MSFT SSPA helps Microsoft suppliers demonstrate that they follow required privacy, security, and data protection practices when handling Microsoft data.
ISO 27018 establishes privacy controls for cloud service providers that process personal data, helping organizations protect information and meet privacy obligations.
PIPEDA requires organizations in Canada to handle personal data responsibly through clear consent, limited collection, safeguards, and individual privacy rights.
DPDP governs the processing of digital personal data in India and requires organizations to manage consent, protect data, and respect individual rights.
ISO 27701 adds privacy-specific requirements to ISO 27001, helping organizations build a privacy information management system for handling personal data.
CCPA gives California residents rights over their personal information and requires businesses to manage data collection, sharing, and disclosure practices responsibly.