With over 900 laws on the use of personal information around the world, managing your privacy program law by law is becoming nearly impossible. Identifying key commonalities is a common approach, but then your program becomes a tangled web where it is difficult to tell outliers from baseline. The better approach is to define your program on an established framework that accounts for commonalities, is predictable and consistent, and accounts for exceptions.