Compliance, jurisdiction by jurisdiction.
A shared-responsibility matrix. We handle the platform controls, residency, contracts and audit primitives. You handle your lawful basis, notices and end-user obligations.
This matrix is app-owned editable content, not an independent legal opinion. Consult counsel for your specific use case. Roadmap items are labeled explicitly.
Regional privacy frameworks
| Jurisdiction | Framework | Our posture | Customer responsibility |
|---|---|---|---|
| EU | GDPR + EU-US DPF | Data-processor role. SCCs + DPF for US transfers. EU-Frankfurt / EU-Ireland residency available. | Determine lawful basis, honor DSRs, sign DPA at signup. |
| UK | UK GDPR + DPA 2018 | UK IDTA addendum available. UK-London residency (MVP). | Register with ICO if required; sign UK IDTA. |
| Switzerland | revFADP | Swiss addendum to SCCs. EU residency covers Swiss data-transfer requirements. | Appoint Swiss representative if outside CH/EU. |
| US · California | CCPA / CPRA | Service-provider role, do-not-sell/share honored, opt-out signals respected. | Provide privacy notice; honor consumer requests via our API. |
| US · Colorado | Colorado AI Act | High-risk AI model cards, bias-testing template surfaced in catalog. | Perform impact assessments for consequential decisions. |
| US · New York | NYC LL144 (AEDT) | Bias-audit hooks in evaluation harness. | Publish independent bias audit before use in hiring. |
| Canada | PIPEDA + Quebec Law 25 | Canada-Montréal residency (MVP). Quebec cross-border transfer assessments supported. | Complete Law 25 PIA before deploying to Quebec residents. |
| Brazil | LGPD | São Paulo residency on roadmap. Portuguese DPA available on request. | Appoint DPO; register processing activities with ANPD. |
| India | DPDP Act 2023 | Mumbai residency (MVP). Data-fiduciary role; consent notices supported. | Obtain verifiable consent; handle grievances within 30 days. |
| Singapore | PDPA | Singapore residency (MVP). Notification, consent and access obligations supported. | Appoint DPO; conduct DPIA for high-risk processing. |
| Japan | APPI | Tokyo residency (roadmap). Cross-border transfer notices supported. | Obtain data-subject consent for cross-border transfer. |
| China | PIPL | Restricted — llmcloud.ai does not route Chinese personal information out of China. Use a China-only self-hosted deployment. | Deploy self-host in a China cloud; do not enable managed routing. |
| Australia | Privacy Act + IRAP | Sydney residency (roadmap). IRAP assessment planned. | Comply with Australian Privacy Principles; complete PIA. |
| UAE | UAE PDPL + DIFC DPL | Dubai residency (roadmap). UAE addendum available. | Register with UAE Data Office; sign local addendum. |
| KSA | KSA PDPL | KSA addendum available; routing via UAE region with data-transfer notices. | Register with SDAIA; obtain data-subject consent. |
| South Africa | POPIA | EU residency + SCCs for cross-border transfer. | Appoint Information Officer; notify Regulator of breaches. |
AI-specific frameworks
| Jurisdiction | Framework | Our posture | Customer responsibility |
|---|---|---|---|
| EU | EU AI Act | GPAI transparency template auto-populated per model. Prohibited-use policy enforced at router. Systemic-risk models flagged in catalog. | Classify your system's risk tier; publish AI-Act notices to end users. |
| Global | NIST AI RMF 1.0 | Controls mapped to Govern / Map / Measure / Manage functions. Evidence bundles available. | Adopt org-level AI RMF profile; run risk assessments. |
| Global | ISO/IEC 42001 | AIMS documentation and evidence bundles available (target: Type I by Q4 2026). | Adopt an AI management system aligned with 42001. |
Do you sign a DPA?+
Yes. Standard DPA with SCCs, UK IDTA and Swiss addendum is available click-through at signup. Custom DPAs go through the account team.
Is there a Data Processing Impact Assessment (DPIA) template?+
Yes — request one under NDA. It covers processing purposes, data classes, retention, sub-processors and technical/organizational measures.
Which frameworks are hard blockers today?+
PIPL (China): managed routing is disabled for Chinese personal information — use self-host inside a China cloud. All others are supported via a combination of residency, contracts and controls.