Pensieve Labs

Search the register

Search all 478 artefacts by title, document ID or content.

Unlock NDA tier

Markets

Jurisdictions

A Danish hospital’s first question is about international transfers and NIS2. An Indian hospital’s first question is about DPDP, CERT-In and whether Pensieve is an ABDM participant. They are not the same review, and answering both from one page answers neither. Each market below has its own governing law, its own regulator, its own breach clock, its own invoice format, and its own set of executed paper.
IN

India

DPDP Act 2023, CERT-In directions, the ABDM and NHCX boundary, GST and e-invoicing, MSMED 45-day payment, stamp duty and Aadhaar eSign.

DPDPCERT-InABDMNHCXGSTMSMEDStamp duty
Regulator
the Data Protection Board of India
Currency
INR
Artefacts written for this market
9
AU

Australia

Privacy Act 1988 and the Australian Privacy Principles, My Health Record, TGA software-as-a-medical-device boundary, Essential Eight and data residency.

Privacy ActAPPsMy Health RecordTGAEssential EightIRAP
Regulator
the Office of the Australian Information Commissioner
Currency
AUD
Artefacts written for this market
6
DK

Denmark

GDPR and the Danish Data Protection Act, Datatilsynet's cloud position, international transfers after Schrems II, MedCom, NIS2 and EU MDR.

GDPRDatatilsynetSchrems IIMedComNIS2EU MDR
Regulator
Datatilsynet
Currency
DKK
Artefacts written for this market
2
NO

Norway

Normen, Norsk Helsenett and HelseID, Pasientjournalloven, NIS2, and EHF invoicing over Peppol.

NormenNorsk HelsenettHelseIDPasientjournallovenNIS2EHF
Regulator
Datatilsynet
Currency
NOK
Artefacts written for this market
3
AE

United Arab Emirates

Federal PDPL, the Federal Law 2/2019 health-data localisation rule, DHA NABIDH and Riayati, and VAT with e-invoicing.

PDPLHealth data localisationNABIDHRiayatiDESCVAT
Regulator
the UAE Data Office
Currency
AED
Artefacts written for this market
6
GL

Everywhere else

74 artefacts carry no jurisdiction because they carry all of them: the security whitepaper, the architecture overview, the data processing agreement, the service level agreement, the exit commitment and the whole policy set. Every market page below sits on top of these rather than beside them.

Open the global set

Why this is a page and not a filter

Jurisdiction changes the answer, not just the wrapper

The governing law, the seat of arbitration, the regulator you would complain to, the hours you have to notify a breach, the tax on the invoice, the format that invoice must take and whether the contract attracts stamp duty are all different in each of these five markets. A single contract with a country dropdown would be wrong in four of them. So each market gets its own executed paper, and this page publishes the values that paper binds to before anybody signs it.

What is not on these pages

A claim of local certification

Pensieve holds no certification in any of these markets: no ISO 27001, no SOC 2, no HITRUST, no CE marking, no ARTG listing, and deliberately no ABDM or NHCX participation in its own name. Each market page states what does exist for that market and what the hospital, as the regulated party, continues to hold itself. The assurance page is the global version of the same statement.