A compliance lint for your code.

Lint your app against the law it answers to. Free.

Claude Code, Codex, or any other coding agent declares what the app does and where it operates. That declaration is the whole input: no source code, schema, or data is uploaded. LexLint returns findings: which obligations apply in each jurisdiction, with citations and freshness dates. It catches the basics early. It is not legal review.

Paste the first line into the agent you already have open. No install, no account, no key.

Some agents will not fetch a page, or will not act on one they fetched. and paste that instead.

declared
generates_content, crawls_web
operates
EU, Canada, US-California
law library
WARNEU AI Act, Article 50since Providers of AI systems that interact directly with people must ensure users are informed they are dealing with an AI system unless obvious from context, and providers of generative AI must mark synthetic audio, image, video, or text output in a machine-readable, detectable format.read against its source
WARNCanada Uber Technologies Inc. v. Hellersince The joint reasons held that unconscionability requires both an inequality of bargaining power and a resulting improvident bargain.read against its source
INFOUS-California AB 2839blocked by a courtAs enacted, prohibited knowingly distributing, with actual malice, materially deceptive AI-generated election media within specified windows around an election, and required a conspicuous manipulation disclaimer for satire or parody content to qualify for that exemption.read against its source , for counsel

3 findings: 2 for code, 1 for counsel

A real run on today's LexLint law library, against a declaration of two activities and three places. See the whole run

This week in software law

What changed in the law

LexLint sweeps the wire every day across every jurisdiction in the law library, keeps what is about software law, and files each story against a law and a place. All 1,638 stories in the press →

You need LexLint if

  • You or your AI agent crawl, train on, or republish other sites' content.
  • AI writes any content your users see.
  • Your app holds personal data, voices, or faces.
  • Under-18s can reach your app, or you check that they can't.
  • Your app has users in more than one country.

One checked box is enough. Is the legal risk real?

I build the app.

Run it in the coding CLI you already have open, read the findings in the terminal, and fix the cheap things while the code is fresh. An account keeps every run and turns each finding into a work item.

A run in the LexLint portal, developer view: six places checked, nine things to do, three with counsel; 72 obligations apply now
What comes back in the portal: the run's findings as work items, one view per reader.

Building it and advising on it? Read the legal page first. It says what the product is for.

The clocks an incident starts

A breach, an exposed person's data, a service down: 254 instruments in 176 jurisdictions set a deadline, each with its own recipient and its own start. LexLint draws every deadline on a single time axis, one flag per clock.

Do you know what to do at each stage of your incident clock?

Sped up. The line is this moment on the drawing; the flags behind it are deadlines already reached.

Every reporting clock in the law library on one time axis, with the SAFE proposal's rungs beside them 275 marks in four lanes, one per instrument at each of its rungs: 62 in the first day, 138 in the first week, 58 in the first month, 17 in the first quarter. The axis is logarithmic from one hour to ninety days. Each mark is the flag of the place whose law it is, and a link to that instrument's page, named by the place, the law and the clock it sets. First day notifications First week notifications First month final reports First quarter notifications The SAFE proposal, 72 hours: notify customers with credible exposure The SAFE proposal, 4 business days: submit a confidential, initial SAFE incident report The SAFE proposal, 14 days: issue a broader customer advisory when warranted The SAFE proposal, 30 days: publish a preliminary factual report, subject to security, legal and investigative constraints, and provide a preliminary control-failure analysis The SAFE proposal, 90 days: publish remediation status Security law China: National Cybersecurity Incident Reporting Measures (1 hour) Jordan: Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty (1 hour) China: National Cybersecurity Incident Reporting Measures (2 hours) European Union: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (4 hours) China: National Cybersecurity Incident Reporting Measures (4 hours) Democratic Republic of the Congo: Digital Code, Livre II: Trust Service Provider Security-Incident Notification (4 hours) Jordan: Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty (4 hours) India: CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation (6 hours) Malta: Gaming Authorisations and Compliance Directive, Notification of Information Security Breaches (12 hours) European Union: Cyber Resilience Act, Manufacturer Reporting Obligations (24 hours) European Union: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (24 hours) European Union: NIS2 Directive, Reporting Obligations (24 hours) Austria: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations (24 hours) Belgium: Loi du 26 avril 2024, Significant-Incident Notification Obligations (24 hours) Bulgaria: Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) (24 hours) Cyprus: Security of Networks and Information Systems Law, Incident Notification Obligations (24 hours) Czech Republic: Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification (24 hours) Germany: BSI-Gesetz (BSIG), Incident Notification (24 hours) Denmark: NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties (24 hours) Estonia: Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident (24 hours) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (24 hours) Finland: Kyberturvallisuuslaki, Significant-Incident Reporting Obligations (24 hours) France: Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) (24 hours) Greece: Law 5160/2024, Significant-Incident Reporting Obligations (24 hours) Croatia: Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations (24 hours) Hungary: Cybersecurity Act, Incident Notification and Cybersecurity Fine (24 hours) Ireland: National Cyber Security Bill, Incident Response Powers and Reporting Obligations (24 hours) Italy: Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification (24 hours) Lithuania: Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification (24 hours) Luxembourg: Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification (24 hours) Latvia: Nacionālās kiberdrošības likums, Incident Notification (24 hours) Malta: Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Significant-Incident Reporting to the National CSIRT (24 hours) Netherlands: Cyberbeveiligingswet, Significant-Incident Reporting Obligations (24 hours) Poland: Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych (24 hours) Portugal: Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations (24 hours) Romania: Ordonanța de urgență nr. 155/2024, Incident Notification (24 hours) Sweden: Cybersäkerhetslag, Incident Notification (24 hours) Slovenia: Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations (24 hours) Slovakia: Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification (24 hours) United States: Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (24 hours) New York: New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent (24 hours) Micronesia: FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock (24 hours) Ghana: Cybersecurity Act, Duty to Report Cybersecurity Incident (24 hours) Jordan: Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty (1 day) Kenya: Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat (24 hours) Kiribati: Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident (24 hours) Liechtenstein: Cyber-Sicherheitsgesetz (CSG), Incident Notification (24 hours) Montenegro: Law on Information Security, Cyber Threat and Incident Reporting (24 hours) Marshall Islands: Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations (24 hours) Serbia: Law on Information Security, Incident Reporting Obligations (24 hours) Tonga: Cybersecurity Act 2025, Duty to Report a Cybersecurity Incident (24 hours) Kosovo: Law No. 08/L-173 on Cyber Security, Incident Reporting and Enforcement (24 hours) United States: Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers (36 hours) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (48 hours) Kyrgyzstan: Digital Code, digital resilience incident notification (48 hours) Ethiopia: Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT (48 hours) European Union: Cyber Resilience Act, Manufacturer Reporting Obligations (72 hours) European Union: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (72 hours) European Union: NIS2 Directive, Reporting Obligations (72 hours) Austria: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations (72 hours) Belgium: Loi du 26 avril 2024, Significant-Incident Notification Obligations (72 hours) Bulgaria: Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) (72 hours) Cyprus: Security of Networks and Information Systems Law, Incident Notification Obligations (72 hours) Czech Republic: Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification (72 hours) Germany: BSI-Gesetz (BSIG), Incident Notification (72 hours) Denmark: NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties (72 hours) Estonia: Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident (72 hours) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (72 hours) Finland: Kyberturvallisuuslaki, Significant-Incident Reporting Obligations (72 hours) France: Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) (72 hours) Greece: Law 5160/2024, Significant-Incident Reporting Obligations (72 hours) Croatia: Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations (72 hours) Hungary: Cybersecurity Act, Incident Notification and Cybersecurity Fine (72 hours) Ireland: European Union (NIS) Regulations 2018, Incident Notification (72 hours) Ireland: National Cyber Security Bill, Incident Response Powers and Reporting Obligations (72 hours) Italy: Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification (72 hours) Lithuania: Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification (72 hours) Luxembourg: Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification (72 hours) Latvia: Nacionālās kiberdrošības likums, Incident Notification (72 hours) Malta: Gaming Authorisations and Compliance Directive, Notification of Information Security Breaches (3 business days) Malta: Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Significant-Incident Reporting to the National CSIRT (72 hours) Netherlands: Cyberbeveiligingswet, Significant-Incident Reporting Obligations (72 hours) Poland: Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych (72 hours) Portugal: Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations (72 hours) Romania: Ordonanța de urgență nr. 155/2024, Incident Notification (72 hours) Sweden: Cybersäkerhetslag, Incident Notification (72 hours) Slovenia: Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations (72 hours) Slovakia: Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification (72 hours) United States: Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (72 hours) United States: Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012) (72 hours) New York: New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent (72 hours) Kyrgyzstan: Digital Code, digital resilience incident notification (72 hours) Andorra: Llei 22/2022, Incident Handling and Notification Obligation (72 hours) Micronesia: FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock (72 hours) Liechtenstein: Cyber-Sicherheitsgesetz (CSG), Incident Notification (72 hours) Montenegro: Law on Information Security, Cyber Threat and Incident Reporting (72 hours) Marshall Islands: Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations (72 hours) United States: SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05) (4 business days) Latvia: Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation (5 business days) Nigeria: Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERT (7 days) Sierra Leone: Cyber Security and Crime Act, 2021, Reporting of Cyber Security Incidents (7 days) European Union: Cyber Resilience Act, Manufacturer Reporting Obligations (14 days) Cyprus: Security of Networks and Information Systems Law, Incident Notification Obligations (15 days) Serbia: Law on Information Security, Incident Reporting Obligations (15 days) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (20 days) European Union: Cyber Resilience Act, Manufacturer Reporting Obligations (1 month) European Union: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (1 month) European Union: NIS2 Directive, Reporting Obligations (1 month) Austria: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations (1 month) Belgium: Loi du 26 avril 2024, Significant-Incident Notification Obligations (1 month) Bulgaria: Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) (1 month) Cyprus: Security of Networks and Information Systems Law, Incident Notification Obligations (1 month) Czech Republic: Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification (30 days) Germany: BSI-Gesetz (BSIG), Incident Notification (1 month) Denmark: NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties (1 month) Estonia: Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident (1 month) Finland: Kyberturvallisuuslaki, Significant-Incident Reporting Obligations (1 month) France: Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) (1 month) Greece: Law 5160/2024, Significant-Incident Reporting Obligations (1 month) Croatia: Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations (30 days) Hungary: Cybersecurity Act, Incident Notification and Cybersecurity Fine (1 month) Ireland: National Cyber Security Bill, Incident Response Powers and Reporting Obligations (1 month) Italy: Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification (1 month) Lithuania: Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification (1 month) Luxembourg: Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification (1 month) Latvia: Nacionālās kiberdrošības likums, Incident Notification (1 month) Malta: Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Significant-Incident Reporting to the National CSIRT (1 month) Netherlands: Cyberbeveiligingswet, Significant-Incident Reporting Obligations (1 month) Poland: Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych (1 month) Portugal: Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations (30 business days) Romania: Ordonanța de urgență nr. 155/2024, Incident Notification (1 month) Sweden: Cybersäkerhetslag, Incident Notification (1 month) Slovenia: Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations (1 month) Slovakia: Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification (1 month) New York: New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent (30 days) China: National Cybersecurity Incident Reporting Measures (30 days) Micronesia: FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock (30 days) Liechtenstein: Cyber-Sicherheitsgesetz (CSG), Incident Notification (1 month) Montenegro: Law on Information Security, Cyber Threat and Incident Reporting (30 days) Marshall Islands: Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations (30 days) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (40 days) 43 41 35 Privacy law El Salvador: Ley para la Protección de Datos Personales, personal data breach notification (2 hours) Idaho: Identity Theft Act, breach of security disclosure duty (24 hours) Jordan: Personal Data Protection Law, breach notification (24 hours) Russia: Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification (24 hours) Zambia: Data Protection Act, 2021, notification of a security breach (24 hours) Zimbabwe: Cyber and Data Protection Act, security breach notification (24 hours) Zimbabwe: Cyber and Data Protection Regulations 2024, security breach notification (24 hours) Ecuador: LOPDP, notificación de vulneración de seguridad (2 days) Kenya: Data Protection Act, 2019, personal data breach notification (48 hours) Rwanda: Law relating to the Protection of Personal Data and Privacy, personal data breach notification (48 hours) European Union: GDPR Articles 33-34, Breach Notification (72 hours) Austria: GDPR Articles 33-34, Breach Notification in Austria (72 hours) Belgium: GDPR Articles 33-34, Breach Notification (72 hours) Bulgaria: GDPR Articles 33-34, Breach Notification (72 hours) Cyprus: GDPR Articles 33-34, Breach Notification in Cyprus (72 hours) Czech Republic: GDPR Articles 33-34, Breach Notification (72 hours) Germany: GDPR Articles 33-34, Breach Notification in Germany (72 hours) Denmark: GDPR Articles 33-34, Breach Notification in Denmark (72 hours) Estonia: GDPR Articles 33-34, Breach Notification in Estonia (72 hours) Spain: GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification (72 hours) Finland: GDPR Articles 33-34, Breach Notification in Finland (72 hours) France: GDPR Articles 33-34, Breach Notification (72 hours) Greece: GDPR Articles 33-34, Breach Notification in Greece (72 hours) Croatia: GDPR Articles 33-34, Breach Notification (72 hours) Hungary: Infotörvény Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018 (72 hours) Ireland: GDPR Articles 33-34, Breach Notification in Ireland (72 hours) Italy: GDPR Articles 33-34, Breach Notification (72 hours) Lithuania: GDPR Articles 33-34, Breach Notification in Lithuania (72 hours) Luxembourg: GDPR Articles 33-34, Breach Notification in Luxembourg (72 hours) Latvia: GDPR Articles 33-34, Breach Notification in Latvia (72 hours) Malta: GDPR Articles 33-34, Breach Notification in Malta (72 hours) Netherlands: GDPR Articles 33-34 and UAVG Article 42, Breach Notification (72 hours) Poland: GDPR Articles 33-34, Breach Notification (72 hours) Portugal: GDPR Articles 33-34, Breach Notification in Portugal (72 hours) Romania: GDPR Articles 33-34, Breach Notification (72 hours) Sweden: GDPR Articles 33-34, Breach Notification (72 hours) Slovenia: GDPR Articles 33-34, Breach Notification (72 hours) Slovakia: GDPR Articles 33-34, Breach Notification (72 hours) United Kingdom: UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom (72 hours) Brunei Darussalam: Personal Data Protection Order 2025, breach notification (3 days) Indonesia: Law on Personal Data Protection, breach notification (72 hours) India: Digital Personal Data Protection Act, 2023, breach notification duties (72 hours) Cambodia: Cambodia's Draft Law on Personal Data Protection, personal data breach notification (72 hours) Singapore: Personal Data Protection Act, data breach notification (3 days) Thailand: Personal Data Protection Act, breach notification (72 hours) Vietnam: Law on Personal Data Protection, breach notification (72 hours) Barbados: Data Protection Act, 2019, personal data breach notification (72 hours) Belize: Data Protection Act 2021, personal data breach notification (72 hours) Ecuador: LOPDP, notificación de vulneración de seguridad (3 days) Jamaica: Data Protection Act, 2020, reporting a contravention or security breach (72 hours) Paraguay: Ley N° 7593/2025, notificación de un incidente de seguridad (72 hours) Suriname: Draft Law on the Protection of Privacy and Personal Data, breach notification (72 hours) Andorra: LQPD, personal data breach notification (72 hours) United Arab Emirates: ADGM Data Protection Regulations, breach notification (72 hours) Albania: Law No. 124/2024, notification of a personal data breach (72 hours) Bosnia and Herzegovina: Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification (72 hours) Botswana: Data Protection Act, 2024, personal data breach notification (72 hours) Belarus: Law of the Republic of Belarus On Personal Data Protection, notification of personal data protection violations (3 business days) Republic of the Congo: Law No. 29-2019, personal-data breach notification (72 hours) Djibouti: Digital Code, Book I: personal-data breach notification (72 hours) Egypt: Egypt Personal Data Protection Law, Personal Data Infringement notification (72 hours) Ethiopia: Personal Data Protection Proclamation, personal data breach notification (72 hours) Georgia: Law on Personal Data Protection, breach notification (72 hours) Gambia: Personal Data Protection and Privacy Act, 2025, personal data breach notification (72 hours) Iceland: Act No. 90/2018, Breach Notification in Iceland (72 hours) Jordan: Personal Data Protection Law, breach notification (72 hours) Kenya: Data Protection Act, 2019, personal data breach notification (72 hours) Monaco: Loi sur la Protection des Données Personnelles, notification des violations de données (72 hours) Moldova: Moldova Law No. 195/2024, personal data breach notification (72 hours) North Macedonia: Law on Personal Data Protection (LPDP), personal data breach notification (72 hours) Mauritius: Data Protection Act 2017, personal data breach notification (72 hours) Maldives: Maldives Personal Data Protection Bill, personal data breach notification (72 hours) Niger: Loi n° 2022-59, notification des violations de données (72 hours) Nigeria: Nigeria Data Protection Act, 2023, data breach notification (72 hours) Norway: Personal Data Act, Breach Notification in Norway (72 hours) Serbia: Law on Personal Data Protection, personal data breach notification (72 hours) Russia: Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification (72 hours) Rwanda: Law relating to the Protection of Personal Data and Privacy, personal data breach notification (72 hours) Seychelles: Data Protection Act, 2023, personal data breach notification (72 hours) San Marino: San Marino Law No. 171, personal data breach notification (72 hours) Somalia: Data Protection Act, 2023, personal data breach notification (72 hours) Syria: Law No. 12 of 2024 on Protection of Electronic Personal Data, personal data breach notification (3 business days) Tonga: Privacy Act 2025, personal information breaches (72 hours) Ukraine: Draft Law No. 8153, personal data breach notification (72 hours) Samoa: National Digital Identification Act 2024, personal data breach notification (72 hours) Kosovo: Law No. 06/L-082 on Protection of Personal Data, personal data breach notification (72 hours) Zimbabwe: Cyber and Data Protection Regulations 2024, security breach notification (72 hours) Iowa: Personal Information Security Breach Protection (5 business days) Ecuador: LOPDP, notificación de vulneración de seguridad (5 days) Algeria: Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données (5 days) Cayman Islands: Data Protection Act 2021 Revision, personal data breach notification (5 days) Maryland: Maryland Personal Information Protection Act (MPIPA), breach notification (7 days) Kenya: Data Protection (General) Regulations, 2021 (7 days) Puerto Rico: Ley de Información al Ciudadano sobre la Seguridad de Bancos de Información (data breach notification) (10 days) Vermont: Security Breach Notice Act (14 business days) Kenya: Data Protection (General) Regulations, 2021 (14 days) California: California Data Breach Notification Law, as amended by SB 446 (15 days) Florida: Florida Information Protection Act, breach notification (15 days) Zimbabwe: Cyber and Data Protection Regulations 2024, security breach notification (21 days) United States: GLBA Safeguards Rule Breach Notification Amendment (30 days) California: California Data Breach Notification Law, as amended by SB 446 (30 days) Colorado: C.R.S. 6-1-716, Notification of Security Breach (30 days) Florida: Florida Information Protection Act, breach notification (30 days) Maine: Notice of Risk to Personal Data (30 days) New York: Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty (30 days) Rhode Island: Identity Theft Protection Act of 2015, notification of breach (30 days) Texas: Identity Theft Enforcement and Protection Act, breach notification (30 days) Washington: Notice of security breaches involving personal information (30 days) Ontario: Personal Health Information Protection Act, 2004, breach notification by custodians and agents (30 days) Arkansas: Arkansas Personal Information Protection Act, breach notification and security (45 days) Arizona: Arizona data breach notification law (45 days) Indiana: Disclosure of Security Breach Act (45 days) Maryland: Maryland Personal Information Protection Act (MPIPA), breach notification (45 days) New Mexico: Data Breach Notification Act (45 days) Ohio: Security Breach Notification Act (45 days) Rhode Island: Identity Theft Protection Act of 2015, notification of breach (45 days) Vermont: Security Breach Notice Act (45 days) Wisconsin: Notice of unauthorized acquisition of personal information (45 days) United States: HIPAA Breach Notification Rule (60 days) Connecticut: Breach of security re computerized data containing personal information (60 days) Delaware: Computer Security Breaches (60 days) Louisiana: Database Security Breach Notification Law, notice duty (60 days) Oklahoma: Security Breach Notification Act (60 days) South Dakota: Breach of system security, notification statute (60 days) Texas: Identity Theft Enforcement and Protection Act, breach notification (60 days) 77 10 AI law, high-risk systems European Union: AI Act, Article 73 (reporting of serious incidents) (2 days) European Union: AI Act, Article 73 (reporting of serious incidents) (10 days) European Union: AI Act, Article 73 (reporting of serious incidents) (15 days) AI law, frontier models California: Transparency in Frontier Artificial Intelligence Act (SB 53) (24 hours) Illinois: Artificial Intelligence Safety Measures Act (24 hours) New York: Responsible AI Safety and Education Act (RAISE Act) (24 hours) Illinois: Artificial Intelligence Safety Measures Act (72 hours) New York: Responsible AI Safety and Education Act (RAISE Act) (72 hours) California: Transparency in Frontier Artificial Intelligence Act (SB 53) (15 days) 1 h 6 h 24 h 72 h 7 d 14 d 30 d 90 d 72 hours 4 business days 14 days 30 days 90 days
Each flag is one law, and a link to it. A keyhole into the drawing, from 12 hours to 12 days.

See every clock, and the sentence that sets it

The law library today

260jurisdictions tracked
3,160provisions on file
1,638stories on file

Counted from the law library at each build, across AI, scraping, privacy, cybersecurity, communications, content-moderation, age-gating and reuse law. The law library is rebuilt and republished daily; the research runs in waves, every provision carries the date it was last read against its source. How current is this

Your code and data are not visible to us.
The declaration is the whole request. A run reaches the portal only if you choose to upload it. What is sent, and what never is
The same deal your linter makes.
Early warning on the basics, cited to the instrument, with a note for counsel where judgment is needed. Nobody mistakes a clean lint for a QA sign-off, and a clean run never says "compliant". What it is, and what it is not
Built on public law, in the open.
Every finding cites its source and links the law note behind it where we keep one, and every note says when it was last checked against its source. The law library

Powered by

UnGovr is a nonprofit transparency platform. It builds and runs LexLint, and the LexLint law library is what the lint reads. About UnGovr →

UnGovr is an Associate Member of

Agentic AI Foundation, Associate Member The Linux Foundation, Associate Member Open Secure AI Alliance, Associate Member

The Agentic AI Foundation is the Linux Foundation initiative behind the Model Context Protocol, the standard LexLint speaks. The Open Secure AI Alliance is the Linux Foundation fund on the security of AI agents and the systems they reach. The memberships are UnGovr's own: none of the three reviews, certifies, or endorses LexLint or its findings.

UnGovr is a licensed Supporter of

CIS Critical Security Controls Supporter, read the CIS Controls against the law

CIS licenses us to show its Controls' Safeguard numbers beside the laws they bear on. The summaries and the mapping are our own; CIS has not reviewed or endorsed them. The CIS Controls, read against the law →