Every regulation. Every authority.
37 regulations across 6 domains — primary legislation, AI rules, AML, competition, and ESG frameworks, all summarised with fine maxima.
Privacy & data protection(16)
Primary EU personal data framework. Basis for the largest regulatory fines in European history.
Post-Brexit UK data protection framework enforced by the ICO. Substantively equivalent to EU GDPR.
National GDPR implementation with additional French-specific obligations. Enforced by the CNIL.
German GDPR implementation with strong employee data provisions and 16 state-level DPA enforcement.
Dutch GDPR implementation enforced by the AP. Includes specific provisions on biometric and employee data.
China's comprehensive personal data law with extraterritorial reach. Requires CAC security assessment for most outbound transfers.
Japan has EU adequacy — the 2022 revision strengthened breach notification and cross-border transfer rules.
2023 revision significantly increased enforcement powers and introduced a new personal information impact assessment requirement.
India's first comprehensive data protection law. Implementation rules under consultation — enforcement expected 2025.
2022 amendment dramatically increased penalty amounts after the Optus and Medibank mega-breaches.
2021 revision introduced mandatory breach notification and increased financial penalties.
Brazil's GDPR-equivalent. ANPD issued its first significant fines in 2023 — enforcement is accelerating.
Most mature data protection law in sub-Saharan Africa. Fully aligned with GDPR principles.
UAE mainland data protection law. Three separate regimes apply: mainland, DIFC, and ADGM.
Current PIPEDA lacks direct fine authority. Bill C-27 (CPPA) will transform Canada's enforcement regime — Quebec Law 25 already active.
Strictest US state privacy law. The CPPA began active enforcement in 2023 with 20+ investigations opened.
AI & digital markets(6)
First comprehensive AI regulation globally. Risk-tiered: prohibited practices banned from Feb 2025; high-risk rules from Aug 2026.
CAC's generative AI framework covering content moderation, algorithm transparency, and data sourcing obligations.
Obligations for designated "gatekeeper" platforms. Apple, Alphabet, Meta, Amazon, Microsoft, ByteDance are currently designated.
Online platform liability and transparency obligations. Very large platforms (>45M EU users) face additional obligations.
UK equivalent of DMA. CMA can designate firms with strategic market status and impose conduct requirements.
The FTC's primary enforcement tool for unfair or deceptive data practices. No consent order ceiling — Meta paid $5B in 2019.
Cybersecurity & resilience(5)
Mandatory security and incident reporting for essential and important entities. National enforcement commenced October 2024.
ICT risk management and incident reporting for financial entities. Applies from January 2025 — supervised by financial regulators.
German critical infrastructure cybersecurity obligations. BSI has powers to mandate security audits and incident disclosure.
Classification and security requirements for all data processed in China. Applies alongside PIPL with additional national security obligations.
Mandatory reporting and risk management obligations for 11 critical infrastructure sectors including energy, water, and health.
Competition & antitrust(2)
Foundation of EU competition law — cartels, abuse of dominance, and merger control. DG COMP issues fines at 80–100% of maximum in major cases.
Foundation of US antitrust law. DOJ Antitrust Division pursues criminal prosecutions — executives face personal imprisonment.
Finance, AML & crypto(6)
Expanded predicate offences for money laundering to 22 categories. Criminal liability extended to legal persons.
World's first comprehensive crypto regulation. Full application from December 2024 — stablecoins already supervised from June 2024.
Dutch financial markets supervision law. AFM and DNB enforce — applies to banks, insurers, investment firms operating in NL.
UK AML framework. FCA has unlimited fine power — Santander received £107.7M in 2022 for AML failings.
Core US AML framework. FinCEN enforces SAR reporting, KYC, and beneficial ownership requirements across financial institutions.
Administrative, physical, and technical safeguards for protected health information. HHS OCR enforcing tracking-pixel violations from 2023.
ESG & sustainability(2)
Mandatory sustainability reporting for large companies and listed SMEs — phased in from 2024. Double materiality assessment required.
Human rights and environmental due diligence obligations across the value chain. Phased rollout from 2027 for largest companies.
We track 35+ regulations and add new jurisdictions every quarter.