Markets
Jurisdictions
India
DPDP Act 2023, CERT-In directions, the ABDM and NHCX boundary, GST and e-invoicing, MSMED 45-day payment, stamp duty and Aadhaar eSign.
- Regulator
- the Data Protection Board of India
- Currency
- INR
- Artefacts written for this market
- 9
Australia
Privacy Act 1988 and the Australian Privacy Principles, My Health Record, TGA software-as-a-medical-device boundary, Essential Eight and data residency.
- Regulator
- the Office of the Australian Information Commissioner
- Currency
- AUD
- Artefacts written for this market
- 6
Denmark
GDPR and the Danish Data Protection Act, Datatilsynet's cloud position, international transfers after Schrems II, MedCom, NIS2 and EU MDR.
- Regulator
- Datatilsynet
- Currency
- DKK
- Artefacts written for this market
- 2
Norway
Normen, Norsk Helsenett and HelseID, Pasientjournalloven, NIS2, and EHF invoicing over Peppol.
- Regulator
- Datatilsynet
- Currency
- NOK
- Artefacts written for this market
- 3
United Arab Emirates
Federal PDPL, the Federal Law 2/2019 health-data localisation rule, DHA NABIDH and Riayati, and VAT with e-invoicing.
- Regulator
- the UAE Data Office
- Currency
- AED
- Artefacts written for this market
- 6
Everywhere else
74 artefacts carry no jurisdiction because they carry all of them: the security whitepaper, the architecture overview, the data processing agreement, the service level agreement, the exit commitment and the whole policy set. Every market page below sits on top of these rather than beside them.
Why this is a page and not a filter
Jurisdiction changes the answer, not just the wrapper
The governing law, the seat of arbitration, the regulator you would complain to, the hours you have to notify a breach, the tax on the invoice, the format that invoice must take and whether the contract attracts stamp duty are all different in each of these five markets. A single contract with a country dropdown would be wrong in four of them. So each market gets its own executed paper, and this page publishes the values that paper binds to before anybody signs it.
What is not on these pages
A claim of local certification
Pensieve holds no certification in any of these markets: no ISO 27001, no SOC 2, no HITRUST, no CE marking, no ARTG listing, and deliberately no ABDM or NHCX participation in its own name. Each market page states what does exist for that market and what the hospital, as the regulated party, continues to hold itself. The assurance page is the global version of the same statement.