Skip to main content
Trust & compliance

Regional Privacy Compliance

Regional privacy frameworks (GDPR, DPDP Act 2023, CCPA and more) framed as alignment applicable per engagement — editable placeholders, never held certifications.

Privacy obligations follow the market an engagement serves. Cognegica aligns data collection, processing and storage to the framework that applies — European, Indian or otherwise — and confirms the scope and status per project. The table below lists frameworks we align to as editable placeholders; none is presented as a held certification, and each is confirmed for the specific engagement.

How to read this page

Which privacy frameworks apply to a project?

There is no single global privacy regime. The framework that governs a dataset depends on where contributors are, where data is processed and stored, and the market the model serves. Rather than claim blanket compliance, we map the applicable frameworks per engagement and align our controls to them.

These are editable placeholders, confirmed per engagement. The status column states alignment applicable to an engagement — not a held or audited certification. The team confirms the applicable framework, scope and status for each project, and the table is editable in the CMS as obligations evolve.

Regional frameworks

Privacy frameworks — alignment per engagement

Each row states the framework, where it applies, and an editable status placeholder. Status reflects alignment applicable per engagement, not a held certification — confirmed per project and editable in the CMS.

FrameworkApplies toStatus (editable placeholder)
GDPREuropean-market engagements (EU/EEA contributors or data subjects)Aligned — applicable per engagement
DPDP Act, 2023Indian operations and India-resident dataAligned — applicable to Indian operations
CCPA / CPRACalifornia-market engagementsConfigurable per engagement
HIPAA-adjacent handlingHealth-data engagements (de-identification & access controls)Configurable per engagement
Other regional frameworksMarkets outside the above, as scopedConfigurable per engagement

Editable placeholders, not held certifications. Status reflects alignment applicable per engagement; the applicable framework, scope and status are confirmed per project and the table is editable in the CMS.

How alignment is delivered

Controls behind the frameworks

Alignment is delivered through the same provenance, residency and PII controls used across our programs.

  • Residency & sovereignty

    India-resident collection, processing and storage where required.

    Sovereign data
  • Consent & provenance

    Consent captured per contributor; provenance tracked per record.

    Provenance framework
  • PII minimisation

    Automated and manual removal of personal information before delivery.

    PII scrubbing

About regional compliance

Questions about privacy frameworks

Are these certifications you hold?

No. The frameworks are presented as alignment applicable per engagement, not held or audited certifications. We confirm the applicable framework, scope and status per project.

How do you handle European-market data?

We align to GDPR for European-market engagements and confirm the scope per project — covering consent basis, data-subject handling and processing records.

Can data stay in India under the DPDP Act?

Yes. We offer India-resident collection, processing and storage aligned with the DPDP Act, 2023. See Sovereign data.

What if my market isn't listed?

The table is editable in the CMS. We add and configure the applicable framework per engagement rather than claim blanket coverage.

Confirm the privacy framework for your engagement.

Tell us your markets and data types — we'll map the applicable frameworks and align our controls.