What the law makes you able to show
About this documentUpdated 2026-09-21ShowHide
Sean McDermott, Co-Founder and CEO, UnGovr
Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.
Every law named here links to its summary page on lexlint.io, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.
© 2026 UnGovr, publishing as LexLint. The text and the figures are licensed under Creative Commons Attribution-ShareAlike 4.0: share and adapt them, including commercially, with credit to LexLint (UnGovr) and under the same licence. Please contact LexLint at hello@ungovr.org to discuss other terms. Logos and wordmarks belong to their owners.
Corpus figures as of 2026-09-21.
Legal information, not legal advice. This document describes the law as written and dated; it does not apply it to any system. The notice at the foot says what that means.
Nine things an operator can be made to produce after an agent has acted: the traces, who acted, what it could reach, where a person was, what it made, what was done about it, when, what was fixed, and how long all of it has to last. The last is the one the law states in periods, and the corpus carries them.
1What this document is
What the law makes you constrain is about the run: the eight places a duty can land on an AGENT while it is working. This document is about afterwards, when somebody asks what happened. The somebody is usually one of four: a regulator with a statutory power to ask, a customer whose systems or data were involved, a person whose data was in it, or a court. What each of them can require is set by law, and it is much narrower and much more specific than the record an engineer would want to have kept.
Nine classes follow. Eight are the kinds of evidence an incident makes relevant. The ninth is how long any of it has to last, which is the one the law answers in numbers rather than in kinds, and the corpus carries those numbers.
Two neighbours carry what this document deliberately leaves out. When a report is due, and to whom, is Incident reporting clocks, which draws every reporting deadline in the corpus on one time axis. What it has cost the organisations that could not answer is Does legal action really happen?.
2How to read a class
Reading the classes
- Ours first
- The nine classes are this section's own vocabulary, named for what somebody can make you produce. The document reads the same with every alignment note removed.
- The count
- A requirement line joins a class when its own wording speaks to that class. The test is words, not judgment, and it is applied to the line rather than to the instrument around it, so a count is a floor rather than a ceiling.
- Small numbers
- Several of these classes are thin, and the thinness is the finding rather than a failure of the reading. Binding law asks for an outcome and for a record of a decision; it very rarely asks for the run-time detail an incident responder needs.
- A record, not a log
- Where a statute does ask for a record, it usually asks for a record of processing, which is a register of what an organisation does with data, and not a trace of what a system did in a particular minute. The two words are worth keeping apart while reading.
- The periods
- The retention section lists every period in force the corpus states, read out of the sentence that states it, with that sentence beside it. A period is shown as a minimum or a maximum where the sentence says which, because a bare number does not.
- A proposal, not a law
- The note under each class quotes the SAFE proposal published by the OSAA, read 2026-09-20 from its request for comments. It is a voluntary undertaking among members and binds nobody.
3The nine classes
In order. Each section names the law first and shows the corpus second.
1 · Prompts, traces and tool calls
The record of what ran and what it did.
This is the class an incident responder cares about most and the one binding law says least about. What privacy law asks for is a record of processing: the purposes, the categories of people and data, the recipients, the transfers. That is an organisational register, and it can be complete while telling you nothing about what happened at eleven o'clock on Tuesday.
The first law in the corpus to ask for the other thing is the
EU AI Act, and it is not in force yet.
Its Article 12 (record-keeping)
requires automatic event logging to be
built into a high-risk system so that it can record events over the
system's lifetime, designed to support identifying an emerging risk, a
substantial modification, and monitoring by the provider and the
deployer; Article 19 and
Article 26(6) put the keeping duty
on the provider and the deployer respectively; and
Article 21(2) lets a competent
authority ask for those logs on a reasoned request. All four apply
from 2027-12-02, not yet in effect.
In force today, the nearest thing is sectoral:
India's CERT-In Cyber Security Directions require an
organisation's system logs to be enabled, retained securely within
Indian jurisdiction on a rolling basis, and provided with an incident
report or on the authority's direction.
What each jurisdiction's law requires of a log, category by category and at length, is the research at What the law requires of logs. This class states what an operator can be made to produce; that section states which law asks for it, where, and in what form.
44 requirement lines in force · 56 provisions · 45 jurisdictions · from: privacy 28 · AI 17 · cybersecurity 15 · scraping 5
The law behind the class Show 7 of the 44 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance)
Source
as of 2026-09-19
|
|
CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022)
Source
as of 2026-09-12
|
|
Law No. 124/2024 On the Protection of Personal Data, Law No. 124/2024 (Ligj Nr. 124/2024) On the Protection of Personal Data, Arts. 1-8, 11, 22-38, 43-46 (general provisions, lawful basis, consent, controller and processor obligations, and specific-purpose exceptions), in force 31 January 2025
Source
as of 2026-09-19
|
|
Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination Duties, Lei n.º 7/17, Artigos 15.º, 16.º, 40.º e 41.º
Source
as of 2026-09-18
|
|
Law on the Protection of Personal Data of Bosnia and Herzegovina, Law on the Protection of Personal Data, Official Gazette of Bosnia and Herzegovina No. 12/25, applicable 4 October 2025, arts. 1-9, 13, 26-34, 37-45, 52-65 (excluding 57a-57b), 75-85, 88-90 (general provisions, lawful basis, controller and processor duties, security, DPIA, DPO)
Source
as of 2026-09-19
|
|
Data Protection Act, 2019, Data Protection Act, 2019 (Act 2019-29), ss. 1-7, 29-62, 65-69 and 96-100
Source
as of 2026-09-19
|
|
Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, transfert transfrontalier de données, Loi n°2017-20 du 20 avril 2018, Livre V, arts. 391-392 (transfert transfrontalier de données)
Source
as of 2026-09-19
|
Prompts, traces, tool calls, logs, configurations, model and safeguard versions and third-party dependencies
SAFE Evidence Preservation, read 2026-09-20.
2 · Agent and workload identity
Which system acted, and on whose authority.
An AGENT acting on behalf of a person raises a question the corpus barely asks: which system acted, and whose authority was it using? The identity duties in force are about people and organisations. Privacy law asks who the controller is and whether a unique identifier may be assigned to a person at all, which is the opposite question. Where an identity duty does reach a machine, it is usually the duty to say that a machine is what you are dealing with, which sits with the disclosure rules in Global AI law: 8 common threads rather than here.
This is the widest gap on the page between what a responder needs and what a statute requires, and it is worth stating plainly: if your record cannot say which agent, which version and which delegation chain produced an action, almost nothing in force today will have told you so. Jurisdiction in logs takes one part of the same problem, the jurisdiction a request was served under, and argues it as a field the record has to carry.
11 requirement lines in force · 13 provisions · 12 jurisdictions · from: privacy 5 · cybersecurity 4 · AI 3 · scraping 1
The law behind the class Show 8 of the 11 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026)
Source
as of 2026-09-07
|
|
Protection of Personal Information Act 4 of 2013 (POPIA), Protection of Personal Information Act 4 of 2013 (POPIA), ss. 1-21, 36-38 and 55-59 (application, the general conditions for lawful processing, exemptions, the Information Officer and prior authorisation)
Source
as of 2026-09-19
|
|
Cybersecurity Law: Network and Information System Security Duty, Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité, Titre II, Chapitre III, Sections I et II (art. 16, 19, 20, 21, 23)
Source
as of 2026-09-20
|
|
Swiss Criminal Code, Pornographic Depictions of Non-Genuine Sexual Acts with Minors, Swiss Criminal Code (StGB/CP/CP), SR 311.0, Art. 197 para. 4-5
Source
as of 2026-09-06
|
|
Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty, Government Regulation No. 71 of 2019 (PP PSTE), Pasal 3, 23, 24(1)-(2), 31, 32, 39, 40
Source
as of 2026-09-16
|
|
Data Protection Act, 2020, rights of data subjects and automated decision-taking, Data Protection Act, 2020 (Act 7 of 2020), ss. 5-13
Source
as of 2026-09-19
|
|
Personal Data Act (personopplysningsloven), Lov om behandling av personopplysninger (personopplysningsloven), LOV-2018-06-15-38, in force 20 July 2018
Source
as of 2026-08-24
|
|
Privacy Act 2020, Information Privacy Principles and Extraterritorial Reach, Privacy Act 2020 (NZ), No 31, ss. 4, 22 (IPP 1, 2, 13)
Source
as of 2026-09-06
|
Agent and workload identities
SAFE Evidence Preservation, read 2026-09-20.
3 · Permissions and credentials at run time
What the run could reach while it ran.
What the run could reach while it ran is the difference between an incident and a catastrophe, and it is nearly absent from binding law as a record-keeping duty. Where it appears, it appears inside security regulations as a monitoring duty with a period attached rather than as evidence to be produced: an automatic mechanism that monitors access to a database's systems, with the record kept, is the shape.
The related duty that is everywhere is the control itself rather than the record of it, which is why this class is thin here and its counterpart is not: see the tools layer of What you must constrain.
10 requirement lines in force · 9 provisions · 8 jurisdictions · from: scraping 5 · cybersecurity 3 · privacy 2
The law behind the class Show 8 of the 10 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
Marco Civil da Internet, Protection of Records and Personal Data, Lei nº 12.965/2014 (Marco Civil da Internet), arts. 7º, 10, e 12
Source
as of 2026-09-05
|
|
Decreto Legislativo 1700, illicit trafficking of computer data (art. 12-A of Ley 30096), Decreto Legislativo 1700 (24 January 2026), incorporating art. 12-A into Ley 30096, as amended by Decreto Legislativo 1741 (13 February 2026)
Source
as of 2026-09-05
|
|
Krimināllikums Sections 241, 243, 244, Automated Data Processing System Offences, Krimināllikums, 241., 243. un 244. pants
Source
as of 2026-09-06
|
|
Law on Information Security, General Security Measures, Law on Information Security, Arts. 1 to 3, 7 to 15 and 18(1) to (3)
Source
as of 2026-09-18
|
|
Ley 81 de 2019, Sobre Protección de Datos Personales, Ley No. 81 de 26 de marzo de 2019, Sobre Protección de Datos Personales, Gaceta Oficial No. 28743-A, arts. 1-4, 6-12, 14, 24-32, 44 and 47 (general provisions, lawful basis and accountability)
Source
as of 2026-09-19
|
|
Organic Act on the Protection of Personal Data, Loi organique n° 2004-63 du 27 juillet 2004, portant sur la protection des données à caractère personnel, arts. 1-12, 16-26, 44-49, 53-61, 66-74, 104-105 (comprehensive regime)
Source
as of 2026-09-19
|
|
|
|
Security requirements for Internet-connected devices, ORS 646A.813 (added by 2019 c.193 (H.B. 2395-A) sec. 1; amending ORS 646.607)
Source
as of 2026-09-12
|
Permissions and credentials available during the run
SAFE Evidence Preservation, read 2026-09-20.
4 · Human approval and intervention
Where a person was, and what they could do.
Where a person was, and what they could do about the outcome, is the
evidence question privacy law answers best. The right not to be subject
to a solely automated decision produces a duty of meaningful human
review before such a decision is finalised, and that review is a fact
somebody can later be asked to show. The corpus holds it
jurisdiction by jurisdiction, as a national reading of
the EU GDPR's data-subject rights chapter in Europe and as its
own provision elsewhere.
AI law is about to ask for the same ground in its own right.
The EU AI Act's Article 14 (human oversight)
(from 2027-12-02, not yet in effect; that date
is for a system classified as high-risk under Annex III, and a system
classified under Annex I follows on the later date the instrument's
page states) makes the provider design the system so the people
assigned to oversee it can understand its capacities and limits,
interpret its output, decide not to use it, override or reverse it, and
stop it, and makes the deployer assign that oversight to people with
the competence, training and authority to exercise it. Read as
evidence, that is two things to produce rather than one: what the
system was built to let a person do, and who held the authority to do
it on the day.
For an AGENT the practical trap is that the review has to be real and has to be recorded as what it was. A person who clicked approve on a queue of four hundred items has not reviewed them, and a record that cannot distinguish that from a considered decision is evidence of the wrong thing.
48 requirement lines in force · 52 provisions · 50 jurisdictions · from: privacy 44 · AI 10
The law behind the class Show 8 of the 48 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
GDPR Articles 12-22, Data Subject Rights, Regulation (EU) 2016/679, Arts. 12-22
Source
as of 2026-08-23
|
|
CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222
Source
as of 2026-09-08
|
|
Data (Use and Access) Act 2025 Section 80, Automated Decision-Making, UK GDPR Articles 22A-22D, Data (Use and Access) Act 2025, c. 18, §80 (new UK GDPR Arts. 22A-22D); S.I. 2026/425
Source
as of 2026-08-24
|
|
GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany, Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37
Source
as of 2026-08-24
|
|
GDPR Article 22, Automated Decision-Making in Ireland, Regulation (EU) 2016/679, Art. 22, as transposed by the Data Protection Act 2018
Source
as of 2026-08-24
|
|
GDPR Article 22 and the Garante's OpenAI/ChatGPT Enforcement, Regulation (EU) 2016/679, Art. 22; Garante Provvedimento 30 marzo 2023
Source
as of 2026-08-24
|
|
GDPR Article 22, Right Against Automated Individual Decision-Making, Regulation (EU) 2016/679, Art. 22
Source
as of 2026-08-24
|
|
GDPR and UAVG Articles 40-43, Data-Subject Rights and Journalistic Exception, Regulation (EU) 2016/679, Arts. 12-23; UAVG, Arts. 40, 41, 43
Source
as of 2026-08-24
|
Human approval and intervention events
SAFE Evidence Preservation, read 2026-09-20.
5 · Artefacts created or changed
What the run made, marked or moved.
What the run made, and what it changed. Two duties meet here. The
first is marking:
the EU AI Act's Article 50 (transparency)
(since 2026-08-02) requires synthetic content to be marked
in a machine-readable way, and
South Korea's AI Framework Act, Article 31
requires the same of AI outputs there, so the artefact itself carries
part of the evidence. The second is integrity: a record that can be altered
without trace is not evidence, and several security regimes say so in
their own words.
An AGENT that writes files, posts content or edits records produces artefacts in other people's systems, which is where the COUNTERPARTY sits. Those artefacts are somebody else's evidence as much as yours.
29 requirement lines in force · 39 provisions · 38 jurisdictions · from: AI 20 · privacy 13 · scraping 7 · cybersecurity 2
The law behind the class Show 7 of the 29 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
AI Act, Article 50 (transparency obligations for AI systems and synthetic content), Regulation (EU) 2024/1689, Article 50
Source
as of 2026-08-14
|
|
California AI Transparency Act (SB 942, as amended by AB 853), Cal. Bus. and Prof. Code Sections 22757 to 22757.6
Source
as of 2026-08-14
|
|
TSE Resolution, AI-Generated Content Disclosure Duty, Resolução TSE nº 23.610/2019, art. 9º-B (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024)
Source
as of 2026-09-05
|
|
Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026)
Source
as of 2026-09-07
|
|
Law on Artificial Intelligence, transparency obligation, Law No. 134/2025/QH15, art. 11
Source
as of 2026-09-06
|
|
Security Standards for Smart Devices, Cyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1
Source
as of 2026-09-12
|
|
LQPD, rights of the data subject, Llei 29/2021, arts. 15-26 (rights of the data subject)
Source
as of 2026-09-19
|
Files and external artifacts created or modified
SAFE Evidence Preservation, read 2026-09-20.
6 · Detection, containment and recovery
What was noticed, stopped and put back.
What was noticed, what was stopped, and what was put back.
The EU NIS2 Directive's Article 21 names incident handling, business
continuity including backup management, and crisis management among its
minimum measures, so the existence of the capability is itself a duty.
The evidence duty arrives through the notification rules: most breach
and incident regimes in the corpus require the notification to describe
the measures taken or proposed, which means the response has to be
recorded as it happens rather than reconstructed afterwards.
67 requirement lines in force · 71 provisions · 61 jurisdictions · from: privacy 40 · cybersecurity 36 · scraping 4
The law behind the class Show 7 of the 67 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
NIS2 Directive, Cybersecurity Risk-Management Measures, Directive (EU) 2022/2555, Art. 21
Source
as of 2026-09-08
|
|
Cybersecurity Law, Information System Classification and Protection Measures, Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10
Source
as of 2026-09-16
|
|
BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities, BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38
Source
as of 2026-09-12
|
|
European Union (NIS) Regulations 2018, Security Requirements, S.I. No. 360/2018, Regs. 17 and 21
Source
as of 2026-09-12
|
|
Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures, D.Lgs. 4 settembre 2024, n. 138, Artt. 23 e 24
Source
as of 2026-09-12
|
|
Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance, Cyberbeveiligingswet, Artt. 21 en 24
Source
as of 2026-09-12
|
|
Nigeria Data Protection Act, 2023, data breach notification, Nigeria Data Protection Act, 2023, data breach notification (s. 40; GAID 2025, art. 33)
Source
as of 2026-09-19
|
Detection, containment and recovery events
SAFE Evidence Preservation, read 2026-09-20.
7 · The incident timeline
When each of those things happened.
When each of those things happened is the most heavily regulated class on this page, because almost every reporting duty in the corpus is stated as a period running from a moment. That makes two facts legally significant that an engineer might not log at all: the moment the organisation became aware, and the moment the incident began.
The EU Cyber Resilience Act's Article 14, which puts the duty on
the manufacturer, is the clearest example of a staged
timeline: an early warning within 24 hours of becoming aware, a
notification within 72, and a final report no later than fourteen days
after a corrective measure becomes available. Every such deadline in
the corpus, with the sentence it was read from, is drawn on one axis
in Incident reporting clocks.
341 requirement lines in force · 252 provisions · 142 jurisdictions · from: privacy 259 · cybersecurity 121 · AI 29 · scraping 1
The law behind the class Show 7 of the 341 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
Digital Services Act, Article 37 (independent audit of very large online platforms and search engines), Regulation (EU) 2022/2065, Article 37, supplemented by Commission Delegated Regulation (EU) 2024/436
Source
as of 2026-09-15
|
|
Transparency in Frontier Artificial Intelligence Act (SB 53), Cal. Bus. and Prof. Code Sections 22757.10 to 22757.16
Source
as of 2026-09-08
|
|
|
|
S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications, Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009
Source
as of 2026-09-06
|
|
UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom, UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025
Source
as of 2026-08-24
|
|
LGPD, rights of the data subject, Lei nº 13.709, de 2018 (LGPD), arts. 17-22 (rights of the data subject)
Source
as of 2026-09-19
|
|
Law on Personal Data Protection, breach notification, Law No. 91/2025/QH15, Article 23
Source
as of 2026-08-29
|
A complete incident timeline
SAFE Evidence Preservation, read 2026-09-20.
8 · Reproduction and remediation
What was fixed, and how that was shown.
What was fixed, and how that was shown. The final-report duties are
where this becomes evidence rather than engineering:
the EU NIS2 Directive's Article 23 and
the EU Cyber Resilience Act's Article 14 both end
their staged sequence with a report, and
the EU AI Act's Article 55 requires a provider of a model with
systemic risk to document and report corrective measures taken or
planned. Elsewhere the same idea appears as a corrective-action duty
attached to a regulator's finding.
Reproduction is the half the law does not ask for and an incident needs most. Nothing in the corpus requires an OPERATOR to be able to run the failing case again, which for a non-deterministic system is the difference between a fix and a hope.
58 requirement lines in force · 58 provisions · 49 jurisdictions · from: cybersecurity 54 · privacy 12 · AI 6
The law behind the class Show 7 of the 58 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk), Regulation (EU) 2024/1689, Article 55
Source
as of 2026-09-20
|
|
Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information, Tex. Bus. & Com. Code sec. 521.052
Source
as of 2026-09-12
|
|
Law on Artificial Intelligence, incident management and reporting obligation, Law No. 134/2025/QH15, art. 12
Source
as of 2026-09-20
|
|
BSI-Gesetz (BSIG), Incident Notification, BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32
Source
as of 2026-09-12
|
|
Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification, D.Lgs. 4 settembre 2024, n. 138, Art. 25
Source
as of 2026-09-12
|
|
Cyberbeveiligingswet, Significant-Incident Reporting Obligations, Cyberbeveiligingswet, Artt. 25-29
Source
as of 2026-09-12
|
|
New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent, 23 NYCRR 500.17
Source
as of 2026-09-20
|
Reproduction testing and remediation evidence
SAFE Evidence Preservation, read 2026-09-20.
9 · How long the record has to last
The one class the law states in periods.
How long any of it has to last is the one question the law answers in numbers. The corpus states the period as prose inside the obligation sentence, so the periods below are read out of those sentences when this page is built, by the rule in section 2, and each is shown with the sentence it came from.
12 of the 128 requirement lines in force in this class state a period a record has to last. They run from 10 days to ten years, and they are not the same kind of number: some are the shortest you may keep something, others the longest.
|
Loi n° 1/10, Articles 3, 4(3) and 14: security-of-service duty and diligence penalty for network operators and service providers, Loi n° 1/10 du 16 mars 2022 portant prevention et repression de la cybercriminalite au Burundi, Arts. 3, 4(3), 14
Source
as of 2026-09-19
|
|
Sécurité des systèmes d'information (dispositions communes), Loi N° 027/2023 du 11 juillet 2023, Titre III, Chapitre III, Section 2, arts. 28-35
Source
as of 2026-09-18
|
|
Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications, Communications and Broadcasting Act 2018 (No. 21 of 2018), ss. 48-49, 70-71
Source
as of 2026-09-19
|
|
Security Standards for Smart Devices, Cyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1
Source
as of 2026-09-12
|
|
CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022)
Source
as of 2026-09-12
|
|
Ley No. 787, Ley de Protección de Datos Personales, Ley No. 787, 29-Mar-2012, Gaceta Oficial No. 61, arts. 1-6, 9, 11-13, 19, 22-24, 27
Source
as of 2026-09-19
|
|
CCPA Cybersecurity Audit Regulations, Cal. Code Regs. tit. 11, Sections 7120 to 7124
Source
as of 2026-09-15
|
|
Privacy Protection Regulations (Data Security), information security programme, Privacy Protection Regulations (Data Security), 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement)
Source
as of 2026-09-18
|
|
HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313)
Source
as of 2026-08-23
|
|
Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties, Loi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 26, 29, 32 et 34, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020)
Source
as of 2026-09-17
|
|
CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022)
Source
as of 2026-09-12
|
|
Federal Law No. 572-FZ, Unified Biometric System for Identification and Authentication, Federal Law No. 572-FZ of 29 December 2022 "On the identification and/or authentication of individuals using biometric personal data"
Source
as of 2026-08-24
|
Two things this table does not show. Periods stated as a test rather
than a number, no longer than is necessary for the purpose being the
commonest of them, bind just as hard and cannot be drawn on a scale.
And the period that will matter most to an agent is not here yet:
the EU AI Act's Article 19 and
Article 26(6)
require the automatically generated logs of a high-risk AI system to be
kept for a period appropriate to the intended purpose and at least six
months, and both apply from 2027-12-02, not yet in effect.
128 requirement lines in force · 139 provisions · 101 jurisdictions · from: privacy 112 · cybersecurity 22 · AI 11 · scraping 8
The law behind the class Show 7 of the 128 requirement lines in forceHide them
Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.
|
California Consumer Privacy Act, as amended by the California Privacy Rights Act (Proposition 24), Cal. Civ. Code section 1798.100 et seq. (CCPA, as amended by the CPRA)
Source
as of 2026-08-23
|
|
HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313)
Source
as of 2026-08-23
|
|
Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information, Tex. Bus. & Com. Code sec. 521.052
Source
as of 2026-09-12
|
|
Marco Civil da Internet, Protection of Records and Personal Data, Lei nº 12.965/2014 (Marco Civil da Internet), arts. 7º, 10, e 12
Source
as of 2026-09-05
|
|
CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022)
Source
as of 2026-09-12
|
|
Text and Data Mining Exceptions, Copyright and Related Rights Act 2000 ss. 53A-53B, European Union (Copyright and Related Rights in the Digital Single Market) Regulations 2021 (S.I. No. 567 of 2021), regs. 3-4, inserting and amending ss. 53A and 53B of the Copyright and Related Rights Act 2000
Source
as of 2026-09-06
|
|
Security Standards for Smart Devices, Cyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1
Source
as of 2026-09-12
|
None. The SAFE Evidence Preservation list says what to preserve and never for how long, which is the one question the corpus answers in numbers.
4The shape of the answer
Read across the nine sections and the law's priorities are plain, and they are not an incident responder's. The class with the most binding law behind it is the incident timeline (341 requirement lines in force). The class with the least is permissions and credentials at run time (10). What the law asks you to produce is mostly the what and the when of an event that has already been judged significant. What it almost never asks you to produce is the run-time detail that would let anyone work out why the system did it.
That asymmetry is the practical finding of this document. A record built only to the standard of what is legally demandable will satisfy a regulator and leave your own engineers unable to answer the first question they will be asked. The law is a floor here in a way it is not on What the law makes you constrain, where the duties bite directly.
5What this document does not claim
It does not say what to log. It says what binding law, as the corpus held it on the date in the byline, can make an organisation produce, and it counts how much of that corpus speaks to each class. A thin class is not permission to keep nothing: contract, sectoral regulation, a customer's own requirements and the ordinary duty to be able to defend yourself all reach past it.
It also does not adopt anyone's framework. The alliance's evidence list is quoted because a reader holding it should be able to find the same ground here with the law underneath, and because the one place our list and theirs differ, retention, is worth seeing rather than smoothing over. It is a proposal, it was open for comment when it was read, and it may be revised; the law beside it is dated on every line.