Read the original article: CSO’s ultimate guide to security and privacy laws, regulations, and compliance
This directory includes laws, regulations and industry guidelines with significant security and privacy impact and requirements. Each entry includes a link to the full text of the law or regulation as well as information about what and who is covered.
CSO updates this directory, originally published on January 28, 2021, frequently as new laws and regulations are put in place.
Click on a link to skip to information and resources on that law:
Broadly applicable laws and regulations
- Sarbanes-Oxley Act (SOX)
- Payment Card Industry Data Security Standard (PCI DSS)
- Payment Service Directive, revised (PSD2)
- Gramm-Leach-Bliley Act (GLBA)
- Customs-Trade Partnership Against Terrorism (C-TPAT)
- Free and Secure Trade Program (FAST)
- Children’s Online Privacy Protection Act (COPPA)
- Fair and Accurate Credit Transaction Act (FACTA), including Red Flags Rule
- Federal Rules of Civil Procedure (FRCP)
Industry-specific guidelines and requirements
- Federal Information Security Management Act (FISMA)
- North American Electric Reliability Corp. (NERC) standards
- Title 21 of the Code of Federal Regulations (21 CFR Part 11) Electronic Records
- Health Insurance Portability and Accountability Act (HIPAA)
- The Health Information Technology for Economic and Clinical Health Act (HITECH)
- Patient Safety and Quality Improvement Act (PSQIA, Patient Safety Rule)
- H.R. 2868: The Chemical Facility Anti-Terrorism Standards Regulation
US state laws
- California Consumer Privacy Act (CCPA)
- California Privacy Rights Act (CPRA)
- Maine Act to Protect the Privacy of Online Consumer Information
- Maryland Personal Information Protection Act – Security Breach Notification Requirements – Modifications (House Bill 1154)
- Massachusetts 201 CMR 17 (aka Mass Data Protection Law)
- Massachusetts Bill H.4806 — An Act relative to consumer protection from security breaches
- Nevada Personal Information Data Privacy Encryption Law NRS 603A
- New Jersey — An ACT concerning disclosure of breaches of security and amending P.L.2005, c.226 (S. 51)
- New York State Department of Financial Services, Cybersecurity Requirements for Financial Services Companies (23 NYCRR 500)
- New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act
- Oregon Consumer Information Protection Act (OCIPA) SB 684
- Texas – An Act relating to the privacy of personal identifying information and the creation of the Texas Privacy Protection Advisory Council
- Virginia — Consumer Data Protection Act (CDPA)
- Washington – An Act Relating to breach of security systems protecting personal information (SHB 1071)
International laws
- Personal Information Protection and Electronic Documents Act (PIPED Act, or PIPEDA) — Canada
- Law on the Protection of Personal Data Held by Private Parties — Mexico
- General Data Protection Regulation (GDPR)
Broadly applicable laws and regulations
Read the original article: CSO’s ultimate guide to security and privacy laws, regulations, and compliance