# Legal, Regulatory & Contractual Requirements Register

> ISO/IEC 27001:2022 A.5.31 + ISO 9001 context. The register auditors
> use to verify the organization knows what it must comply with –
> ignorance is not a defense.

| Field | Value |
|-------|-------|
| Document ID | DOC-ISMS-014 |
| Owner | Compliance / legal |
| Review | On regulatory change + annual |

## Register

| ID | Requirement | Type | Jurisdiction | Applies to (process/data) | Key obligation | How complied | Evidence | Owner | Review date |
|----|-------------|------|--------------|---------------------------|----------------|--------------|----------|-------|-------------|
| LR-01 | GDPR | Regulation | EU | personal data processing | consent, DPO, 72h breach notice | DPIA + policies | DPO records | @name | YYYY-MM |
| LR-02 | Data breach law | Statute | country/state | PII systems | notify authority+subjects | IR plan | IR tests | @name | YYYY-MM |
| LR-03 | Client contract NDA | Contractual | – | customer data | confidentiality, audit rights | access controls | contract review | @name | YYYY-MM |
| LR-04 | Industry standard | Regulation | sector | products | certification | QA records | certs | @name | YYYY-MM |
| LR-05 | Employment records law | Statute | country | HR data | retention period | retention schedule | HRIS | @name | YYYY-MM |

## Obligation mapping

| Requirement | Relevant controls | Compliance gap |
|-------------|-------------------|----------------|
| LR-01 | A.5.34 privacy + DPIA | none / gap + plan |

## Change log

| Date | Regulatory change | Impact assessment | Action |
|------|-------------------|-------------------|--------|
| | new/updated law | what must change | plan |

## Sources monitored

- Regulator websites, industry bodies, legal counsel alerts
