Regional Privacy Compliance
Regional privacy frameworks (GDPR, DPDP Act 2023, CCPA and more) framed as alignment applicable per engagement — editable placeholders, never held certifications.
Privacy obligations follow the market an engagement serves. Cognegica aligns data collection, processing and storage to the framework that applies — European, Indian or otherwise — and confirms the scope and status per project. The table below lists frameworks we align to as editable placeholders; none is presented as a held certification, and each is confirmed for the specific engagement.
How to read this page
Which privacy frameworks apply to a project?
There is no single global privacy regime. The framework that governs a dataset depends on where contributors are, where data is processed and stored, and the market the model serves. Rather than claim blanket compliance, we map the applicable frameworks per engagement and align our controls to them.
These are editable placeholders, confirmed per engagement. The status column states alignment applicable to an engagement — not a held or audited certification. The team confirms the applicable framework, scope and status for each project, and the table is editable in the CMS as obligations evolve.
Regional frameworks
Privacy frameworks — alignment per engagement
Each row states the framework, where it applies, and an editable status placeholder. Status reflects alignment applicable per engagement, not a held certification — confirmed per project and editable in the CMS.
| Framework | Applies to | Status (editable placeholder) |
|---|---|---|
| GDPR | European-market engagements (EU/EEA contributors or data subjects) | Aligned — applicable per engagement |
| DPDP Act, 2023 | Indian operations and India-resident data | Aligned — applicable to Indian operations |
| CCPA / CPRA | California-market engagements | Configurable per engagement |
| HIPAA-adjacent handling | Health-data engagements (de-identification & access controls) | Configurable per engagement |
| Other regional frameworks | Markets outside the above, as scoped | Configurable per engagement |
Editable placeholders, not held certifications. Status reflects alignment applicable per engagement; the applicable framework, scope and status are confirmed per project and the table is editable in the CMS.
How alignment is delivered
Controls behind the frameworks
Alignment is delivered through the same provenance, residency and PII controls used across our programs.
-
Residency & sovereignty
India-resident collection, processing and storage where required.
Sovereign data -
Consent & provenance
Consent captured per contributor; provenance tracked per record.
Provenance framework -
PII minimisation
Automated and manual removal of personal information before delivery.
PII scrubbing
About regional compliance
Questions about privacy frameworks
- Are these certifications you hold?
No. The frameworks are presented as alignment applicable per engagement, not held or audited certifications. We confirm the applicable framework, scope and status per project.
- How do you handle European-market data?
We align to GDPR for European-market engagements and confirm the scope per project — covering consent basis, data-subject handling and processing records.
- Can data stay in India under the DPDP Act?
Yes. We offer India-resident collection, processing and storage aligned with the DPDP Act, 2023. See Sovereign data.
- What if my market isn't listed?
The table is editable in the CMS. We add and configure the applicable framework per engagement rather than claim blanket coverage.
Confirm the privacy framework for your engagement.
Tell us your markets and data types — we'll map the applicable frameworks and align our controls.