overdue
|
|||||||
UK ICO / UK-GDPRUK Information Commissioner's Office Guidelines |
Data Privacy | United Kingdom | Compliant |
87%
|
2025-01-25 | 2025-07-25 | |
π Key RequirementsUK-GDPR Registrationβ Met
Data Protection Policyβ Met
ICO Fee Paymentβ Met
7 Principles Alignmentβ Met
π Compliance DetailsTotal Requirements46
Fully Met40
Partially Met6
Assigned OfficerEmily Watson
β οΈ Identified Gapsβ’ International transfers β adequacy decision review needed
β’ ICO registration β renewed (resolved 2025-01-20)
|
|||||||
See how different frameworks overlap and share common requirements.
European Union β Data Protection
United States β Healthcare Privacy
United States β Corporate Finance
See which of your policies satisfy requirements across multiple frameworks.
| Policy Name | Frameworks | Status |
|---|---|---|
| Data Retention Policy | GDPR, CCPA, UK-GDPR | β Active |
| Privacy Notice | GDPR, CCPA, UK-GDPR, HIPAA | β Active |
| Data Breach Response Plan | GDPR, HIPAA, PCI DSS | β Active |
| Vendor Assessment Policy | GDPR, ISO 27001, PCI DSS | β Active |
| Consent Management | GDPR, CCPA, UK-GDPR | β Review |
| Policy Name | Frameworks | Status |
|---|---|---|
| Access Control Policy | SOX, ISO 27001, PCI DSS, HIPAA | β Active |
| Incident Response Plan | ISO 27001, PCI DSS, HIPAA, SOX | β Active |
| Business Continuity Plan | ISO 27001, SOX, PCI DSS | β Active |
| Encryption Standards | PCI DSS, HIPAA, ISO 27001 | β Review |
| Anti-Discrimination Policy | OCC / EEOC | β Missing |