Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
Methodology & sources

How we build your pack, and how we keep it current

PrivMatrix is built on a simple principle: the privacy and AI rules you answer to differ by market, so your documents should too. This page sets out where our content comes from, the grades we use, how we keep packs current as the law moves, and - just as important - what this service is and is not.

deterministic generation · cited to primary-source law · version-stamped
Market-first

Market-first, not one template relabelled

Most compliance tools assume a single regime, usually the EU GDPR, then relabel it for everywhere else. We do the opposite. Each document is assembled from your own answers and tuned to the specific requirements of the markets you select - the things a regulator in that market actually checks. That means the UAE's three separate regimes are treated as three regimes, Saudi Arabia's transfer basis is built in, India's grievance-officer duty appears where it should, and the EU AI Act's risk tiers drive the AI pack. Nothing is invented on the fly: the generation engine is deterministic, so the same answers always produce the same, reviewable output.

Grades

The grades we use

Every control in your obligations matrix carries a grade for each market, so you can see at a glance what is mandatory versus advisable where you operate.

RRequiredBinding law or regulation mandates it, cited to the provision.
EExpectedNear-mandatory once a common trigger is met, or backed by binding guidance.
PPrudentAdvisable and risk-reducing, though not strictly mandated.
OOptionalGood practice you may choose to adopt.
n/aNot applicableThe control does not apply in that market.
Sources

The laws behind each core market

Our four core privacy markets are researched against, and cited to, primary-source law. The instruments below are the backbone of what your pack is built on.

MarketPrimary instruments
UAEFederal Decree-Law No. 45 of 2021 (PDPL); DIFC Data Protection Law No. 5 of 2020; ADGM Data Protection Regulations 2021
Saudi ArabiaPersonal Data Protection Law (Royal Decree M/19 of 2021, amended by M/148 of 2023), its Implementing Regulations and the Data Transfer Regulations; SDAIA guidance
IndiaDigital Personal Data Protection Act 2023 and the DPDP Rules 2025; the IT Act and IT Rules for online and AI-adjacent duties
EU & UKEU GDPR (Regulation 2016/679); UK GDPR and Data Protection Act 2018; the ePrivacy Directive; and for AI, the EU AI Act (Regulation 2024/1689)
QatarLaw No. 13 of 2016 on Personal Data Privacy Protection (PDPPL) and the National Data Privacy Office guidance

A further set of markets is covered from published statute and regulator guidance and is expanded over time. Each market page under Privacy laws and AI laws names the instruments it relies on.

Currency

How we keep it current

The law moves. A document that was right last quarter can be wrong this one. Currency is part of the product, not an afterthought.

Version-stamped packs

Every pack records the version of the compliance library it was built against, so you always know what it reflects.

Law-change monitoring

When the ruleset for one of your markets advances, we flag your pack in your portal, and on ongoing monitoring we refresh it for you.

Dated reviews

Market content carries a last-reviewed date so you can see how fresh it is, rather than trusting an undated template.

AI grades are provisional

AI-governance law is new and moving fast, so the AI market grades are marked provisional (v0.1) and are reviewed against primary sources before you rely on them commercially.

Scope

What this is, and what it is not

Being clear about this protects you as much as us.

PrivMatrix is self-serve software that generates market-tuned documents and templates from your answers. It is a strong, specialist-informed starting point that saves you the cost and weeks of a bespoke engagement.

It is not legal advice, it does not create a lawyer-client relationship, it is not an appointed Data Protection Officer, and it is not a guarantee of compliance. You remain responsible for reviewing the documents and for how you use them, and we recommend an independent legal review before you rely on them - every document says so.

Where a market regulates who may hold themselves out as a data-protection consultant, we operate strictly as a software and template provider, not as an advisor to your organisation.

Try it

See it applied to your markets

Take the free check and see the grades and gaps for the markets you actually sell in.

This page describes our current methodology and is provided for information. It does not vary the terms of any purchase, which govern if there is a conflict.

Part of one platform, not a pile of tools.

Cookie consent, data requests, the Trust Center and monitoring all read from the same compliance core - your markets, your documents and your obligations, defined once and shared across every module.