The laws, and what they mean in practice
Privacy, AI and cybersecurity laws that shape digital trust work, from the GDPR to every US state privacy law. Each entry says who it applies to, who enforces it and when, in plain words, with the sources. Free for everyone.
Regulatory Watch follows new rules, enforcement and court decisions as they happen.
European Union 3
NIS2
Cybersecurity risk management, management accountability and staged incident reporting starting with an early warning within 24 hours.
See details · Guide in progress In forceDORA
ICT risk management, incident reporting, resilience testing and a register of ICT third-party arrangements for the financial sector.
Since 17 Jan 2025 In forceCRA
Security requirements across the life of hardware and software products, with vulnerability handling and reporting duties.
Since 10 Dec 2024US federal 4
HIPAA
Governs protected health information held by the health care system and its vendors: permitted uses and disclosures, patient rights, security safeguards for electronic records, and breach notice.
Since 14 Apr 2003 · Guide in progress In forceFTC Act Section 5
The main federal privacy enforcement tool: unfair or deceptive practices, including privacy promises not kept and unreasonable security.
Since 26 Sep 1914 · Guide in progress In forceGLBA
Privacy notices and opt-outs for sharing customer financial information, and an information security program with specific safeguards under the Safeguards Rule.
Since 12 Nov 1999 · Guide in progress In forceSEC cyber disclosure
Disclosure of material cybersecurity incidents within four business days of determining materiality, and annual disclosure of risk management and governance.
Since 5 Sep 2023US states 3
SHIELD Act
Broadened New York's breach notification law and requires reasonable administrative, technical and physical safeguards.
Since 21 Mar 2020 In force · Massachusetts201 CMR 17.00
One of the first prescriptive state security rules: a written information security program, encryption and vendor oversight.
Since 1 Mar 2010 In force · New YorkNYDFS Part 500
A detailed cybersecurity program regulation with annual certification, CISO reporting, incident notice within 72 hours and personal liability exposure for certifying executives.
Since 1 Mar 2017 · Guide in progressThis library explains laws for practitioners. It is not legal advice, and laws change: check the sources on each page and take advice from counsel before acting.