Regulations
The laws that reach an API. Most of them do not require an interface — they restrict one, or demand that something be provable about it — which is exactly why so little of compliance ends up machine-readable, and why a catalog of API contracts can see the gap.
Each regulation here is joined to the countries, regions and industries it binds, so you can go from a regime straight to the scored cohort that lives under it.
124 regulations · profiled at API Evangelist
21 CFR Part 11
21 CFR Part 11 is the FDA rule setting the conditions under which electronic records and electronic signatures are treated as equivalent to paper and ink. It requires validated ...
21st Century Cures Act
The 21st Century Cures Act is a 2016 US law whose ONC Final Rule (2020) prohibits 'information blocking' — practices that interfere with the access, exchange, or use of electron...
Accessibility for Ontarians with Disabilities Act
AODA and its Integrated Accessibility Standards Regulation require organisations with 50 or more employees in Ontario to make their public websites and web content conform to WC...
ADA Title III (web accessibility)
Title III of the ADA prohibits discrimination in places of public accommodation, and US courts have overwhelmingly read that to reach websites and mobile apps — without any regu...
Air Passenger Protection Regulations
The Air Passenger Protection Regulations set out what Canadian air carriers owe passengers when a flight is delayed, cancelled or oversold — compensation tiers, rebooking duties...
App Store Accountability Laws
App Store Accountability laws move age verification from individual apps to the app stores, requiring Apple and Google to determine a user's age category, obtain verifiable pare...
APRA Prudential Standards
APRA is Australia's prudential regulator for banks, insurers and superannuation funds, operating through binding Prudential Standards — notably CPS 234 on information security a...
ATOL
ATOL is the United Kingdom's statutory financial protection scheme for air package holidays, administered by the Civil Aviation Authority since 1973. Any business selling flight...
Australia Cyber Security Act 2024
Australia's first standalone cyber security statute does three things: it creates mandatory security standards for smart devices, it requires businesses above a turnover thresho...
Australia Online Safety Act
The Online Safety Act gives Australia's eSafety Commissioner takedown powers, Basic Online Safety Expectations and industry codes — and, since 10 December 2025, the Social Media...
Australia Spam Act 2003
The Spam Act prohibits sending commercial electronic messages to Australian addresses without consent, requires accurate sender identification and a functional unsubscribe honou...
Australian Consumer Law
The Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010, is the national regime governing misleading conduct, unfair contract terms and consumer guarant...
Australian Telecommunications Act 1997
The Telecommunications Act 1997 is the framework for Australian telecommunications regulation, administered by the Australian Communications and Media Authority alongside the Ra...
BSA / AML
The Bank Secrecy Act and the anti-money-laundering rules built on it require US financial institutions — including money services businesses, which is how they reach crypto firm...
California AI Training Data Transparency Act
AB 2013 requires any developer of a generative AI system made publicly available to Californians to publish, on its website, a documented summary of the datasets used to train i...
California Transparency in Frontier AI Act
SB 53 is the first US law requiring public, standardised safety disclosures from developers of frontier AI models — those trained above 10^26 FLOPs. Large frontier developers mu...
CAN-SPAM
CAN-SPAM sets the United States rules for commercial email: accurate headers and subject lines, identification as an advertisement, a physical postal address, and a working unsu...
Canada's Anti-Spam Legislation
CASL is the strictest commercial-messaging law in the world — express opt-in consent, prescribed sender identification, a working unsubscribe honoured within ten business days, ...
CAP Accreditation
The CAP Laboratory Accreditation Program is a peer-based inspection regime holding laboratories to checklists that meet or exceed CLIA requirements, with CMS deeming authority. ...
Carbon Border Adjustment Mechanism
Regulation (EU) 2023/956 puts a carbon price on imports of cement, iron and steel, aluminium, fertilisers, electricity and hydrogen, requiring importers to report the greenhouse...
CCPA / CPRA
The California Consumer Privacy Act, as amended and expanded by the California Privacy Rights Act, gives Californians rights over the personal information businesses hold about ...
CFPB Personal Financial Data Rights Rule
The Consumer Financial Protection Bureau's Personal Financial Data Rights Rule, finalized in 2024 under Dodd-Frank Section 1033, requires covered financial institutions to make ...
CHIPS and Science Act
US legislation providing approximately $52 billion in subsidies, grants and tax credits for domestic semiconductor manufacturing, research and workforce development, with condit...
CLIA
CLIA establishes federal quality standards for all laboratory testing performed on human specimens for diagnosis, prevention or treatment. Administered by CMS, it certifies labo...
CMA Open Banking Order
The UK Competition and Markets Authority's Retail Banking Market Investigation Order 2017 is the competition remedy that created UK Open Banking. It required the nine largest UK...
CMS Interoperability & Prior Authorization Rule
The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), finalized in 2024, requires impacted US payers — Medicare Advantage, Medicaid, CHIP, and ACA exchange p...
Colorado AI Act
Colorado passed the first US comprehensive algorithmic-discrimination law, delayed it twice, then repealed and replaced it with a narrower automated-decision statute arriving 1 ...
Consumer Data Right
Australia's Consumer Data Right (CDR) is an economy-wide data-portability law that gives consumers the right to share their data with accredited third parties, beginning with ba...
Consumer-Driven Banking Framework
Canada's Consumer-Driven Banking framework is the federal open-banking regime legislated in the 2024 budget and fall economic statement, with the Financial Consumer Agency of Ca...
COPPA
COPPA governs the online collection of personal information from children under thirteen in the United States. It requires verifiable parental consent before collection, limits ...
Corporate Sustainability Due Diligence Directive
Directive (EU) 2024/1760 requires large companies operating in the EU to identify, prevent, mitigate and account for adverse human rights and environmental impacts across their ...
Corporate Sustainability Reporting Directive
Directive (EU) 2022/2464 requires a large population of companies operating in the EU to report sustainability information under the European Sustainability Reporting Standards,...
Data (Use and Access) Act 2025
The DUAA amends UK GDPR, the Data Protection Act 2018 and PECR, replaces the ICO with the Information Commission, and creates statutory smart-data schemes that generalise the op...
Digital Markets Act
The Digital Markets Act designates large platforms that act as important gateways between businesses and consumers as "gatekeepers" and imposes ex-ante obligations on them — aro...
Digital Services Act
The Digital Services Act governs how online intermediaries handle illegal content, advertising, recommendation and risk — layered by size, from every hosting provider up to the ...
Digital Technology Assessment Criteria
The Digital Technology Assessment Criteria (DTAC) is the NHS's national baseline that digital health technologies are assessed against before being adopted across the health and...
DMCC Act 2024
The DMCC Act gives the Competition and Markets Authority a standing digital-markets regime. The CMA may designate a firm as holding Strategic Market Status in a digital activity...
Dodd-Frank Section 1033
Section 1033 of the 2010 Dodd-Frank Wall Street Reform and Consumer Protection Act gives US consumers a statutory right to access their financial data in a usable electronic for...
DOJ Bulk Sensitive Data Rule
The DOJ Data Security Program prohibits or restricts transfers of bulk US sensitive personal data and government-related data to countries of concern and to covered persons — in...
DORA
DORA is the EU regulation governing information and communication technology risk across the financial sector — banks, insurers, investment firms, payment institutions, crypto-a...
Drug Supply Chain Security Act
Title II of the US Drug Quality and Security Act, requiring an interoperable, electronic, package-level traceability system for prescription drugs across manufacturers, repackag...
EASA U-space
U-space is the European framework for managing large numbers of drones in shared airspace. It defines mandatory services — network identification, geo-awareness, flight authoris...
eIDAS
eIDAS is the EU regulation governing electronic identification and trust services — including the qualified website (QWAC) and seal (QSEAL) certificates that identify regulated ...
eIDAS 2 / EU Digital Identity Wallet
eIDAS 2 amends the original eIDAS Regulation to create the European Digital Identity Wallet — a member-state-issued wallet every EU citizen and resident must be offered, and whi...
Electronic Conveyancing National Law
The Electronic Conveyancing National Law is the uniform legislation, enacted state by state across Australia, that authorises electronic lodgement and settlement of property tra...
ePrivacy Directive
The ePrivacy Directive governs privacy in electronic communications across the European Union, regulating the confidentiality of communications, traffic data, and — most relevan...
ESIGN and UETA
ESIGN is the US federal statute giving electronic signatures and records the same legal effect as their paper equivalents, and UETA is the uniform state law adopted in almost ev...
EU AI Act
The EU Artificial Intelligence Act is the world's first comprehensive, horizontal regulation of artificial intelligence — a risk-tiered regime that bans some practices outright,...
EU Cyber Resilience Act
The EU Cyber Resilience Act is the first horizontal law to impose cybersecurity obligations on products with digital elements across their whole lifecycle — secure-by-design and...
EU Data Act
The EU Data Act governs who may access and use the data generated by connected products and related services, and requires cloud and data-processing providers to enable switchin...
EU Deforestation Regulation
Regulation (EU) 2023/1115 prohibits placing specified commodities — cattle, cocoa, coffee, oil palm, rubber, soya and wood, and products derived from them — on the EU market unl...
EU Digital Omnibus
The Digital Omnibus is the European Commission's simplification package amending the AI Act, GDPR, ePrivacy, the Data Act, NIS2 and DORA at once. It split in practice: the AI ha...
EU IVDR
IVDR replaced the IVD Directive in May 2022 and reclassified most in vitro diagnostics into risk classes requiring notified-body conformity assessment. It brings diagnostic soft...
EU Machinery Regulation
The Machinery Regulation replaces the Machinery Directive across the EU and extends it to software that performs a safety function, machines with self-evolving behaviour, and di...
EU Medical Device Regulation
The EU Medical Device Regulation (Regulation (EU) 2017/745, MDR) governs the safety and performance of medical devices placed on the European market, and — critically for digita...
EU Taxonomy Regulation
Regulation (EU) 2020/852 establishes a classification system defining which economic activities count as environmentally sustainable, with technical screening criteria per activ...
European Accessibility Act
The European Accessibility Act requires a defined set of products and services — including e-commerce, e-books, banking services and consumer digital services — to meet accessib...
European Chips Act
Regulation (EU) 2023/1781 establishing a framework to strengthen Europe's semiconductor ecosystem — investment in first-of-a-kind facilities, a pilot-line and design infrastruct...
FAA Part 107 and Remote ID
Part 107 governs commercial small unmanned aircraft operation in the United States — pilot certification, operating limits, and the waiver and authorization process for flying b...
Fair Credit Reporting Act
The Fair Credit Reporting Act is the US law governing the collection, use, and sharing of consumer credit information, giving consumers rights to access and dispute their data h...
FATF Travel Rule
The FATF Travel Rule requires originator and beneficiary information to travel alongside a transfer between regulated institutions. Extended to virtual asset service providers i...
FCA and PRA Insurance Regulation
The United Kingdom regulates insurance through two bodies: the Financial Conduct Authority for market conduct and the Prudential Regulation Authority, part of the Bank of Englan...
FERC Order 889
FERC Order 889, issued in 1996 alongside the Order 888 open-access rules, requires public utilities that own or control interstate transmission to operate an Open Access Same-Ti...
FERPA
FERPA is the United States statute governing the privacy of student education records. It gives parents, and students once they turn eighteen, the right to inspect and seek corr...
FMCSA ELD Mandate
The FMCSA rule requiring most commercial motor vehicle drivers to record hours of service on a certified electronic logging device rather than on paper, fully effective from Dec...
FSMA Section 204 Food Traceability Rule
The FDA rule implementing Section 204 of the Food Safety Modernization Act, requiring persons who manufacture, process, pack or hold foods on the Food Traceability List to keep ...
GDPR
The General Data Protection Regulation is the EU's comprehensive data-protection law (retained in the UK as the UK GDPR), governing how personal data is processed, consented to,...
German Supply Chain Due Diligence Act
The Lieferkettensorgfaltspflichtengesetz obliges companies above an employee threshold with a presence in Germany to conduct human rights and environmental due diligence in thei...
Gramm-Leach-Bliley Act
The Gramm-Leach-Bliley Act is the 1999 US law governing how financial institutions handle and protect consumers' nonpublic personal information, including the Privacy Rule and t...
GxP
GxP is the umbrella for the good-practice quality regimes governing regulated life-science work: GLP (21 CFR Part 58) for nonclinical safety studies, GCP (ICH E6) for clinical t...
HIPAA
HIPAA is the 1996 US law that governs the privacy and security of protected health information (PHI). Its Privacy Rule sets the terms under which PHI may be used and disclosed a...
HITECH Act
The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009 as part of the American Recovery and Reinvestment Act, funded the nationwide ado...
IATA Resolution 787
Resolution 787 is the IATA industry resolution, adopted in 2012, that authorised New Distribution Capability — the XML messaging standard for airline retailing. It is not law an...
IATA Resolution 824
Resolution 824 establishes the Passenger Sales Agency Agreement — the standard contract between IATA member airlines and accredited travel agencies, and the basis of the accredi...
IATA Resolution 850m
Resolution 850m governs Agency Debit Memos — the instrument by which an airline charges an accredited agency for a breach of fare rules, booking policy or distribution terms. AD...
IDX
Internet Data Exchange is the National Association of REALTORS policy framework, implemented through each local MLS's own rules, that permits participating brokers to display ot...
Illinois Biometric Information Privacy Act
BIPA requires written consent before collecting a fingerprint, faceprint, voiceprint, retina or hand scan, mandates a published retention and destruction schedule, bans selling ...
ITU Constitution and Radio Regulations
The International Telecommunication Union is the United Nations agency for information and communication technologies, and its Constitution, Convention and Radio Regulations for...
McCarran-Ferguson Act
The McCarran-Ferguson Act is the 1945 US statute that delegated the regulation of insurance to the states and exempted the business of insurance from most federal law where a st...
MiCA
MiCA is the EU regulation that brings crypto-asset issuance and services inside a single authorisation regime. It covers asset-referenced tokens and e-money tokens — the stablec...
MiFID II
The Markets in Financial Instruments Directive II and its accompanying regulation govern investment services across the EU — including pre- and post-trade transparency obligatio...
NAIC Model Laws
The NAIC is the standard-setting and coordinating body of the United States' fifty state insurance regulators. It writes model laws and regulations that states may adopt, accred...
NAR Policy Statement 7.90
Policy Statement 7.90 of the National Association of REALTORS' Multiple Listing Service policy requires association-owned MLSs to certify against the RESO Data Dictionary and RE...
NHS Data Security and Protection Toolkit
The NHS Data Security and Protection Toolkit (DSPT) is an annual online self-assessment that organizations must complete to demonstrate they meet the National Data Guardian's da...
NIS2
NIS2 is the EU's second-generation network and information security directive, widening the scope of regulated 'essential' and 'important' entities across eighteen sectors, impo...
Ofgem Data Best Practice Guidance
Ofgem's Data Best Practice Guidance sets the data obligations of Great Britain's energy network licensees. Published in November 2021 and applied through licence conditions unde...
ONC Health IT Certification Program
The ONC Health IT Certification Program is the US voluntary-but-effectively-mandatory program under which health IT is certified against federal criteria. Its Cures Act Final Ru...
Ontario Regulation 633/21
Ontario Regulation 633/21, made under section 25.35.8 of the Electricity Act, 1998, requires Ontario electricity and natural gas local distribution companies to make customer en...
Open Government Licence
The Open Government Licence is the United Kingdom's standard legal instrument for releasing public sector information for reuse. Administered by The National Archives, it grants...
OSFI Guideline B-13
OSFI is Canada's federal prudential regulator for banks and insurers, and Guideline B-13 sets its expectations for technology and cyber risk management, alongside Guideline B-10...
Package Travel Regulations 2018
The Package Travel and Linked Travel Arrangements Regulations 2018 implement the EU Package Travel Directive in UK law, extending long-standing package-holiday protections to mo...
PHIPA
The Personal Health Information Protection Act (PHIPA) is Ontario's health-sector privacy law, in force since 2004 and overseen by the Information and Privacy Commissioner of On...
PIPEDA
PIPEDA is Canada's federal private-sector privacy law, governing how organizations collect, use, and disclose personal information in the course of commercial activity. It is th...
Privacy Act 1988
The Privacy Act 1988 is Australia's principal data-protection law, setting the Australian Privacy Principles that govern how personal information is collected, used, and disclos...
Protecting Privacy and Consumer Data Act (Bill C-36)
Tabled 15 June 2026, Bill C-36 is Canada's third attempt to replace PIPEDA — after Bill C-11 died in 2020 and Bill C-27 died on prorogation in January 2025. It would create a ne...
PSD2
PSD2 is the European Union directive that opened bank payment accounts to licensed third parties, mandating that banks provide access to accounts (XS2A) for account-information ...
PSD3 & PSR
PSD3 (the third Payment Services Directive) and the accompanying Payment Services Regulation (PSR) are the European Union's proposed successors to PSD2, intended to fix its unev...
Quebec Law 25
Quebec's Law 25 is the province's modernization of personal-information protection, introducing consent requirements, breach notification, privacy-by-default, automated-decision...
Retail Payment Activities Act
The Retail Payment Activities Act is Canada's federal law bringing payment service providers under supervision by the Bank of Canada, requiring registration and operational-risk...
RoHS
The EU's material-compliance regime for electrical and electronic equipment — RoHS restricting hazardous substances in products, WEEE governing collection and recycling, and REA...
Safe Social Media Act (Bill C-34)
Introduced 10 June 2026, Bill C-34 would enact the Digital Safety Act and create a Digital Safety Commission of Canada — imposing safety duties, risk assessment and transparency...
Sarbanes-Oxley
Sarbanes-Oxley requires management of US public companies to assess and attest to the effectiveness of internal control over financial reporting, with auditor attestation alongs...
SEC Cybersecurity Disclosure Rules
SEC rules require public companies to disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining materiality, and to describe thei...
Section 508
Section 508 requires US federal agencies — and, through procurement rules and state adoptions, the institutions that take federal funds — to make information and communications ...
Security of Critical Infrastructure Act
The SOCI Act imposes registration, mandatory incident reporting and a Critical Infrastructure Risk Management Program on responsible entities across eleven sectors — and, unusua...
Smart Energy Code
The Smart Energy Code is the multiparty contract governing Great Britain's smart-metering infrastructure. It binds energy suppliers, network operators and other parties to a com...
SOPIPA
SOPIPA is California's student privacy law, and the template most other US states adopted. Where FERPA regulates what a school may disclose, SOPIPA regulates the operator direct...
Strong Customer Authentication
Strong Customer Authentication (SCA) is the security requirement mandated by PSD2's Regulatory Technical Standards, requiring multi-factor authentication (two of knowledge, poss...
Sustainable Finance Disclosure Regulation
Regulation (EU) 2019/2088 requires financial market participants and advisers to disclose how sustainability risks are integrated into investment decisions and to report princip...
TEFCA
TEFCA is a US framework, established under the 21st Century Cures Act and operationalized by the ONC with a Recognized Coordinating Entity, that creates a nationwide floor for h...
Texas Responsible AI Governance Act
TRAIGA took effect 1 January 2026 as an intent-based AI statute: rather than imposing risk-management duties on classes of system, it prohibits developing or deploying AI with t...
UK Communications Act 2003
The Communications Act 2003 established Ofcom as the United Kingdom's converged regulator for telecommunications, broadcasting and spectrum. It governs licensing, competition, u...
UK Cyber Security and Resilience Bill
The Cyber Security and Resilience Bill is the UK's intended successor to the NIS Regulations 2018 and its answer to the EU's NIS2 — extending regulatory reach to managed service...
UK Online Safety Act
The Online Safety Act imposes duties of care on user-to-user and search services with links to the UK, enforced by Ofcom with fines to 10% of global turnover and, ultimately, bu...
UK Product Security and Telecommunications Infrastructure Act
The PSTI Act and its 2023 security regime make three baseline security requirements legally binding on consumer connectable products sold in the UK: no universal default passwor...
UNECE WP.29
UN Regulations 155 and 156, developed under UNECE WP.29, require vehicle manufacturers to operate a certified Cyber Security Management System and Software Update Management Sys...
US advanced-computing export controls
US Bureau of Industry and Security controls under the Export Administration Regulations restricting the export, reexport and in-country transfer of advanced computing chips, sem...
US Communications Act
The Communications Act of 1934, as amended by the Telecommunications Act of 1996, is the statutory basis for US telecommunications regulation and the Federal Communications Comm...
US State Age Verification Laws
Roughly half of US states now require age verification for access to adult content, and a growing group requires parental consent for minors' social media accounts. The Supreme ...
US State and Local Employment AI Laws
Employment is where US AI regulation actually bit first. Illinois HB 3773 amends the Human Rights Act to reach AI in employment decisions; New York City Local Law 144 requires a...
US State Comprehensive Privacy Laws
In the absence of a federal privacy statute, twenty US states have comprehensive consumer privacy laws in effect and twenty-four have enacted one. They converge on six rights — ...
Uyghur Forced Labor Prevention Act
US law establishing a rebuttable presumption that any goods mined, produced or manufactured wholly or in part in the Xinjiang Uyghur Autonomous Region, or by entities on an asso...
VOW
A Virtual Office Website is the National Association of REALTORS policy framework permitting a broker to provide MLS listing data to consumers who have registered and establishe...
Washington My Health My Data Act
The My Health My Data Act regulates consumer health data held by anyone HIPAA does not cover, on an extremely broad definition that reaches inferences, biometrics, precise locat...
Each regulation's full profile is written at regulations.apievangelist.com; this section is the join between those laws and the industries, countries and regions apis.io scores.