GEODI Compliance | PIPEDA, Law 25, HIPAA, CCPA, LFPDPPP and PCI DSS

Every regime opens with the same question.

What personal data do you hold, and who can reach it. Ten regulations across three countries, and they all begin there.

GEODI answers it once against the systems you run, then reports it in whichever form the auditor asks for. Map your obligations

Coverage across North America

RegulationMarketFind itLabel itMask itControl accessEvidence
PIPEDACanadaYesYesYesYesYes
Quebec Law 25CanadaYesYesYesYesYes
PHIPAOntarioYesYesYesYesYes
FIPPA and MFIPPACanada, public sectorYesYesYesYes
HIPAAUnited StatesYesYesYesYesYes
CCPA and CPRACaliforniaYesYesYesYesYes
GLBAUnited StatesYesYesYesYesYes
SOXUnited StatesYesYesYesYes
LFPDPPPMexicoYesYesYesYesYes
PCI DSSCross-borderYesYesYesYesYes

A mark records that GEODI performs that function against data in scope. It does not record that your organization is compliant, which stays the outcome of your own program.

Obligations by market

Canada

PIPEDA
Safeguards matched to sensitivity, and a response to individual access requests.
Law 25
An inventory of personal information, destruction or anonymization once the purpose ends, and assessment before disclosure outside Quebec.
PHIPA
Limits on who reaches personal health information held by a custodian.
FIPPA, MFIPPA
Records inventories for provincial and municipal institutions, answered on a statutory clock.

United States

HIPAA
Protected health information located, access restricted to the minimum necessary, activity recorded.
CCPA and CPRA
Consumer requests to know and to delete, answered across every system holding the record.
GLBA
Customer financial information identified and protected under the safeguards rule.
SOX
Control evidence over financial records, produced from live data.

Mexico

LFPDPPP
Personal data identified across holdings, with security measures proportionate to sensitivity.
ARCO rights
Access, rectification, cancellation and opposition requests answered from a single index.
Residency
Processing kept inside the country where policy or contract requires it.

Compliance stays a program, run by people. What software removes is the excuse that nobody could find the data.

GEODI suppliesYour program still owns
A current inventory of personal and regulated dataLawful basis and consent records
Sensitivity labels on every findingRetention schedules and policy decisions
Masking and anonymization for sharingVendor contracts and transfer assessments
Access mapping and correctionStaff training and breach response
An audit record of every actionCertification and attestation

Evidence produced on request

All of it generated from the index at the time of asking rather than assembled in the week before a review.

01

Inventory

Which systems hold regulated data, by category and volume.

02

Classification

How each item was labelled and against which rule.

03

Access

Who could reach sensitive content at a point in time.

04

Actions

What was masked, moved or removed, by which account.

05

Requests

Subject access responses with the source path for every hit.

Bring the clause you have to satisfy

We walk your regulatory scope against the deployment and say plainly which parts the software covers, and which parts stay with your program.