Legal, Regulatory & Contractual Requirements Register
Legal/regulatory/contractual obligations
Cara menggunakan: Proves you know what applies to you. The obligation-mapping column is where auditors test that the register is operational, not decorative.
Pratinjau
Legal, Regulatory & Contractual Requirements Register
ISO/IEC 27001:2022 A.5.31 + ISO 9001 context. The register auditors use to verify the organization knows what it must comply with – ignorance is not a defense.
| Field | Value |
|---|---|
| Document ID | DOC-ISMS-014 |
| Owner | Compliance / legal |
| Review | On regulatory change + annual |
Register
| ID | Requirement | Type | Jurisdiction | Applies to (process/data) | Key obligation | How complied | Evidence | Owner | Review date |
|---|---|---|---|---|---|---|---|---|---|
| LR-01 | GDPR | Regulation | EU | personal data processing | consent, DPO, 72h breach notice | DPIA + policies | DPO records | @name | YYYY-MM |
| LR-02 | Data breach law | Statute | country/state | PII systems | notify authority+subjects | IR plan | IR tests | @name | YYYY-MM |
| LR-03 | Client contract NDA | Contractual | – | customer data | confidentiality, audit rights | access controls | contract review | @name | YYYY-MM |
| LR-04 | Industry standard | Regulation | sector | products | certification | QA records | certs | @name | YYYY-MM |
| LR-05 | Employment records law | Statute | country | HR data | retention period | retention schedule | HRIS | @name | YYYY-MM |
Obligation mapping
| Requirement | Relevant controls | Compliance gap |
|---|---|---|
| LR-01 | A.5.34 privacy + DPIA | none / gap + plan |
Change log
| Date | Regulatory change | Impact assessment | Action |
|---|---|---|---|
| new/updated law | what must change | plan |
Sources monitored
- Regulator websites, industry bodies, legal counsel alerts