Regulations

Regulations

Binding legal instruments, reproduced in their own words. Each record's scope quote, date and penalty ceiling are verbatim from the official text, with the article number and a link to the source — this library does not interpret whether a regulation applies to any particular organisation.

GDPREU
Regulation (EU) 2016/679

GDPR is Regulation (EU) 2016/679, applicable from 25 May 2018 — its territorial scope and fine ceilings are reproduced verbatim on this page.

NIS2 DirectiveEU
Directive (EU) 2022/2555

Directive (EU) 2022/2555 (NIS2): Article 2 sets out which entities are in scope; Member States had to transpose it by 17 October 2024.

DORAEU
Regulation (EU) 2022/2554

Regulation (EU) 2022/2554 (DORA) applies from 17 January 2025; Article 2 lists the financial entities and ICT third-party providers in scope.

HIPAAUS
Public Law 104-191 (Aug. 21, 1996); Administrative Simplification rules at 45 CFR Parts 160 and 164

HIPAA is Public Law 104-191 (1996); the applicability rule in 45 CFR 160.102 and the civil penalty tiers are reproduced verbatim on this page.

CCPAUS — California
Cal. Civ. Code §§ 1798.100–1798.199.100 (Division 3, Part 4, Title 1.81.5)

The CCPA is Cal. Civ. Code §§ 1798.100–1798.199.100; the "business" thresholds and the administrative fine ceiling are reproduced verbatim here.

UK GDPRGB
Regulation (EU) 2016/679 (UK GDPR)

The UK GDPR is Regulation (EU) 2016/679 as it applies in UK law; Article 3 scope and the Article 83 fine ceilings are reproduced verbatim here.

Data Protection Act 2018GB
2018 c. 12

The Data Protection Act 2018 (2018 c. 12) sits alongside the UK GDPR; s.207 scope and the s.157 penalty maximums are reproduced verbatim here.

Texas Data Privacy and Security ActUS — Texas
Tex. Bus. & Com. Code ch. 541 (added by HB 4, 88th Legislature, Regular Session, 2023)

The Texas Data Privacy and Security Act applies by business-size test rather than a revenue threshold; its scope and $7,500 penalty cap are reproduced here.

Virginia Consumer Data Protection ActUS — Virginia
Va. Code §§ 59.1-575 et seq. (Title 59.1, Chapter 53)

Virginia's Consumer Data Protection Act has no revenue threshold: scope turns on consumer counts, and the statute's own exemption list is reproduced here.

PECRGB
S.I. 2003 No. 2426

PECR's cookie rule and penalty regime were rewritten on 5 February 2026; this record carries the wording now in force, not the superseded text.

This page is for information only and is not legal advice. It reproduces the regulation's own wording; always confirm against the primary source linked above and consult qualified counsel for how it applies to your organisation.