Website & platform compliance

40 laws across all jurisdictions

US Federal (14)
Transparency & Open Government
Freedom of Information Act
FOIA — 5 U.S.C. § 552
Gives any person the right to request access to federal agency records. Heavily used by businesses, law firms, and lawyers to obtain government data about competitors, regulatory proceedings, enforcement actions, and agency decision-making. Official portal: foia.gov.
website-platform-compliance
Last updated
Technology Standards & Compliance
ADA Title II Web Accessibility Rule
ADA Title II — 42 U.S.C. §§ 12131–12165
The U.S. Department of Justice's 2024 rule under Title II of the Americans with Disabilities Act requiring state and local governments to make their websites and mobile apps accessible to people with disabilities. It adopts WCAG 2.1 Level AA as the technical standard and sets phased compliance deadlines based on population size. It applies to public entities including state agencies, cities, counties, public colleges, and K–12 school districts — as well as to third-party EdTech and software vendors whose content or services are offered through those entities.
website-platform-compliance
Last updated
Americans with Disabilities Act Title III
ADA Title III — 42 U.S.C. §§ 12181–12189
Prohibits discrimination on the basis of disability by places of public accommodation. Courts are split on whether websites qualify, but plaintiffs continue to pursue website accessibility claims — the practical standard is WCAG 2.1 AA.
website-platform-compliance
Last updated
CAN-SPAM Act
CAN-SPAM — 15 U.S.C. §§ 7701–7713
Sets rules for commercial email and gives recipients the right to opt out. Requires honest subject lines, clear sender identification, a functional unsubscribe mechanism, and a valid physical postal address in every commercial message.
website-platform-compliance
Last updated
Communications Decency Act Section 230
Section 230 — 47 U.S.C. § 230
Section 230 provides significant immunity to online platforms for third-party content posted by users. It is particularly relevant to AI chat systems, social platforms, marketplaces, moderation systems, and products involving user-generated or AI-assisted content, although important limitations and ongoing legal challenges exist.
website-platform-compliance
Last updated
Computer Fraud and Abuse Act
CFAA — 18 U.S.C. § 1030
The federal anti-hacking statute. Criminalizes unauthorized access to computer systems and creates a civil cause of action companies use against former employees and competitors who misuse credentials or exceed authorized access.
website-platform-compliance
Last updated
Digital Millennium Copyright Act
DMCA — 17 U.S.C. § 512
Establishes safe harbors for online service providers against liability for user-uploaded infringing content, provided they implement notice-and-takedown procedures. Critical for any platform hosting user-generated content.
website-platform-compliance
Last updated
Electronic and Information Technology Accessibility (Section 508)
Section 508 — 29 U.S.C. § 794d
Requires federal agencies to make their electronic and information technology accessible to people with disabilities. Directly applicable to any tech company selling to the federal government — your product must meet Section 508 standards or you cannot win federal contracts. Standards align with WCAG 2.1 AA for web content. Enforced through the Access Board and federal procurement requirements.
website-platform-compliance
Last updated
FTC Act Section 5
FTC Act — 15 U.S.C. § 45
Section 5 prohibits unfair or deceptive acts or practices in commerce and serves as the FTC's primary authority for regulating deceptive AI claims, unfair automated systems, and problematic data practices. It applies broadly to technology companies making representations about AI capabilities, automation, security, personalization, or algorithmic decision-making.
website-platform-compliance
Last updated
Federal Risk and Authorization Management Program
FedRAMP — 44 U.S.C. §§ 3607–3616
A government-wide program establishing security assessment standards for cloud services used by federal agencies. Not a law but effectively mandatory if you want to sell cloud services to the federal government. Authorization is expensive and time-consuming but creates a significant competitive moat — relatively few cloud providers have full authorization. Managed by GSA. Authorization levels: Low, Moderate, High corresponding to sensitivity of data processed.
website-platform-compliance
Last updated
Health Insurance Portability and Accountability Act
HIPAA — 42 U.S.C. §§ 1320d–1320d-9
Any tech company building health apps, handling patient records, operating as a business associate of a covered entity, or processing protected health information must understand HIPAA. The Privacy Rule, Security Rule, and Breach Notification Rule each impose distinct obligations. HIPAA's definition of "covered entity" and "business associate" is broader than most tech founders assume — a SaaS platform that processes health data on behalf of a hospital is a business associate and must have a signed BAA. HHS Office for Civil Rights actively enforces, particularly against tech companies following data breaches.
website-platform-compliance
Last updated
NIST Cybersecurity Framework 2.0
NIST CSF
A voluntary framework — not a law — but practically functions as a de facto compliance standard. Referenced in state breach notification laws (Tennessee), required or strongly encouraged for federal contractors, and used by courts and regulators to assess reasonableness of cybersecurity programs. CSF 2.0 released February 2024 adds a new "Govern" function to the original five (Identify, Protect, Detect, Respond, Recover). Any tech company should understand this framework before claiming to have "reasonable" security.
website-platform-compliance
Last updated
Open Source Licensing Frameworks
OSS Licenses
Not a single law but a critical compliance area. Open source licenses create legally binding obligations when you use, modify, or distribute open source software. Key license families: Permissive (MIT, Apache 2.0, BSD — few obligations, allow proprietary use); Weak Copyleft (LGPL, MPL — share-alike requirements apply only to the licensed component); Strong Copyleft (GPL, AGPL — require distributing source code of the entire combined work). AGPL is particularly significant for SaaS companies — network use may trigger copyleft obligations even without distributing software. Every tech company needs an open source policy.
website-platform-compliance
Last updated
Other
Children's Online Privacy Protection Act
COPPA — 15 U.S.C. §§ 6501–6506
Prohibits unfair or deceptive practices in the online collection of personal information from children under 13. Requires parental consent before collecting, using, or disclosing a child's data. Enforced by the FTC through the COPPA Rule (16 CFR Part 312), which specifies notice, consent, security, and data retention obligations for operators of child-directed websites and services.
website-platform-compliance
Last updated
US States (20)
California Consumer Privacy Act / California Privacy Rights Act
CPRA/CCPA — Cal. Civ. Code §§ 1798.100–1798.199.100
Applies to businesses with $25M+ revenue, or processing data of 100,000+ California residents, or deriving 50%+ of revenue from selling personal information. Grants rights to know, delete, correct, and opt out of data sales or sharing. Enforced by the California Privacy Protection Agency.
website-platform-compliance
Last updated
Colorado Privacy Act
CPA — Colo. Rev. Stat. §§ 6-1-1301–6-1-1313
Applies to businesses processing data of 100,000+ Colorado residents, or 25,000+ if deriving revenue from data sales. Grants access, deletion, correction, portability, and opt-out rights. Requires data protection assessments for high-risk processing.
website-platform-compliance
Last updated
Connecticut Data Privacy Act
CTDPA — Conn. Gen. Stat. §§ 42-515–42-525
Applies to businesses processing data of 100,000+ Connecticut residents, or 25,000+ if deriving revenue from data sales. Grants access, correction, deletion, portability, and opt-out rights for targeted advertising, data sales, and profiling.
website-platform-compliance
Last updated
Delaware Personal Data Privacy Act
DPDPA — Del. Code tit. 6, ch. 12C
Applies to businesses processing data of 35,000+ Delaware residents, or 10,000+ if deriving revenue from data sales. Grants standard consumer privacy rights. One of the lower applicability thresholds among state privacy laws.
website-platform-compliance
Last updated
Florida Digital Bill of Rights
FDBR — Fla. Stat. §§ 501.701–501.721
Applies to businesses with $1B+ in global revenue that process data of 50,000+ Florida residents. One of the highest thresholds in the US — primarily targets large tech companies. Grants access, deletion, and opt-out rights.
website-platform-compliance
Last updated
Indiana Consumer Data Protection Act
Indiana CDPA — Ind. Code §§ 24-15-1–24-15-9
Applies to businesses processing data of 100,000+ Indiana residents, or 25,000+ if deriving revenue from data sales. Grants access, correction, deletion, and opt-out rights. Follows the Virginia model. Effective January 2026.
website-platform-compliance
Last updated
Iowa Consumer Data Protection Act
Iowa CDPA — Iowa Code ch. 715D
Applies to businesses processing data of 100,000+ Iowa residents, or 25,000+ if deriving revenue from data sales. More limited than most — no correction right and no profiling opt-out.
website-platform-compliance
Last updated
Kentucky Consumer Data Protection Act
KCDPA — Ky. Rev. Stat. §§ 367.800–367.870
Applies to businesses processing data of 100,000+ Kentucky residents, or 25,000+ if deriving revenue from data sales. Follows the Virginia framework. Grants access, correction, deletion, and opt-out rights. Effective January 2026.
website-platform-compliance
Last updated
Maryland Online Data Privacy Act
MODPA — Md. Code, Com. Law §§ 14-4601–14-4616
Applies to businesses processing data of 35,000+ Maryland residents, or 10,000+ if deriving revenue from data sales. One of the strictest state privacy laws — bans the sale of sensitive data without affirmative consent and imposes data minimization requirements.
website-platform-compliance
Last updated
Minnesota Consumer Data Privacy Act
MNDPA — Minn. Stat. ch. 325O
Applies to businesses processing data of 100,000+ Minnesota residents, or 25,000+ if deriving revenue from data sales. Includes strong protections around profiling and automated decision-making, with rights to access profiling logic and contest decisions.
website-platform-compliance
Last updated
Montana Consumer Data Privacy Act
MCDPA — Mont. Code §§ 30-14-2801–30-14-2817
Applies to businesses processing data of 50,000+ Montana residents, or 25,000+ if deriving revenue from data sales. Follows the Connecticut model. Grants access, correction, deletion, portability, and opt-out rights.
website-platform-compliance
Last updated
Nebraska Data Privacy Act
NDPA — Neb. Rev. Stat. §§ 87-1101–87-1116
Applies to businesses that are not small businesses under the SBA definition and process Nebraska residents' data. Modeled on the Texas framework — broader applicability than most state privacy laws. Grants standard consumer privacy rights.
website-platform-compliance
Last updated
New Hampshire Privacy Act
NH Privacy Act — N.H. Rev. Stat. ch. 359-R
Applies to businesses processing data of 35,000+ New Hampshire residents, or 10,000+ if deriving revenue from data sales. Grants standard consumer privacy rights.
website-platform-compliance
Last updated
New Jersey Data Privacy Act
NJ DPA — N.J.S.A. §§ 56:8-166–56:8-199
Applies to businesses processing data of 100,000+ New Jersey residents, or 25,000+ if deriving revenue from data sales. Grants access, correction, deletion, portability, and opt-out rights. AG enforcement only.
website-platform-compliance
Last updated
New York SHIELD Act
SHIELD Act — N.Y. Gen. Bus. Law § 899-aa
New York's data security and breach notification law. Requires businesses that own or license private information of New York residents to implement reasonable safeguards and notify affected individuals after a breach.
website-platform-compliance
Last updated
Oregon Consumer Privacy Act
OCPA — Or. Rev. Stat. §§ 646A.570–646A.604
Applies to businesses processing data of 100,000+ Oregon residents, or 25,000+ if deriving revenue from data sales. Includes strong protections for sensitive data and children's information. No revenue threshold — smaller companies may be covered.
website-platform-compliance
Last updated
Rhode Island Data Transparency and Privacy Protection Act
RIDPA — R.I. Gen. Laws §§ 6-48.1-1–6-48.1-13
Applies to businesses processing data of 35,000+ Rhode Island residents, or 10,000+ if deriving revenue from data sales. Focused on transparency and notice obligations. Effective January 2026.
website-platform-compliance
Last updated
Tennessee Information Protection Act
TIPA — Tenn. Code §§ 47-18-3301–47-18-3313
Applies to businesses processing data of 100,000+ Tennessee residents, or 25,000+ if deriving revenue from data sales. Provides an affirmative defense for businesses that implement NIST-aligned privacy programs.
website-platform-compliance
Last updated
Texas Data Privacy and Security Act
TDPSA — Tex. Bus. & Com. Code ch. 541
Applies to any business processing Texas residents' data that is not a small business under the SBA definition — no revenue or volume threshold beyond that, making it broader than most state privacy laws. Grants standard consumer privacy rights.
website-platform-compliance
Last updated
Virginia Consumer Data Protection Act
VCDPA — Va. Code §§ 59.1-575–59.1-585
Applies to businesses processing data of 100,000+ Virginia residents, or 25,000+ if deriving revenue from data sales. The first state to follow CCPA (effective 2023) and became the template for CO, CT, UT, and many others. AG enforcement only.
website-platform-compliance
Last updated
International (6)
Marco Civil da Internet
Marco Civil — Lei nº 12.965/2014
Brazil's "Internet Bill of Rights" establishing principles of net neutrality, privacy, and freedom of expression online. Imposes data retention, user notification, and due process requirements on internet service providers.
Official source is in Portuguese
website-platform-compliance
Last updated
Digital Services Act
DSA — Regulation (EU) 2022/2065
Comprehensive EU regulation governing online intermediaries and platforms. Imposes content moderation, transparency, and risk-mitigation obligations — with tiered requirements based on platform size. Very Large Online Platforms face the strictest rules.
website-platform-compliance
Last updated
Digital Republic Act
Loi République Numérique — Loi n° 2016-1321
French law establishing principles of openness, fairness, and loyalty for digital platforms. Includes provisions on data portability, platform transparency, and algorithmic accountability.
Official source is in French
website-platform-compliance
Last updated
Harmful Digital Communications Act 2015
HDCA 2015 — No. 63 of 2015
New Zealand law creating civil and criminal remedies for online harassment and digital abuse. Imposes takedown and content-moderation obligations on digital communications providers.
website-platform-compliance
Last updated
Act on Promotion of Information and Communications Network Utilization and Information Protection
Network Act — Act No. 19310
Imposes data protection, security, and user consent obligations on operators of information and communications networks in South Korea. One of Asia's earliest comprehensive internet regulatory frameworks.
Official source is in Korean
website-platform-compliance
Last updated
Online Safety Act 2023
OSA 2023 — c.50
UK law imposing duty-of-care obligations on online platforms to protect users — especially children — from illegal and harmful content. Ofcom enforces with fines up to 10% of global turnover.
website-platform-compliance
Last updated

Press Enter to go · ESC to close · Press / to open