Where the rules apply
Federal and EU laws apply everywhere. Click a state to see what applies there — darker teal means more requirements in the current filter set. Click again to deselect.
Fewer requirements
More requirements
Always applies
Federal & EU requirements
HIPAA, FDA, FTC, DOJ 28 CFR Part 202, NIST AI RMF, EU AI Act, EU GDPR, and other federal/EU rules apply regardless of state.
— federal / EU requirements in current filter
Click any state to open its requirements
The full detail panel with what it is, why it matters, actions, penalties, and sources opens on any row.
Coverage by category
Requirements by domain in the current filter
Compliance functions engaged
Which internal functions own action items in current filter
Function codes: PC Privacy · LG Legal · IT IT/InfoSec · MK Marketing · VR Vendor Risk · RD R&D/Clinical · CO Commercial · AI AI Governance · RA Regulatory Affairs · MA Medical Affairs · HR HR
Jur.
Requirement
Status
Category
Effective
Funcs
September 2026 release
Data current as of 2026-09-05 · Next update: 2026-10-01 · Delivered as consulting; when retained by a GC or outside counsel, deliverables are attorney-client privileged when applicable.
Added this release
- Alabama Personal Data Protection Act (HB 351) — added to Comprehensive State Privacy. Signed April 17, 2026; effective May 1, 2027. Lowest applicability threshold in the U.S. at 25,000 consumers.
- Oklahoma Consumer Data Privacy Act (SB 546) — added to Comprehensive State Privacy. Signed March 20, 2026; effective January 1, 2027. Virginia-model.
- Louisiana Data Privacy Act (SB 386 / Act 502) — added to Comprehensive State Privacy. Signed May 29, 2026; effective January 1, 2027. CCPA-style thresholds.
- Vermont Data Privacy and Online Surveillance Act (S.71 / Act 145) — added to Comprehensive State Privacy. Signed June 16, 2026; effective January 1, 2028. Low 3,000-consumer sensitive-data threshold particularly relevant to life sciences.
Verified this release
- DOJ Data Security Program (28 CFR Part 202) — re-verified in force per justice.gov/nsd/data-security (updated Sept 24, 2025).
- GDPR — Pseudonymisation / Health Data — re-verified; CNIL IQVIA €5M fine (May 26, 2026) drives continued relevance.
- OCR HIPAA Online Tracking Technologies Bulletin — re-verified as partially-vacated per AHA v. Becerra.
- State Wiretapping Statutes Applied to Web Pixels (CIPA) — re-verified active; LA Superior Court NetScout dismissal (May 27, 2026) notes narrowing but statute-level exposure stands.
Monitored, no material change
- EU AI Act — 2026/1744 (Digital Omnibus): no substantive amendments this cycle.
- HHS OCR — Online Tracking Technologies bulletin: no updates since June 2024 partial vacatur.
- FTC — no new pixel/adtech consent orders since last release.
Upcoming — next 90 days
- Monthly release · Sep 1, 2026 — Full monthly audit across state privacy, federal privacy, AI/cross-border, consumer health, HHS-OIG advisories.
- Quarterly release · Oct 1, 2026 — Adtech pixel litigation refresh · MGMA/Sullivan Cotter benchmark check · CMS Open Payments annual data.