Law / Cybersecurity

Cybersecurity law, instrument by instrument

Every cybersecurity law instrument LexLint holds, grouped by the place that made it. Choose which stages of law to show: the map, the counts and the tables all answer to that choice. To see every area of law, follow Law in the breadcrumb above.

Where cybersecurity law applies, at the stages chosen below. A darker fill means more instruments at those stages. Point at, click, or tab to a place for the cybersecurity law that applies there.
  • 1
  • 5
  • 10
  • 20+
  • instruments shown
  • law on file, none at these stages
  • tracked, no law on file
  • not tracked
The United States is drawn as its states; its federal instruments are a row group in Countries below.

Stages of law

Stages of law to show

219 instruments in 123 places.

No commencement date on file for 27.

Unions5 in 1 place

Law made above the state, binding its members.

Stage Instrument In force from
European Union eu 5 instruments
Cyber Resilience Act, Essential Requirements and Manufacturer ObligationsRegulation (EU) 2024/2847, Art. 13 and Annex I 2027-12-11[future]
Cyber Resilience Act, Manufacturer Reporting ObligationsRegulation (EU) 2024/2847, Art. 14 2026-09-11
DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301Regulation (EU) 2022/2554, Article 19 2025-01-17
NIS2 Directive, Cybersecurity Risk-Management MeasuresDirective (EU) 2022/2555, Art. 21 2024-10-18
NIS2 Directive, Reporting ObligationsDirective (EU) 2022/2555, Art. 23 2024-10-18

Countries172 in 90 places

Grouped by region, the European Union heading its member states as a block; alphabetical within each group.

Stage Instrument In force from
Europe
European Union · 27 member states
Austria at 4 instruments
Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification ObligationsNISG, BGBl. I Nr. 111/2018, §§ 19 und 21 2018-12-28
Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service ProvidersNISG, BGBl. I Nr. 111/2018, §§ 17 und 21 2018-12-28
Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management MeasuresNISG 2026, BGBl. I Nr. 94/2025, §§ 24, 25, 28 und 32 2026-10-01[future]
Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting ObligationsNISG 2026, BGBl. I Nr. 94/2025, §§ 34 und 35 2026-10-01[future]
Belgium be 2 instruments
Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and GovernanceLoi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique, Artt. 30-33 2024-10-18
Loi du 26 avril 2024, Significant-Incident Notification ObligationsLoi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique, Artt. 34-37 2024-10-18
Bulgaria bg 2 instruments
Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS)Закон за киберсигурност (ЗКС), чл. 23, изм. с § 27 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Art. 23, as substituted by § 27 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026) 2026-02-17
Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)Закон за киберсигурност (ЗКС), чл. 21 и 22, изм. с §§ 25 и 26 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Arts. 21 and 22, as substituted by §§ 25 and 26 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026) 2026-02-17
Croatia hr 2 instruments
Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting ObligationsZakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 37.-44.; Uredba o kibernetičkoj sigurnosti, Narodne novine, broj 135/2024, čl. 64.-71. i 85. 2024-11-30
Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and GovernanceZakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 29. i 30. 2024-02-15
Cyprus cy 3 instruments
Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and GovernanceArts. 35 and 35A of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 2025-04-25
Security of Networks and Information Systems Law, Incident Notification ObligationsArt. 35B of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 2025-04-25
Security of Networks and Information Systems Law, Radio Equipment Cybersecurity RequirementsArt. 42A of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as inserted by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 2025-04-25
Czech Republic cz 2 instruments
Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident NotificationAct No. 264/2025 Coll., Cybersecurity Act, Sections 15-16 2025-11-01
Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security MeasuresAct No. 264/2025 Coll., Cybersecurity Act, Sections 13-14 2025-11-01
Denmark dk 2 instruments
NIS 2-loven, Cybersecurity Risk-Management Measures and RegistrationNIS 2-loven, §§ 6-10 2025-07-01
NIS 2-loven, Significant-Incident Reporting and Recipient-Notice DutiesNIS 2-loven, §§ 12-13, 15 2025-07-01
Estonia ee 2 instruments
Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber IncidentKüberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 8 and 8-1 2026-01-01
Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body DutiesKüberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 6-1 and 7 2026-01-01
Finland fi 3 instruments
Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience ActLaki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista (439/2026), 1, 7-9, 15-16 ja 31-38 § 2026-06-01
Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and GovernanceKyberturvallisuuslaki (124/2025), 3 ja 7-10 § 2025-04-08
Kyberturvallisuuslaki, Significant-Incident Reporting ObligationsKyberturvallisuuslaki (124/2025), 11-14 ja 22 § 2025-04-08
France fr 3 instruments
Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Incident NotificationLoi n° 2018-133 du 26 février 2018, Titre Ier, art. 7 et 13 2018-05-10
Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security RequirementsLoi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12 2018-05-10
Loi n° 2022-309 du 3 mars 2022 (loi Cyberscore), Cybersecurity Audit and Disclosure DutyLoi n° 2022-309 du 3 mars 2022, art. 1 (Code de la consommation, art. L. 111-7-3) 2023-10-01
Germany de 2 instruments
BSI-Gesetz (BSIG), Incident NotificationBSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32 2025-12-06
BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important EntitiesBSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38 2025-12-06
Greece gr 2 instruments
Law 5160/2024, Cybersecurity Risk-Management Measures and GovernanceLaw 5160/2024 (Ν. 5160/2024), Arts. 14-15 2024-11-27
Law 5160/2024, Significant-Incident Reporting ObligationsLaw 5160/2024 (Ν. 5160/2024), Art. 16 2024-11-27
Hungary hu 2 instruments
Cybersecurity Act, Incident Notification and Cybersecurity Fine2024. évi LXIX. törvény, 66. §; 418/2024. (XII. 23.) Korm. rendelet, 42. § és 77. § 2025-01-01
Cybersecurity Act, Risk-Management Measures2024. évi LXIX. törvény (Magyarország kiberbiztonságáról), 6. § 2025-01-01
Ireland ie 2 instruments
European Union (NIS) Regulations 2018, Incident NotificationS.I. No. 360/2018, Regs. 18 and 22 2018-09-18
European Union (NIS) Regulations 2018, Security RequirementsS.I. No. 360/2018, Regs. 17 and 21 2018-09-18
Italy it 2 instruments
Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident NotificationD.Lgs. 4 settembre 2024, n. 138, Art. 25 2024-10-16
Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management MeasuresD.Lgs. 4 settembre 2024, n. 138, Artt. 23 e 24 2024-10-16
Latvia lv 3 instruments
Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and RemediationNacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti 2024-09-01
Nacionālās kiberdrošības likums, Cybersecurity Risk-Management MeasuresNacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024, redakcija uz 18.06.2026), 25.-28. panti 2024-09-01
Nacionālās kiberdrošības likums, Incident NotificationNacionālās kiberdrošības likums (adopted 20.06.2024, notification clock applying from 01.07.2025), 34. pants 2025-07-01
Lithuania lt 2 instruments
Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident NotificationLietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428, as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 18 2024-10-18
Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management MeasuresLietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428, as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 14 2024-10-18
Luxembourg lu 2 instruments
Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident NotificationLoi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 14 2026-05-10
Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important EntitiesLoi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 11, 12, 13 2026-05-10
Malta mt 1 instrument
Cyber Resilience Regulations, MDIA Designation under the Cyber Resilience ActS.L. 591.6, Cyber Resilience Regulations, made under Chapter 591 (Malta Digital Innovation Authority Act) 2026-09-11[future]
Netherlands nl 2 instruments
Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and GovernanceCyberbeveiligingswet, Artt. 21 en 24 2026-08-15
Cyberbeveiligingswet, Significant-Incident Reporting ObligationsCyberbeveiligingswet, Artt. 25-29 2026-08-15
Poland pl 2 instruments
Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem InformacjiArt. 8 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20), w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252) 2027-04-03[future]
Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów PoważnychArt. 11 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20), w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252) 2027-04-03[future]
Portugal pt 2 instruments
Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and GovernanceDecreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 25.º a 29.º 2026-04-03
Regime Jurídico da Cibersegurança, Significant-Incident Reporting ObligationsDecreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 40.º a 44.º 2026-04-03
Romania ro 2 instruments
Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management MeasuresOrdonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 11-14 2024-12-31
Ordonanța de urgență nr. 155/2024, Incident NotificationOrdonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 15-17 2024-12-31
Slovakia sk 2 instruments
Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability NotificationZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5 2025-01-01
Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management MeasuresZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., §§ 17 až 20 2025-01-01
Slovenia si 2 instruments
Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and GovernanceZakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 20-22 2026-12-18[future]
Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification ObligationsZakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 29-30 2025-06-18
Spain es 2 instruments
Real Decreto-ley 12/2018, Incident Notification ObligationReal Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, arts. 19, 21 y 22, developed by Real Decreto 43/2021, de 26 de enero 2018-09-09
Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service ProvidersReal Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero 2018-09-09
Sweden se 2 instruments
Cybersäkerhetslag, Cybersecurity Risk-Management MeasuresCybersäkerhetslag (2025:1506), 2 kap. 3-4 §§ 2026-01-15
Cybersäkerhetslag, Incident NotificationCybersäkerhetslag (2025:1506), 2 kap. 5-10 §§ 2026-01-15
Europe (non EU)
Albania al 1 instrument
Law No. 25/2024, On CybersecurityLaw No. 25/2024 (Ligj Nr. 25/2024), 21 March 2024, "Për sigurinë kibernetike" ("On Cybersecurity"), Fletorja Zyrtare No. 67/2024, p. 7767 2024-05-03
Andorra ad 2 instruments
Llei 22/2022, Cybersecurity Risk-Management ObligationsLlei 22/2022, del 9 de juny, arts. 12, 13, 17 i 18 2022-06-23
Llei 22/2022, Incident Handling and Notification ObligationLlei 22/2022, del 9 de juny, arts. 14 i 15 2022-06-23
Belarus by 1 instrument
Law No. 455-Z, Information System Operator's Duty to Protect Information (Article 40)Law of the Republic of Belarus No. 455-Z of 10 November 2008 On Information, Informatization and Protection of Information (as amended to 2016), art. 40 not recorded
Iceland is 2 instruments
Minimum Risk-Management and Preparedness Requirements for Critical InfrastructureLog nr. 78/2019, Art. 7 2020-09-01
Notification of Serious Incidents and Risk to the National Cybersecurity Incident-Response TeamLog nr. 78/2019, Art. 8 2020-09-01
Liechtenstein li 2 instruments
Cyber-Sicherheitsgesetz (CSG), Incident NotificationCyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 6 2025-02-01
Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important EntitiesCyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 1, 3, 4, 5 2025-02-01
Montenegro me 3 instruments
Law on Information Security, Cyber Threat and Incident ReportingLaw on Information Security, Arts. 28 to 37 2024-12-05
Law on Information Security, Essential and Important EntitiesLaw on Information Security, Arts. 4, 16, 18(4) to (6), and 19 to 27 2024-12-05
Law on Information Security, General Security MeasuresLaw on Information Security, Arts. 1 to 3, 7 to 15 and 18(1) to (3) 2024-12-05
Serbia rs 2 instruments
Law on Information Security, ICT Systems of Special Importance and Security MeasuresZakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 5-12 2026-01-01
Law on Information Security, Incident Reporting ObligationsZakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 13-14, 24-25 2026-01-01
Ukraine ua 2 instruments
Law on the Basic Principles of Ensuring Cybersecurity, CERT-UA Incident Notification DutyЗакон України "Про основні засади забезпечення кібербезпеки України" № 2163-VIII від 05.10.2017 (редакція від 03.04.2025, підстава - 4070-IX), ст. 6(4)-(5), ст. 9(2) 2018-05-09
Law on the Basic Principles of Ensuring Cybersecurity, Critical Infrastructure Owner Cyber-Defense and Audit DutyЗакон України "Про основні засади забезпечення кібербезпеки України" № 2163-VIII від 05.10.2017 (редакція від 03.04.2025, підстава - 4070-IX), ст. 6(4) 2018-05-09
United Kingdom gb 1 instrument
Product Security Requirements for Connectable ProductsProduct Security and Telecommunications Infrastructure Act 2022, c. 46, Part 1; Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, SI 2023/1007 2024-04-29
Americas
Brazil br 1 instrument
Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)Ato nº 2.436, de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019 2024-03-10
Cuba cu 2 instruments
Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System dutyDecreto No. 360/2019 ‘Sobre la Seguridad de las Tecnologías de la Información y la Comunicación y la Defensa del Ciberespacio Nacional’ (Gaceta Oficial de la República de Cuba, Ordinaria No. 45, GOC-2019-549-O45, 4 de julio de 2019), arts. 10, 12, 17-20, 41, 56, 89, 109; and its implementing Reglamento de Seguridad de las Tecnologías de la Información y la Comunicación, approved by Resolución 128/2019 of the Ministry of Communications (GOC-2019-555-O45), arts. 2, 4-8, 50 not recorded
Resolución 105/2021, Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de CiberseguridadResolución 105/2021 of the Ministry of Communications, ‘Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad’ (Gaceta Oficial de la República de Cuba, Ordinaria No. 92, GOC-2021-762-O92, 17 de agosto de 2021), arts. 1, 2, 21-23 and resolving clause SEGUNDO not recorded
Haiti ht 1 instrument
BRH Circulaire 126, Information Security Rules for Financial InstitutionsBanque de la République d'Haïti, Circulaire 126, Sur les règles en matière de sécurité informatique, 13 janvier 2022, arts. 1-5 2022-02-01
Mexico mx 1 instrument
Ley Federal de Protección al Consumidor, Electronic Transaction Security Duty (Arts. 76 Bis, 76 Bis 1)Ley Federal de Proteccion al Consumidor (LFPC), Capitulo VIII Bis "De los Derechos de los Consumidores en las Transacciones Efectuadas a traves del Uso de Medios Electronicos, Opticos o de Cualquier Otra Tecnologia", Arts. 76 Bis y 76 Bis 1, capitulo adicionado por decreto publicado en el Diario Oficial de la Federacion el 29 de mayo de 2000, texto vigente con ultima reforma DOF 14-11-2025 2000-05-29
United States us 4 instruments
Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers12 CFR Part 53 (OCC); 12 CFR Part 225, Subpart N (Federal Reserve Board); 12 CFR Part 304, Subpart C (FDIC) 2022-05-01
Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)6 U.S.C. 681-681g (CIRCIA) [future]
SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05)17 CFR 229.106; 17 CFR 249.308 (Form 8-K Item 1.05) 2023-12-18
Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012)48 CFR 252.204-7012 2015-08-26
Asia
Bangladesh bd 1 instrument
Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber IncidentCyber Security Act, 2026 (Act No. 81 of 2026), s. 9 2025-05-21
China cn 4 instruments
Cybersecurity Law, Network Product and Service Security DutiesCybersecurity Law of the People's Republic of China (as amended by the Decision of October 28, 2025, effective January 1, 2026), Art. 24 2026-01-01
Data Security Law, Data Security Protection ObligationsData Security Law of the People's Republic of China, Art. 27 2021-09-01
Data Security Law, Risk Monitoring and Incident Reporting DutyData Security Law of the People's Republic of China, Art. 29 2021-09-01
National Cybersecurity Incident Reporting MeasuresMeasures for the Administration of National Cybersecurity Incident Reporting (Cyberspace Administration of China, issued September 11, 2025), Arts. 2, 4, 5, 8, 9, 12, 14 2025-11-01
India in 2 instruments
CERT-In Cyber Security Directions, Incident Reporting, Logging and Time SynchronisationDirections under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) 2022-06-27
Information Technology Act, Compensation for Failure to Protect Data, and Sensitive Personal Data or Information Rules, Reasonable Security PracticesInformation Technology Act, 2000 (No. 21 of 2000), s.43A; Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (G.S.R. 313(E), 11 April 2011), rr. 3, 4, 5, 6, 8 2011-04-11
Indonesia id 2 instruments
Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security dutyGovernment Regulation No. 71 of 2019 (PP PSTE), Pasal 3, 23, 24(1)-(2), 31, 32, 39, 40 2019-10-10
Government Regulation on the Operation of Electronic Systems and Transactions, security-incident reporting dutyGovernment Regulation No. 71 of 2019 (PP PSTE), Pasal 24(3) 2019-10-10
Israel il 1 instrument
Privacy Protection Regulations (Data Security), information security programmePrivacy Protection Regulations (Data Security), 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement) 2018-05-08
Jordan jo 1 instrument
Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation dutyCyber Security Law No. (16) of 2019, Article 8(b) not recorded
Kazakhstan kz 1 instrument
Digital Code, general cybersecurity duty on digital-object owners and holdersDigital Code No. 255-VIII (9 January 2026), Arts. 20, 97-98 2026-07-10
Kuwait kw 1 instrument
Data Classification PolicyData Classification Policy, version 2.3 (Communication and Information Technology Regulatory Authority, listed 16 June 2022) 2022-06-16
Kyrgyzstan kg 2 instruments
Digital Code, digital resilience baseline security measuresDigital Code, Law No. 178, Art. 63(1)-(4) 2026-02-06
Digital Code, digital resilience incident notificationDigital Code, Law No. 178, Art. 63 2026-02-06
Lebanon lb 1 instrument
Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts)Banque du Liban Basic Decision No. 12725 of 28 November 2017 (Basic Circular No. 144 to Banks, also addressed to Financial Institutions), Prevention of Electronic Criminal Acts, Arts. 1-6 2017-11-28
Mongolia mn 1 instrument
Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal PersonsLaw of Mongolia on Cyber Security, adopted 17 December 2021, in force 1 May 2022, Art. 17.3 2022-05-01
South Korea kr 1 instrument
Information and Communications Network Act, Report on Computer Security IncidentsArts. 48-3 and 48-4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 20069, Jan. 23, 2024) 2022-06-10
State of Palestine ps 1 instrument
Law by Decree No. 41 of 2022 concerning National Payments, Licensing and Security-Systems DutyLaw by Decree No. 41 of 2022 concerning National Payments, Art. 8 2022-08-14
Turkey tr 1 instrument
Cybersecurity Law, Reporting and Cooperation DutiesLaw No. 7545 (12 March 2025), Art. 7 2025-03-19
Turkmenistan tm 2 instruments
Law on Communications, network and subscriber-information protection dutiesLaw of Turkmenistan No. 93-IV, "On Communications" (Vedomosti Mejlisa Turkmenistana 2010, No. 1, art. 17; as last amended by Law No. 184-VII of 22 November 2025), arts. 18, 43 2010-03-12
Law on Information and Its Protection, information-security dutyLaw of Turkmenistan No. 72-V, "On Information and Its Protection" (Vedomosti Mejlisa Turkmenistana 2014, No. 2, art. 72; as amended by Laws No. 234-VI of 14 March 2020, No. 390-VI of 5 June 2021, and No. 445-VI of 18 December 2021), art. 15 2014-05-03
Uzbekistan uz 3 instruments
Law on Cybersecurity, cybersecurity incident notification dutyLaw No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 22-24 2022-07-17
Law on Cybersecurity, general cybersecurity duties on cybersecurity subjectsLaw No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 37 2022-07-17
Law on Informatization, information security duty for information resource and system ownersLaw No. 560-II (11 December 2003) "On Informatization," Arts. 19-20 2004-02-11
Vietnam vn 2 instruments
Cybersecurity Law, Incident Response and Reporting DutiesLaw No. 116/2025/QH15 (Law on Cybersecurity), arts. 40(1)(c), 41(2)-(4) 2026-07-01
Cybersecurity Law, Information System Classification and Protection MeasuresLaw No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10 2026-07-01
Yemen ye 1 instrument
Law No. 40 of 2006 on Electronic Payment Systems and Financial and Banking Operations, Secure-Services and Banking-Confidentiality DutyLaw No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations, art. 27 2006-12-28
Africa
Angola ao 2 instruments
Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination DutiesLei n.º 7/17, Artigos 15.º, 16.º, 40.º e 41.º not recorded
Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and DatabasesLei n.º 7/17, Artigos 12.º, 13.º, 14.º, 17.º, 18.º e 19.º not recorded
Benin bj 1 instrument
Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybersécurité), sécurité des réseaux et essai de vulnérabilité des produitsLoi n°2017-20 du 20 avril 2018, Livre VI, Titre I, Chapitre XIII, Article 598, portant Code du Numérique en République du Bénin 2018-04-20
Burundi bi 1 instrument
Loi n° 1/10, Articles 3, 4(3) and 14: security-of-service duty and diligence penalty for network operators and service providersLoi n° 1/10 du 16 mars 2022 portant prevention et repression de la cybercriminalite au Burundi, Arts. 3, 4(3), 14 2022-03-16
Cameroon cm 1 instrument
Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)Loi n°2010/012 du 21 décembre 2010, art. 6-7, 13-14, 24, 26-30, 32, 61(3) 2010-12-21
Central African Republic cf 3 instruments
Cybersecurity Law: Essential-Service Operator Cybersecurity RegimeLoi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité, Titre II, Chapitre I (art. 7 à 12) 2024-02-21
Cybersecurity Law: Mandatory Security Audit RegimeLoi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité, Titre II, Chapitre II (art. 14, 15 et 25) et Titre III, Chapitre I (art. 43) 2024-02-21
Cybersecurity Law: Network and Information System Security DutyLoi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité, Titre II, Chapitre III, Sections I et II (art. 16, 19, 20, 21, 23) 2024-02-21
Côte d'Ivoire ci 3 instruments
Mandatory Information Systems Security Audit and CertificationDécret n°2021-917 du 22 décembre 2021, Arts. 3-4, 19-21 2021-12-22
Mandatory Reporting of Attacks and Intrusions to ARTCIDécret n°2021-917 du 22 décembre 2021, Arts. 16-17 2021-12-22
RGSSI and PPIC Compliance DutyDécret n°2021-916 du 22 décembre 2021, Arts. 1-2 2021-12-22
Democratic Republic of the Congo cd 5 instruments
Digital Code, Livre II: Trust Service Provider Security Risk-Management DutyCode du numérique, Livre II, Titre II, Chapitre III, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 147, et art. 164 pour les sanctions) 2023-03-13
Digital Code, Livre II: Trust Service Provider Security-Incident NotificationCode du numérique, Livre II, Titre II, Chapitre III, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 148 et 149) 2023-03-13
Digital Code, Livre IV: Digital Services Provider Security ObligationsCode du numérique, Livre IV, Titre III, Chapitre I, Section 2, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 295 à 297) 2023-03-13
Digital Code, Livre IV: General Cyberattack Cooperation and Incident-Reporting DutyCode du numérique, Livre IV, Titre II, Chapitre I, et Titre III, Chapitre I, Section 1, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 276 et 281) 2023-03-13
Digital Code, Livre IV: ICT Product and Service Vendor Security CertificationCode du numérique, Livre IV, Titre III, Chapitre I, Section 1, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 294) 2023-03-13
Djibouti dj 4 instruments
Digital Code, Book II: Electronic Communications Network and Service SecurityLoi n° 019/AN/23/9ème L portant Code Numérique, Livre Deuxième, Art. 169 2025-09-18
Digital Code, Book VI: Critical Installation Protection and Operator Security ControlsLoi n° 019/AN/23/9ème L portant Code Numérique, Livre Sixième, Titre 3 (Arts. 679 à 684) 2025-09-18
Digital Code, Book VII: Health-Data Hosting Security CertificationLoi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, Arts. 760 à 763 2025-09-18
Digital Code, Book VII: National Health Data System Security Incident ReportingLoi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, Art. 747 2025-09-18
Egypt eg 1 instrument
Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System ManagerLaw No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, Arts. 29, 42, 44 2018-08-15
Ethiopia et 3 instruments
Computer Crime Proclamation, Duty to Report Computer Crime and Illegal ContentComputer Crime Proclamation No. 958/2016, art. 2(13), art. 2(19), art. 17, art. 27, art. 46 2016-07-07
Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner ObligationsCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, art. 3, art. 4, art. 5, art. 7, art. 8, art. 22(1)(a), art. 22(1)(d)-(f), art. 22(2)-(3), art. 22(5), art. 25(1)(a), art. 25(1)(c)-(d), art. 25(2)-(4), art. 28 2027-07-21[future]
Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERTCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, art. 7(14), art. 9(2), art. 22(1)(b)-(c), art. 22(2)-(3), art. 22(5), art. 25(1)(b), art. 25(2)-(4), art. 28 2027-07-21[future]
Gabon ga 1 instrument
Sécurité des systèmes d'information (dispositions communes)Loi N° 027/2023 du 11 juillet 2023, Titre III, Chapitre III, Section 2, arts. 28-35 2023-07-15
Gambia gm 2 instruments
Information and Communications Act, 2009, security of information and communications services (safeguards duty)Information and Communications Act, 2009 (No. 2 of 2009), sec. 140(1)-(2) 2009-05-29
Information and Communications Act, 2009, security of information and communications services (subscriber risk notification)Information and Communications Act, 2009 (No. 2 of 2009), sec. 140(3)-(6) 2009-05-29
Ghana gh 3 instruments
Cybersecurity Act, Cybersecurity Standards and EnforcementCybersecurity Act, 2020 (Act 1038), s. 59, and Second Schedule item 59(4) 2020-12-29
Cybersecurity Act, Duty to Report Cybersecurity IncidentCybersecurity Act, 2020 (Act 1038), ss. 47(2) and 47(5)-(6), and Second Schedule item 47(6) 2020-12-29
Cybersecurity Act, Licensing of Cybersecurity Service ProvidersCybersecurity Act, 2020 (Act 1038), ss. 49-53, First Schedule, and Second Schedule items 49(2) and 51(5) 2020-12-29
Kenya ke 1 instrument
Computer Misuse and Cybercrimes Act, Reporting of Cyber ThreatComputer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40 2018-05-30
Liberia lr 1 instrument
Telecommunications Act 2007, Security Safeguards for Customer Information and Communications§ 51(5), Telecommunications Act 2007 (Republic of Liberia) not recorded
Morocco ma 2 instruments
Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Incident and Vulnerability Notification DutiesLoi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 27, 30 et 33, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020) not recorded
Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security DutiesLoi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 26, 29, 32 et 34, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020) not recorded
Mozambique mz 3 instruments
Cybersecurity Law, General Security Requirements for the Public Administration and the Private SectorLei n.º 13/2026, arts. 47 a 50 2026-09-29[future]
Cybersecurity Law, Incident Notification and Responsible Vulnerability DisclosureLei n.º 13/2026, arts. 57 a 66 2026-09-29[future]
Cybersecurity Law, Sector-Specific Security Requirements for Critical Infrastructure, Essential Services and Digital ProvidersLei n.º 13/2026, arts. 51 a 56 2026-09-29[future]
Nigeria ng 1 instrument
Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERTCybercrimes (Prohibition, Prevention, etc.) Act, 2015, section 21, Reporting of Cyber Threats not recorded
Sierra Leone sl 2 instruments
Cyber Security and Crime Act, 2021, Critical National Information InfrastructureCyber Security and Crime Act, 2021 (Act No. 7 of 2021), ss. 7-8 (Critical National Information Infrastructure) 2021-11-15
Cyber Security and Crime Act, 2021, Reporting of Cyber Security IncidentsCyber Security and Crime Act, 2021 (Act No. 7 of 2021), s. 53 (Reporting Cyber Threats) 2021-11-15
Somalia so 1 instrument
National Cybersecurity Law (2025)National Cybersecurity Law (2025) (Federal Republic of Somalia); no law number located not recorded
South Sudan ss 1 instrument
National Communication Act, 2012, Licensee Security DutyNational Communication Act, 2012 (Act No. 24), sec. 88 not recorded
Togo tg 1 instrument
Loi n° 2018-026, opérateurs de services essentiels and the National Cybersecurity Agency (ANCy)Titre II (Arts. 3, 5-7), Loi n° 2018-026 du 07 décembre 2018 sur la cybersécurité et la lutte contre la cybercriminalité 2018-12-07
Tunisia tn 2 instruments
Cybersecurity Incident Reporting and Emergency ResponseDécret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 17-20, 24-25 2023-09-11
Mandatory Security Audit and Digital-Trust ClassificationDécret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 6-9, 14-16, 24-25 2023-09-11
Oceania
Australia au 1 instrument
Security Standards for Smart DevicesCyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1 2026-03-04
Kiribati ki 2 instruments
Cybersecurity Act 2026, Critical Infrastructure Operator ObligationsCybersecurity Act 2026 (Act No. 7 of 2026), ss. 12-20, 22-23 (Parts V-VI) [future]
Cybersecurity Act 2026, Duty to Report a Cybersecurity IncidentCybersecurity Act 2026 (Act No. 7 of 2026), s. 21 (Part VI) [future]
Marshall Islands mh 2 instruments
Cybersecurity Act 2025, Cybersecurity Incident Reporting ObligationsCybersecurity Act 2025, 40 MIRC Ch. 4 § 407 (P.L. 2025-0027) 2025-04-21
Cybersecurity Act 2025, Cybersecurity of Critical Information InfrastructureCybersecurity Act 2025, 40 MIRC Ch. 4 §§ 405-406 (P.L. 2025-0027) 2025-04-21
Micronesia fm 1 instrument
FSM Telecommunications Act of 2014, Security Safeguards for Customer Information§ 349(1)(b), Title 21 (Telecommunications), Chapter 3, FSM Code, as inserted by Public Law No. 18-52 (2014) 2014-04-03
Solomon Islands sb 1 instrument
Telecommunications Act 2009, Security Safeguards for Consumer Informations. 72(1)(b), Telecommunications Act 2009 (Solomon Islands) not recorded
Tonga to 2 instruments
Cybersecurity Act 2025, Critical Infrastructure Operator ObligationsAct 14 of 2025, ss. 11-14, 16-17 [future]
Cybersecurity Act 2025, Duty to Report a Cybersecurity IncidentAct 14 of 2025, s. 15 [future]
Other
Kosovo xk 2 instruments
Law No. 08/L-173 on Cyber Security, Incident Reporting and EnforcementLaw No. 08/L-173 on Cyber Security, Arts. 6, 8 and 24 2023-03-14
Law No. 08/L-173 on Cyber Security, Security MeasuresLaw No. 08/L-173 on Cyber Security, Arts. 2, 3, 5 and 7 2023-03-14
Taiwan tw 4 instruments
Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security UnitArts. 24-25 of the Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries (金融控股公司及銀行業內部控制及稽核制度實施辦法), full-text revision promulgated May 6, 2026 (Financial Supervisory Commission Order Jin-Guan-Yin-Guo-Zi No. 11502710961), effective on promulgation for the articles cited here 2026-05-06
Cyber Security Management Act, Cyber Security Incident ReportingArts. 24 and 29 of the Cyber Security Management Act (資通安全管理法), full-text amendment promulgated Sept. 24, 2025 (Presidential Order Hua-Zong-Yi-Yi-Zi No. 11400095391), effective Dec. 1, 2025 2025-12-01
Cyber Security Management Act, Specific Non-Government Agency Cyber Security ManagementArts. 3(6)-(8), 7-8, 20-23 and 30 of the Cyber Security Management Act (資通安全管理法), full-text amendment promulgated Sept. 24, 2025 (Presidential Order Hua-Zong-Yi-Yi-Zi No. 11400095391), effective Dec. 1, 2025 2025-12-01
Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection PlansArts. 15, 42, 76 and 79 of the Telecommunications Management Act (電信管理法), enacted June 26, 2019, effective July 1, 2020 for the provisions cited here 2020-07-01

United States: states42 in 32 places

Law made below the national level, binding inside it. The slug beside each name says which tier it is.

Stage Instrument In force from
Alabama us/al 1 instrument
Data Breach Notification Act, reasonable security measures and disposal of recordsAla. Code secs. 8-38-3, 8-38-10 2018-06-01
Alaska us/ak 1 instrument
Alaska Personal Information Protection Act, disposal of records dutyAlaska Stat. Secs. 45.48.500-45.48.590 2009-07-01
Arizona us/az 1 instrument
Discarding and disposing of records containing personal identifying informationA.R.S. sec. 44-7601 2005-01-01
Arkansas us/ar 1 instrument
Arkansas Personal Information Protection Act, reasonable security proceduresArk. Code Ann. section 4-110-104(b) not recorded
California us/ca 2 instruments
Customer Records Act, Reasonable Security ProceduresCal. Civ. Code section 1798.81.5, as amended by AB 825 (2021, Ch. 527) 2022-01-01
Security of Connected DevicesCal. Civ. Code sections 1798.91.04-1798.91.06 (Title 1.81.26, added by Stats. 2018, Ch. 860 (AB 1906) and Ch. 886 (SB 327); sections 1798.91.04 and 1798.91.05 amended by Stats. 2022, Ch. 785 (AB 2392)) 2023-01-01
Colorado us/co 2 instruments
Disposal of personal identifying information, written policy dutyC.R.S. 6-1-713 (amended by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 1) 2018-09-01
Protection of personal identifying information, reasonable security procedures dutyC.R.S. 6-1-713.5 (added by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 2) 2018-09-01
Connecticut us/ct 3 instruments
Adoption of cybersecurity controls by businesses, exemption from punitive damagesConn. Gen. Stat. sec. 42-901 2021-10-01
Connected device provider's duty to protect recorded personal information with reasonable security measuresPublic Act No. 25-44, Sec. 2(c) (2025) 2026-07-01
Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction dutyConn. Gen. Stat. sec. 42-471 2008-10-01
Delaware us/de 1 instrument
Computer Security Breaches, protection of personal informationDel. Code Ann. tit. 6, section 12B-100 2018-04-14
District of Columbia us/dc 1 instrument
Security requirements for personal information (Security Breach Protection Amendment Act of 2020)D.C. Code § [28-3852.01] (Title 28, Chapter 38, Subchapter II, "Security requirements," added by the Security Breach Protection Amendment Act of 2020, D.C. Law 23-98, § 2(a)(5), 67 DCR 3923) 2020-06-17
Florida us/fl 1 instrument
Florida Information Protection Act, data security and disposal dutyFla. Stat. § 501.171(2), (8) 2014-07-01
Georgia us/ga 1 instrument
Disposal of records containing personal informationO.C.G.A. Sec. 10-15-2 not recorded
Hawaii us/hi 1 instrument
Destruction of Personal Information RecordsHaw. Rev. Stat. Secs. 487R-1 to 487R-3 2007-01-01
Illinois us/il 2 instruments
Personal Information Protection Act, data security duty815 ILCS 530/45 (P.A. 99-503, eff. 2017-01-01) 2017-01-01
Personal Information Protection Act, safe disposal of personal information815 ILCS 530/40 (P.A. 97-483, eff. 2012-01-01) 2012-01-01
Indiana us/in 1 instrument
Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of recordsInd. Code sec. 24-4.9-3-3.5 [future]
Iowa us/ia 1 instrument
Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security programIowa Code ch. 554G (554G.1 to 554G.4, added by 2023 Acts, ch. 63 (H.F. 553)) 2023-07-01
Kansas us/ks 1 instrument
Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal informationK.S.A. 50-6,139b 2016-07-01
Louisiana us/la 1 instrument
Database Security Breach Notification Law, reasonable security procedures and destruction dutyLa. R.S. 51:3074(A), (B) 2006-01-01
Maryland us/md 1 instrument
Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal dutyMd. Code Ann., Com. Law sections 14-3502, 14-3503 (Maryland Personal Information Protection Act, Title 14, Subtitle 35, added by 2007 Md. Laws ch. 531 (S.B. 194)) 2008-01-01
Massachusetts us/ma 1 instrument
Standards for the Protection of Personal Information of Residents of the Commonwealth201 CMR 17.01-17.05 2010-03-01
Michigan us/mi 1 instrument
Identity Theft Protection Act, destruction of data no longer neededMCL 445.72a (Sec. 12a of Act 452 of 2004, added by 2006 PA 566) 2007-07-02
Nebraska us/ne 1 instrument
Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices dutyNeb. Rev. Stat. section 87-808 (added by Laws 2018, LB757, section 7) 2018-07-19
Nevada us/nv 2 instruments
Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shieldNRS 603A.215 [future]
Security measures for data collectors maintaining personal informationNRS 603A.210 [future]
New Jersey us/nj 1 instrument
Identity Theft Prevention Act, methods of destruction of customer recordsN.J. Stat. Ann. § 56:8-162 (L. 2005, c.226, s.11) 2006-01-01
New Mexico us/nm 1 instrument
Data Breach Notification Act, security and disposal dutiesNMSA 1978 Secs. 57-12C-3 to 57-12C-5 [future]
New York us/ny 2 instruments
New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent23 NYCRR 500.17 2023-11-01
Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program dutyN.Y. Gen. Bus. Law section 899-bb (Article 39-F, added by L. 2019, ch. 117 (S5575-B/A5635-B), section 4) 2020-03-21
North Carolina us/nc 1 instrument
Identity Theft Protection Act, destruction of personal information recordsN.C. Gen. Stat. section 75-64 (Chapter 75, Article 2A, added by S.L. 2005-414, s. 1) 2005-12-01
Ohio us/oh 1 instrument
Ohio Data Protection Act, cybersecurity program safe harborOhio Rev. Code sections 1354.01 to 1354.05 (enacted by Senate Bill 220, 132nd General Assembly, effective November 2, 2018; section 1354.01 last amended by House Bill 66, 132nd General Assembly, effective April 5, 2019) 2018-11-02
Oregon us/or 2 instruments
Oregon Consumer Information Protection Act, requirement to develop safeguards for personal informationORS 646A.622 (2007 c.759 sec. 12; amended 2015 c.357 sec. 3; 2018 c.10 sec. 6; 2019 c.180 sec. 4) not recorded
Security requirements for Internet-connected devicesORS 646A.813 (added by 2019 c.193 (H.B. 2395-A) sec. 1; amending ORS 646.607) not recorded
Rhode Island us/ri 1 instrument
Identity Theft Protection Act of 2015, risk-based information security programR.I. Gen. Laws secs. 11-49.3-2, 11-49.3-5 [future]
Texas us/tx 2 instruments
Cybersecurity Program safe harbor from exemplary damages (S.B. 2610)Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004) 2025-09-01
Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal informationTex. Bus. & Com. Code sec. 521.052 2009-04-01
Utah us/ut 2 instruments
Cybersecurity Affirmative Defense ActUtah Code 78B-4-701 to 78B-4-704 2021-05-05
Protection of Personal Information Act, reasonable procedures and records-destruction dutyUtah Code 13-44-201 2019-05-14
Vermont us/vt 1 instrument
Document Safe Destruction Act, safe destruction of records containing personal information9 V.S.A. § 2445 (Added 2005, No. 162 (Adj. Sess.), § 1, eff. Jan. 1, 2007) 2007-01-01

What this page claims, and what it does not

The stages are LexLint's own vocabulary. Four of the five boxes are the binding classes the /law/<jurisdiction> docket already draws (In force, Enacted but not yet in force, Proposed, and Repealed, withdrawn or blocked), so a square here and a square there mean the same thing. A struck-down instrument is spent on both readings.

Enjoined has its own box. Inside "Repealed, withdrawn or blocked" it would sit beside a mark that is a false description of a law a court has paused, and it would pool away a count that reads as a signal: how contested a jurisdictional hook is. The certainty ladder files enjoined as present law and the docket draws it spent; splitting it out here makes that disagreement the reader's choice instead of our silent one. It is off by default, which follows the docket.

One date column, and where a bare date would mislead it says what kind of date it is. "In force from" is commencement: the earlier of a published commencement event and the instrument's own effective date, the same choice lifecycle_band() makes and for the same reason, neither source is reliably the commencement, and the earlier one cannot make a law look newer than it is. A bracket qualifies the date where a bare one would mislead ([future] for a start date still ahead, [proposed] for a bill with no commencement to show, [enjoined], [struck down], [repealed], [superseded] or [withdrawn] for a spent instrument). Nothing is inferred from our own review date: a row with neither a date nor a status to explain the gap says "not recorded" instead.

The map is the table. Its fill is the count of instruments at the stages you chose, binned on the same RAMP_BINS edges /law/map uses, and it redraws on every change. Point at, click, or tab to a place for what applies there, every stage it holds shown even when your filter is excluding it.

Three ways of showing nothing, and they are different claims. A place washed pale holds cybersecurity law your filter is excluding, so widening the filter brings it back. A hatched place is one we track and hold no cybersecurity law for at all: that is a statement about our research, not about the law. A white place has no jurisdiction record for this topic at all. Only the first of the three moves when you change the filter; the other two are facts about us and hold still.

Nothing here needs the script. The default resultset is in the HTML: counts, tally, map fills and the hidden rows are all rendered at build. The script recomputes them when a box changes and does nothing else, which is what lets this page ship under script-src 'self' and be read whole by a crawler.

Every instrument here links its own note page, which carries the primary source and the date it was read. This is a research index, not legal advice.