StructureClerk

Methodology

StructureClerk assesses organizational compliance across four complementary domains: personal data protection, artificial intelligence governance, cybersecurity, and algorithmic compliance.

Approach

The 200+ question questionnaire is built from official regulatory texts of 192 jurisdictions. Each question is mapped to specific requirements of applicable frameworks, enabling cross-assessment when the organization operates in multiple markets simultaneously.

The assessment produces a score by domain and jurisdiction, identifies priority gaps, and generates a professional-grade PDF report immediately usable by compliance, legal, or executive teams.

Four domains

Data Protection

GDPR, Law 25, PIPEDA, CCPA, LGPD, PIPL and national frameworks

AI Governance

EU AI Act, C-27, sectoral guidelines

Cybersecurity

NIS2, CIRCIA, ISO 27001, NIST CSF 2.0

Algorithmic Compliance

EU AI Act, Law 25, transparency, audit and traceability

Quebec and Canadian legal framework in force

Data protection

Loi 25 — Loi modernisant des dispositions législatives en matière de protection des renseignements personnels

RLRQ c P-39.1 · Québec · Secteur privé · En vigueur : septembre 2022 — septembre 2024 (déploiement progressif)

Act respecting access to documents held by public bodies and the protection of personal information

RLRQ c A-2.1 · Québec · Secteur public · En vigueur : 1982, mod. 2006 et 2021-2024

LPRPDE — Personal Information Protection and Electronic Documents Act (PIPEDA)

L.C. 2000, c. 5 · Canada (fédéral) · Secteur privé — activités commerciales · En vigueur : 2000, mod. 2015 et 2018

Privacy Act

L.R.C. 1985, c. P-21 · Canada (fédéral) · Institutions gouvernementales · En vigueur : 1983

AI governance

Indication IA-RI-2025-003-OP

MCN Québec, déc. 2025 · Québec · Secteur public · Conformité exigée : 5 juin 2026

Directive on Automated Decision-Making

Treasury Board of Canada, 2019 · Canada (federal) · Federal institutions · In force: 2019

Cybersecurity

LGGRI — Act respecting the governance and management of information resources

RLRQ c G-1.03 · Québec · Secteur public · En vigueur : 2011, mod. 2021 et 2023

Act respecting the Ministère de la Cybersécurité et du Numérique

RLRQ c M-17.1.1 · Québec · Secteur public · En vigueur : 2021

Algorithmic compliance

Loi 25, automated decision provisions (art. 12.1)

RLRQ c P-39.1 · Québec · Secteur privé · En vigueur : septembre 2023

Bills under consideration, not yet in force: Bill C-8 (critical systems cybersecurity, 2nd reading), C-27/AIDA (died on the order paper, January 2025).

Regulatory sources

  • Regulations and directives: GDPR, AI Act, NIS2, Law 25, PIPEDA, CCPA, LGPD, POPIA, NDPA, PIPL, and 150+ other frameworks
  • International standards: ISO 27001, NIST CSF 2.0, SOC 2
  • Supervisory authority guidelines: CNIL, OPC, ICO, CISA, ENISA, and others

Coverage

192 jurisdictions across 8 regions:

Europe48
Africa42
Asia-Pacific34
Americas51
Middle East17

Depth by domain

DomainJurisdictions mapped
Data protection — law in force168
Data protection — regime in progress24
AI governance18
Cybersecurity5

Oldest verification in the dataset: 2025-01-31. Most recent: 2026-07-12. Every authority API decision publishes the verification date of each law it cites, along with the oldest of them.

Two verification tiers

Priority73

Jurisdictions the authority engine actually decides on: cross-border transfer regime, localisation duty, right to human involvement. Re-verified every cycle. We re-verify what we decide on.

Indicative119

Sourced coverage, useful for knowing a regime exists, but no decision is staked on it. Re-verified less often, and every citation carries its own date.

Regulatory monitoring process

Legislative changes are detected through official sources from supervisory authorities (CNIL, OPC, ICO, CISA, ENISA and others), official gazettes of covered jurisdictions, and publications from standardization bodies (ISO, NIST). Monitoring prioritises high-traffic jurisdictions (Canada, Quebec, EU, France, UK, US), re-verified every cycle. The remaining jurisdictions are indicative coverage and are re-verified less often: the last-verified date of each law is published with every citation rather than promised. The oldest in the dataset is 2025-01-31.

The author

Michel Fotsing

Michel Fotsing is a cybersecurity architect, CISSP, and member of the ISC2 Exam Review Commission. He is the author of L'Architecte Numérique and publishes the newsletter of the same name, followed by 1,700+ professionals.

Limitations

StructureClerk is a decision-support tool. The report results identify potential gaps and guide action priorities. They do not constitute legal advice and do not replace the expertise of a legal counsel or certified auditor for final compliance decisions.

Assess your compliance

192 jurisdictions mapped. Free PDF report. In minutes.