Adequacy

Six jurisdictions · official sources only

Every answer shows
its source.

Adequacy answers data-protection questions from a corpus built exclusively out of regulator publications — and quotes the exact passage it relied on, every time.

Q · breach notification · EU / UK

How quickly must we notify the authority after a personal data breach?

In both the EU and the UK, a notifiable breach must be reported to the supervisory authority without undue delay and no later than 72 hours after you become aware of it 01 02. Breaches unlikely to risk individuals' rights are exempt, but must still be documented internally.

  1. “…the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority…”
    [EU]GDPR, Article 33 — Notification of a personal data breach
  2. “You must report a notifiable breach to the ICO without undue delay, but not later than 72 hours after becoming aware of it.”
    [UK]ICO — Personal data breaches: a guide

What's covered

EU

European Union

GDPR (Reg. 2016/679)

UK

United Kingdom

UK GDPR + DPA 2018

US

United States

FTC Act + state laws (CCPA/CPRA)

IN

India

DPDP Act 2023

HK

Hong Kong

PDPO (Cap. 486)

AU

Australia

Privacy Act 1988

NZ

New Zealand

Privacy Act 2020

Corpus refreshed daily. Audit the full document list.

From gazette to answer

01

Watch the regulators

A daily checker polls official sources — EUR-Lex, ICO, EDPB, MeitY, PCPD, OAIC, OPC — and spots newly published texts and guidance.

02

Ingest the official text

New documents are downloaded, extracted and indexed into a citable corpus. Nothing enters the corpus that isn't an official publication.

03

Answer with the exact passage

Questions are answered only from that corpus. Every claim carries the quoted span and a link back to the regulator's own page.

Built for your tools, too

The same cited answers are available over a REST API and an MCP server, so your internal tools and AI agents can query the corpus with the keys you manage from the dashboard.

Get an API key →
curl https://api.theadequacy.com/v1/query \
  -H "Authorization: Bearer gdpr_sk_..." \
  -d '{"question": "Do we need a DPO in India?",
       "jurisdiction": "IN"}'

One plan, everything in it

Enterprise

$100 / month

  • Chat workspace with cited answers
  • REST API and MCP server access
  • All six jurisdictions, refreshed daily
  • Compliance obligations matrix