Compliance Blog — Regulation Guides and Analysis
In-depth guides to privacy, cybersecurity and AI regulations worldwide: GDPR, EU AI Act, NIS2, CCPA, DORA, state privacy laws and more, updated as the rules change.
- UK Pro-Innovation Approach to AI Regulation —
UK pro-innovation AI regulation guide: scope, regulators, obligations, deadlines, penalties, compliance steps, overlaps, and current 2026 status. - NIST AI Risk Management Framework (AI RMF 1.0) —
NIST AI RMF 1.0 is a voluntary framework for managing AI risk; it guides trustworthy AI practices, has no penalties, and is being revised in 2026. - Blueprint for an AI Bill of Rights —
Non-binding U.S. OSTP Blueprint for an AI Bill of Rights: five principles, no enforcement, no compliance deadlines, and no penalties as of 15 September 2026. - Measures for Managing Generative Artificial Intelligence Services —
China’s generative AI services rules: scope, compliance duties, 2025–2026 labeling updates, deadlines, penalties, and practical steps for providers. - Brazilian Artificial Intelligence Act —
Brazil’s AI bill is not yet law as of 13 September 2026; this guide covers Bill 2338/2023’s scope, status, obligations, deadlines, penalties and compliance steps. - European Union Artificial Intelligence Act —
EU AI Act guide: scope, applicability, deadlines, penalties, compliance steps, and related laws, updated for 2026 changes and delays under Regulation 2024/1689. - Development Security Operations Framework —
NIST’s DevSecOps work package explains how to operationalize secure software development and operations; this guide covers scope, dates, obligations, enforcement, penalties, and compliance steps. - Center for Internet Security Critical Security Controls —
CIS Critical Security Controls v8.1 guide: scope, governance, update status, implementation groups, compliance mapping, deadlines, penalties, and practical adoption steps. - Control Objectives for Information and Related Technologies —
COBIT is ISACA’s enterprise IT governance framework; it remains current in 2026, with a planned late-2026 update and no legal fines. - Cloud Security Alliance Security Trust Assurance and Risk —
CSA STAR is a cloud security assurance registry with Level 1 self-assessments, Level 2 certifications, and a 2026 CCM v4.1 transition ending in December 2027. - OWASP Top 10 Web Application Security Risks —
OWASP Top 10:2025 guide covering scope, current status, key risks, compliance expectations, timelines, penalties, and practical implementation steps for web security - NIST Cybersecurity Framework 2.0 —
NIST CSF 2.0 is a voluntary cybersecurity framework with six functions, updated references, and no mandatory federal penalties; this guide covers scope, dates, and compliance steps. - Zero Trust Security Model —
Zero Trust is a security model, not a law; this guide explains current U.S. federal guidance, scope, milestones, obligations, penalties, compliance steps, and overlaps. - Statement on Standards for Attestation Engagements 18 —
SSAE 18 governs SOC 1 and SOC 2 attestation engagements; this guide covers scope, obligations, deadlines, penalties, compliance steps, and related rules. - SANS Critical Security Controls —
CIS Critical Security Controls v8.1 guide: scope, who should adopt it, core safeguards, milestones, penalties, implementation steps, overlaps, and sources for compliance teams. - ISO 31000 Risk Management —
ISO 31000:2018 remains the current risk management guideline in 2026, with an active revision underway but no published 2025–2026 amendment or delayed replacement. - Cloud Security Alliance Controls Matrix —
CSA Cloud Controls Matrix v4.1 guide covering scope, obligations, dates, penalties, compliance steps, overlaps, and official sources for cloud security teams. - ISO/IEC 27001 Information Security Management —
ISO/IEC 27001:2022 is the current certifiable ISMS standard, amended in 2024 for climate context, with 2025 transition completion from the 2013 edition. - Defense Information Systems Agency Security Technical Implementation Guides —
DISA STIGs set DoD configuration baselines for systems and software, with current 2026 releases, NIST-aligned controls, and no standalone statutory fine regime. - Swiss-US Privacy Framework —
Swiss-US Privacy Framework guide for 2026: scope, self-certification rules, enforcement, deadlines, penalties, and practical compliance steps for transfers from Switzerland to certified US companies. - EU-US Data Privacy Framework (DPF) —
EU-U.S. Data Privacy Framework governs certified transatlantic transfers; explains scope, obligations, milestones, enforcement, and related privacy laws. - Personal Data Protection Act (Singapore) —
Singapore PDPA guide for compliance officers: scope, obligations, enforcement dates, penalties, deadlines, compliance steps, overlaps, and current 2026 status - Australian Privacy Principles —
Australian Privacy Principles set Australia’s privacy baseline for most agencies and larger businesses, with 13 rules, OAIC enforcement, and major 2025–2026 reform activity. - ASEAN Model Contractual Clauses —
ASEAN Model Contractual Clauses are voluntary cross-border data transfer templates for ASEAN states, with no direct penalties, used to support compliant personal data flows. - Cybersecurity Maturity Model Certification —
Authoritative guide to CMMC 2.0: scope, applicability, 2025–2026 phase dates, current suspension of Phase 2, duties, deadlines, penalties, and compliance steps. - NIST Special Publication 800-53 —
NIST SP 800-53 is the federal security and privacy control catalog; Rev. 5.2.0 was finalized in 2025, with no 2026 changes to baselines or mandatory dates. - Health Information Technology for Economic and Clinical Health Act —
HITECH Act guide for compliance officers: scope, enforcement, deadlines, penalties, compliance steps, overlaps, and current 2025–2026 status. - NCUA Cyber Incident Notification Requirements —
NCUA’s cyber incident rule requires federally insured credit unions to notify the agency within 72 hours of a reportable incident, with enforcement and reporting channels in place. - Sarbanes-Oxley Act of 2002 (SOX) —
SOX requires U.S. public companies to maintain effective internal controls, accurate financial reporting, and auditor oversight, with criminal penalties for fraud and retention failures. - Federal Information Security Management Act —
FISMA governs federal cybersecurity programs, sets agency security duties, and remains in force under the 2014 modernization act, with no verified 2025–2026 repeal. - Computer Fraud and Abuse Act —
Federal anti-hacking law covering unauthorized computer access, protected computers, criminal penalties, and a civil claim; current through 2026 with DOJ charging guidance and no 2025–2026 statutory overhaul. - Kentucky Consumer Data Protection Act (KCDPA) —
Kentucky Consumer Data Protection Act (KCDPA) guide for 2026: scope, thresholds, rights, duties, 2025–2026 amendments, deadlines, penalties, and compliance steps. - Cyber Civilian Corps Act —
Michigan’s Cyber Civilian Corps Act creates a volunteer cyber response program, governs deployment by DTMB, and has been in force since 24 January 2018 with 2021 amendments. - Social Security Number Privacy Act —
Michigan’s Social Security Number Privacy Act limits SSN display, storage, and disposal by businesses and public bodies, with civil damages and misdemeanor penalties for willful violations. - Tennessee Information Protection Act (TIPA) —
Tennessee’s privacy law gives consumers access, correction, deletion, portability, and opt-out rights; it applies to covered controllers, took effect 1 July 2025, and is AG-enforced. - Virginia Consumer Data Protection Act (VCDPA) —
Virginia’s VCDPA applies to qualifying businesses handling Virginians’ personal data, with a 1 July 2026 ban on selling precise geolocation data and attorney general enforcement. - Delaware Personal Data Privacy Act (DPDPA) —
Delaware’s DPDPA is a comprehensive consumer privacy law effective 1 January 2025; 2026 amendments are pending final approval and would tighten scope, rights, and obligations. - Maryland Online Data Privacy Act (MODPA) —
Maryland’s privacy law bars certain data practices, grants consumer rights, and became enforceable in 2026 for covered businesses meeting Maryland thresholds. - West Virginia Consumer Credit and Protection Act —
West Virginia’s breach-notification rules under the Consumer Credit and Protection Act require notice after certain data breaches, with AG enforcement and capped civil penalties. - Identity Theft Protection Act —
North Carolina’s Identity Theft Protection Act sets breach-notification and data-security duties for businesses handling personal information, with penalties under Chapter 75. - Insurance Data Security Act —
South Carolina Insurance Data Security Act guide on scope, compliance duties, deadlines, penalties, exemptions, and 2025–2026 status for insurance licensees. - Georgia Consumer Data Protection Act (GCDPA) —
Georgia’s consumer privacy bill was not enacted in 2026; this guide explains the failed GCDPA, the related 2026 Georgia privacy enactment, and current compliance implications. - Florida Digital Bill of Rights —
Florida Digital Bill of Rights: who it covers, consumer rights, compliance duties, deadlines, enforcement, penalties, and key overlaps with other privacy laws. - Arizona Revised Statutes (A.R.S.) Title 44, Chapter 32 —
Arizona breach-notification law requires notice after personal-data breaches, sets a 45-day deadline, AG reporting, and penalties for knowing or willful violations. - Kansas Consumer Protection Act —
Kansas Consumer Protection Act overview: scope, enforcement, compliance duties, deadlines, penalties, and 2026 status, including related Kansas breach-notification rules. - Colorado Privacy Act (CPA) —
Colorado Privacy Act guide: scope, who must comply, 2025–2026 amendments, deadlines, penalties, and practical compliance steps for covered businesses in Colorado. - Wyoming Data Breach Notification Law —
Wyoming’s breach-notification law requires prompt resident notice, broader PII coverage, and record-destruction controls; this guide covers scope, duties, deadlines, penalties, and compliance. - Louisiana Database Security Breach Notification Law —
Louisiana’s breach notification law covers businesses and agencies with personal information, requires notice within 60 days, and imposes attorney general enforcement and penalties. - Iowa Consumer Data Protection Act (ICDPA) —
Iowa’s consumer privacy law took effect 1 January 2025; this guide covers scope, rights, enforcement, deadlines, penalties, and compliance steps. - Nebraska Data Privacy Act (NDPA) —
Nebraska’s Data Privacy Act gives state residents consumer privacy rights, imposes controller duties, and is enforced by the Attorney General, with penalties up to $7,500 per violation. - Massachusetts Data Privacy Law —
Massachusetts privacy legislation is still pending in 2026; this guide covers the current Massachusetts Consumer Data Privacy Act bills, scope, rights, duties, timelines, penalties, and compliance steps. - Massachusetts Data Security Regulation (201 CMR 17.00) —
Massachusetts 201 CMR 17.00 requires any holder of residents’ personal information to maintain a written security program, encrypt key data, and meet breach-safe handling rules. - Connecticut Data Privacy Act (CTDPA) —
Connecticut’s privacy law now covers more businesses, with July and October 2026 amendments expanding scope, rights, sensitive data rules, and penalties. - New Hampshire Data Privacy Act —
New Hampshire’s privacy law covers controllers meeting thresholds, grants consumer rights, and, from 1 January 2027, bans sale of children’s personal data. - Data Broker Regulation —
Vermont’s data broker registry law requires annual registration, disclosure, a surety bond, and new 2027 breach and deletion duties, with higher penalties for noncompliance. - Rhode Island Identity Theft Protection Act —
Rhode Island’s Identity Theft Protection Act now has 2025–2026 updates in progress, including tighter breach notice deadlines, expanded data definitions, and stronger security-program requirements. - Maine Data Privacy and Protections Act —
Maine’s proposed consumer privacy law, the MDPPA, phases in 2025–2027 with lower thresholds, rights, assessments, and Attorney General enforcement - Hawaii Revised Statutes Chapter 487N - Security Breach of Personal Information —
Hawaii Chapter 487N requires breach notice for personal information, with 2026 amendment efforts pending and civil penalties up to $2,500 per violation - Utah Consumer Privacy Act (UCPA) —
Utah Consumer Privacy Act overview with current 2026 amendments, applicability, rights, deadlines, penalties, compliance steps, and related laws for privacy and security teams. - Montana Consumer Data Privacy Act (MCDPA) —
Montana Consumer Data Privacy Act guide: scope, thresholds, consumer rights, 2025 amendments, deadlines, penalties, and compliance steps for businesses - Alaska Personal Information Protection Act (APIPA) —
Alaska APIPA breach-notice law requires covered entities to protect personal data, notify residents quickly after breaches, and coordinate notices to agencies and credit bureaus. - New Mexico Data Breach Notification Act —
New Mexico’s Data Breach Notification Act requires notice to residents within 45 days, AG notice for large breaches, and sets enforcement penalties and security duties. - Washington Privacy Act —
Washington privacy law guide on scope, rights, compliance duties, deadlines, penalties, and current 2026 status for privacy, security, and legal teams. - Idaho Consumer Data Protection Act (ICDPA) —
Idaho has no comprehensive consumer data privacy law; the ICDPA is a misnomer, so this guide explains the actual Idaho privacy and data-security regime. - Nevada Privacy of Information Collected on the Internet from Consumers Act (NPICICA) —
Nevada’s NPICICA gives residents an opt-out right for sales of covered information, applies to qualifying website operators and data brokers, and is enforced by the Attorney General. - Amendment to NPICICA (SB 260) —
Nevada’s SB 260 amendment to NPICICA expands “sale,” covers data brokers, adds opt-out rights, and took effect 1 October 2021. - Oregon Consumer Privacy Act (OCPA) —
Oregon Consumer Privacy Act guide: scope, rights, duties, 2026 updates, deadlines, penalties, and compliance steps for businesses, nonprofits, and counsel. - GLBA (Gramm-Leach-Bliley Act) —
GLBA requires financial institutions to disclose data-sharing practices, protect customer information, and meet privacy and safeguard rule duties enforced by the FTC and other regulators. - COPPA (Children's Online Privacy Protection Act) —
COPPA regulates online collection of children under 13’s data, with FTC amendments effective 23 June 2025 and full compliance by 22 April 2026. - FERPA (Family Educational Rights and Privacy Act) —
FERPA requires schools to protect student education records, limit disclosures without consent, and follow federal notice, access, amendment, and complaint rules. - CCPA Compliance for National Companies —
California CCPA guide for national companies: scope, thresholds, rights, deadlines, penalties, enforcement, and 2026 compliance steps for U.S. businesses. - Understanding Act on Privacy and Processing of Personal Data No. 90/2018: A Comprehensive Guide —
Iceland’s Act 90/2018 implements GDPR in domestic law, sets Persónuvernd enforcement, and has been updated through 2026 with national privacy rules, penalties, and sector carve-outs. - Local Law 144 (AI Hiring Tool Regulation) - Compliance Guide —
New York City’s AEDT law requires bias audits, public notices, and candidate disclosures before using AI in hiring, with civil penalties for noncompliance. - Texas Data Privacy and Security Act (TDPSA) - Compliance Guide —
Texas Data Privacy and Security Act guide: scope, duties, deadlines, penalties, enforcement, exemptions, and 2025-2026 updates for compliance teams. - Texas Identity Theft Enforcement and Protection Act (TITEPA) - Compliance Guide —
Texas ITEPA guide: scope, Texas AG enforcement, breach notice deadlines, penalties, compliance steps, overlaps, and key dates through 2026. - Federal Law on the Protection of Personal Data Held by Private Parties - Compliance Guide —
Mexico’s private-sector data protection law, effective 21 March 2025, regulating personal data processing, rights, compliance duties, and sanctions nationwide. - Personal Information Protection and Electronic Documents Act (PIPEDA) - Compliance Guide —
Canada’s PIPEDA privacy law for private-sector organizations: scope, compliance duties, deadlines, penalties, and current 2026 reform status. - Data Protection Act 2018 - Compliance Guide —
UK Data Protection Act 2018 guide: scope, compliance duties, 2025–2026 amendments, deadlines, penalties, and practical steps for regulated organisations. - UK GDPR - Compliance Guide —
UK GDPR compliance guide for 2026: scope, obligations, deadlines, penalties, and DUAA 2025 updates for organisations handling UK personal data. - GDPR - Compliance Guide —
GDPR applies worldwide to organizations handling EU personal data; this guide covers scope, core duties, enforcement dates, fines, compliance steps, and related EU privacy laws. - AI Transparency Bill (SB 313) - Compliance Guide —
California’s AI Transparency Act requires certain AI firms and large platforms to disclose AI-generated or altered content, with phased duties and civil penalties starting August 2, 2026. - California Privacy Rights Act (CPRA) - Compliance Guide —
California Privacy Rights Act guide: scope, who must comply, key rights, 2026 rule updates, deadlines, penalties, and compliance steps for California businesses. - California Consumer Privacy Act (CCPA) - Compliance Guide —
California CCPA guide for 2026: scope, who must comply, core obligations, deadlines, penalties, compliance steps, overlaps, FAQs, and primary sources - INGAA (Natural Gas) - Compliance Guide —
INGAA pipeline safety and compliance guide covering scope, obligations, deadlines, penalties, compliance steps, overlaps, and current 2025–2026 status updates. - PCI DSS (Payment Security) - Compliance Guide —
PCI DSS v4.0.1 is the active global card data security standard; this guide covers scope, mandates, deadlines, penalties, and compliance steps for 2026 - HIPAA (Healthcare) - Compliance Guide —
HIPAA sets national privacy and security rules for health data, covering covered entities and business associates, with 2026 penalty updates and pending security-rule amendments. - AI Governance Guidelines - Compliance Guide —
Japan’s AI Governance Guidelines are voluntary METI/MIC soft law for AI actors, with 2026 Ver. 1.2 updating 2025 guidance on governance, transparency, safety, privacy and accountability. - Understanding Administrative Provisions on Deep Synthesis Internet Information Services: A Comprehensive Guide —
China’s deep synthesis rules require real-name verification, labels, consent, moderation, and security filings for providers, with fines and corrective orders. - Understanding Act to Protect the Privacy of Online Consumer Information: A Comprehensive Guide —
Maine’s ISP privacy law requires broadband providers to obtain express opt-in consent before using or sharing customer personal information, with strict consent, notice, and revocation rules. - Understanding Act on Protection of Personal Information (Japan): A Comprehensive Guide —
Japan’s APPI governs business handling of personal data, including consent, safeguards, breach notices, cross-border transfers, and 2026 reforms still phasing in. - NYDFS Cybersecurity Regulation - Compliance Guide —
NYDFS Cybersecurity Regulation 23 NYCRR Part 500 guide with current 2026 status, phase-in dates, scope, duties, penalties, and compliance steps for regulated financial firms - New York SHIELD Act - Compliance Guide —
New York SHIELD Act guide: scope, breach notice, security safeguards, 2024-2025 amendments, deadlines, penalties, compliance steps, and related laws. - Artificial Intelligence Video Interview Act (AIVIA) - Compliance Guide —
Illinois AI Video Interview Act requires employers using AI in video interviews to disclose use, explain the system, obtain consent, restrict sharing, and delete videos on request. - Biometric Information Privacy Act (BIPA) - Compliance Guide —
Illinois BIPA guide: scope, who must comply, 2024 amendments, 2026 litigation status, deadlines, penalties, compliance steps, and related privacy laws - Information Technology Act, 2000 —
India’s IT Act 2000 governs cyber offences, intermediary liability, and data-security duties, with sections 43A and 72A still central despite later rules and amendments. - Personal Data Protection Bill (Proposed) —
Proposed personal data protection bill remains unpassed as of 2026, with no enforceable duties yet; this guide covers status, scope, obligations, deadlines, penalties, and compliance planning. - Privacy Act 1988 —
Australia’s Privacy Act 1988 governs handling of personal information, with APPs, breach-notification duties, strengthened penalties, and 2024-2026 reforms shaping current compliance. - General Data Protection Law (LGPD) —
Brazil’s LGPD guide: scope, ANPD enforcement, obligations, deadlines, penalties, compliance steps, and 2026 EU adequacy update. - Personal Information Protection Law (PIPL) —
China’s PIPL sets nationwide rules for personal information processing, extra-territorial reach, sensitive data, minors, cross-border transfers, audits, and heavy fines. - GDPR Compliance for US Companies —
GDPR applies to US companies that target or monitor EU residents, with fines up to €20 million or 4% of global turnover, plus breach and transfer duties.