Regulations
Regulations
Binding legal instruments, reproduced in their own words. Each record's scope quote, date and penalty ceiling are verbatim from the official text, with the article number and a link to the source — this library does not interpret whether a regulation applies to any particular organisation.
GDPR is Regulation (EU) 2016/679, applicable from 25 May 2018 — its territorial scope and fine ceilings are reproduced verbatim on this page.
Directive (EU) 2022/2555 (NIS2): Article 2 sets out which entities are in scope; Member States had to transpose it by 17 October 2024.
Regulation (EU) 2022/2554 (DORA) applies from 17 January 2025; Article 2 lists the financial entities and ICT third-party providers in scope.
HIPAA is Public Law 104-191 (1996); the applicability rule in 45 CFR 160.102 and the civil penalty tiers are reproduced verbatim on this page.
The CCPA is Cal. Civ. Code §§ 1798.100–1798.199.100; the "business" thresholds and the administrative fine ceiling are reproduced verbatim here.
The UK GDPR is Regulation (EU) 2016/679 as it applies in UK law; Article 3 scope and the Article 83 fine ceilings are reproduced verbatim here.
The Data Protection Act 2018 (2018 c. 12) sits alongside the UK GDPR; s.207 scope and the s.157 penalty maximums are reproduced verbatim here.
The Texas Data Privacy and Security Act applies by business-size test rather than a revenue threshold; its scope and $7,500 penalty cap are reproduced here.
Virginia's Consumer Data Protection Act has no revenue threshold: scope turns on consumer counts, and the statute's own exemption list is reproduced here.
PECR's cookie rule and penalty regime were rewritten on 5 February 2026; this record carries the wording now in force, not the superseded text.
This page is for information only and is not legal advice. It reproduces the regulation's own wording; always confirm against the primary source linked above and consult qualified counsel for how it applies to your organisation.