PrivMatrix is built on a simple principle: the privacy and AI rules you answer to differ by market, so your documents should too. This page sets out where our content comes from, the grades we use, how we keep packs current as the law moves, and - just as important - what this service is and is not.
Most compliance tools assume a single regime, usually the EU GDPR, then relabel it for everywhere else. We do the opposite. Each document is assembled from your own answers and tuned to the specific requirements of the markets you select - the things a regulator in that market actually checks. That means the UAE's three separate regimes are treated as three regimes, Saudi Arabia's transfer basis is built in, India's grievance-officer duty appears where it should, and the EU AI Act's risk tiers drive the AI pack. Nothing is invented on the fly: the generation engine is deterministic, so the same answers always produce the same, reviewable output.
Every control in your obligations matrix carries a grade for each market, so you can see at a glance what is mandatory versus advisable where you operate.
Our four core privacy markets are researched against, and cited to, primary-source law. The instruments below are the backbone of what your pack is built on.
| Market | Primary instruments |
|---|---|
| UAE | Federal Decree-Law No. 45 of 2021 (PDPL); DIFC Data Protection Law No. 5 of 2020; ADGM Data Protection Regulations 2021 |
| Saudi Arabia | Personal Data Protection Law (Royal Decree M/19 of 2021, amended by M/148 of 2023), its Implementing Regulations and the Data Transfer Regulations; SDAIA guidance |
| India | Digital Personal Data Protection Act 2023 and the DPDP Rules 2025; the IT Act and IT Rules for online and AI-adjacent duties |
| EU & UK | EU GDPR (Regulation 2016/679); UK GDPR and Data Protection Act 2018; the ePrivacy Directive; and for AI, the EU AI Act (Regulation 2024/1689) |
| Qatar | Law No. 13 of 2016 on Personal Data Privacy Protection (PDPPL) and the National Data Privacy Office guidance |
A further set of markets is covered from published statute and regulator guidance and is expanded over time. Each market page under Privacy laws and AI laws names the instruments it relies on.
The law moves. A document that was right last quarter can be wrong this one. Currency is part of the product, not an afterthought.
Every pack records the version of the compliance library it was built against, so you always know what it reflects.
When the ruleset for one of your markets advances, we flag your pack in your portal, and on ongoing monitoring we refresh it for you.
Market content carries a last-reviewed date so you can see how fresh it is, rather than trusting an undated template.
AI-governance law is new and moving fast, so the AI market grades are marked provisional (v0.1) and are reviewed against primary sources before you rely on them commercially.
Being clear about this protects you as much as us.
PrivMatrix is self-serve software that generates market-tuned documents and templates from your answers. It is a strong, specialist-informed starting point that saves you the cost and weeks of a bespoke engagement.
Where a market regulates who may hold themselves out as a data-protection consultant, we operate strictly as a software and template provider, not as an advisor to your organisation.
Take the free check and see the grades and gaps for the markets you actually sell in.
This page describes our current methodology and is provided for information. It does not vary the terms of any purchase, which govern if there is a conflict.
Cookie consent, data requests, the Trust Center and monitoring all read from the same compliance core - your markets, your documents and your obligations, defined once and shared across every module.