Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Privacy Law Finder

Tell us where your users and customers are and what kind of data you handle. We will show which major privacy laws are likely to apply to you and the headline obligations of each. This is guidance, not legal advice.

1. Where are your users and customers?

Check every region where you have people whose personal data you collect.

2. What data or context applies?

Optional. These sharpen the obligations we surface.

Laws that likely apply

Select at least one region to see results.

Pick where your users are on the left.

This is a scoping aid, not legal advice. Privacy laws turn on specific facts about your business, your data flows, and your role as controller or processor. The mappings here reflect how these laws commonly apply, but only a qualified privacy professional or lawyer can confirm your exact obligations. Thresholds, exemptions, and enforcement change over time. Use this to understand your likely landscape and to scope the work, then validate it before you rely on it.

Questions

How is this different from legal advice?

It is not legal advice. It maps your answers to the privacy laws that commonly apply based on where your users are and what data you handle. Use it to understand your likely obligations and to scope work with a privacy professional or counsel.

Does GDPR apply if I am not based in the EU?

It can. GDPR applies to the processing of personal data of individuals in the EU when you offer goods or services to them or monitor their behaviour, regardless of where your company is located.

What is the difference between PIPEDA and Quebec Law 25?

PIPEDA is Canada's federal private-sector privacy law. Quebec Law 25 is a Quebec provincial law that modernized privacy rules for organizations handling the personal information of people in Quebec, with its own requirements and penalties.

Is this tool free?

Yes, it is free with no signup. If you want help actually meeting the obligations it surfaces, our privacy readiness services can get you compliant. See pricing for details.

Not ready for a call yet?

Get the privacy compliance playbook

A few short notes from Jacob on meeting GDPR, PIPEDA, Law 25, and CPRA obligations without drowning in legalese. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

Privacy Law Readiness

We get you compliant with the privacy laws that apply to you.

Explore Privacy Law Readiness →

Know the laws. Now meet them.

Knowing which laws apply is step one. As part of our broader compliance services, we help startups build the notices, records, and controls to actually comply with the privacy laws that reach them.

See Privacy Law Readiness Book a call

Want the full picture on GDPR?

This gives you the shape of the problem. The full picture is all 60 obligations of GDPR, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

Start your free GDPR assessment See what is in the Workspace

No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.