For customer's protection, definitely the Consumer Protection Act is the guiding force. However, there are other laws too, like the "Distance Selling Directive," if the company engages in web/catalog/tele sales. For security, apart from patent/trademark/copyright acts, there are three main standards: ISO 27001 (Information Security Management Systems), ISO 28001 (Supply Chain Management), and CTPAT (Customs-Trade Partnership Against Terrorism). Out of these, ISO 27001 is very comprehensive; for example, background checks and workplace surveillance are just two of the 127 controls specified.
Surya