-
ADA Title II Web Accessibility Rule (ADA Title II — 42 U.S.C. §§ 12131–12165)
The U.S. Department of Justice's 2024 rule under Title II of the Americans with Disabilities Act requiring state and local governments to make their websites and mobile apps accessible to people with disabilities. It adopts WCAG 2.1 Level AA as the technical standard and sets phased compliance deadlines based on population size. It applies to public entities including state agencies, cities, counties, public colleges, and K–12 school districts — as well as to third-party EdTech and software vendors whose content or services are offered through those entities.
Website & platform compliance
-
Age Discrimination in Employment Act (ADEA — 29 U.S.C. §§ 621–634)
Protects employees and applicants age 40 and older from discrimination in hiring, promotion, discharge, compensation, and terms of employment. Applies to employers with 20 or more employees.
Hiring & employment tech
-
Americans with Disabilities Act Title III (ADA Title III — 42 U.S.C. §§ 12181–12189)
Prohibits discrimination on the basis of disability by places of public accommodation. Courts are split on whether websites qualify, but plaintiffs continue to pursue website accessibility claims — the practical standard is WCAG 2.1 AA.
Hiring & employment tech, Website & platform compliance
-
Bank Secrecy Act (BSA — 31 U.S.C. §§ 5311–5332)
Requires financial institutions (broadly defined to include many fintechs and money services businesses) to keep records, file reports, and maintain customer identification programs to assist in detecting money laundering and financial crime.
Accepting payments / fintech
-
CAN-SPAM Act (CAN-SPAM — 15 U.S.C. §§ 7701–7713)
Sets rules for commercial email and gives recipients the right to opt out. Requires honest subject lines, clear sender identification, a functional unsubscribe mechanism, and a valid physical postal address in every commercial message.
Marketing & communications, Website & platform compliance
-
Children's Online Privacy Protection Act (COPPA — 15 U.S.C. §§ 6501–6506)
Prohibits unfair or deceptive practices in the online collection of personal information from children under 13. Requires parental consent before collecting, using, or disclosing a child's data. Enforced by the FTC through the COPPA Rule (16 CFR Part 312), which specifies notice, consent, security, and data retention obligations for operators of child-directed websites and services.
Collecting & handling user data, Website & platform compliance, Privacy & data protection
-
Clayton Antitrust Act (Clayton Act — 15 U.S.C. §§ 12–27)
Prohibits specific anticompetitive practices including price discrimination, tying arrangements, and mergers that substantially lessen competition. It supplements the Sherman Act by giving regulators and private plaintiffs more targeted tools to challenge anti-competitive conduct. Applies to all businesses engaged in interstate commerce.
Antitrust & competition
-
Communications Decency Act Section 230 (Section 230 — 47 U.S.C. § 230)
Section 230 provides significant immunity to online platforms for third-party content posted by users. It is particularly relevant to AI chat systems, social platforms, marketplaces, moderation systems, and products involving user-generated or AI-assisted content, although important limitations and ongoing legal challenges exist.
Using or building AI, Website & platform compliance
-
Computer Fraud and Abuse Act (CFAA — 18 U.S.C. § 1030)
The federal anti-hacking statute. Criminalizes unauthorized access to computer systems and creates a civil cause of action companies use against former employees and competitors who misuse credentials or exceed authorized access.
Website & platform compliance, Data security & breach response, Cybersecurity
-
Copyright Act (17 U.S.C. §§ 101–1205)
The foundational federal law protecting original works of authorship. Copyright attaches automatically upon fixation; registration is not required for protection but is required before suing for infringement and to recover statutory damages.
Protecting intellectual property
-
Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA — 6 U.S.C. §§ 681–681g)
Requires critical infrastructure entities to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. CISA is developing final implementing rules. Applies to entities in the 16 critical infrastructure sectors — including IT, communications, financial services, and energy. Tech companies operating critical infrastructure or providing services to those that do should monitor CISA's rulemaking.
Data security & breach response, Cybersecurity
-
DOJ Bulk Sensitive Data Rule
Implements Executive Order 14117 restricting the bulk transfer of Americans' sensitive personal data to countries of concern (China, Russia, Iran, North Korea, Cuba, Venezuela). Effective April 2025. Covers genomic data, biometric data, precise geolocation, health data, financial data, and certain government-related data. Tech companies handling large-scale personal data should evaluate whether their data flows implicate these restrictions.
Collecting & handling user data, Privacy & data protection
-
Defend Trade Secrets Act (DTSA — 18 U.S.C. §§ 1836–1839)
Created a federal civil cause of action for trade secret misappropriation. Lets companies sue in federal court and seek injunctions, damages, and — in egregious cases — seizure of misappropriated materials.
Protecting intellectual property
-
Digital Millennium Copyright Act (DMCA — 17 U.S.C. § 512)
Establishes safe harbors for online service providers against liability for user-uploaded infringing content, provided they implement notice-and-takedown procedures. Critical for any platform hosting user-generated content.
Protecting intellectual property, Website & platform compliance
-
Dodd-Frank Wall Street Reform and Consumer Protection Act (Dodd-Frank — 12 U.S.C. § 5301 et seq.)
Sweeping financial reform law that created the Consumer Financial Protection Bureau and imposed new obligations on fintech companies, payment processors, and any business offering consumer financial products.
Accepting payments / fintech
-
Electronic Communications Privacy Act (ECPA — 18 U.S.C. §§ 2510–2522)
Governs how the government and private parties can access electronic communications and stored data, covering real-time interception, stored records, and metadata collection. It is the primary federal statute protecting the privacy of digital communications. Applies to any entity that intercepts, accesses, or stores electronic communications.
Collecting & handling user data, Data security & breach response, Privacy & data protection, Cybersecurity
-
Electronic Fund Transfer Act (EFTA — 15 U.S.C. §§ 1693–1693r)
Governs electronic fund transfers involving consumer accounts — ACH, debit cards, and digital wallets. Sets disclosure requirements, error resolution procedures, and liability limits for unauthorized transactions.
Accepting payments / fintech
-
Electronic and Information Technology Accessibility (Section 508) (Section 508 — 29 U.S.C. § 794d)
Requires federal agencies to make their electronic and information technology accessible to people with disabilities. Directly applicable to any tech company selling to the federal government — your product must meet Section 508 standards or you cannot win federal contracts. Standards align with WCAG 2.1 AA for web content. Enforced through the Access Board and federal procurement requirements.
Website & platform compliance, Government contracting
-
Employee Polygraph Protection Act (EPPA — 29 U.S.C. §§ 2001–2009)
Prohibits most private employers from requiring, requesting, or suggesting that employees or job applicants take lie detector tests. Provides limited exceptions for certain security-related positions.
Hiring & employment tech
-
Export Administration Regulations (EAR — 15 CFR §§ 730–774)
Controls the export and re-export of dual-use items -- commercial goods with potential military applications -- including encryption technology and certain software. Administered by the Bureau of Industry and Security, it requires export licenses for controlled items. Applies to any company exporting technology, software, or technical data outside the United States.
Selling or operating internationally
-
FTC Act Section 5 (FTC Act — 15 U.S.C. § 45)
Section 5 prohibits unfair or deceptive acts or practices in commerce and serves as the FTC's primary authority for regulating deceptive AI claims, unfair automated systems, and problematic data practices. It applies broadly to technology companies making representations about AI capabilities, automation, security, personalization, or algorithmic decision-making.
Collecting & handling user data, Using or building AI, Marketing & communications, Website & platform compliance, Privacy & data protection
-
Fair Credit Reporting Act (FCRA — 15 U.S.C. §§ 1681–1681x)
Regulates the collection, use, and sharing of consumer credit and background information. Applies to any company using background checks, credit reports, or algorithmic consumer evaluations for employment, housing, or credit decisions.
Collecting & handling user data, Accepting payments / fintech, Hiring & employment tech, Privacy & data protection
-
Fair Labor Standards Act (FLSA — 29 U.S.C. §§ 201–219)
Establishes minimum wage, overtime pay, recordkeeping, and child labor standards for full-time and part-time workers in the private sector and federal, state, and local governments.
Hiring & employment tech
-
Family and Medical Leave Act (FMLA — 29 U.S.C. §§ 2601–2654)
Entitles eligible employees of covered employers to take unpaid, job-protected leave for specified family and medical reasons with continuation of group health insurance coverage. Applies to employers with 50 or more employees.
Hiring & employment tech
-
Federal Acquisition Regulation (FAR — 48 CFR Ch. 1)
The primary body of rules governing all federal government procurement. Applies to all executive branch agencies. Micro-purchase threshold: $15,000. Simplified acquisition threshold: $350,000. Formal competition required above $350,000.
Government contracting, Procurement & government contracting
-
Federal Advisory Committee Act (FACA — 5 U.S.C. §§ 1001–1014)
Governs advisory committees that advise federal agencies — including many AI and technology advisory panels. Requires public notice and open meetings for most advisory committee sessions.
Government contracting, Open meetings & sunshine laws
-
Federal Risk and Authorization Management Program (FedRAMP — 44 U.S.C. §§ 3607–3616)
A government-wide program establishing security assessment standards for cloud services used by federal agencies. Not a law but effectively mandatory if you want to sell cloud services to the federal government. Authorization is expensive and time-consuming but creates a significant competitive moat — relatively few cloud providers have full authorization. Managed by GSA. Authorization levels: Low, Moderate, High corresponding to sensitivity of data processed.
Website & platform compliance, Data security & breach response, Government contracting, Cybersecurity
-
Freedom of Information Act (FOIA — 5 U.S.C. § 552)
Gives any person the right to request access to federal agency records. Heavily used by businesses, law firms, and lawyers to obtain government data about competitors, regulatory proceedings, enforcement actions, and agency decision-making. Official portal: foia.gov.
Website & platform compliance, Government contracting, Open records & FOIA
-
Government in the Sunshine Act (Sunshine Act — 5 U.S.C. § 552b)
Requires multi-member federal agencies to conduct meetings open to the public. Applies to agencies like the FTC, FCC, SEC, and similar collegial bodies. Relevant for monitoring regulatory rulemaking and enforcement policy decisions.
Government contracting, Open meetings & sunshine laws
-
Gramm-Leach-Bliley Act (GLBA — 15 U.S.C. §§ 6801–6809)
Requires financial institutions to explain their information-sharing practices and protect sensitive customer data. The Safeguards Rule mandates specific administrative, technical, and physical data security measures.
Collecting & handling user data, Accepting payments / fintech, Data security & breach response, Privacy & data protection, Cybersecurity
-
Health Information Technology for Economic and Clinical Health Act (HITECH — 42 U.S.C. §§ 17931–17954)
Strengthened HIPAA enforcement and extended HIPAA obligations directly to business associates. Introduced tiered civil penalties and required HHS to conduct periodic audits of covered entities and business associates. Relevant to any tech company that is or may become a HIPAA business associate.
Collecting & handling user data, Data security & breach response, Privacy & data protection, Cybersecurity
-
Health Insurance Portability and Accountability Act (HIPAA — 42 U.S.C. §§ 1320d–1320d-9)
Any tech company building health apps, handling patient records, operating as a business associate of a covered entity, or processing protected health information must understand HIPAA. The Privacy Rule, Security Rule, and Breach Notification Rule each impose distinct obligations. HIPAA's definition of "covered entity" and "business associate" is broader than most tech founders assume — a SaaS platform that processes health data on behalf of a hospital is a business associate and must have a signed BAA. HHS Office for Civil Rights actively enforces, particularly against tech companies following data breaches.
Collecting & handling user data, Website & platform compliance, Data security & breach response, Privacy & data protection, Cybersecurity
-
Immigration Reform and Control Act (IRCA — 8 U.S.C. § 1324a)
Requires employers to verify the identity and employment authorization of all individuals hired in the United States using Form I-9. Prohibits employment of unauthorized workers and discrimination based on citizenship status or national origin.
Hiring & employment tech
-
NIST Cybersecurity Framework 2.0 (NIST CSF)
A voluntary framework — not a law — but practically functions as a de facto compliance standard. Referenced in state breach notification laws (Tennessee), required or strongly encouraged for federal contractors, and used by courts and regulators to assess reasonableness of cybersecurity programs. CSF 2.0 released February 2024 adds a new "Govern" function to the original five (Identify, Protect, Detect, Respond, Recover). Any tech company should understand this framework before claiming to have "reasonable" security.
Website & platform compliance, Data security & breach response, Cybersecurity
-
National Labor Relations Act (NLRA — 29 U.S.C. §§ 151–169)
Protects employee rights to organize, form or join unions, bargain collectively, and engage in concerted activity for mutual aid or protection. Applies to most private-sector employers regardless of union presence.
Hiring & employment tech
-
Occupational Safety and Health Act (OSH Act — 29 U.S.C. §§ 651–678)
Requires employers to provide a workplace free from recognized hazards likely to cause death or serious physical harm. Establishes safety standards, inspection authority, and reporting requirements enforced by OSHA.
Hiring & employment tech
-
Open Source Licensing Frameworks (OSS Licenses)
Not a single law but a critical compliance area. Open source licenses create legally binding obligations when you use, modify, or distribute open source software. Key license families: Permissive (MIT, Apache 2.0, BSD — few obligations, allow proprietary use); Weak Copyleft (LGPL, MPL — share-alike requirements apply only to the licensed component); Strong Copyleft (GPL, AGPL — require distributing source code of the entire combined work). AGPL is particularly significant for SaaS companies — network use may trigger copyleft obligations even without distributing software. Every tech company needs an open source policy.
Protecting intellectual property, Website & platform compliance
-
Patent Act (35 U.S.C. §§ 1–390)
The federal law governing patents for inventions and designs. Establishes the USPTO, defines patentable subject matter, and creates enforcement rights. Patent eligibility for software remains a contested area post-Alice.
Protecting intellectual property
-
Privacy Act of 1974 (Privacy Act — 5 U.S.C. § 552a)
Governs federal agency collection, maintenance, use, and dissemination of personal information. Applies to information the government holds about individuals — relevant to tech companies whose products interact with federal agencies or whose data may be in government systems.
Government contracting, Open records & FOIA, Privacy & data protection
-
SBIR/STTR Programs (SBIR/STTR — 15 U.S.C. § 638)
Small Business Innovation Research and Small Business Technology Transfer programs provide federal R&D funding to small businesses across 11 agencies. Awardees generally retain IP rights under Bayh-Dole principles. A major entry point for tech companies seeking federal contracts.
Government contracting, Procurement & government contracting
-
Sherman Antitrust Act (Sherman Act — 15 U.S.C. §§ 1–7)
The foundational federal antitrust statute, prohibiting agreements in restraint of trade and monopolization or attempted monopolization of any market. Violations can carry criminal penalties including imprisonment. Applies to all businesses in interstate commerce and is increasingly used to challenge the market power of major technology platforms.
Antitrust & competition
-
TAKE IT DOWN Act (TAKE IT DOWN Act — Pub. L. 119-10)
Federal law criminalizing the nonconsensual publication of intimate deepfake images and requiring platforms to remove such content within 48 hours of a victim's request. Applies to any platform hosting user-generated content.
Using or building AI
-
Telephone Consumer Protection Act (TCPA — 47 U.S.C. § 227)
Restricts telemarketing calls, auto-dialed calls, prerecorded voice messages, and unsolicited text messages. It requires prior express consent for most automated contacts and maintains the National Do Not Call Registry. Applies to any business that contacts consumers by phone or text, making it one of the most heavily litigated consumer protection statutes in the country.
Marketing & communications
-
Title VII of the Civil Rights Act of 1964 (Title VII — 42 U.S.C. §§ 2000e et seq.)
Prohibits employment discrimination based on race, color, religion, sex, or national origin. Applies to employers with 15 or more employees. Covers hiring, firing, promotions, compensation, and workplace conditions. Enforced by the EEOC.
Hiring & employment tech
-
Video Privacy Protection Act (VPPA — 18 U.S.C. § 2710)
The VPPA restricts the disclosure of personally identifiable information relating to a consumer's video viewing history without consent. Although originally enacted for video rental records, it is increasingly invoked in litigation involving online video platforms, embedded video content, tracking pixels, analytics tools, and advertising technologies that share user viewing activity with third parties.
Collecting & handling user data, Privacy & data protection
-
Worker Adjustment and Retraining Notification Act (WARN Act — 29 U.S.C. §§ 2101–2109)
Requires employers with 100 or more employees to provide 60 calendar days advance written notice of plant closings and mass layoffs to affected workers, unions, and state and local government officials.
Hiring & employment tech