All data is fictional

Legal & Regulatory Register

ISO 27001:2022 Clause 4.2 — Applicable laws, regulations & contractual obligations

14

Total Obligations

10

Compliant

3

Partially Compliant

1

Under Review
All Legal & Regulatory Obligations
Regulation / LawJurisdictionTypeHow It Applies to AcmeCorpContactNext ReviewStatus
UK GDPR & Data Protection Act 2018UKLegislationProcessing personal data of UK data subjects; controller obligationsSarah Lin (DPO)1 Feb 2027Compliant
EU General Data Protection RegulationEULegislationProcessing personal data of EU data subjects via Dublin entitySarah Lin (DPO)1 Feb 2027Compliant
NIS 2 Directive (EU 2022/2555)EUDirectiveEssential entity; 24h cyber incident reporting obligation from Oct 2024Jane Cooper (CISO)31 Mar 2026Partial
ISO 27001:2022GlobalStandardVoluntary standard maintained for customer assuranceMike Patel (GRC)Jan 2027Compliant
SOC 2 Type II (AICPA)USFrameworkCustomer contractual requirement for SaaS platformMike Patel (GRC)Sep 2026Partial
BSI C5 (Cloud Computing)DEStandardGerman enterprise customer procurement requirementMike Patel (GRC)Jun 2026Partial
UK Computer Misuse Act 1990UKLegislationUnauthorised access provisions; employee awareness trainingSarah Lin (DPO)Jan 2027Compliant
Payment Card Industry DSS v4.0GlobalStandardPayment processing via Stripe; applicable cardholder data controlsCFOMar 2026Compliant
ePrivacy Directive (Cookie Law)EUDirectiveCookie consent on salvinta.com and customer portalsSarah Lin (DPO)Jan 2027Compliant
Network & Information Security (NIS) UKUKLegislationOperational technology security obligationsJane Cooper (CISO)Jun 2026Under Review
Cyber Essentials (NCSC)UKCertificationPublic sector client supply chain requirementThomas RichardsNov 2026Compliant
UK Modern Slavery Act 2015UKLegislationAnnual disclosure statement (revenue >£36m threshold approaching)HR DirectorJan 2027Compliant