What each regime expects of a customer agreement
Ten regimes, all ticked on the register by default, and the EU AI Act named on EU rows and quoted only where the agreement supplies an AI system. Each page says which customers the regime reaches, what it expects term by term, and quotes the clauses.
The GDPR (Regulation (EU) 2016/679) 6 clausesThe UK GDPR 2 clausesDORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554) 3 clausesThe NIS2 Directive (Directive (EU) 2022/2555) 5 clausesThe HIPAA Security Rule (45 CFR Part 164, Subpart C) 7 clausesThe CCPA as amended by the CPRA, with its regulations 3 clausesAPRA CPS 230 Operational Risk Management 6 clausesAPRA CPS 234 Information Security 4 clausesISO/IEC 27001:2022, your own certification 8 clausesISO/IEC 27701:2025, your own certification as a processor 9 clauses
Named references the register links and never quotes, by country: the EU AI Act (Art. 25 and 26 are quoted only on an agreement that supplies an AI system); the UK operational resilience rules for financial firms; the US state breach notification laws; the Australian Privacy Act and its notifiable data breaches scheme; the Swiss Federal Act on Data Protection; the Canadian federal private-sector privacy law (PIPEDA), and the rest on each country's page.