Regulation & Compliance
Data Landscape for Regulation
What the law requires of your data, and the frameworks you get audited against to show it.
The Data Landscape maps the open standards a data architecture is built on. This one maps the other half of the room. It starts with the regulation itself (GDPR, the EU AI Act, the Data Act, NIS2, DORA, BCBS 239) and then covers the management systems, control catalogues and assurance schemes you actually implement and get audited against. European instruments come first, with the global heavyweights alongside them. Click any entry to learn more.
The original version of this sub-landscape was donated by Mark McCalla; curated since by Simon Harrer.
Regulation: what the law requires
EU Data & AI Acts
frameworksGlobal & Sector Regulation
frameworksGovernance & Management: how data is governed
Data Management Frameworks
frameworksMetadata & Quality
frameworksSecurity & Risk: how data is protected
Management Systems
frameworksSecurity Controls
frameworksPrivacy
frameworksThreat Intelligence
frameworksIdentity & Agents: who is acting, and on whose behalf
Identity & Access
frameworksAgent Identity & Trust
frameworksAgent Interaction
frameworksAI & Applications: how systems built on data are held accountable
AI Governance
frameworksApplication & API Security
frameworksAssurance & Exchange: how compliance is evidenced and data is shared
Cloud & Certification
frameworksAudit & Attestation
frameworksSoftware Supply Chain
frameworksData Spaces & Sovereignty
frameworks|
|
Click any row to open the framework. Click a column header to sort.
FAQ
Why are regulations and frameworks on the same page?
Because neither half means much alone. A regulation tells you what must be true and almost never how to show it: GDPR requires appropriate technical and organisational measures, the AI Act requires risk management and data governance, DORA requires ICT third-party oversight. None of them names a control.
The frameworks below fill that gap: the management systems, control catalogues and assurance reports an auditor, a supervisor or a customer's third-party risk team will actually accept as evidence. The first section is what binds you; everything after it is how you demonstrate it. Regulation tiles carry an amber band so the two never blur together.
How does this relate to the main Data Landscape?
The Data Landscape answers "what do I build with?": contracts, schemas, table formats, lineage, protocols. This page answers "what do I get held to?" Same structure, same judgements, different half of the problem.
They meet in a handful of places. ODRL and Open Policy Agent appear on both, because a usage policy is simultaneously an architectural choice and a compliance artefact. Lineage and data contracts are the technical evidence that most of the frameworks here quietly assume you already produce.
Why is there no Adopt / Assess judgement here?
Because you do not pick these. The main Data Landscape carries an opinion on every standard, because choosing between Iceberg and Delta is a real decision with a defensible default. Compliance frameworks are not that kind of choice: ISO/IEC 27001 is not better than BSI C5, and NIST SP 800-53 is not something you adopt because it is good: you implement it because a contract, a supervisor or a customer's procurement team requires it.
What decides applicability is jurisdiction and sector, so that is what the toolbar filters on. Each entry states who governs it, where it has force, and what it is actually used to evidence, and leaves the verdict to you.
Is this legal advice?
No. It is an engineering map of the frameworks that regulated data work tends to run into, written by practitioners rather than lawyers. Whether a given framework satisfies a given obligation in your jurisdiction, sector and set-up is a question for counsel and your auditor, and the answer moves.
Certification status, edition numbers and the scope of harmonised standards change frequently. Follow the links to the source before you rely on anything here.
Thank you
The original version of this sub-landscape was donated by Mark McCalla, who built it and made the case that the compliance half of the picture deserved a map of its own. Curated since by Simon Harrer at Entropy Data.
Missed a framework? Spotted something out of date?
Compliance moves faster than most standards, so corrections are especially welcome.