Privacy Compliance · North America

Privacy compliance for North America

Support CCPA / CPRA, USCP, GPDP and DPDx (partner-delivered) – plus general data protection assessments for USA-focused privacy programmes. PIPEDA for Canada.

4.7

★★★★★

G2 · 46+ verified reviews

375+

Customers worldwide

36+

Countries

12+

Privacy regulations & frameworks

TRUSTED BY PRIVACY, RISK AND COMPLIANCE TEAMS

Quick answer

Privacy compliance software for North America, on one page.

North America’s privacy landscape is fragmented: no US federal law, a growing patchwork of state laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, more), and PIPEDA in Canada.
PrivIQ runs CCPA/CPRA, USCP (unified consumer protection), GPDP (baseline), DPDx (partner-delivered) and PIPEDA on a single configurable platform – with state-specific overlays where required.
Who runs North American privacy on PrivIQ

US-headquartered organisations. Multi-state operators. Canadian organisations.

Three patterns dominate North American privacy programmes.
01

US-headquartered organisations

Running state-by-state compliance with a unified consumer-protection floor.

02

Multi-state operators

Companies operating across multiple state regimes needing consistent operational practice.

03

Canadian organisations

PIPEDA compliance, often with US extensions for cross-border processing.

CCPA / CPRA

Full California compliance - notices, rights workflows, sensitive data, opt-outs.

USCP framework

PrivIQ's unified US consumer-protection layer - consistent across all states.

GPDP baseline

General Personal Data Protection baseline for jurisdictions without dedicated law.

DPDx (partner)

Partner-delivered USA framework for organisations preferring methodology-led delivery.

PIPEDA

Canadian Personal Information Protection and Electronic Documents Act compliance.

Multi-state expansion

New state laws (VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA, ICDPA, TIPA) supported as the patchwork grows.

Built for both sides

Rated 4.7 on G2.
Read in their words.

375+ teams in 36+ countries use PrivIQ to run privacy, AI governance and risk programmes – from independent DPO consultants to global enterprise compliance teams.

G2 Awards · Spring 2026

Services FAQs

What buyers usually ask.

Why a unified US framework alongside state-specific compliance?

USCP provides the operational consistency that state-by-state implementation can't. State-specific overlays handle the local nuance; USCP handles the shared substance - notices, rights workflows, opt-outs, sensitive-data limits.

What about the EU-US Data Privacy Framework?

PrivIQ tracks the EU-US DPF for adequacy-based transfers to certified US recipients. For non-certified recipients, Transfer Impact Assessments still apply.

Does PrivIQ support sectoral US laws (HIPAA, GLBA, COPPA)?

PrivIQ focuses on general privacy compliance. Sectoral laws can be configured into PrivIQ's framework engine, often as overlays alongside USCP.

How does PIPEDA fit alongside US frameworks?

PIPEDA runs as its own configured framework alongside US frameworks. Multi-regulation is a common pattern for organisations operating across the US-Canada border.

What about a federal US privacy law?

PrivIQ tracks federal proposals and would update USCP and state frameworks to align with whatever federal regime emerges.