The laws, and what they mean in practice
Privacy, AI and cybersecurity laws that shape digital trust work, from the GDPR to every US state privacy law. Each entry says who it applies to, who enforces it and when, in plain words, with the sources. Free for everyone.
Regulatory Watch follows new rules, enforcement and court decisions as they happen.
US federal 12
HIPAA
Governs protected health information held by the health care system and its vendors: permitted uses and disclosures, patient rights, security safeguards for electronic records, and breach notice.
Since 14 Apr 2003 · Guide in progress In forceFTC Act Section 5
The main federal privacy enforcement tool: unfair or deceptive practices, including privacy promises not kept and unreasonable security.
Since 26 Sep 1914 · Guide in progress In forceGLBA
Privacy notices and opt-outs for sharing customer financial information, and an information security program with specific safeguards under the Safeguards Rule.
Since 12 Nov 1999 · Guide in progress In forceCOPPA
Verifiable parental consent before collecting personal information from children under 13, with notice, access and deletion rights for parents.
Since 21 Apr 2000 · Guide in progress In forceCAN-SPAM
Honest headers and subject lines, a postal address, and an opt-out honored within ten business days. No consent is required to send.
Since 1 Jan 2004 · Guide in progress In forceTCPA
Consent rules for automated and prerecorded calls and texts, the National Do Not Call Registry, and statutory damages per call.
Since 20 Dec 1991 · Guide in progress In forceFCRA
Accuracy, permissible purpose and dispute rights for consumer reports, including background checks for employment.
Since 25 Apr 1971 In forceFERPA
Parent and eligible student rights over education records, and limits on disclosing them.
Since 21 Aug 1974 In forceVPPA
Limits disclosure of what video a person watched; now a frequent basis for lawsuits over tracking pixels on video pages.
Since 5 Nov 1988 In forceGINA
Prohibits use of genetic information in employment and health insurance decisions.
Since 21 May 2008 In forceSEC cyber disclosure
Disclosure of material cybersecurity incidents within four business days of determining materiality, and annual disclosure of risk management and governance.
Since 5 Sep 2023 In forceFTC HBNR
Breach notice for health apps and similar services outside HIPAA, where unauthorized sharing counts as a breach.
Since 24 Sep 2009This library explains laws for practitioners. It is not legal advice, and laws change: check the sources on each page and take advice from counsel before acting.