21st Century Cures Act
The 21st Century Cures Act is a 2016 US law whose ONC Final Rule (2020) prohibits 'information blocking' — practices that interfere with the access, exchange, or use of electronic health informatio...
The 21st Century Cures Act is a 2016 US law whose ONC Final Rule (2020) prohibits 'information blocking' — practices that interfere with the access, exchange, or use of electronic health informatio...
The Air Passenger Protection Regulations set out what Canadian air carriers owe passengers when a flight is delayed, cancelled or oversold — compensation tiers, rebooking duties, standards of treat...
APRA is Australia's prudential regulator for banks, insurers and superannuation funds, operating through binding Prudential Standards — notably CPS 234 on information security and CPS 230 on operat...
ATOL is the United Kingdom's statutory financial protection scheme for air package holidays, administered by the Civil Aviation Authority since 1973. Any business selling flight-inclusive packages ...
The Privacy Act 1988 is Australia's principal data-protection law, setting the Australian Privacy Principles that govern how personal information is collected, used, and disclosed. It is the privac...
The Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010, is the national regime governing misleading conduct, unfair contract terms and consumer guarantees. Enforced by the...
The Telecommunications Act 1997 is the framework for Australian telecommunications regulation, administered by the Australian Communications and Media Authority alongside the Radiocommunications Ac...
The Bank Secrecy Act and the anti-money-laundering rules built on it require US financial institutions — including money services businesses, which is how they reach crypto firms — to identify thei...
CAN-SPAM sets the United States rules for commercial email: accurate headers and subject lines, identification as an advertisement, a physical postal address, and a working unsubscribe honoured pro...
Regulation (EU) 2023/956 puts a carbon price on imports of cement, iron and steel, aluminium, fertilisers, electricity and hydrogen, requiring importers to report the greenhouse gas emissions embed...
The California Consumer Privacy Act, as amended and expanded by the California Privacy Rights Act, gives Californians rights over the personal information businesses hold about them — to know, to d...
The Consumer Financial Protection Bureau's Personal Financial Data Rights Rule, finalized in 2024 under Dodd-Frank Section 1033, requires covered financial institutions to make consumer financial d...
The UK Competition and Markets Authority's Retail Banking Market Investigation Order 2017 is the competition remedy that created UK Open Banking. It required the nine largest UK banks (the CMA9) to...
The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), finalized in 2024, requires impacted US payers — Medicare Advantage, Medicaid, CHIP, and ACA exchange plans — to build FHIR...
Australia's Consumer Data Right (CDR) is an economy-wide data-portability law that gives consumers the right to share their data with accredited third parties, beginning with banking (open banking)...
Canada's Consumer-Driven Banking framework is the federal open-banking regime legislated in the 2024 budget and fall economic statement, with the Financial Consumer Agency of Canada named as overse...
COPPA governs the online collection of personal information from children under thirteen in the United States. It requires verifiable parental consent before collection, limits retention, requires ...
Directive (EU) 2024/1760 requires large companies operating in the EU to identify, prevent, mitigate and account for adverse human rights and environmental impacts across their own operations, thei...
The Digital Markets Act designates large platforms that act as important gateways between businesses and consumers as "gatekeepers" and imposes ex-ante obligations on them — around self-preferencin...
The DMCC Act gives the Competition and Markets Authority a standing digital-markets regime. The CMA may designate a firm as holding Strategic Market Status in a digital activity and then impose tai...
Section 1033 of the 2010 Dodd-Frank Wall Street Reform and Consumer Protection Act gives US consumers a statutory right to access their financial data in a usable electronic form. It is the legal a...
DORA is the EU regulation governing information and communication technology risk across the financial sector — banks, insurers, investment firms, payment institutions, crypto-asset providers and m...
Title II of the US Drug Quality and Security Act, requiring an interoperable, electronic, package-level traceability system for prescription drugs across manufacturers, repackagers, wholesale distr...
The Digital Technology Assessment Criteria (DTAC) is the NHS's national baseline that digital health technologies are assessed against before being adopted across the health and care system. Introd...
U-space is the European framework for managing large numbers of drones in shared airspace. It defines mandatory services — network identification, geo-awareness, flight authorisation and traffic in...
eIDAS is the EU regulation governing electronic identification and trust services — including the qualified website (QWAC) and seal (QSEAL) certificates that identify regulated third parties in ope...
The Electronic Conveyancing National Law is the uniform legislation, enacted state by state across Australia, that authorises electronic lodgement and settlement of property transactions. It establ...
The ePrivacy Directive governs privacy in electronic communications across the European Union, regulating the confidentiality of communications, traffic data, and — most relevantly for network APIs...
ESIGN is the US federal statute giving electronic signatures and records the same legal effect as their paper equivalents, and UETA is the uniform state law adopted in almost every state that does ...
The EU Artificial Intelligence Act is the world's first comprehensive, horizontal regulation of artificial intelligence — a risk-tiered regime that bans some practices outright, imposes conformity ...
Regulation (EU) 2023/1781 establishing a framework to strengthen Europe's semiconductor ecosystem — investment in first-of-a-kind facilities, a pilot-line and design infrastructure pillar, and a co...
The EU Cyber Resilience Act is the first horizontal law to impose cybersecurity obligations on products with digital elements across their whole lifecycle — secure-by-design and secure-by-default r...
The EU Data Act governs who may access and use the data generated by connected products and related services, and requires cloud and data-processing providers to enable switching between them. Unli...
The Machinery Regulation replaces the Machinery Directive across the EU and extends it to software that performs a safety function, machines with self-evolving behaviour, and digital documentation....
The EU Medical Device Regulation (Regulation (EU) 2017/745, MDR) governs the safety and performance of medical devices placed on the European market, and — critically for digital health — brings mu...
Regulation (EU) 2023/1115 prohibits placing specified commodities — cattle, cocoa, coffee, oil palm, rubber, soya and wood, and products derived from them — on the EU market unless they are defores...
The European Accessibility Act requires a defined set of products and services — including e-commerce, e-books, banking services and consumer digital services — to meet accessibility requirements, ...
Part 107 governs commercial small unmanned aircraft operation in the United States — pilot certification, operating limits, and the waiver and authorization process for flying beyond them. Part 89,...
The FATF Travel Rule requires originator and beneficiary information to travel alongside a transfer between regulated institutions. Extended to virtual asset service providers in 2019, it obliges c...
The United Kingdom regulates insurance through two bodies: the Financial Conduct Authority for market conduct and the Prudential Regulation Authority, part of the Bank of England, for prudential so...
The Fair Credit Reporting Act is the US law governing the collection, use, and sharing of consumer credit information, giving consumers rights to access and dispute their data held by credit report...
FERC Order 889, issued in 1996 alongside the Order 888 open-access rules, requires public utilities that own or control interstate transmission to operate an Open Access Same-Time Information Syste...
FERPA is the United States statute governing the privacy of student education records. It gives parents, and students once they turn eighteen, the right to inspect and seek correction of those reco...
The FDA rule implementing Section 204 of the Food Safety Modernization Act, requiring persons who manufacture, process, pack or hold foods on the Food Traceability List to keep key data elements fo...
The General Data Protection Regulation is the EU's comprehensive data-protection law (retained in the UK as the UK GDPR), governing how personal data is processed, consented to, and ported. It is t...
The Gramm-Leach-Bliley Act is the 1999 US law governing how financial institutions handle and protect consumers' nonpublic personal information, including the Privacy Rule and the Safeguards Rule. ...
HIPAA is the 1996 US law that governs the privacy and security of protected health information (PHI). Its Privacy Rule sets the terms under which PHI may be used and disclosed and grants patients a...
The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009 as part of the American Recovery and Reinvestment Act, funded the nationwide adoption of electronic ...
Resolution 787 is the IATA industry resolution, adopted in 2012, that authorised New Distribution Capability — the XML messaging standard for airline retailing. It is not law and no regulator enfor...
Resolution 824 establishes the Passenger Sales Agency Agreement — the standard contract between IATA member airlines and accredited travel agencies, and the basis of the accreditation regime that d...
Resolution 850m governs Agency Debit Memos — the instrument by which an airline charges an accredited agency for a breach of fare rules, booking policy or distribution terms. ADMs are the enforceme...
Internet Data Exchange is the National Association of REALTORS policy framework, implemented through each local MLS's own rules, that permits participating brokers to display other brokers' listing...
The International Telecommunication Union is the United Nations agency for information and communication technologies, and its Constitution, Convention and Radio Regulations form the treaty framewo...
The Lieferkettensorgfaltspflichtengesetz obliges companies above an employee threshold with a presence in Germany to conduct human rights and environmental due diligence in their own operations and...
The McCarran-Ferguson Act is the 1945 US statute that delegated the regulation of insurance to the states and exempted the business of insurance from most federal law where a state already regulate...
MiCA is the EU regulation that brings crypto-asset issuance and services inside a single authorisation regime. It covers asset-referenced tokens and e-money tokens — the stablecoins — with reserve,...
The Markets in Financial Instruments Directive II and its accompanying regulation govern investment services across the EU — including pre- and post-trade transparency obligations, the unbundling o...
The NAIC is the standard-setting and coordinating body of the United States' fifty state insurance regulators. It writes model laws and regulations that states may adopt, accredits state department...
Policy Statement 7.90 of the National Association of REALTORS' Multiple Listing Service policy requires association-owned MLSs to certify against the RESO Data Dictionary and RESO Web API within on...
The NHS Data Security and Protection Toolkit (DSPT) is an annual online self-assessment that organizations must complete to demonstrate they meet the National Data Guardian's data security standard...
NIS2 is the EU's second-generation network and information security directive, widening the scope of regulated 'essential' and 'important' entities across eighteen sectors, imposing baseline risk-m...
Ofgem's Data Best Practice Guidance sets the data obligations of Great Britain's energy network licensees. Published in November 2021 and applied through licence conditions under the RIIO price con...
The ONC Health IT Certification Program is the US voluntary-but-effectively-mandatory program under which health IT is certified against federal criteria. Its Cures Act Final Rule 'Standardized API...
Ontario Regulation 633/21, made under section 25.35.8 of the Electricity Act, 1998, requires Ontario electricity and natural gas local distribution companies to make customer energy data available ...
The Open Government Licence is the United Kingdom's standard legal instrument for releasing public sector information for reuse. Administered by The National Archives, it grants a worldwide, royalt...
OSFI is Canada's federal prudential regulator for banks and insurers, and Guideline B-13 sets its expectations for technology and cyber risk management, alongside Guideline B-10 on third-party risk...
The Package Travel and Linked Travel Arrangements Regulations 2018 implement the EU Package Travel Directive in UK law, extending long-standing package-holiday protections to modern dynamic packagi...
The Personal Health Information Protection Act (PHIPA) is Ontario's health-sector privacy law, in force since 2004 and overseen by the Information and Privacy Commissioner of Ontario. It governs ho...
PIPEDA is Canada's federal private-sector privacy law, governing how organizations collect, use, and disclose personal information in the course of commercial activity. It is the privacy backdrop a...
PSD2 is the European Union directive that opened bank payment accounts to licensed third parties, mandating that banks provide access to accounts (XS2A) for account-information and payment-initiati...
PSD3 (the third Payment Services Directive) and the accompanying Payment Services Regulation (PSR) are the European Union's proposed successors to PSD2, intended to fix its uneven execution — tight...
Quebec's Law 25 is the province's modernization of personal-information protection, introducing consent requirements, breach notification, privacy-by-default, automated-decision transparency and a ...
The Retail Payment Activities Act is Canada's federal law bringing payment service providers under supervision by the Bank of Canada, requiring registration and operational-risk and safeguarding st...
The EU's material-compliance regime for electrical and electronic equipment — RoHS restricting hazardous substances in products, WEEE governing collection and recycling, and REACH requiring declara...
Sarbanes-Oxley requires management of US public companies to assess and attest to the effectiveness of internal control over financial reporting, with auditor attestation alongside. Sections 302 an...
Section 508 requires US federal agencies — and, through procurement rules and state adoptions, the institutions that take federal funds — to make information and communications technology accessibl...
SOPIPA is California's student privacy law, and the template most other US states adopted. Where FERPA regulates what a school may disclose, SOPIPA regulates the operator directly: it prohibits tar...
Strong Customer Authentication (SCA) is the security requirement mandated by PSD2's Regulatory Technical Standards, requiring multi-factor authentication (two of knowledge, possession, and inherenc...
TEFCA is a US framework, established under the 21st Century Cures Act and operationalized by the ONC with a Recognized Coordinating Entity, that creates a nationwide floor for health information ex...
US law establishing a rebuttable presumption that any goods mined, produced or manufactured wholly or in part in the Xinjiang Uyghur Autonomous Region, or by entities on an associated list, are mad...
The Communications Act 2003 established Ofcom as the United Kingdom's converged regulator for telecommunications, broadcasting and spectrum. It governs licensing, competition, universal service and...
The Smart Energy Code is the multiparty contract governing Great Britain's smart-metering infrastructure. It binds energy suppliers, network operators and other parties to a common set of technical...
UN Regulations 155 and 156, developed under UNECE WP.29, require vehicle manufacturers to operate a certified Cyber Security Management System and Software Update Management System as a condition o...
US Bureau of Industry and Security controls under the Export Administration Regulations restricting the export, reexport and in-country transfer of advanced computing chips, semiconductor manufactu...
US legislation providing approximately $52 billion in subsidies, grants and tax credits for domestic semiconductor manufacturing, research and workforce development, with conditions on recipients c...
The Communications Act of 1934, as amended by the Telecommunications Act of 1996, is the statutory basis for US telecommunications regulation and the Federal Communications Commission's authority. ...
A Virtual Office Website is the National Association of REALTORS policy framework permitting a broker to provide MLS listing data to consumers who have registered and established a broker-consumer ...