What personal data do you hold, and who can reach it. Ten regulations across three countries, and they all begin there.
GEODI answers it once against the systems you run, then reports it in whichever form the auditor asks for. Map your obligations
| Regulation | Market | Find it | Label it | Mask it | Control access | Evidence |
|---|---|---|---|---|---|---|
| PIPEDA | Canada | Yes | Yes | Yes | Yes | Yes |
| Quebec Law 25 | Canada | Yes | Yes | Yes | Yes | Yes |
| PHIPA | Ontario | Yes | Yes | Yes | Yes | Yes |
| FIPPA and MFIPPA | Canada, public sector | Yes | Yes | — | Yes | Yes |
| HIPAA | United States | Yes | Yes | Yes | Yes | Yes |
| CCPA and CPRA | California | Yes | Yes | Yes | Yes | Yes |
| GLBA | United States | Yes | Yes | Yes | Yes | Yes |
| SOX | United States | Yes | Yes | — | Yes | Yes |
| LFPDPPP | Mexico | Yes | Yes | Yes | Yes | Yes |
| PCI DSS | Cross-border | Yes | Yes | Yes | Yes | Yes |
A mark records that GEODI performs that function against data in scope. It does not record that your organization is compliant, which stays the outcome of your own program.
Compliance stays a program, run by people. What software removes is the excuse that nobody could find the data.
| GEODI supplies | Your program still owns |
|---|---|
| A current inventory of personal and regulated data | Lawful basis and consent records |
| Sensitivity labels on every finding | Retention schedules and policy decisions |
| Masking and anonymization for sharing | Vendor contracts and transfer assessments |
| Access mapping and correction | Staff training and breach response |
| An audit record of every action | Certification and attestation |
All of it generated from the index at the time of asking rather than assembled in the week before a review.
Which systems hold regulated data, by category and volume.
How each item was labelled and against which rule.
Who could reach sensitive content at a point in time.
What was masked, moved or removed, by which account.
Subject access responses with the source path for every hit.
We walk your regulatory scope against the deployment and say plainly which parts the software covers, and which parts stay with your program.