Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Which countries' breach laws might apply to this incident?

Updated

Walk establishment, targeting, data-subject location, processing location, and sectoral reach. Those tests decide which regimes may attach to one incident. This applicability map is not legal advice and does not start a clock.

Applicability map, last verified 7 September 2026 against Regulation (EU) 2016/679 Article 3, EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) version 2.1 (adopted 12 November 2019; formatting 7 January 2020), UK GDPR Article 3, India Digital Personal Data Protection Act 2023 section 3, Australia Privacy Act 1988 section 5B, and Cal. Civ. Code §1798.140(d) CCPA/CPRA business thresholds. It is not legal advice, not a filing, and not a substitute for counsel.

This is an applicability map, not YOUR determination

Audience: a founder selling internationally, a CISO, or counsel scoping which countries' breach laws might bind one incident. This page is not legal advice. It does not start a clock. Mapping a class of test is not a determination that any regime applies to YOUR facts, and reading this page does not start a reporting clock.

Applicability is not 'we have customers there.' It is a set of legal tests that differ by instrument: establishment, offering goods or services (targeting), data-subject location, processing location, sectoral reach, and named extra-territorial provisions. One incident can fire more than one test at once. A yes on an earlier row does not skip later rows. Last verified 7 September 2026. Not legal advice.

  • This page lists tests that may attach a regime. It is not a determination that GDPR, UK GDPR, DPDP, the Australian Privacy Act, or CCPA/CPRA applies, and it is not an instruction to submit a filing.
  • GDPR Article 3 is a legal requirement only if GDPR applies. EDPB Guidelines 3/2018 are regulator guidance on how Article 3 is understood; they are not the regulation.
  • Clock-start is a later question. The reporting-decision-tree page on this site is the branching tree. The reporting-deadlines page on this site is the statute table. This page does not start a clock.
  • A dedicated GDPR, UK GDPR, and US-state-laws jurisdiction guide is not on this site yet. Naming them is not a link.

Decision tree — which applicability tests might fire

Work every row that might match. People in more than one place, an entity established in more than one place, and a product on more than one market can stack regimes. The instruments named below are examples of each class of test, not a complete world list. Last verified 7 September 2026. Not legal advice.

Applicability tests (establishment, targeting, data-subject location, processing location, sectoral reach — not a determination; not a world list; not legal advice)
QuestionIf the facts point yesIf the facts point no
Establishment — is personal data processed in the context of the activities of an establishment of a controller or a processor in the Union (GDPR Article 3(1)), or in the United Kingdom (UK GDPR Article 3(1))?GDPR Article 3(1) is a legal requirement only if GDPR applies: the regulation applies to that processing regardless of whether the processing takes place in the Union. Recital 22: establishment implies the effective and real exercise of activity through stable arrangements; legal form (branch or subsidiary) is not the determining factor. EDPB Guidelines 3/2018 (regulator guidance, version 2.1) read that threshold as capable of being quite low for online services — in some circumstances one employee or agent acting with a sufficient degree of stability — and as not met merely because a website is accessible in the Union. UK GDPR Article 3(1) is a separate UK legal requirement with the same structure, substituting the United Kingdom for the Union. A dedicated GDPR jurisdiction guide is not on this site yet. A dedicated UK GDPR jurisdiction guide is not on this site yet.Absence of an establishment does not end the walk. Continue to targeting, data-subject location, processing location, and sector. GDPR Article 3(2) and UK GDPR Article 3(2) exist precisely for controllers and processors not established there.
Offering goods or services (targeting) — does a controller or processor not established in the Union (or the UK) process personal data of data subjects who are in the Union (or the UK) in connection with offering goods or services to them, irrespective of payment (GDPR Article 3(2)(a); UK GDPR Article 3(2)(a))?The targeting limb of Article 3(2)(a) may attach. Recital 23 (not a separate duty): mere accessibility of a website, an email address, or a language generally used in the third country is insufficient to show intention; a language or currency generally used in one or more Member States with the possibility of ordering in that language, or mentioning customers who are in the Union, may make that intention apparent. EDPB Guidelines 3/2018 are regulator guidance on that recital, not the article. India DPDP Act 2023 section 3(b), as enacted, is a separate class: processing of digital personal data outside India if that processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India. MeitY G.S.R. 843(E) (13 November 2025) appointed eighteen months from that gazette as the date sections 3 to 5 (among others) come into force — last verified 7 September 2026, that commencement had not yet arrived. A dedicated GDPR, UK GDPR, and India DPDP / CERT-In guide is not on this site yet.Do not treat a website that happens to load in a browser in the Union as an offer. Recital 23 and EDPB 3/2018 treat inadvertent or incidental provision as outside Article 3(2)(a). Continue other rows. Monitoring of behaviour in the Union is Article 3(2)(b), a different limb.
Data-subject location — are the people whose personal data is in play in the Union, the UK, California, Australia, or India at the moment the relevant trigger activity takes place?Location is an input to several tests; it is not, by itself, a determination. GDPR Article 3(2) requires data subjects who are in the Union and a related offering or monitoring activity; EDPB 3/2018 (guidance) assesses that location at the moment of offering or monitoring, and treats nationality of a person who is not in the Union as insufficient. CCPA/CPRA class: a 'consumer' is a California resident (Cal. Civ. Code §1798.140(i)), but the statute binds a 'business' that does business in California and meets a threshold in §1798.140(d) — location of residents is necessary, not sufficient. Australia Privacy Act 1988 section 5B extra-territorial operation is a different class (Australian link, including carrying on business in Australia). DPDP section 3(a), when in force, applies to processing of digital personal data within India. A dedicated US-state-laws, Australia NDB, and India DPDP / CERT-In guide is not on this site yet.Do not treat 'no one was physically there at the time of the incident' as 'no regime attaches.' Establishment, targeting, processing location, and sector can still fire. GDPR Article 3(1) does not restrict application to individuals who are in the Union (EDPB 3/2018, guidance, citing Recital 14).
Processing location — is the processing taking place in a particular country (a data centre, a region, a vendor's facility)?Processing location is a legal test in some instruments and not in others. GDPR Article 3(1) applies 'regardless of whether the processing takes place in the Union or not' — EDPB 3/2018 (guidance) states that for Article 3(1) the place of processing is not the territorial test. DPDP section 3(a), when in force, applies to processing of digital personal data within the territory of India (collected in digital form, or in non-digital form and digitised subsequently); section 3(b) separately reaches processing outside India that is in connection with offering goods or services to Data Principals in India. Hosting in a Member State is not, by itself, an establishment under Recital 22. A dedicated GDPR and India DPDP / CERT-In guide is not on this site yet.Do not treat an AWS region, an EU-West cluster, or a vendor's facility as a determination that GDPR Article 3(1) applies, or that it does not. Counsel maps processing location to the instrument that actually uses it.
Sectoral reach — is the organization an essential or important entity under NIS2 as transposed, a financial entity under DORA, a HIPAA covered entity or business associate, an SEC registrant, or a manufacturer of a product with digital elements on the Union market under the CRA?Sector class is entity-and-service specific, not a data-subject-location test. NIS2 Article 23, DORA Article 19, HIPAA 45 CFR §§164.400–414, Form 8-K Item 1.05, and CRA Article 14 (from 11 September 2026) may attach because of what you are, not because of where a user sat. The reporting-decision-tree page on this site is the sector branch. A dedicated NIS2, DORA, HIPAA, SEC cyber-disclosure, and CRA jurisdiction guide is not on this site yet.Do not import a sector duty because the incident is serious, or because personal data was involved. Scope, transposition, 'significant', 'major', covered-entity status, materiality, and 'product with digital elements' are legal and factual tests. This page does not apply them.

Classes of extra-territorial provision (examples, not a world list)

These rows are classes of extra-territorial or threshold test, cited as last verified. Mapping a class is not a determination that the class applies. A dedicated jurisdiction guide for each is not on this site yet. Last verified 7 September 2026. Not legal advice.

Extra-territorial and threshold classes (legal requirement only if that instrument applies — not a determination; not legal advice)
Class as citedWhat the cited text doesKind
GDPR Article 3 — legal requirement only if GDPR appliesArticle 3(1) establishment criterion; Article 3(2) targeting criterion (offering goods or services, or monitoring behaviour of data subjects who are in the Union); Article 3(3) public-international-law limb. Recitals 22–24 interpret those limbs; they are not a separate duty.Legal requirement (only if it applies). EDPB Guidelines 3/2018 are regulator guidance on Article 3, not the regulation.
UK GDPR Article 3 — legal requirement only if UK GDPR appliesParallel structure: establishment in the United Kingdom (Article 3(1)); relevant processing of personal data of data subjects who are in the United Kingdom by a controller or processor not established there, related to offering goods or services or monitoring behaviour (Article 3(2), including 3(2A) 'relevant processing'); public-international-law limb (Article 3(3)). Treat as a separate leaf from EU GDPR.Legal requirement (only if it applies). A dedicated UK GDPR jurisdiction guide is not on this site yet.
India DPDP Act 2023 section 3 — enacted application provision; commencement as notifiedSection 3(a): processing of digital personal data within the territory of India where collected in digital form, or in non-digital form and digitised subsequently. Section 3(b): also processing of digital personal data outside India if in connection with any activity related to offering of goods or services to Data Principals within India. Section 3(c): does not apply to personal or domestic processing, or to personal data made publicly available as that clause describes. MeitY G.S.R. 843(E) (13 November 2025) appointed eighteen months from that gazette for sections 3 to 5 (among others). Last verified 7 September 2026, that commencement had not yet arrived. CERT-In Directions 2022 are a separate incident-reporting instrument.Legal requirement when that section is in force (only if it applies). A dedicated India DPDP / CERT-In guide is not on this site yet.
Australia Privacy Act 1988 section 5B — extra-territorial operationSection 5B(1A): the Act, a registered APP code, and the registered CR code extend to an act done, or practice engaged in, outside Australia and the external Territories by an organisation, or small business operator, that has an Australian link. Australian link includes being an Australian citizen, a body corporate incorporated in Australia, or (section 5B(3), compilation no. 104, 4 June 2026) carrying on business in Australia or an external Territory. Agencies are reached by section 5B(1). This is the extra-territorial class; Part IIIC (NDB) is the eligible-data-breach notification scheme that sits on top of it.Legal requirement (only if the Act applies). A dedicated Australia NDB guide is not on this site yet.
CCPA/CPRA Cal. Civ. Code §1798.140(d) — who is a 'business'A 'business' under Title 1.81.5 includes a for-profit entity that collects consumers' personal information, that does business in the State of California, and that satisfies one or more of: annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to §1798.199.95; annually buys, sells, or shares the personal information of 100,000 or more consumers or households; or derives 50 percent or more of its annual revenues from selling or sharing consumers' personal information (as amended, Stats. 2025, Ch. 67, AB 1170, effective 1 January 2026). 'Consumer' means a California resident (§1798.140(i)). CCPA/CPRA is this applicability class. California's personal-information breach-disclosure statute is a different instrument (Cal. Civ. Code §1798.82). This page does not apply the dollar or volume thresholds to YOUR books.Legal requirement (only if CCPA/CPRA applies). A dedicated US-state-laws guide is not on this site yet. Do not treat CCPA thresholds as a GDPR Article 3 test.

Worked example — a multi-jurisdiction SaaS incident (fictional)

The facts below are labelled fictional. They are a teaching walk of which tests fire, not a filing, not a determination, and not YOUR facts. Counsel applies the tests to the real incident. Last verified 7 September 2026. Not legal advice.

Fictional facts. 'Northloop' is a privately held Delaware corporation with headquarters in Austin, Texas. It sells a B2B project-management SaaS. It has no subsidiary, branch, or employee in the EEA or the UK. The marketing site is in English. Prices are listed in USD, EUR, and GBP, and EU and UK organisations can create a workspace and pay in those currencies. Paying customers include organisations in Germany, France, the United Kingdom, California, New South Wales, and Karnataka. Production hosts run in us-east-1 and, for some EU workspaces, eu-west-1 (Ireland). It is not a HIPAA covered entity or business associate, not an SEC registrant, and not a credit institution.

Fictional incident. An unauthorised actor used a stolen admin token to read a production table of workspace-member email addresses, display names, and source IP addresses for those EU, UK, California, Australian, and Indian workspaces. This page does not decide that a personal data breach, an eligible data breach, or a CCPA-covered incident occurred.

  • Establishment (GDPR Article 3(1) / UK GDPR Article 3(1)): no EEA or UK subsidiary or employee on these fictional facts. A website that loads in the Union is not, by itself, an establishment (EDPB 3/2018, guidance). eu-west-1 is processing location, not an establishment under Recital 22. This limb does not obviously fire. Counsel still checks 'stable arrangements' on the real facts.
  • Offering goods or services (GDPR Article 3(2)(a) / UK GDPR Article 3(2)(a)): EUR and GBP pricing, the ability to order, and paying EU and UK organisations are the kinds of factors Recital 23 lists as capable of making an intention to offer apparent. EDPB 3/2018 is guidance on that recital. This limb may fire for EU GDPR and, separately, for UK GDPR. That is not a determination that Article 3(2) applies, and it is not a filing.
  • Data-subject location: people using those workspaces were in the Union, the UK, California, Australia, and India on these fictional facts. Location feeds Article 3(2), UK GDPR Article 3(2), CCPA 'consumer', DPDP Data Principals in India, and Australian individuals — it does not finish any of those tests.
  • Processing location: some EU-workspace rows sat in Ireland. GDPR Article 3(1) still applies regardless of whether processing takes place in the Union; the Ireland region does not, by itself, create an establishment. DPDP section 3(a) (when in force) cares about processing within India; 3(b) cares about processing outside India in connection with offering to Data Principals in India. Counsel maps the table, the region, and the Indian customers separately.
  • Sectoral reach: HIPAA, SEC Item 1.05, DORA, and CRA do not obviously fire on these fictional facts. NIS2 essential/important status is a legal classification this page does not apply. A dedicated NIS2 jurisdiction guide is not on this site yet.
  • Extra-territorial classes: Australia section 5B(3) 'carries on business in Australia' may be in play if the New South Wales customer means Northloop carries on business there — this page does not decide that. CCPA/CPRA §1798.140(d) fires only if Northloop does business in California and meets a revenue, volume, or selling-or-sharing threshold; this page does not apply those numbers. DPDP section 3(b), when in force, may be in play because of offering to Data Principals in India. CERT-In Directions 2022 are a separate incident-reporting instrument. None of those sentences is a filing.
  • Output of the walk, still fictional: a set of regimes that may apply (EU GDPR personal-data notification, UK GDPR as a separate leaf, California §1798.82 as a different statute from CCPA, Australian NDB if the Act applies, DPDP when section 3 is in force). The reporting-decision-tree page on this site is the next walk. This example does not start a clock.

Legal requirement versus guidance on extra-territoriality

Extra-territorial reach is easy to over-read. The article or section is the legal requirement (only if that instrument applies). Recitals interpret the article. EDPB Guidelines 3/2018 are regulator guidance. Agency explainers and this page are not the law. Last verified 7 September 2026. Not legal advice.

Legal requirement vs guidance vs recital vs this page (not a determination; not legal advice)
TextKindWhat this page does not do
GDPR Article 3(1)–(3)Legal requirement (only if GDPR applies). Operative territorial scope of the regulation.Does not decide that you have an establishment, that you offer goods or services to data subjects in the Union, or that you monitor behaviour in the Union.
GDPR Recitals 22, 23, and 24Recitals. They inform interpretation of establishment, offering, and monitoring. They are not a separate duty and are not EDPB guidance.Does not treat a recital as a filing trigger. Does not convert Recital 23's factors into a score.
EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), version 2.1 (12 November 2019; formatting 7 January 2020)Regulator guidance. A common interpretation by EU data protection authorities of how to apply Article 3. Not the regulation. Not a court judgment.Does not treat an EDPB example as YOUR facts. The examples in those guidelines, and the fictional SaaS walk on this page, are teaching tools.
UK GDPR Article 3, including 3(2A)Legal requirement (only if UK GDPR applies). Parallel UK territorial scope, not discharged by an EU GDPR analysis.Does not decide that UK GDPR attaches. A dedicated UK GDPR jurisdiction guide is not on this site yet.
DPDP Act 2023 section 3; MeitY G.S.R. 843(E) commencementSection 3 is the enacted application provision. Whether it is in force is a commencement question (eighteen months from the 13 November 2025 gazette for sections 3 to 5, among others, last verified 7 September 2026). Not EDPB guidance, and not GDPR Article 3.Does not treat DPDP as already in force on the last-verified date, and does not invent a numeric DPDP clock.
Australia Privacy Act 1988 section 5B (compilation no. 104, 4 June 2026)Legal requirement (only if the Act applies). Extra-territorial operation via Australian link, including carrying on business in Australia (section 5B(3)).Does not decide that you carry on business in Australia. Does not apply Part IIIC.
Cal. Civ. Code §1798.140(d) and (i)Legal requirement (only if CCPA/CPRA applies). Who is a 'business' and who is a 'consumer'. Agency pages that restate the $25 million / 100,000 / 50 percent figures are explainers of that section, not a substitute for it, and the dollar figure is adjusted under §1798.199.95.Does not apply the revenue or volume thresholds to YOUR books. Does not collapse CCPA into Cal. Civ. Code §1798.82.

Checklist for the founder and counsel

This is a question list, not a filing. The reporting-decision-tree page on this site is the branching tree. The do-I-have-to-report page on this site is the class map. The who-to-notify page on this site is the recipient-class map. The regulator-customer-individual page on this site is the three-stream comparison. The document-your-decision page on this site is the decision record. A dedicated jurisdiction guide is not on this site yet.

  • List the places of establishment, of offering, of the people whose data is in play, of the processing, and of the sector or product class. Walk every row. A yes on targeting does not skip sector.
  • For each instrument that may attach, write whether the cited test is establishment, targeting, data-subject location, processing location, sectoral reach, or a named extra-territorial or threshold provision. Counsel decides on YOUR facts whether any of them requires a filing.
  • Label every source as legal requirement (only if it applies), recital, regulator guidance, or this page. Do not treat EDPB Guidelines 3/2018 as GDPR Article 3.
  • Do not treat a data-centre region as an establishment. Do not treat website accessibility as an offer. Do not treat nationality as location.
  • EU GDPR and UK GDPR are separate leaves. Filing one never discharges the other. CCPA/CPRA thresholds are not Cal. Civ. Code §1798.82. DPDP section 3 is not CERT-In Directions 2022.
  • Who is authorised to decide applicability, and who is not. A named human, with counsel, decides. The product does not. This page does not. This page does not start a clock.

Glossary

These are teaching labels for this page. They are not legal conclusions about YOUR facts.

Terms used on this page (teaching labels — not a determination)
TermHow this page uses it
Applicability mapA classing of tests (establishment, targeting, data-subject location, processing location, sectoral reach, extra-territorial provisions) that decide which regimes may attach. Not a determination that any duty applies.
EstablishmentGDPR Article 3(1) / UK GDPR Article 3(1): processing in the context of the activities of an establishment of a controller or processor there. Recital 22: effective and real exercise of activity through stable arrangements. EDPB 3/2018 is guidance on that notion.
Targeting / offering goods or servicesGDPR Article 3(2)(a) / UK GDPR Article 3(2)(a): offering goods or services to data subjects who are in the Union or the UK, irrespective of payment. Recital 23 lists intention factors. DPDP section 3(b) is a separate 'offering' class for Data Principals in India.
MonitoringGDPR Article 3(2)(b): monitoring of the behaviour of data subjects who are in the Union, as far as that behaviour takes place within the Union. Recital 24 discusses tracking and profiling. A different limb from offering.
Data-subject locationWhere the natural person is at the moment the trigger activity takes place (EDPB 3/2018, guidance, on Article 3(2)). Not nationality, and not the only test on this page.
Processing locationWhere the processing operation is carried out. GDPR Article 3(1) applies regardless of that place. DPDP section 3(a) (when in force) uses processing within India as a limb. A region is not an establishment.
Australian linkPrivacy Act 1988 section 5B(2) and (3): the extra-territorial hook, including carrying on business in Australia. Not a GDPR Article 3 test.
CCPA/CPRA 'business' thresholdsCal. Civ. Code §1798.140(d): do business in California plus one of the revenue, volume, or selling-or-sharing limbs, as adjusted. Not a determination this page computes, and not §1798.82.

Where this shows up in ShipReady Metrics

The signed-in app does not decide which jurisdictions apply, does not run GDPR Article 3 tests, does not decide that GDPR, UK GDPR, DPDP, the Australian Privacy Act, or CCPA/CPRA applies, does not start a notification clock, does not file with a regulator, and does not interpret YOUR facts. None of the surfaces below is 'these countries bind you.'

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organization has classified as CRA-in-scope. It tracks a clock the organization already started. It is not a determination that CRA applies, and it is not an Article 3 analysis. A named human still submits.

The obligation map lists frameworks the organization has marked in-scope. That mark is not a determination that GDPR, CCPA, or DPDP applies, not an Article 3 test, not an extra-territorial analysis, and not a legal opinion that a reporting duty applies. The cyber risk register lives under Security. None of those surfaces files a GDPR Article 33 notice, a UK ICO notice, a DPDP intimation, an Australian NDB statement, a CCPA/CPRA response, or a California §1798.82 disclosure.

Primary sources (last verified 7 September 2026)

Every regulatory claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2016/679 Article 3 is a legal requirement only when GDPR applies. Recitals 22–24 interpret that article. EDPB Guidelines 3/2018 (version 2.1, 12 November 2019; formatting 7 January 2020) are regulator guidance. UK GDPR Article 3 is a legal requirement only when UK GDPR applies (legislation.gov.uk text as amended). Digital Personal Data Protection Act 2023 section 3 is the enacted Indian application provision; MeitY G.S.R. 843(E) of 13 November 2025 appointed eighteen months from that gazette for sections 3 to 5 (among others). Australia Privacy Act 1988 section 5B is extra-territorial operation (compilation no. 104, 4 June 2026). Cal. Civ. Code §1798.140(d) and (i) are the CCPA/CPRA 'business' and 'consumer' definitions, last checked in the official Legislative Counsel text. These are examples of classes, not a complete world list. Not legal advice.

The reporting-decision-tree page on this site is the branching tree. The do-I-have-to-report page on this site is the class map. The reporting-deadlines page on this site is the statute table. The who-to-notify page on this site is the recipient-class map. The regulator-customer-individual page on this site is the three-stream comparison. The prepare-regulatory-report page on this site is the field checklist. The supporting-evidence page on this site is the evidentiary record. The document-your-decision page on this site is the decision record. A dedicated failure-to-report-consequences, how-regulators-determine-knowledge, GDPR, NIS2, DORA, CRA, UK GDPR, US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Which countries' breach laws might apply to this incident?

This map cannot tell you. Walk establishment, targeting (offering goods or services), data-subject location, processing location, and sectoral reach with counsel. GDPR Article 3, UK GDPR Article 3, DPDP Act 2023 section 3, Australia Privacy Act 1988 section 5B, and Cal. Civ. Code §1798.140(d) are examples of classes, not a world list. Last verified 7 September 2026. Not legal advice.

Is this legal advice?

No. It is an applicability map distilled from GDPR Article 3, EDPB Guidelines 3/2018, UK GDPR Article 3, DPDP Act 2023 section 3, Australia Privacy Act 1988 section 5B, and Cal. Civ. Code §1798.140(d). Whether any regime attaches, and whether a clock has started, are legal questions for counsel on your facts. This page does not start a reporting clock.

Does having an EU data centre mean GDPR applies?

Not by itself. GDPR Article 3(1) applies to processing in the context of the activities of an establishment in the Union, regardless of whether the processing takes place in the Union. EDPB Guidelines 3/2018 (regulator guidance) treat the place of processing as not the Article 3(1) test, and Recital 22 does not treat technical means as establishment. Counsel maps YOUR region, YOUR arrangements, and Article 3(2) targeting separately. Not legal advice.

Does this page start a reporting clock?

No. Applicability is a prior question. GDPR Article 33 runs from becoming aware; other statutes use discovery, determination, or noticing. Reading a public page is none of those events. The signed-in CRA ladder tracks recorded awareness; it does not start a clock either, and it does not run Article 3 tests.

Does ShipReady Metrics decide that GDPR or CCPA applies?

No. The signed-in app does not decide which jurisdictions apply, does not run GDPR Article 3 tests, and does not decide that GDPR, CCPA, or DPDP applies. The obligation map is frameworks the organization marked in-scope, not an extra-territorial analysis. Compliance → CRA reporting tracks a ladder from recorded awareness for findings the org classified as CRA-in-scope. The cyber risk register lives under Security.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.