Evidence before inference
Every comparative proposition needs a rationale, primary source, confidence, reviewer and review date.
Methodology · version 2.3.0
A transparent editorial comparison plus a separate reader-controlled research brief. Comparison values measure official-source resolution under declared weights; reading values prioritise questions only.
In plain English
The model is a transparent way to inspect how directly official sources answer selected questions. It is not a league table, a law-quality score or a compliance assessment.
Sources checked 2026-08-30; legal-status dates stay attached to the records they qualify.
Evidence horizon
We keep these four stages separate. They are a reading aid, not a ranking or score.
What the controlling law says.
Which parts apply on the stated date.
What can be examined in real use.
What dated evidence can support a result.
Every comparative proposition needs a rationale, primary source, confidence, reviewer and review date.
Enacted, operative and officially explained are different states and remain visibly labelled.
The comparison publishes every value and weight; the reading tool separately prioritises questions. Neither changes legal facts.
Missing, unreviewed or non-equivalent evidence produces a non-comparable state.
Weighted comparison · model v1.0.0
Values describe how directly the cited official record resolves each research question. They do not measure legal quality, rights strength, compliance, regulator effectiveness or an objectively best jurisdiction.
score_j = sum_i(w_i * value_ij) / sum_i(w_i for comparable i,j)coverage_j = sum_i(w_i for comparable i,j) / sum_i(w_i)
unknown and non_comparable values are excluded from numerator and denominator, remain visible, and never become zero.
A framework enters the displayed order only when comparable evidence covers at least 75% of selected weight.
only coverage-qualified frameworks enter the displayed ordering; equal rounded values share a rank. Sensitivity removes each positive-weight factor once and recalculates the qualified leader.
Each definition applies across the row. “NC” means structurally non-comparable; “?” means the current cited record is insufficient. Neither becomes zero.
| Factor and definition | DPDP | GDPR | CCPA | PDPA | LGPD |
|---|---|---|---|---|---|
| Accessibility and drafting clarityHow directly the current official record lets a reader locate the governing rule. A higher value means the cited text and official guidance resolve the research question more explicitly; it does not mean the law is better. | 7/10A compact Act, final Rules and a separate commencement table make the architecture traceable.developing · status 2026-08-30SourceSourceSource | 6/10The official regulation is comprehensive and internally structured.moderate · status 2026-08-30Source | 6/10The consolidated statute and regulations index expose current requirements.moderate · status 2026-08-30SourceSource | 8/10The official consolidation and obligations guide provide complementary statute and plain-language entry points.moderate · status 2026-08-30SourceSource | 6/10The consolidated Portuguese text is structured and an official English aid is available.moderate · status 2026-08-30SourceSource |
| Scope and extra-territorial reachHow explicitly current primary sources define covered people, entities, data and territorial connections. A higher value means the scope question is more directly resolved in the cited record, not broader or stronger protection. | 7/10The enacted Act states digital-data and territorial connections, including specified overseas processing.developing · status 2026-08-30SourceSource | 9/10Articles 2 and 3 publish detailed material and territorial scope rules.moderate · status 2026-08-30Source | 6/10The statute defines consumers, businesses, thresholds, personal information and covered conduct.moderate · status 2026-08-30Source | 7/10The statute states organisational and territorial application with defined exclusions.moderate · status 2026-08-30Source | 8/10Articles 3 and 4 state territorial triggers and principal exclusions.moderate · status 2026-08-30Source |
| Permitted grounds and processing architectureHow explicitly current sources enumerate or structure lawful routes for processing. A higher value means more of the research map is resolved in the cited record, not that more or fewer grounds are preferable. | 7/10The Act publishes consent and specified certain legitimate uses as its architecture.developing · status 2026-08-30SourceSource | 9/10Article 6 and related provisions enumerate multiple lawful bases and special-category conditions.moderate · status 2026-08-30Source | NCThe CCPA structures duties and consumer controls without using an omnibus lawful-bases taxonomy comparable to GDPR-style models.not_comparable · status 2026-08-30Source | 8/10The statute and regulator guidance distinguish consent from statutory alternatives and exceptions.moderate · status 2026-08-30SourceSource | 9/10Articles 7 and 11 enumerate legal bases for general and sensitive personal data.moderate · status 2026-08-30Source |
| Notice and consent usabilityHow explicitly current sources specify what must be communicated and how meaningful choice is structured. A higher value measures published resolution, not real-world interface quality. | 8/10The Act and Rule 3 publish detailed notice and consent mechanics.developing · status 2026-08-30SourceSourceSource | 8/10Articles 7 and 12–14 specify consent conditions and layered transparency duties.moderate · status 2026-08-30Source | 9/10The statute details notice at collection and consumer-control disclosures, supplemented by regulations.moderate · status 2026-08-30SourceSource | 8/10Official sources connect notification, purpose and consent obligations.moderate · status 2026-08-30SourceSource | 8/10The LGPD states transparency principles, consent conditions and information rights.moderate · status 2026-08-30Source |
| Withdrawal and preference controlHow explicitly the current record provides a route to reverse consent or exercise an analogous preference control. A higher value measures published procedural clarity, not ease in every service. | 8/10The enacted framework requires withdrawal ease comparable to giving consent and Rule 3 identifies a route.developing · status 2026-08-30SourceSourceSource | 8/10Article 7 states withdrawal and requires it to be as easy as giving consent.moderate · status 2026-08-30Source | 8/10The statute and regulations publish opt-out and sensitive-information preference controls.moderate · status 2026-08-30SourceSource | 8/10Withdrawal of consent is a visible part of the official obligations map.moderate · status 2026-08-30SourceSource | 8/10Article 8 provides a facilitated, free revocation route for consent.moderate · status 2026-08-30Source |
| Individual rights and grievance pathwaysHow explicitly current sources define rights, request routes and redress steps. A higher value measures legal and procedural resolution, not the likelihood of a successful outcome. | 7/10The Act publishes access, correction, erasure, grievance and nomination pathways.developing · status 2026-08-30SourceSourceSource | 9/10Articles 12–22 define a broad rights architecture and response conditions.moderate · status 2026-08-30Source | 8/10The current statute defines access, correction, deletion, opt-out and non-retaliation controls.moderate · status 2026-08-30SourceSource | 7/10Access, correction and complaint pathways are present in the statute and official guide.moderate · status 2026-08-30SourceSource | 8/10Article 18 publishes a multi-part data-subject rights framework.moderate · status 2026-08-30Source |
| Children and guardian treatmentHow explicitly current sources identify age, guardian authority and special safeguards. A higher value measures source specificity, not a declaration of superior child protection. | 8/10The Act and final Rules publish child, guardian and verifiable-consent mechanics.developing · status 2026-08-30SourceSourceSource | 8/10Article 8 and related recitals state child-consent rules for information-society services.moderate · status 2026-08-30Source | 8/10The statute publishes age-banded opt-in rules for sale and sharing.moderate · status 2026-08-30Source | 6/10The general consent framework and official guidance provide a starting point.moderate · status 2026-08-30SourceSource | 7/10Article 14 specifically addresses children and adolescents and best interests.moderate · status 2026-08-30Source |
| Processor and accountability architectureHow explicitly current sources divide responsibility among organisations and service providers. A higher value measures role resolution, not lower implementation cost. | 7/10The Act keeps the Data Fiduciary responsible for processing on its behalf and the Rules add operational detail.developing · status 2026-08-30SourceSourceSource | 9/10Articles 24–30 publish controller, joint-controller, processor and recordkeeping duties.moderate · status 2026-08-30Source | 8/10The statute details business, service-provider, contractor and third-party relationships and contracts.moderate · status 2026-08-30SourceSource | 8/10Accountability and data-intermediary responsibilities are identifiable in official sources.moderate · status 2026-08-30SourceSource | 8/10The law defines controller and operator roles and accountability duties.moderate · status 2026-08-30Source |
| Security and breach responseHow explicitly current sources define safeguards and incident response. A higher value measures published specificity, not breach prevention performance. | 8/10Rule 6 and the Act specify safeguards and breach notification mechanics.developing · status 2026-08-30SourceSourceSource | 9/10Articles 32–34 state risk-based security and controller/authority/individual notification duties.moderate · status 2026-08-30Source | 7/10The statute requires reasonable security and provides a breach-related private action.moderate · status 2026-08-30Source | 8/10Protection and data-breach notification obligations are clearly mapped in official sources.moderate · status 2026-08-30SourceSource | 8/10Articles 46–49 publish security and incident duties.moderate · status 2026-08-30Source |
| Data protection impact and risk dutiesHow explicitly current sources require structured assessment for higher-risk processing. A higher value measures published triggers and method, not safer outcomes. | 8/10The Act and Rules publish additional risk duties for Significant Data Fiduciaries.developing · status 2026-08-30SourceSourceSource | 9/10Articles 35–36 define DPIA and prior-consultation structures.moderate · status 2026-08-30Source | 8/10Current rules publish risk-assessment and cybersecurity-audit structures for defined businesses.moderate · status 2026-08-30SourceSource | 6/10Accountability and protection duties support risk analysis in official guidance.moderate · status 2026-08-30SourceSource | 7/10The LGPD defines impact reports and grants ANPD request powers.moderate · status 2026-08-30Source |
| Automated decision and algorithmic accountabilityHow explicitly current sources address automated or profiled outcomes and recourse. A higher value measures direct legal treatment, not the quality of algorithms. | ?The cited general DPDP records do not resolve a standalone automated-decision right comparable across all five models.unknown · status 2026-08-30SourceSource | 9/10Articles 13–15 and 22 directly address automated decision-making and related information.moderate · status 2026-08-30Source | 8/10The statute authorises rulemaking and current regulations address defined automated decisionmaking contexts.moderate · status 2026-08-30SourceSource | ?The cited general statute and obligations overview do not resolve one symmetric automated-decision metric.unknown · status 2026-08-30SourceSource | 7/10Article 20 provides review and information rights concerning solely automated decisions.moderate · status 2026-08-30Source |
| Cross-border transfer modelHow explicitly current sources state routes, restrictions and continuing safeguards for overseas data movement. A higher value measures model resolution, not openness or restrictiveness. | 6/10The enacted Act publishes a government-restriction model for transfers.developing · status 2026-08-30SourceSource | 9/10Chapter V publishes adequacy, safeguards and derogation routes.moderate · status 2026-08-30Source | NCThe CCPA does not use a general international-transfer chapter comparable to GDPR, LGPD or Singapore PDPA.not_comparable · status 2026-08-30Source | 8/10The transfer-limitation obligation and official guidance state a continuing-protection model.moderate · status 2026-08-30SourceSource | 8/10Articles 33–36 enumerate transfer routes and safeguards.moderate · status 2026-08-30Source |
| Regulator design and procedural digitisationHow explicitly current official evidence establishes institutional powers and reachable procedures. A higher value measures published institutional resolution, not regulator quality. | NCThe Board is legally established and appointment activity is documented, but the cited record does not establish a mature public procedure or outcome record.not_comparable · status 2026-08-30SourceSourceSource | 9/10Chapter VI publishes independent supervisory-authority powers and cooperation structures.moderate · status 2026-08-30Source | 9/10The statute establishes the CPPA and the official site publishes current regulatory processes.moderate · status 2026-08-30SourceSource | 9/10The PDPC has an established statutory and guidance-facing institutional record.moderate · status 2026-08-30SourceSource | 8/10The LGPD establishes ANPD functions and powers in the consolidated text.moderate · status 2026-08-30Source |
| Penalty designHow explicitly current sources connect sanctions to conduct, ceilings and procedure. A higher value measures inspectability, not severity or deterrence. | 8/10The Act publishes a schedule of maximum monetary penalties and Board inquiry architecture.developing · status 2026-08-30SourceSource | 9/10Articles 58, 82–84 publish authority powers, compensation and tiered administrative-fine criteria.moderate · status 2026-08-30Source | 8/10The statute publishes administrative enforcement and a defined breach-related private action.moderate · status 2026-08-30Source | 8/10The statute publishes enforcement directions and financial-penalty architecture.moderate · status 2026-08-30Source | 8/10Articles 52–54 enumerate administrative sanctions and criteria.moderate · status 2026-08-30Source |
| MSME implementation burdenHow explicitly current official evidence allows a smaller organisation to estimate fixed work and available tailoring. A higher value means burden is more researchable, not necessarily lower. | ?The final design is published, but evidence of actual smaller-organisation implementation cost is premature before the main cohort operates.unknown · status 2026-08-30SourceSourceSource | 6/10The regulation exposes obligations and some risk-based tailoring.moderate · status 2026-08-30Source | 5/10Statutory thresholds and defined applicability help identify coverage.moderate · status 2026-08-30SourceSource | 7/10The obligations guide makes the core organisational map relatively approachable.moderate · status 2026-08-30SourceSource | 6/10The law publishes general duties and risk-sensitive elements.moderate · status 2026-08-30Source |
| Interoperability and ecosystem potentialHow explicitly current sources support reusable implementation patterns while preserving jurisdiction-specific meaning. A higher value measures documented portability, not legal equivalence. | 7/10Notice, consent, security and role concepts support identifiable implementation patterns.developing · status 2026-08-30SourceSource | 9/10Mature role, rights, security, impact and transfer structures support well-documented patterns.moderate · status 2026-08-30Source | 8/10Notice, request and preference-control structures can be mapped into reusable product patterns.moderate · status 2026-08-30SourceSource | 8/10The accountability and obligations framework supports reusable operational maps.moderate · status 2026-08-30SourceSource | 8/10Controller/operator, rights, security and transfer structures align with common privacy-program patterns.moderate · status 2026-08-30Source |
| Enforcement maturity and published guidanceHow much dated official evidence exists about guidance, decisions and operational practice. A higher value measures the observed public record, not whether enforcement is better. | NCThe framework is partially commenced and institution-building is documented, but an operational enforcement record is not yet available.not_comparable · status 2026-08-30SourceSourceSource | 10/10The regulation has applied since 2018 within an extensive supervisory ecosystem.moderate · status 2026-08-30Source | 8/10The operative statute, agency regulations and public regulatory history create a substantial record.moderate · status 2026-08-30SourceSource | 9/10The regime has an established statutory, guidance and enforcement history.moderate · status 2026-08-30SourceSource | 8/10The law and sanction framework have operated for several years with ANPD material.moderate · status 2026-08-30SourceSource |
The 17-factor agenda
How the legal architecture can be found, understood and translated into a research plan.
How easily a reader can locate and understand the relevant rule.
How much interpretation is needed before a team can identify the rule that governs its activity?Pair essay trace · Current legal statusWho, what data and which cross-border activities the framework covers.
Which entities, people, data and overseas activities fall inside the framework?Pair essay trace · Processing architectureThe legal routes available for processing personal data.
Which processing grounds exist, and how does an organisation document the one it relies on?Pair essay trace · Processing architectureHow the framework structures clear information and meaningful choice.
What must a person be told, when, and in what form before data is used?Pair essay trace · Processing architectureWhat people can understand, choose, contest and ask organisations to do.
How a person can revise a choice or stop consent-based processing.
Can a person reverse a choice through a practical, understandable route?Pair essay trace · Individual pathwayRights, complaint routes and routes to correction or redress.
Which rights exist, and what must happen before a person can obtain a remedy?Pair essay trace · Individual pathwaySpecial rules and safeguards for children and people represented by guardians.
How does the framework recognise age, guardianship and risks to younger people?Pair essay trace · Individual pathwayRules and recourse connected with automated or profiled outcomes.
What transparency or recourse applies when automated processing affects a person?Pair essay trace · Individual pathwayHow duties, safeguards, risk processes and transfer mechanisms are organised.
How responsibility is divided across organisations and service providers.
Who remains accountable when processing is delegated or shared?Pair essay trace · Organisational pathwaySafeguard duties and incident-notification pathways.
Which safeguards and breach steps are specified, and when are they triggered?Pair essay trace · Organisational pathwayStructured assessment duties for higher-risk processing.
When must an organisation investigate and document risk before processing?Pair essay trace · Organisational pathwayHow overseas transfers are permitted, restricted or documented.
Which transfer routes exist, and what continuing safeguards travel with the data?Pair essay trace · Organisational pathwayThe implementation work a smaller organisation may need to investigate.
Which obligations create fixed costs, and what tailoring exists for smaller organisations?Pair essay trace · Organisational pathwayPotential for reusable, documented technical and procedural patterns.
Could teams implement the rule through portable patterns without weakening legal context?Pair essay trace · Organisational pathwayHow rules are supervised, enforced, explained and tested through practice.
Institutional structure, powers and accessible procedures.
How can people and organisations reach the institution, and what can it do?Pair essay trace · Institutions and maturityThe published structure for sanctions and procedural safeguards.
How are sanctions linked to conduct, context and due process?Pair essay trace · Institutions and maturityThe observed record of guidance, decisions and implementation practice.
What has the framework's operation, guidance and enforcement record actually demonstrated?Pair essay trace · Institutions and maturityFour documented starting lenses
Every value is visible and reversible. No preset is named “balanced,” because balance is itself an editorial judgment.
| Research factor | Default editorial model | Individual-rights priority | SME deployability | Regulatory certainty |
|---|---|---|---|---|
| Drafting clarityreadable rules | 8 out of 10 | 4 out of 10 | 10 out of 10 | 6 out of 10 |
| Scope and reachreadable rules | 5 out of 10 | 7 out of 10 | 4 out of 10 | 6 out of 10 |
| Processing groundsreadable rules | 6 out of 10 | 7 out of 10 | 7 out of 10 | 7 out of 10 |
| Notice usabilityreadable rules | 7 out of 10 | 8 out of 10 | 8 out of 10 | 6 out of 10 |
| Preference controlindividual agency | 7 out of 10 | 10 out of 10 | 6 out of 10 | 6 out of 10 |
| Rights and remedyindividual agency | 7 out of 10 | 10 out of 10 | 6 out of 10 | 7 out of 10 |
| Children and guardiansindividual agency | 5 out of 10 | 8 out of 10 | 5 out of 10 | 6 out of 10 |
| Accountability rolesorganisational architecture | 6 out of 10 | 8 out of 10 | 5 out of 10 | 8 out of 10 |
| Security and breachorganisational architecture | 7 out of 10 | 8 out of 10 | 6 out of 10 | 7 out of 10 |
| Risk assessmentorganisational architecture | 5 out of 10 | 8 out of 10 | 3 out of 10 | 8 out of 10 |
| Automated decisionsindividual agency | 4 out of 10 | 7 out of 10 | 2 out of 10 | 6 out of 10 |
| Cross-border transferorganisational architecture | 5 out of 10 | 6 out of 10 | 4 out of 10 | 7 out of 10 |
| Regulator designinstitutions and remedy | 6 out of 10 | 7 out of 10 | 6 out of 10 | 9 out of 10 |
| Penalty designinstitutions and remedy | 5 out of 10 | 7 out of 10 | 4 out of 10 | 7 out of 10 |
| MSME burdenorganisational architecture | 8 out of 10 | 2 out of 10 | 10 out of 10 | 4 out of 10 |
| Interoperabilityorganisational architecture | 7 out of 10 | 5 out of 10 | 7 out of 10 | 5 out of 10 |
| Enforcement maturityinstitutions and remedy | 7 out of 10 | 8 out of 10 | 4 out of 10 | 10 out of 10 |
A broad starting lens that keeps deployability and maturity visible without treating either as decisive.
Brings rights, withdrawal, children and accountable decision-making to the front of the reading list.
Prioritises comprehension, notice design and implementation burden for smaller organisations.
Prioritises mature guidance, institutional design and documented accountability pathways.
Legal-status vocabulary
Source type and legal status are separate. An official explainer can be authoritative context without being binding text.
The cited provision or instrument is operative on the editorial as-of date.
The text is final and notified, but the cited provision has a future commencement date.
The material is a proposal, consultation or draft and is not treated as binding law.
An official explanation or guidance record; it does not replace binding legal text.
A contestable interpretation by DPDP Editorial Desk, not a statement of law.
Observed implementation evidence that is not itself a legal duty.
Different provisions in the same instrument have different operative dates.
Source hierarchy
Statutes, regulations, Gazette notices and official consolidated texts establish the legal baseline.
Useful for interpretation and procedure, but never used to override the controlling legal text.
Observed service or tooling evidence is labelled as evidence—not silently converted into a legal requirement.
Every thesis remains contestable, dated and separate from claims about the law itself.
Method in practice
The controls update only the URL and browser view. They create no account, server profile, compliance result or hidden weighting.
Article revision record
This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.
METHOD-20260830-01METHOD-20260826-01