← All guides
Product5 min read25 July 2026

ComplyKit Now Has 126 Free Compliance Generators: UAE PDPL + Canada PIPEDA / Bill C-27

ComplyKit adds UAE PDPL Compliance Checker (125th) and Canada PIPEDA / Bill C-27 Compliance Checklist (126th). Free, no account required.

126 Free Compliance Generators — UAE PDPL + Canada PIPEDA / Bill C-27

ComplyKit now has 126 free compliance generators — no account required. Today we're adding two highly-requested tools: the UAE PDPL Compliance Checker (125th) and the Canada PIPEDA / Bill C-27 Compliance Checklist (126th). Both cover 42 compliance items across six categories and generate a full AI compliance report.

UAE PDPL Compliance Checker (125th generator)

The UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection established the UAE's first comprehensive federal data protection framework, effective January 2, 2022. Administered by the UAE Data Office (established under Cabinet Resolution No. 44 of 2023), the law applies to all organisations in the UAE and to foreign companies processing UAE resident personal data. With the UAE's position as a global business hub — DIFC, ADGM, Dubai Internet City, Abu Dhabi tech sector — UAE PDPL compliance is increasingly a requirement for MENA expansion. The UAE PDPL Compliance Checker covers 42 key obligations across six categories:

  • Lawful Basis & Consent (Arts. 5–10): Lawful basis documentation (6 bases), consent architecture (freely given/specific/informed/unambiguous), separate explicit consent for sensitive data categories (health/genetic/biometric/financial/criminal/political/religious/racial), children's data guardian consent, purpose limitation, data minimisation, consent records
  • Data Subject Rights (Arts. 13–21): Right to access (30-day response), rectification (third-party notification), erasure, restriction, data portability (machine-readable), objection (immediate for direct marketing), rights request intake and 30-day response tracking
  • Controller Obligations & Privacy Notice (Arts. 22–29): Privacy notice at collection point (identity/purposes/legal basis/retention/rights/transfers), Arabic language availability, retention schedule with automated deletion, data accuracy, Data Processing Register (RoPA equivalent), processor contracts with required clauses, Privacy by Design and by Default
  • Security & Breach Notification (Arts. 30–33): Technical and organisational security measures appropriate to risk; 72-hour UAE Data Office breach notification; individual notification for high-risk breaches; breach incident register; processor breach notification chain
  • Cross-Border Transfers & Processor Management (Arts. 34–38): Adequacy country list (UAE Data Office); Data Transfer Agreements (DTAs) for non-adequate countries; BCRs for intra-group; cross-border transfer inventory; sub-processor controls; DIFC/ADGM regime separate assessment; vendor due diligence
  • Governance, UAE Data Office & Accountability (Arts. 39–50): Accountability framework; DPO/Privacy Officer (recommended for high-risk processing); UAE-resident representative for foreign controllers; DPIA for high-risk processing; staff training; UAE Data Office registration; penalty risk management (AED 20M administrative penalty)

Who it's for: UAE mainland and free zone companies; MNCs with UAE/MENA operations; SaaS companies serving UAE enterprise customers; financial services (DIFC/ADGM); e-commerce platforms targeting UAE consumers; healthtech, edtech, and fintech companies; legal/compliance teams preparing for UAE Data Office inquiry.

Canada PIPEDA / Bill C-27 Compliance Checklist (126th generator)

Canada's privacy law landscape is in transition: PIPEDA (the Personal Information Protection and Electronic Documents Act) remains in force while Bill C-27 (the Digital Charter Implementation Act) — proposing to replace PIPEDA with the Consumer Privacy Protection Act (CPPA) and introduce the Artificial Intelligence and Data Act (ATIDA) — moves through Parliament. Meanwhile, Québec Law 25 (Act 25) — fully in force since September 2023 — has introduced GDPR-plus obligations for all organisations collecting personal information in Québec, including mandatory PIAs for technology projects, privacy officers, 72-hour CAI breach notification, right to portability, and right to de-indexing. The Canada PIPEDA / Bill C-27 Compliance Checklist covers 42 key obligations across six categories:

  • Lawful Collection & Consent (PIPEDA Principle 3, CPPA Arts. 15–22): Consent for each purpose (knowledge and consent standard), secondary purpose limitations, express consent for sensitive information, consent withdrawal, data minimisation, Bill C-27 legitimate interest basis readiness, children's consent (under 14 verifiable parental consent)
  • Individual Rights (PIPEDA Principles 8–9, CPPA Arts. 27–36): Right to access (30-day response), correction/amendment (notation if refused; third-party notification), Bill C-27 right to erasure (minors), Bill C-27 right to portability, Bill C-27 right to explanation for automated decisions, rights request intake and OPC complaint escalation, Québec right to de-indexing
  • Accountability & Governance (PIPEDA Principle 1, CPPA Arts. 9–14): CPO/Privacy Officer designation, Privacy Management Programme, public privacy policy (plain language), PIAs (Québec technology project PIAs mandatory), data inventory and records of processing, third-party processor contracts, Bill C-27 ATIDA AI system assessment
  • Breach Notification & Security (PIPEDA Principle 7, RROSH Regulations 2018): Security safeguards appropriate to sensitivity (technical/organisational/physical), breach detection and response plan, OPC RROSH notification (as soon as feasible, 72-hour best practice), individual notification for RROSH breaches, 24-month breach records, Québec 72-hour CAI breach notification and 5-year Québec incident register, processor notification chain
  • Québec Law 25 & Provincial Laws: Privacy Officer designated and published (Art. 3.1), Québec privacy policy (French language), consent reform (no pre-ticked boxes, biometric database declaration), mandatory technology PIA (Art. 63.5), portability (Art. 27), cross-border disclosure safeguards (Art. 17), Alberta/BC PIPA assessment
  • Bill C-27 CPPA & ATIDA Readiness: CPPA applicability gap analysis, consent reform readiness (opt-in for sensitive data), transparency obligations, de-identification standards, Privacy Management Programme documentation, ATIDA high-impact AI system compliance, penalty readiness (CAD $25M/5%)

Who it's for: Canadian federally-regulated organisations; SaaS companies with Canadian customers; e-commerce and retail brands serving Canada; Québec-operating enterprises; companies with AI products targeting Canadian consumers; foreign companies processing Canadian personal data; legal/compliance teams preparing for OPC or CAI investigation.

Browse all 126 generators

All 126 free compliance generators are at /generate. No account required. Covers GDPR, CCPA, SOC 2, HIPAA, ISO 27001/27701, EU AI Act (GPAI + High-Risk), NIS2, DORA, PSD2/PSD3, FCA Consumer Duty, CSRD, CRA, NIST CSF 2.0, NIST AI RMF, NIST SP 800-53 Rev 5, CMMC 2.0, Digital Markets Act, EU Data Governance Act, EU Data Act, ePrivacy, AI Fairness, SOC 2 Trust Services Criteria, US State Privacy Laws, APRA CPS 230, APRA CPS 234, Singapore PDPA, India DPDP Act, Saudi Arabia PDPL, Australia Privacy Act 2024, Thailand PDPA, Japan APPI 2022, South Korea PIPA, PCI DSS v4.0 SAQ-D, UAE PDPL, Canada PIPEDA / Bill C-27, and more.