57 frameworks · enforcement reviewed August 2026

Which regulations apply to you,
and what ignoring them actually costs.

Twelve questions about where you operate, what sector you are in, and what is in your databases. In return: the frameworks commonly in scope for an organisation that answered that way, who enforces each one, what the published ceiling is — and, for 7 of them, which named role can be prosecuted personally. Every figure is quoted from the instrument and linked to its source.

Tell it about your organisation

Tick everything that applies and leave the rest. Nothing is submitted anywhere — the answers are evaluated in your browser and never leave it. Skip anything you are not sure about; the result gets more specific as you go.

Where is your organisation established?
01

Where is your organisation established?

Where you are incorporated or have a place of business. Tick everywhere that applies.

Whose personal data do you hold?
02

Whose personal data do you hold?

Asked separately from the last question on purpose. Almost every privacy law here reaches organisations that have no presence in its territory at all.

What sector do you operate in?
03

What sector do you operate in?

What is actually in your databases?
04

What is actually in your databases?

The question the frameworks care about is what you hold, not what your product is for.

Who do you sell to?
05

Who do you sell to?

Does any of this describe your entity?
06

Does any of this describe your entity?

These are the statuses instruments name when they define who they bind.

Do you build, sell, or deploy AI systems?
07

Do you build, sell, or deploy AI systems?

Do you run a platform hosting content your users post?
08

Do you run a platform hosting content your users post?

Has any of your infrastructure been formally designated critical or essential?
09

Has any of your infrastructure been formally designated critical or essential?

A designation is a fact about you, not something to infer from your sector — which is why it is asked rather than derived.

What are you asked to prove before a deal closes?
10

What are you asked to prove before a deal closes?

Do third parties or vendors reach your databases directly?
11

Do third parties or vendors reach your databases directly?

Support contractors, managed service providers, offshore development, analytics vendors.

Do any of these describe your scale?
12

Do any of these describe your scale?

Several instruments turn on a threshold rather than on what you do.

Nothing ticked yet — all 54 instruments are shown below.

See the result

All 54 instruments,
grouped by how they are enforced.

These instruments differ in kind, not only in amount. Some are enforced by a regulator with a fine. Some put a named person in front of a court. Some carry no penalty at all and simply stop a deal from closing. Answer the questions above and this narrows to the ones commonly in scope for an organisation like yours. Several appear in more than one group, because several bite in more than one way. The corpus carries 57framework pages; 3 of them are sector views of an instrument already listed, because there is only one NIS2 and one GDPR.

This is a starting point for a scoping conversation, not a legal determination. Whether an instrument reaches you turns on facts a questionnaire cannot see — the scope tests that decide it are cited on each card. Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforcement data reviewed August 2026.

A regulator can fine the entity

27 frameworks
GDPR

EU General Data Protection Regulation

European UnionAll Industries

Up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher

Article 83(5) sets the upper tier for breaches of the basic principles, data subject rights, and transfer rules. A lower tier of EUR 10 million or 2% applies to controller and processor obligations, including the Article 32 security duty. Separately, Article 82 gives any person who suffers damage a direct right to compensation from the controller or processor, which is pursued in the national courts rather than through the regulator.

Covers. Any information relating to an identified or identifiable natural person.

Beyond money. Supervisory authorities can order processing to stop, suspend data transfers to a third country, and impose a temporary or definitive ban.

Enforced by National supervisory authorities, led by the lead authority for the main establishment.

GDPR itself creates no criminal offence. Article 84 leaves criminal penalties to each Member State, and several have legislated them separately.

CCPA/CPRA

California Consumer Privacy Act / California Privacy Rights Act

California, USAAll Industries

USD 2,663 per violation, or USD 7,988 per intentional violation or one involving a minor

No ceiling — scales with the breach

Administrative penalties are assessed per violation, and a violation is usually counted per affected consumer, so a single practice can compound quickly. Separately, Section 1798.150 gives consumers a private right of action after a breach of unencrypted personal information caused by a failure to maintain reasonable security, with statutory damages of USD 100 to USD 750 per consumer per incident and no need to prove harm.

Covers. Information that identifies, relates to, or could reasonably be linked with a consumer or household — the household limb is broader than most privacy laws.

Enforced by The California Privacy Protection Agency and the Attorney General — and, for breaches, consumers themselves.

Both the administrative penalties and the Section 1798.150 damages range are adjusted for inflation in odd-numbered years, so published figures drift.

LGPD

Lei Geral de Proteção de Dados

BrazilAll Industries

Up to 2% of revenue in Brazil, capped at BRL 50 million per violation

Article 52 sets a simple fine of up to 2% of the group revenue in Brazil for the last financial year, excluding taxes, with a hard per-violation cap. A daily fine may run alongside it, subject to the same cap.

Covers. Information relating to an identified or identifiable natural person.

Beyond money. ANPD can publicise the infringement, block or delete the personal data concerned, and partially or wholly suspend the processing activity.

Enforced by ANPD, the Brazilian national data protection authority.

Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.

PIPEDA

Personal Information Protection and Electronic Documents Act

CanadaAll Industries

Up to CAD 100,000 per violation

PIPEDA is deliberately weak on money next to the instruments beside it in this list. The Commissioner cannot levy administrative fines at all; the offence provisions cover obstructing an investigation and destroying records that are the subject of a request, and are prosecuted rather than assessed. Federal reform to change this died with Bill C-27 in January 2025.

Covers. Information about an identifiable individual, held in the course of commercial activity.

Enforced by The Office of the Privacy Commissioner of Canada, with prosecution by the Crown.

The Commissioner has recommendation and reporting powers, not order-making powers. The practical exposure is reputational and, increasingly, a provincial one.

PDPA

Singapore Personal Data Protection Act

SingaporeAll Industries

Up to SGD 1 million, or 10% of annual turnover in Singapore for larger organisations, whichever is higher

The turnover-linked ceiling was introduced by the 2020 amendments and applies where annual Singapore turnover exceeds SGD 10 million. Alongside the organisational penalty, Part 9B creates personal criminal offences for individuals who mishandle personal data held by their own employer.

Covers. Data about an individual who can be identified from that data, or from that data and other information the organisation has or is likely to have access to.

Personally. Any individual who knowingly or recklessly discloses, uses, or re-identifies personal data held by their organisation without authorisation — A fine of up to SGD 5,000, imprisonment for up to 2 years, or both.

Enforced by The Personal Data Protection Commission of Singapore.

Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.

PIPL

Personal Information Protection Law of China

ChinaAll Industries

Up to CNY 50 million or 5% of the previous year turnover, for serious violations

Article 66 sets a two-step scheme: an order to rectify and a fine of up to CNY 1 million for ordinary breaches, escalating to the CNY 50 million or 5% ceiling where the circumstances are serious. The same article reaches the people who ran the processing, not only the company.

Covers. Information recorded electronically or otherwise relating to identified or identifiable natural persons within China.

Beyond money. Authorities can order the suspension of the relevant business, order a full suspension for rectification, and refer the revocation of business permits or licences.

Personally. The directly liable person in charge, and other directly liable staff — A personal fine of CNY 100,000 to CNY 1 million, and a bar on serving as a director, supervisor, senior manager, or person in charge of a relevant company for a set period.

Enforced by The Cyberspace Administration of China and provincial-level authorities.

Separate criminal liability for infringing personal information exists under PRC Criminal Law and is prosecuted independently of Art. 66; it is not claimed here.

SOX

Sarbanes-Oxley Act

United StatesPublic Companies

USD 5 million and up to 20 years imprisonment for a wilful false certification

SOX is the clearest case on this page of an instrument that reaches a person rather than a balance sheet. Section 906 attaches criminal liability to the certification the CEO and CFO sign personally. Section 802 and the obstruction provisions add a separate 20-year exposure for destroying or altering records, which reaches anyone, not only officers.

Covers. Regulates the reliability of the financial reporting PROCESS, not a class of data. What comes into scope is whatever feeds a financial statement assertion, which is decided by the control narrative rather than by a definition. 18 U.S.C. Sec. 1520 separately reaches audit workpapers as records.

Personally. The CEO and the CFO, by name, on their own certification — and, separately, anyone who alters, destroys, or conceals a record to impair an official proceeding — Certification: up to USD 1 million and 10 years for a knowing false certification, rising to USD 5 million and 20 years where it is wilful. Records: up to 20 years.

Enforced by The SEC civilly; the Department of Justice criminally.

The certification offences turn on state of mind. Knowing and wilful are different thresholds carrying different maximums.

18 U.S.C. Sec. 1350as at 2026-08
GLBA

Gramm-Leach-Bliley Act

United StatesFinancial Services

Up to USD 100,000 per violation for the institution

The Safeguards Rule obliges financial institutions to maintain a written information security programme with named accountability. Enforcement is by the functional regulator, and the statute reaches the officers and directors as well as the institution.

Covers. Nonpublic personal information about a customer of a financial institution, in any form the institution handles.

Personally. Any person who obtains customer information from a financial institution under false pretences, including officers and employees who do so — Imprisonment for up to 5 years, rising to 10 years where the offence is aggravated. The officer-level fine of USD 10,000 per violation is widely cited but sits in the general enforcement provisions rather than in the criminal section.

Enforced by The FTC, the SEC, and the federal banking regulators, depending on the institution.

Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.

FTC Safeguards Ruleas at 2026-08
DORA

EU Digital Operational Resilience Act

European UnionFinancial Services

For designated critical ICT providers, 1% of average daily worldwide turnover, charged every day

Article 35 lets the Lead Overseer impose a periodic penalty payment of 1% of the average daily worldwide turnover of the preceding business year, levied daily until the provider complies, for up to six months. For financial entities themselves, penalties are set by each Member State rather than by the Regulation.

Covers. Regulates ICT risk management and operational resilience at the level of the ENTITY. Scope follows the financial entity and its critical functions, not any category of data.

Enforced by National financial regulators; the ESAs directly, for designated critical ICT providers.

The daily mechanism is designed to compel compliance rather than to punish, so it stops the moment the deficiency is remedied.

HIPAA

Health Insurance Portability and Accountability Act

United StatesHealthcare

USD 145 to USD 73,011 per violation, to a calendar-year cap of USD 2,190,294 per identical provision

Civil penalties run in four tiers keyed to culpability, from no knowledge through wilful neglect that was never corrected. The figures are adjusted for inflation annually; the amounts here took effect on 28 January 2026. Criminal referrals go to the Department of Justice and target people, not the covered entity.

Covers. Protected health information — individually identifiable health information held or transmitted by a covered entity or business associate.

Personally. Any person who knowingly obtains or discloses protected health information — employees, executives, and contractors alike. Prosecuted by the Department of Justice, not by OCR — Up to USD 50,000 and 1 year. Up to USD 100,000 and 5 years where the offence is committed under false pretences. Up to USD 250,000 and 10 years where there is intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm.

Enforced by HHS Office for Civil Rights civilly; the Department of Justice criminally.

OCR continues to apply a 2019 enforcement discretion policy that lowers the annual caps for the first three tiers below the published figure.

CMMC

Cybersecurity Maturity Model Certification

United StatesDefense Industrial Base

Treble damages plus per-claim civil penalties under the False Claims Act, and loss of contract eligibility

The exposure here is not a compliance fine but a fraud claim. The DOJ Civil Cyber-Fraud Initiative treats an inaccurate security assessment score or a false affirmation as a misrepresentation, and liability can arise with no breach and no harm to the government at all. One contractor settled for USD 4.6 million after reporting a positive score when the true score was negative 142.

Covers. Two borrowed classes. Federal contract information is the lower tier; controlled unclassified information is the higher one.

Beyond money. Suspension and debarment remove the ability to hold federal contracts.

Enforced by The Department of Defense contractually; the Department of Justice under the False Claims Act.

Phase II of the CMMC rollout was suspended in July 2026. During the interim, the Department enforces against NIST SP 800-171 self-assessment rather than requiring third-party certification — which moves the exposure onto the accuracy of your own assessment.

DoD CIO — CMMCas at 2026-08
NIS2

EU Network and Information Security Directive 2

European UnionEssential & Important Entities

Essential entities: EUR 10 million or 2% of worldwide turnover. Important entities: EUR 7 million or 1.4%

Both ceilings take the higher of the fixed sum and the percentage. The more consequential provision is not the money: Article 20 places the approval and oversight of cybersecurity risk-management measures on the management body itself, and Article 32(6) lets an authority ask a court to bar a named executive from running the business.

Covers. Regulates the security of network and information SYSTEMS. Art. 21 lists measures rather than data classes, and an entity is in scope for its sector and size, not for what it stores.

Beyond money. Authorities can also suspend a certification or authorisation covering the services concerned.

Personally. Any natural person discharging managerial responsibilities at chief executive or legal representative level in an essential entity — A temporary prohibition on exercising managerial functions in that entity, lasting until the deficiencies are remedied. Article 20 separately makes the management body accountable for approving and overseeing the measures.

Enforced by The national competent authority designated by each Member State.

Article 34 sets a floor, not a ceiling. Member States may and do set higher maximums when transposing, so the national figure is the one that governs.

EU EHDS

European Health Data Space

European UnionHealthcare / Research

Up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher

The European Health Data Space carries a GDPR-shaped penalty structure of its own, with a lower tier of EUR 10 million or 2% for less serious infringements. Health data access bodies can also act against a data user directly, independently of the supervisory authority.

Covers. Electronic health data — personal or non-personal data relating to health, in electronic form.

Beyond money. A health data access body can exclude a data user from access to the Space for up to five years.

Enforced by National health data access bodies and market surveillance authorities.

Obligations phase in over several years from entry into force, so which provisions are live depends on the date.

UK DPA

UK Data Protection Act 2018

United KingdomAll Industries

Up to GBP 17.5 million or 4% of total annual worldwide turnover, whichever is higher

The standard maximum for the UK GDPR is GBP 8.7 million or 2%; the higher maximum applies to the more serious infringements. The Act adds criminal offences that the Commissioner prosecutes in her own name, and those reach individuals who act outside their employer instructions.

Covers. Personal data as under UK GDPR, with a second heightened class the EU instrument does not have.

Personally. Any person who knowingly or recklessly obtains or discloses personal data without the consent of the controller — and, separately, a controller or their staff who alter records to defeat a subject access request — An unlimited fine on conviction. There is no custodial sentence for either offence.

Enforced by The Information Commissioner, who also prosecutes the criminal offences.

Individual prosecutions under s.170 and s.173 have resulted in convictions of employees and of company directors, but never in a prison sentence, because the sentence is not available.

SEC 17a-4

SEC Rule 17a-4 - Records to be Preserved

United StatesSecurities / Broker-Dealers

No statutory cap. Roughly USD 2.7 billion assessed across around 60 firms since 2021

No ceiling — scales with the breach

The recordkeeping rules carry no ceiling, and the off-channel communications sweep shows what that means in practice: business conducted on personal devices and unapproved messaging apps was not captured, and the penalties were sized to the firm rather than to a schedule. This is an enforcement pattern, not a published maximum.

Covers. Defined by record TYPE rather than by data class — the books and records a broker-dealer must make and then preserve.

Personally. Any person who wilfully violates the Exchange Act or a rule made under it, including supervisors and compliance officers charged individually — Up to USD 5 million and 20 years imprisonment for a wilful violation.

Enforced by The SEC and FINRA civilly; the Department of Justice for wilful violations.

The USD 2.7 billion figure describes what has been assessed to date. It is not a ceiling and should not be read as one.

17 CFR 240.17a-4as at 2026-08
NAIC MDL-668

NAIC Insurance Data Security Model Law

United States (State)Insurance

A model law. It binds only where a state has enacted its own version.

Set by each state. The model suggests USD 500 per violation to a USD 10,000 cap

Model Law 668 deliberately does not fix a national penalty. Section 10 defers to each state general insurance code, so the answer to what it costs is genuinely which state. The suggested figures rise to USD 10,000 per violation, capped at USD 50,000, where a commissioner cease-and-desist order is breached.

Covers. A three-part definition: business information whose disclosure would harm the licensee, plus consumer information by identifier, plus health information.

Beyond money. A commissioner can suspend or revoke the licence to write business in the state.

Enforced by The insurance commissioner of each state that has enacted a version of the model.

Around 28 jurisdictions have enacted some version, and the enacted texts differ. Only the version adopted in your states of licensure binds you.

MiCA

EU Markets in Crypto-Assets Regulation

European UnionCrypto / Web3 / Digital Assets

Set in national transposition. Published ceilings range from EUR 5 million or 3% of turnover upwards

MiCA sets minimum maximums and requires Member States to legislate the rest, so the tiers differ by infringement type and by country. Published summaries disagree with each other for exactly that reason. The reliable statement is that the ceilings are turnover-linked, that they reach the management body as well as the firm, and that the authorising national regulator is the one to ask.

Covers. Regulates crypto-asset SERVICES and the entities providing them. The regulated object is the activity and the authorisation, not a data class.

Beyond money. Withdrawal of the crypto-asset service provider authorisation removes the ability to operate in the Union at all.

Enforced by National competent authorities, with EBA and ESMA supervision for significant issuers.

Because the tiers are set nationally, a single headline figure would be wrong somewhere. Check the transposition in your authorising Member State.

DPDP Act

India Digital Personal Data Protection Act 2023

IndiaAll Industries

Up to INR 250 crore for failing to maintain reasonable security safeguards

The Schedule to the Act sets a distinct maximum per obligation: INR 250 crore for security safeguards, INR 200 crore for failing to notify a breach, INR 200 crore for the children provisions, and INR 150 crore for the additional obligations on significant data fiduciaries. Notably, the Act carries no imprisonment at all — the design is civil penalties only.

Covers. Digital personal data — data about an identifiable individual, in digital form or digitised afterwards.

Enforced by The Data Protection Board of India, with appeal to the Appellate Tribunal.

The Rules were notified in November 2025, but the substantive compliance obligations take effect on 13 May 2027, and enforcement begins then with no grace period.

APPI

Japan Act on Protection of Personal Information

JapanAll Industries

Up to JPY 100 million for a corporate offender

The Commission works through guidance and orders first. The penalty attaches to breaching an order or to providing a false report, rather than to the underlying handling failure, and the corporate ceiling was raised substantially by the 2020 amendments.

Covers. Information about a living individual which identifies them, including by an individual identification code.

Enforced by The Personal Information Protection Commission of Japan.

The enforcement culture is corrective rather than punitive; orders and published guidance are far more common than fines.

Quebec Law 25

Quebec Law 25 - An Act to Modernize Legislative Provisions Respecting Personal Information

Quebec, CanadaAll Industries

Penal fines to CAD 25 million or 4% of worldwide turnover; administrative penalties to CAD 10 million or 2%

No ceiling — scales with the breach

Quebec runs two parallel tracks. Administrative monetary penalties are imposed by the Commission; penal fines are prosecuted and can be doubled for a repeat offence. Section 93.1 adds a private right of action, and an infringement that is intentional or results from gross fault carries a minimum award of CAD 1,000 in punitive damages per person, which is what makes class proceedings viable.

Covers. Any information which relates to a natural person and directly or indirectly allows that person to be identified.

Enforced by The Commission d’accès à l’information, and individuals directly.

The punitive damages minimum is per individual and does not require proof of pecuniary loss, so the aggregate in a class action is driven by headcount.

SOCI Act

Australia Security of Critical Infrastructure Act 2018

AustraliaCritical Infrastructure

Civil penalties set per provision — 200 penalty units for a risk management programme failure, 750 units per day for annual reporting

The Act prices each obligation separately rather than setting one ceiling. Failing to adopt and maintain a critical infrastructure risk management programme attracts up to 200 penalty units; missing the annual report attracts 750 units per day of contravention for a company. Where the contravener is a body corporate a court may order up to five times the maximum.

Covers. Data that, if compromised, would prejudice the socio-economic stability, defence or national security of Australia — defined partly by a headcount threshold.

Beyond money. Government assistance powers allow direct intervention in the operation of a critical asset during a serious incident.

Enforced by The Cyber and Infrastructure Security Centre, within the Department of Home Affairs.

The value of a penalty unit is indexed periodically, so the dollar equivalent of each figure moves.

NERC CIP-007-6

NERC Critical Infrastructure Protection - Systems Security Management

North AmericaPower / Utilities

Up to USD 1.54 million per day per violation, indexed from the statutory USD 1 million

The Energy Policy Act of 2005 set the original ceiling at USD 1 million per day per violation and it is adjusted for inflation. Because the exposure accrues daily and per violation, a control gap that persisted across an audit period compounds. Penalties are public once filed with FERC.

Covers. Information about a BES Cyber System that could be used to gain unauthorised access to it, or to compromise its operation.

Beyond money. Findings require a mitigation plan with milestones, and can bring a public letter of reprimand, placement on a reliability watch list, and additional spot checks.

Enforced by NERC and the Regional Entities, with penalties approved by FERC.

Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.

TSA SD 1580/82

TSA Security Directives for Surface Transportation

United StatesRail / Transit

Civil penalties assessed per violation under 49 CFR Part 1503, with no schedule published for these directives

Security Directives are issued and amended without notice-and-comment, and they bind the designated owner-operators directly. TSA opens an action by serving a Notice of Proposed Civil Penalty setting out the provision, the facts, and the proposed amount, which is drawn from its published sanction guidance rather than from the directive itself.

Covers. Information whose disclosure would be detrimental to transportation security. The directives themselves are SSI.

Enforced by The Transportation Security Administration.

The directives are reissued periodically with new numbers and amended requirements, so the obligations in force change more often than a statute would.

CER Directive

EU Critical Entities Resilience Directive

European UnionWater / Waste / Energy

Penalties are set by each Member State in transposition — the Directive itself fixes no amount

Article 22 requires Member States to lay down penalties that are effective, proportionate and dissuasive, and leaves the figures to them. The obligations themselves — resilience measures, incident notification, background checks on sensitive roles — are harmonised even though the sanction is not.

Covers. Regulates the physical and organisational resilience of critical ENTITIES. It is the non-cyber sibling of NIS2 and defines no data category at all.

Enforced by The national competent authority designated by each Member State.

Because CER and NIS2 were adopted together and often transposed together, the national penalty regime for the two is frequently the same instrument.

EU AI Act

EU Artificial Intelligence Act

European Union / GlobalAI Systems / All Industries

Up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher

Article 99 sets three tiers. The top tier applies to the prohibited practices in Article 5. Breaching the provider, deployer, and other operator obligations attracts EUR 15 million or 3%; supplying incorrect or misleading information to a notified body or an authority attracts EUR 7.5 million or 1%.

Covers. The data sets used to build a high-risk AI system, plus the input data it consumes in operation.

Beyond money. Market surveillance authorities can require a system to be withdrawn from the market or recalled.

Enforced by National market surveillance authorities, and the AI Office for general-purpose models.

For SMEs and start-ups the rule inverts: the fine is the lower of the fixed sum and the percentage, not the higher.

DSA

EU Digital Services Act

European UnionDigital Platforms / Social Media

Up to 6% of annual worldwide turnover

The 6% ceiling covers infringements of the obligations, failure to comply with interim measures, and breach of binding commitments. Separately, periodic penalty payments of up to 5% of average daily worldwide turnover accrue for each day of delay in complying with an order.

Covers. Regulates intermediary SERVICES and the handling of illegal content. Obligations attach to the service and its size, not to a defined category of data.

Beyond money. For persistent and serious infringements the Commission can ask for temporary restriction of access to the service.

Enforced by The European Commission for very large platforms; national Digital Services Coordinators otherwise.

Very large online platforms and search engines carry additional obligations that smaller services do not, so the applicable duties depend on designation.

HMS OHIP

Health Management System Billing (OHIP/Alberta)

CanadaHealthcare Billing

Recovery of amounts paid, plus provincial health privacy penalties for the information itself

Billing integrity and health information privacy are two different exposures that arrive together. The ministry can audit, recover payments, and refer billing conduct for prosecution; the personal health information in the same systems is governed by provincial health privacy legislation with its own offence provisions and prosecutions.

Covers. Identifying information about an individual relating to their physical or mental health, or to the provision of health care.

Beyond money. Billing privileges can be suspended.

Enforced by The provincial health ministry and, for personal health information, the Information and Privacy Commissioner of Ontario.

The applicable statute is provincial, so Ontario and Alberta differ in both the obligations and the amounts.

Prosecution of a person is the main exposure

8 frameworks
PDPA

Singapore Personal Data Protection Act

SingaporeAll Industries

Up to SGD 1 million, or 10% of annual turnover in Singapore for larger organisations, whichever is higher

The turnover-linked ceiling was introduced by the 2020 amendments and applies where annual Singapore turnover exceeds SGD 10 million. Alongside the organisational penalty, Part 9B creates personal criminal offences for individuals who mishandle personal data held by their own employer.

Covers. Data about an individual who can be identified from that data, or from that data and other information the organisation has or is likely to have access to.

Personally. Any individual who knowingly or recklessly discloses, uses, or re-identifies personal data held by their organisation without authorisation — A fine of up to SGD 5,000, imprisonment for up to 2 years, or both.

Enforced by The Personal Data Protection Commission of Singapore.

Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.

SOX

Sarbanes-Oxley Act

United StatesPublic Companies

USD 5 million and up to 20 years imprisonment for a wilful false certification

SOX is the clearest case on this page of an instrument that reaches a person rather than a balance sheet. Section 906 attaches criminal liability to the certification the CEO and CFO sign personally. Section 802 and the obstruction provisions add a separate 20-year exposure for destroying or altering records, which reaches anyone, not only officers.

Covers. Regulates the reliability of the financial reporting PROCESS, not a class of data. What comes into scope is whatever feeds a financial statement assertion, which is decided by the control narrative rather than by a definition. 18 U.S.C. Sec. 1520 separately reaches audit workpapers as records.

Personally. The CEO and the CFO, by name, on their own certification — and, separately, anyone who alters, destroys, or conceals a record to impair an official proceeding — Certification: up to USD 1 million and 10 years for a knowing false certification, rising to USD 5 million and 20 years where it is wilful. Records: up to 20 years.

Enforced by The SEC civilly; the Department of Justice criminally.

The certification offences turn on state of mind. Knowing and wilful are different thresholds carrying different maximums.

18 U.S.C. Sec. 1350as at 2026-08
GLBA

Gramm-Leach-Bliley Act

United StatesFinancial Services

Up to USD 100,000 per violation for the institution

The Safeguards Rule obliges financial institutions to maintain a written information security programme with named accountability. Enforcement is by the functional regulator, and the statute reaches the officers and directors as well as the institution.

Covers. Nonpublic personal information about a customer of a financial institution, in any form the institution handles.

Personally. Any person who obtains customer information from a financial institution under false pretences, including officers and employees who do so — Imprisonment for up to 5 years, rising to 10 years where the offence is aggravated. The officer-level fine of USD 10,000 per violation is widely cited but sits in the general enforcement provisions rather than in the criminal section.

Enforced by The FTC, the SEC, and the federal banking regulators, depending on the institution.

Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.

FTC Safeguards Ruleas at 2026-08
HIPAA

Health Insurance Portability and Accountability Act

United StatesHealthcare

USD 145 to USD 73,011 per violation, to a calendar-year cap of USD 2,190,294 per identical provision

Civil penalties run in four tiers keyed to culpability, from no knowledge through wilful neglect that was never corrected. The figures are adjusted for inflation annually; the amounts here took effect on 28 January 2026. Criminal referrals go to the Department of Justice and target people, not the covered entity.

Covers. Protected health information — individually identifiable health information held or transmitted by a covered entity or business associate.

Personally. Any person who knowingly obtains or discloses protected health information — employees, executives, and contractors alike. Prosecuted by the Department of Justice, not by OCR — Up to USD 50,000 and 1 year. Up to USD 100,000 and 5 years where the offence is committed under false pretences. Up to USD 250,000 and 10 years where there is intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm.

Enforced by HHS Office for Civil Rights civilly; the Department of Justice criminally.

OCR continues to apply a 2019 enforcement discretion policy that lowers the annual caps for the first three tiers below the published figure.

21 CFR Part 11

FDA Electronic Records and Electronic Signatures

United States / GlobalPharmaceuticals & Life Sciences

No fine schedule. Warning letters, import alerts, consent decrees, and product seizure

Part 11 has no penalty table. Failure shows up as a data integrity observation, and data integrity is the single most cited category in drug GMP warning letters. If the electronic records are unreliable, every batch they support becomes suspect. Consent decrees in this area have routinely cost hundreds of millions.

Covers. Records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under any FDA predicate rule.

Beyond money. An import alert stops product at the border without a hearing.

Personally. Responsible corporate officers, under the Park doctrine — liability attaches by position, without proof that the officer knew or intended the violation — A misdemeanour on strict liability, rising to a felony with imprisonment where there is intent to defraud or mislead, or a repeat offence.

Enforced by The FDA, through inspection findings, warning letters, and referral to the Department of Justice.

The Park doctrine is used sparingly and is controversial, but it is settled law and it reaches officers who did not personally participate.

21 CFR Part 11as at 2026-08
IRS Pub 1075

IRS Publication 1075 - Tax Information Security Guidelines

United StatesTaxation / Government

Unauthorised disclosure of federal tax information is a felony: USD 5,000, 5 years, and dismissal

Publication 1075 is unusual in this list because the sanction lands almost entirely on people. Disclosure of federal tax information without statutory authority is a felony; inspection without authority is a separate misdemeanour. Conviction carries mandatory dismissal for a federal officer or employee, and the taxpayer can sue for damages separately.

Covers. Federal tax information — returns and return information received from the IRS or from a secondary source.

Beyond money. The IRS can suspend the agency access to federal tax information entirely.

Personally. Any officer, employee, or contractor of an agency that receives federal tax information — Disclosure: a felony carrying up to USD 5,000, 5 years, or both, plus mandatory dismissal from office on conviction. Inspection: a misdemeanour carrying up to USD 1,000 and 1 year, also with dismissal.

Enforced by The IRS Office of Safeguards, with prosecution by the Department of Justice.

Unauthorised disclosure includes disclosure through gross negligence, not only deliberate acts.

UK DPA

UK Data Protection Act 2018

United KingdomAll Industries

Up to GBP 17.5 million or 4% of total annual worldwide turnover, whichever is higher

The standard maximum for the UK GDPR is GBP 8.7 million or 2%; the higher maximum applies to the more serious infringements. The Act adds criminal offences that the Commissioner prosecutes in her own name, and those reach individuals who act outside their employer instructions.

Covers. Personal data as under UK GDPR, with a second heightened class the EU instrument does not have.

Personally. Any person who knowingly or recklessly obtains or discloses personal data without the consent of the controller — and, separately, a controller or their staff who alter records to defeat a subject access request — An unlimited fine on conviction. There is no custodial sentence for either offence.

Enforced by The Information Commissioner, who also prosecutes the criminal offences.

Individual prosecutions under s.170 and s.173 have resulted in convictions of employees and of company directors, but never in a prison sentence, because the sentence is not available.

SEC 17a-4

SEC Rule 17a-4 - Records to be Preserved

United StatesSecurities / Broker-Dealers

No statutory cap. Roughly USD 2.7 billion assessed across around 60 firms since 2021

No ceiling — scales with the breach

The recordkeeping rules carry no ceiling, and the off-channel communications sweep shows what that means in practice: business conducted on personal devices and unapproved messaging apps was not captured, and the penalties were sized to the firm rather than to a schedule. This is an enforcement pattern, not a published maximum.

Covers. Defined by record TYPE rather than by data class — the books and records a broker-dealer must make and then preserve.

Personally. Any person who wilfully violates the Exchange Act or a rule made under it, including supervisors and compliance officers charged individually — Up to USD 5 million and 20 years imprisonment for a wilful violation.

Enforced by The SEC and FINRA civilly; the Department of Justice for wilful violations.

The USD 2.7 billion figure describes what has been assessed to date. It is not a ceiling and should not be read as one.

17 CFR 240.17a-4as at 2026-08

Individuals or classes can sue directly

3 frameworks
GDPR

EU General Data Protection Regulation

European UnionAll Industries

Up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher

Article 83(5) sets the upper tier for breaches of the basic principles, data subject rights, and transfer rules. A lower tier of EUR 10 million or 2% applies to controller and processor obligations, including the Article 32 security duty. Separately, Article 82 gives any person who suffers damage a direct right to compensation from the controller or processor, which is pursued in the national courts rather than through the regulator.

Covers. Any information relating to an identified or identifiable natural person.

Beyond money. Supervisory authorities can order processing to stop, suspend data transfers to a third country, and impose a temporary or definitive ban.

Enforced by National supervisory authorities, led by the lead authority for the main establishment.

GDPR itself creates no criminal offence. Article 84 leaves criminal penalties to each Member State, and several have legislated them separately.

CCPA/CPRA

California Consumer Privacy Act / California Privacy Rights Act

California, USAAll Industries

USD 2,663 per violation, or USD 7,988 per intentional violation or one involving a minor

No ceiling — scales with the breach

Administrative penalties are assessed per violation, and a violation is usually counted per affected consumer, so a single practice can compound quickly. Separately, Section 1798.150 gives consumers a private right of action after a breach of unencrypted personal information caused by a failure to maintain reasonable security, with statutory damages of USD 100 to USD 750 per consumer per incident and no need to prove harm.

Covers. Information that identifies, relates to, or could reasonably be linked with a consumer or household — the household limb is broader than most privacy laws.

Enforced by The California Privacy Protection Agency and the Attorney General — and, for breaches, consumers themselves.

Both the administrative penalties and the Section 1798.150 damages range are adjusted for inflation in odd-numbered years, so published figures drift.

Quebec Law 25

Quebec Law 25 - An Act to Modernize Legislative Provisions Respecting Personal Information

Quebec, CanadaAll Industries

Penal fines to CAD 25 million or 4% of worldwide turnover; administrative penalties to CAD 10 million or 2%

No ceiling — scales with the breach

Quebec runs two parallel tracks. Administrative monetary penalties are imposed by the Commission; penal fines are prosecuted and can be doubled for a repeat offence. Section 93.1 adds a private right of action, and an infringement that is intentional or results from gross fault carries a minimum award of CAD 1,000 in punitive damages per person, which is what makes class proceedings viable.

Covers. Any information which relates to a natural person and directly or indirectly allows that person to be identified.

Enforced by The Commission d’accès à l’information, and individuals directly.

The punitive damages minimum is per individual and does not require proof of pecuniary loss, so the aggregate in a class action is driven by headcount.

You lose authorisation, certification, or the right to operate

26 frameworks
PIPL

Personal Information Protection Law of China

ChinaAll Industries

Up to CNY 50 million or 5% of the previous year turnover, for serious violations

Article 66 sets a two-step scheme: an order to rectify and a fine of up to CNY 1 million for ordinary breaches, escalating to the CNY 50 million or 5% ceiling where the circumstances are serious. The same article reaches the people who ran the processing, not only the company.

Covers. Information recorded electronically or otherwise relating to identified or identifiable natural persons within China.

Beyond money. Authorities can order the suspension of the relevant business, order a full suspension for rectification, and refer the revocation of business permits or licences.

Personally. The directly liable person in charge, and other directly liable staff — A personal fine of CNY 100,000 to CNY 1 million, and a bar on serving as a director, supervisor, senior manager, or person in charge of a relevant company for a set period.

Enforced by The Cyberspace Administration of China and provincial-level authorities.

Separate criminal liability for infringing personal information exists under PRC Criminal Law and is prosecuted independently of Art. 66; it is not claimed here.

PCI-DSS

Payment Card Industry Data Security Standard

GlobalPayment Card Processing

A scheme rule or contract, not law. Enforced by the counterparty.

USD 5,000 to USD 100,000 per month, tiered by how long non-compliance persists

Indicative, not a published tariff

PCI DSS is not law and no government enforces it. It becomes binding because you signed a merchant agreement. Published tiers run from USD 5,000 to USD 10,000 a month for the first quarter of non-compliance up to USD 50,000 to USD 100,000 a month from the seventh month, and the brands fine the acquirer rather than you directly.

Covers. Account data. The primary account number is what pulls a system into scope; the other cardholder fields are covered because they travel with it.

Beyond money. The real exposure is not the monthly fee. Visa and Mastercard can withdraw your right to accept their cards after persistent non-compliance or a serious breach, and an acquirer can terminate the account.

Enforced by The card brands, assessed against your acquiring bank, which passes the cost on to you.

Fine schedules are set in private scheme rules and passed through contractually, so the published figures are indicative rather than statutory.

FedRAMP

Federal Risk and Authorization Management Program

United StatesGovernment & Cloud Providers

No fine. Suspension and then revocation of the Authority to Operate

FedRAMP has no penalty schedule because it does not need one. Unresolved items on a corrective action plan escalate from the plan itself to suspension to permanent revocation, and a revoked system re-enters the authorisation process from the beginning. There is no expedited path back.

Covers. Scope is set by the FIPS 199 IMPACT LEVEL of the system — low, moderate or high — which is derived from the consequence of compromise rather than from any data definition of its own.

Beyond money. Loss of the ATO removes the ability to sell the service to federal agencies at all.

Enforced by The FedRAMP PMO and the authorising agency.

Misrepresenting FedRAMP status in a federal contract is a separate matter, and is pursued under the False Claims Act rather than under FedRAMP.

FedRAMPas at 2026-08
FISMA

Federal Information Security Management Act

United StatesFederal Government

No fine. Adverse findings, budget consequences, and loss of system authorisation

FISMA obliges agencies rather than firms, so its teeth are administrative. Annual Inspector General assessments and OMB scorecards are public, and a system that cannot sustain its authorisation to operate is taken out of service. Contractors feel it through the contract clauses that flow the obligations down.

Covers. Same structure as FedRAMP: the unit is the FIPS 199 impact level of the information system, categorised under FIPS 199 and NIST SP 800-60, not a class of data named by the Act.

Enforced by OMB, agency Inspectors General, and Congress through the appropriations process.

For a contractor the practical exposure is contractual and, where compliance was misrepresented, the False Claims Act.

StateRAMP

State Risk and Authorization Management Program

United States (State Level)State Government

No fine. Loss of authorised status on the StateRAMP Authorized Product List

StateRAMP mirrors the FedRAMP model for state and local procurement. Continuous monitoring deliverables keep a product on the Authorized Product List; missing them moves it to a lower status and eventually removes it, and a growing number of states will not buy from a product that is not listed.

Covers. Mirrors the FedRAMP impact-level model for state and local procurement, and defines no data category of its own.

Enforced by The StateRAMP Program Management Office and the participating state or local government.

Participation and mandate vary by state, so the commercial consequence varies with your market.

StateRAMPas at 2026-08
CMMC

Cybersecurity Maturity Model Certification

United StatesDefense Industrial Base

Treble damages plus per-claim civil penalties under the False Claims Act, and loss of contract eligibility

The exposure here is not a compliance fine but a fraud claim. The DOJ Civil Cyber-Fraud Initiative treats an inaccurate security assessment score or a false affirmation as a misrepresentation, and liability can arise with no breach and no harm to the government at all. One contractor settled for USD 4.6 million after reporting a positive score when the true score was negative 142.

Covers. Two borrowed classes. Federal contract information is the lower tier; controlled unclassified information is the higher one.

Beyond money. Suspension and debarment remove the ability to hold federal contracts.

Enforced by The Department of Defense contractually; the Department of Justice under the False Claims Act.

Phase II of the CMMC rollout was suspended in July 2026. During the interim, the Department enforces against NIST SP 800-171 self-assessment rather than requiring third-party certification — which moves the exposure onto the accuracy of your own assessment.

DoD CIO — CMMCas at 2026-08
NIS2

EU Network and Information Security Directive 2

European UnionEssential & Important Entities

Essential entities: EUR 10 million or 2% of worldwide turnover. Important entities: EUR 7 million or 1.4%

Both ceilings take the higher of the fixed sum and the percentage. The more consequential provision is not the money: Article 20 places the approval and oversight of cybersecurity risk-management measures on the management body itself, and Article 32(6) lets an authority ask a court to bar a named executive from running the business.

Covers. Regulates the security of network and information SYSTEMS. Art. 21 lists measures rather than data classes, and an entity is in scope for its sector and size, not for what it stores.

Beyond money. Authorities can also suspend a certification or authorisation covering the services concerned.

Personally. Any natural person discharging managerial responsibilities at chief executive or legal representative level in an essential entity — A temporary prohibition on exercising managerial functions in that entity, lasting until the deficiencies are remedied. Article 20 separately makes the management body accountable for approving and overseeing the measures.

Enforced by The national competent authority designated by each Member State.

Article 34 sets a floor, not a ceiling. Member States may and do set higher maximums when transposing, so the national figure is the one that governs.

21 CFR Part 11

FDA Electronic Records and Electronic Signatures

United States / GlobalPharmaceuticals & Life Sciences

No fine schedule. Warning letters, import alerts, consent decrees, and product seizure

Part 11 has no penalty table. Failure shows up as a data integrity observation, and data integrity is the single most cited category in drug GMP warning letters. If the electronic records are unreliable, every batch they support becomes suspect. Consent decrees in this area have routinely cost hundreds of millions.

Covers. Records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under any FDA predicate rule.

Beyond money. An import alert stops product at the border without a hearing.

Personally. Responsible corporate officers, under the Park doctrine — liability attaches by position, without proof that the officer knew or intended the violation — A misdemeanour on strict liability, rising to a felony with imprisonment where there is intent to defraud or mislead, or a repeat offence.

Enforced by The FDA, through inspection findings, warning letters, and referral to the Department of Justice.

The Park doctrine is used sparingly and is controversial, but it is settled law and it reaches officers who did not personally participate.

21 CFR Part 11as at 2026-08
CMS

Centers for Medicare & Medicaid Services Requirements

United StatesHealthcare / Medicare & Medicaid

No CMS penalty schedule. Corrective action plans, payment suspension, and termination of the provider agreement

CMS enforces through the programme rather than through a fine schedule. Conditions of participation are audited, findings produce a corrective action plan, and unresolved findings escalate to suspension of payment and ultimately termination. Where claims data is involved the False Claims Act applies on top.

Covers. Borrows HIPAA’s definition of protected health information and adds programme integrity requirements on top. It defines no data class of its own.

Beyond money. Termination of the provider agreement ends Medicare and Medicaid revenue.

Enforced by The Centers for Medicare & Medicaid Services, with the OIG and DOJ for fraud.

The monetary exposure in this area almost always arrives through the False Claims Act rather than through a CMS penalty.

CMSas at 2026-08
ISO 13485

Medical Devices Quality Management Systems

GlobalMedical Devices

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction — but the certificate gates the market

ISO 13485 is voluntary as a standard, yet in practice it is the route by which a device manufacturer demonstrates a quality management system to a notified body. Suspension of the certificate suspends the CE marking that depends on it, which stops sales.

Covers. Governs the quality management SYSTEM for medical devices. Records are defined by process — design history, device master record — rather than by data class.

Enforced by Your notified body or certification body, at surveillance audits.

The standard is voluntary; the regulation that relies on it is not. The consequence you feel comes from the latter.

ISO 13485as at 2026-08
IRS Pub 1075

IRS Publication 1075 - Tax Information Security Guidelines

United StatesTaxation / Government

Unauthorised disclosure of federal tax information is a felony: USD 5,000, 5 years, and dismissal

Publication 1075 is unusual in this list because the sanction lands almost entirely on people. Disclosure of federal tax information without statutory authority is a felony; inspection without authority is a separate misdemeanour. Conviction carries mandatory dismissal for a federal officer or employee, and the taxpayer can sue for damages separately.

Covers. Federal tax information — returns and return information received from the IRS or from a secondary source.

Beyond money. The IRS can suspend the agency access to federal tax information entirely.

Personally. Any officer, employee, or contractor of an agency that receives federal tax information — Disclosure: a felony carrying up to USD 5,000, 5 years, or both, plus mandatory dismissal from office on conviction. Inspection: a misdemeanour carrying up to USD 1,000 and 1 year, also with dismissal.

Enforced by The IRS Office of Safeguards, with prosecution by the Department of Justice.

Unauthorised disclosure includes disclosure through gross negligence, not only deliberate acts.

CJIS

FBI Criminal Justice Information Services Security Policy

United StatesLaw Enforcement

No fine schedule. Termination of access to NCIC and to criminal history record information

CJIS enforcement runs through audit and access rather than money. Findings produce corrective action; unresolved or serious findings suspend and then terminate the agency access to the national systems, which stops queries an operational unit depends on. Misuse of criminal justice information is separately a criminal matter in most states.

Covers. Criminal justice information — the data provided by the FBI CJIS systems, needed by law enforcement to perform its mission.

Beyond money. Loss of NCIC access is an operational stop, not a financial penalty.

Enforced by The FBI CJIS Division, through the state CJIS Systems Agency.

State law, not the CJIS Security Policy, supplies the criminal offence for misuse, so the exposure varies by state.

NAIC MDL-668

NAIC Insurance Data Security Model Law

United States (State)Insurance

A model law. It binds only where a state has enacted its own version.

Set by each state. The model suggests USD 500 per violation to a USD 10,000 cap

Model Law 668 deliberately does not fix a national penalty. Section 10 defers to each state general insurance code, so the answer to what it costs is genuinely which state. The suggested figures rise to USD 10,000 per violation, capped at USD 50,000, where a commissioner cease-and-desist order is breached.

Covers. A three-part definition: business information whose disclosure would harm the licensee, plus consumer information by identifier, plus health information.

Beyond money. A commissioner can suspend or revoke the licence to write business in the state.

Enforced by The insurance commissioner of each state that has enacted a version of the model.

Around 28 jurisdictions have enacted some version, and the enacted texts differ. Only the version adopted in your states of licensure binds you.

MiCA

EU Markets in Crypto-Assets Regulation

European UnionCrypto / Web3 / Digital Assets

Set in national transposition. Published ceilings range from EUR 5 million or 3% of turnover upwards

MiCA sets minimum maximums and requires Member States to legislate the rest, so the tiers differ by infringement type and by country. Published summaries disagree with each other for exactly that reason. The reliable statement is that the ceilings are turnover-linked, that they reach the management body as well as the firm, and that the authorising national regulator is the one to ask.

Covers. Regulates crypto-asset SERVICES and the entities providing them. The regulated object is the activity and the authorisation, not a data class.

Beyond money. Withdrawal of the crypto-asset service provider authorisation removes the ability to operate in the Union at all.

Enforced by National competent authorities, with EBA and ESMA supervision for significant issuers.

Because the tiers are set nationally, a single headline figure would be wrong somewhere. Check the transposition in your authorising Member State.

SOCI Act

Australia Security of Critical Infrastructure Act 2018

AustraliaCritical Infrastructure

Civil penalties set per provision — 200 penalty units for a risk management programme failure, 750 units per day for annual reporting

The Act prices each obligation separately rather than setting one ceiling. Failing to adopt and maintain a critical infrastructure risk management programme attracts up to 200 penalty units; missing the annual report attracts 750 units per day of contravention for a company. Where the contravener is a body corporate a court may order up to five times the maximum.

Covers. Data that, if compromised, would prejudice the socio-economic stability, defence or national security of Australia — defined partly by a headcount threshold.

Beyond money. Government assistance powers allow direct intervention in the operation of a critical asset during a serious incident.

Enforced by The Cyber and Infrastructure Security Centre, within the Department of Home Affairs.

The value of a penalty unit is indexed periodically, so the dollar equivalent of each figure moves.

TSA SD 1580/82

TSA Security Directives for Surface Transportation

United StatesRail / Transit

Civil penalties assessed per violation under 49 CFR Part 1503, with no schedule published for these directives

Security Directives are issued and amended without notice-and-comment, and they bind the designated owner-operators directly. TSA opens an action by serving a Notice of Proposed Civil Penalty setting out the provision, the facts, and the proposed amount, which is drawn from its published sanction guidance rather than from the directive itself.

Covers. Information whose disclosure would be detrimental to transportation security. The directives themselves are SSI.

Enforced by The Transportation Security Administration.

The directives are reissued periodically with new numbers and amended requirements, so the obligations in force change more often than a statute would.

IATA IOSA

IATA Operational Safety Audit (ISM v16)

GlobalAviation

A scheme rule or contract, not law. Enforced by the counterparty.

No fine. Loss of IOSA registration, and with it IATA membership

IOSA is an industry audit programme, not a regulation. Registration is a condition of IATA membership and is written into a great many codeshare and interline agreements, so losing it removes commercial relationships rather than triggering a penalty.

Covers. An operational safety AUDIT programme. Its scope is the operator’s processes against the ISM standards, not a class of data.

Enforced by IATA, through the audit programme and the conditions of membership.

Several national authorities reference IOSA in their own oversight, which converts a private scheme into a regulatory expectation in those jurisdictions.

IMO MSC.428(98)

IMO Maritime Cyber Risk Management

GlobalMaritime

No fine. An ISM non-conformity, which cascades into detention

MSC.428(98) requires cyber risk to be addressed in the safety management system. It carries no penalty of its own, because it does not need one: a weak SMS produces non-conformities at Document of Compliance and Safety Management Certificate audits, and ISM non-conformities lead to port state control detention, insurance consequences, and charterer rejection.

Covers. Requires cyber risk to be addressed within the safety management SYSTEM. It names no data category, which is why implementations differ so widely between operators.

Beyond money. A detained vessel is not earning.

Enforced by Flag administrations and classification societies at audit; port state control at inspection.

Inspectors increasingly ask for vessel-specific evidence rather than a fleet-level policy document.

ECC-1:2018

Saudi Arabia Essential Cybersecurity Controls (NCA)

Saudi ArabiaGovernment / Critical Infrastructure

No published fine schedule. Compliance is mandatory and assessed by the Authority

The Essential Cybersecurity Controls are mandatory for government entities and for organisations that own or operate critical national infrastructure. The Authority assesses compliance and reports it; the consequence of a poor assessment is directive and reputational rather than monetary, and it reaches procurement.

Covers. A control set for organisations. Data classification levels come from the separate Saudi NDMO data management framework, not from the ECC.

Enforced by The National Cybersecurity Authority of Saudi Arabia.

The Authority does not publish a penalty table. Treat the absence of a figure as an absence of published information, not as an absence of consequence.

EU AI Act

EU Artificial Intelligence Act

European Union / GlobalAI Systems / All Industries

Up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher

Article 99 sets three tiers. The top tier applies to the prohibited practices in Article 5. Breaching the provider, deployer, and other operator obligations attracts EUR 15 million or 3%; supplying incorrect or misleading information to a notified body or an authority attracts EUR 7.5 million or 1%.

Covers. The data sets used to build a high-risk AI system, plus the input data it consumes in operation.

Beyond money. Market surveillance authorities can require a system to be withdrawn from the market or recalled.

Enforced by National market surveillance authorities, and the AI Office for general-purpose models.

For SMEs and start-ups the rule inverts: the fine is the lower of the fixed sum and the percentage, not the higher.

DSA

EU Digital Services Act

European UnionDigital Platforms / Social Media

Up to 6% of annual worldwide turnover

The 6% ceiling covers infringements of the obligations, failure to comply with interim measures, and breach of binding commitments. Separately, periodic penalty payments of up to 5% of average daily worldwide turnover accrue for each day of delay in complying with an order.

Covers. Regulates intermediary SERVICES and the handling of illegal content. Obligations attach to the service and its size, not to a defined category of data.

Beyond money. For persistent and serious infringements the Commission can ask for temporary restriction of access to the service.

Enforced by The European Commission for very large platforms; national Digital Services Coordinators otherwise.

Very large online platforms and search engines carry additional obligations that smaller services do not, so the applicable duties depend on designation.

IACS UR E26/E27

IACS Unified Requirements for Cyber Resilience

GlobalMaritime Industrial / Mining

A scheme rule or contract, not law. Enforced by the counterparty.

No fine. Class approval is withheld, and without class the vessel does not trade

UR E26 and E27 are unified requirements applied by IACS member societies to new-build vessels and their onboard systems. They are enforced through classification: a design that does not meet them does not get approval, and a vessel without class cannot be insured or, in practice, chartered.

Covers. Governs onboard computer-based SYSTEMS on new-build vessels, through classification. The unit is the system and its criticality.

Enforced by The classification society, at plan approval and survey.

These apply on a contractual date basis to new construction, so whether they bind depends on the contract date of the vessel.

UN R155

UN Regulation 155 - Cyber Security and Cyber Security Management System

GlobalAutomotive

No fine. Without a valid CSMS certificate there is no type approval, and without type approval there is no sale

R155 turns cybersecurity into a market access condition rather than a compliance obligation. A manufacturer must hold a Cyber Security Management System certificate before a vehicle type can be approved, and since July 2024 the requirement extends to all new vehicles sold in the European Union, including types approved before 2022 that remain in production.

Covers. Governs the cyber security management SYSTEM and the vehicle type. Annex 5 lists threats and mitigations rather than data classes.

Beyond money. Approval can be withdrawn, which removes registration eligibility across more than sixty contracting parties.

Enforced by National type approval authorities across the contracting parties.

The consequence is binary and commercial. There is no partial-compliance position that still lets you sell.

HMS OHIP

Health Management System Billing (OHIP/Alberta)

CanadaHealthcare Billing

Recovery of amounts paid, plus provincial health privacy penalties for the information itself

Billing integrity and health information privacy are two different exposures that arrive together. The ministry can audit, recover payments, and refer billing conduct for prosecution; the personal health information in the same systems is governed by provincial health privacy legislation with its own offence provisions and prosecutions.

Covers. Identifying information about an individual relating to their physical or mental health, or to the provision of health care.

Beyond money. Billing privileges can be suspended.

Enforced by The provincial health ministry and, for personal health information, the Information and Privacy Commissioner of Ontario.

The applicable statute is provincial, so Ontario and Alberta differ in both the obligations and the amounts.

FERPA

Family Educational Rights and Privacy Act

United StatesEducation

No fine, and no private right of action. Withdrawal of Department of Education funding

FERPA is enforced by one instrument only, and it is a blunt one: an institution that fails to comply can lose federal education funding entirely. Because that sanction is all or nothing, the Department has never imposed it on anyone, and pursues corrective action instead. The Supreme Court confirmed in 2002 that students cannot sue under Section 1983 for a FERPA violation.

Covers. Records directly related to a student and maintained by an educational agency or institution, or by a party acting for it.

Enforced by The Student Privacy Policy Office at the US Department of Education.

The absence of a fine does not mean the absence of consequence — investigations, corrective action plans, and the reputational effect on an institution are the real mechanism.

Dubai ISR v2

Dubai Information Security Regulation Version 2

United Arab EmiratesGovernment / Real Estate / Services

No published fine schedule. Compliance is assessed and scored, and the score is visible

The Information Security Regulation is mandatory for Dubai Government entities and for the organisations that serve them. Compliance is established by audit against the control set and reported centrally; a poor result drives directives and remediation timelines, and it is visible to the entities deciding who to contract with.

Covers. A control set for Dubai Government entities. Classification levels come from the separate Dubai Data Law, not from the ISR.

Enforced by Digital Dubai, through the mandatory ISR compliance audit.

No penalty table is published. The consequence is procurement and directive, not a fine.

Digital Dubaias at 2026-08

No regulator — but the deal does not close

9 frameworks
PCI-DSS

Payment Card Industry Data Security Standard

GlobalPayment Card Processing

A scheme rule or contract, not law. Enforced by the counterparty.

USD 5,000 to USD 100,000 per month, tiered by how long non-compliance persists

Indicative, not a published tariff

PCI DSS is not law and no government enforces it. It becomes binding because you signed a merchant agreement. Published tiers run from USD 5,000 to USD 10,000 a month for the first quarter of non-compliance up to USD 50,000 to USD 100,000 a month from the seventh month, and the brands fine the acquirer rather than you directly.

Covers. Account data. The primary account number is what pulls a system into scope; the other cardholder fields are covered because they travel with it.

Beyond money. The real exposure is not the monthly fee. Visa and Mastercard can withdraw your right to accept their cards after persistent non-compliance or a serious breach, and an acquirer can terminate the account.

Enforced by The card brands, assessed against your acquiring bank, which passes the cost on to you.

Fine schedules are set in private scheme rules and passed through contractually, so the published figures are indicative rather than statutory.

SOC 2

Service Organization Control 2

GlobalService Providers

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction. A qualified opinion, or no report at all

SOC 2 is an attestation performed by an independent CPA firm against criteria you select. Nobody can sanction you for failing it. What happens instead is that the report carries exceptions, procurement asks about them, and the contract that required a clean report does not renew.

Covers. Scope is whatever the service organisation defines in its system description and the criteria it selects. There is no fixed data class — which is why two SOC 2 reports can cover very different things.

Enforced by No regulator. Your customers, through the contract and the renewal.

Where a customer contract warrants that you hold a clean SOC 2, failing it becomes a breach of that contract — which is a real exposure, just not a regulatory one.

ISO 27001

ISO/IEC 27001 Information Security Management

GlobalAll Industries

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction. Major nonconformities suspend or withdraw the certificate

Certification is a contract with a certification body, not a legal obligation. A major nonconformity that is not closed within the agreed window suspends the certificate and can lead to withdrawal, which is visible to every customer who asked for it in the first place.

Covers. Scope is whatever the organisation puts inside its ISMS boundary and its own asset inventory under A.5.9. The standard governs the management system, not a category of data.

Enforced by Your accredited certification body, at surveillance and recertification audits.

Several instruments elsewhere in this list treat an ISO 27001 certificate as evidence of appropriate technical measures, so losing it can weaken a defence under those.

ISO/IEC 27001as at 2026-08
ISO 13485

Medical Devices Quality Management Systems

GlobalMedical Devices

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction — but the certificate gates the market

ISO 13485 is voluntary as a standard, yet in practice it is the route by which a device manufacturer demonstrates a quality management system to a notified body. Suspension of the certificate suspends the CE marking that depends on it, which stops sales.

Covers. Governs the quality management SYSTEM for medical devices. Records are defined by process — design history, device master record — rather than by data class.

Enforced by Your notified body or certification body, at surveillance audits.

The standard is voluntary; the regulation that relies on it is not. The consequence you feel comes from the latter.

ISO 13485as at 2026-08
ISO 27701

ISO/IEC 27701 Privacy Information Management System

GlobalAll Industries

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction. The certificate is withdrawn or never issued

ISO 27701 extends an information security management system to cover privacy. It cannot be certified on its own, and no authority enforces it. Its value is evidentiary: it is a structured way of showing a supervisory authority or a customer what your privacy programme actually does.

Covers. Personally identifiable information — any information that can be used to identify a PII principal, or that is or might be linked to one.

Enforced by Your certification body, as an extension to an ISO 27001 certificate.

A certificate is evidence of a management system, not evidence of compliance with any privacy law.

ISO/IEC 27701as at 2026-08
IATA IOSA

IATA Operational Safety Audit (ISM v16)

GlobalAviation

A scheme rule or contract, not law. Enforced by the counterparty.

No fine. Loss of IOSA registration, and with it IATA membership

IOSA is an industry audit programme, not a regulation. Registration is a condition of IATA membership and is written into a great many codeshare and interline agreements, so losing it removes commercial relationships rather than triggering a penalty.

Covers. An operational safety AUDIT programme. Its scope is the operator’s processes against the ISM standards, not a class of data.

Enforced by IATA, through the audit programme and the conditions of membership.

Several national authorities reference IOSA in their own oversight, which converts a private scheme into a regulatory expectation in those jurisdictions.

ISO/IEC 42001

ISO/IEC 42001 Artificial Intelligence Management System

GlobalAI Systems

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction. The certificate is suspended or withdrawn

ISO/IEC 42001 certifies an AI management system. Nobody can sanction you for lacking one. It is increasingly asked for in procurement, and it is a credible way to evidence the governance the AI Act expects, but the standard and the Regulation are separate things.

Covers. Governs an AI management SYSTEM. It defers to whichever data protection regime applies for what the data actually is.

Enforced by Your certification body, at surveillance and recertification audits.

A 42001 certificate is not a conformity assessment under the AI Act and does not substitute for one.

ISO/IEC 42001as at 2026-08
ISA/IEC 62443

ISA/IEC 62443 Industrial Automation and Control Systems Security

GlobalManufacturing / Industrial

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction of its own

ISA/IEC 62443 is the reference standard for industrial automation and control system security. It is voluntary in itself, and it is heavily referenced: EU product regulation, national critical infrastructure rules, and asset-owner procurement all point at it, and those are what carry consequences.

Covers. Governs industrial automation and control SYSTEMS, organised by zones, conduits and security levels rather than by data class.

Enforced by Certification bodies where certification is sought; otherwise nobody.

Where a regulation adopts 62443 by reference, the obligation and the penalty belong to that regulation.

ISA/IEC 62443as at 2026-08
IACS UR E26/E27

IACS Unified Requirements for Cyber Resilience

GlobalMaritime Industrial / Mining

A scheme rule or contract, not law. Enforced by the counterparty.

No fine. Class approval is withheld, and without class the vessel does not trade

UR E26 and E27 are unified requirements applied by IACS member societies to new-build vessels and their onboard systems. They are enforced through classification: a design that does not meet them does not get approval, and a vessel without class cannot be insured or, in practice, chartered.

Covers. Governs onboard computer-based SYSTEMS on new-build vessels, through classification. The unit is the system and its criticality.

Enforced by The classification society, at plan approval and survey.

These apply on a contractual date basis to new construction, so whether they bind depends on the contract date of the vessel.

No enforcement; a benchmark you are measured against

11 frameworks
SOC 2

Service Organization Control 2

GlobalService Providers

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction. A qualified opinion, or no report at all

SOC 2 is an attestation performed by an independent CPA firm against criteria you select. Nobody can sanction you for failing it. What happens instead is that the report carries exceptions, procurement asks about them, and the contract that required a clean report does not renew.

Covers. Scope is whatever the service organisation defines in its system description and the criteria it selects. There is no fixed data class — which is why two SOC 2 reports can cover very different things.

Enforced by No regulator. Your customers, through the contract and the renewal.

Where a customer contract warrants that you hold a clean SOC 2, failing it becomes a breach of that contract — which is a real exposure, just not a regulatory one.

ISO 27001

ISO/IEC 27001 Information Security Management

GlobalAll Industries

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction. Major nonconformities suspend or withdraw the certificate

Certification is a contract with a certification body, not a legal obligation. A major nonconformity that is not closed within the agreed window suspends the certificate and can lead to withdrawal, which is visible to every customer who asked for it in the first place.

Covers. Scope is whatever the organisation puts inside its ISMS boundary and its own asset inventory under A.5.9. The standard governs the management system, not a category of data.

Enforced by Your accredited certification body, at surveillance and recertification audits.

Several instruments elsewhere in this list treat an ISO 27001 certificate as evidence of appropriate technical measures, so losing it can weaken a defence under those.

ISO/IEC 27001as at 2026-08
NIST CSF

NIST Cybersecurity Framework

United States / GlobalAll Industries

A voluntary standard. No regulator enforces it.

No enforcement mechanism of any kind

The Cybersecurity Framework is descriptive. It exists to give an organisation a common vocabulary for what it does and does not do, and it is frequently referenced by contracts and by regulators as a reasonable structure. Neither of those makes the framework itself enforceable.

Covers. A framework for organising a programme. It is deliberately data-agnostic so that it can sit above whichever regime actually applies.

Enforced by Nobody. It is a framework for organising a programme, not an obligation.

Where a contract or a regulator has adopted the CSF by reference, the obligation comes from that instrument, not from this one.

CIS Controls

Center for Internet Security Critical Security Controls

GlobalAll Industries

A voluntary standard. No regulator enforces it.

No enforcement mechanism of any kind

The CIS Critical Security Controls are a community-maintained, prioritised list of defensive actions. They are widely used as a starting point and are mapped into other frameworks, but there is no certification, no assessor, and no sanction.

Covers. A prioritised list of defensive ACTIONS. Safeguard 3.1 tells you to build a data inventory; it does not tell you what belongs in it, because that comes from the law you answer to.

Enforced by Nobody. A prioritised control list maintained by a non-profit.

Some cyber insurers and some state statutes reference the Controls as a safe harbour, which is where any practical consequence comes from.

NIST 800-53

NIST Special Publication 800-53 Revision 5

United StatesFederal Government / Contractors

A voluntary standard. No regulator enforces it.

No enforcement mechanism of its own — it is a control catalogue

SP 800-53 is a catalogue that other instruments point at. FISMA, FedRAMP, and a great many contract clauses adopt selected baselines from it, and the obligation then belongs to whichever of those you actually answer to.

Covers. A control CATALOGUE. Which controls apply is decided by the impact level assigned under FIPS 199, so the catalogue itself never defines what data it is protecting.

Enforced by Not enforced as a standard. Binding only where a contract or an agency policy adopts it.

If a contract flows down an 800-53 baseline, the exposure is the contract, and potentially the False Claims Act if compliance was asserted falsely.

ISO 27701

ISO/IEC 27701 Privacy Information Management System

GlobalAll Industries

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction. The certificate is withdrawn or never issued

ISO 27701 extends an information security management system to cover privacy. It cannot be certified on its own, and no authority enforces it. Its value is evidentiary: it is a structured way of showing a supervisory authority or a customer what your privacy programme actually does.

Covers. Personally identifiable information — any information that can be used to identify a PII principal, or that is or might be linked to one.

Enforced by Your certification body, as an extension to an ISO 27001 certificate.

A certificate is evidence of a management system, not evidence of compliance with any privacy law.

ISO/IEC 27701as at 2026-08
BSIMM12

Building Security In Maturity Model

GlobalSoftware Development

A voluntary standard. No regulator enforces it.

No enforcement mechanism, and nothing to comply with

BSIMM describes what a set of real software security programmes actually do, and scores yours against that distribution. There is no pass mark, no certificate, and no assessor with authority over you. It is a mirror, not a bar.

Covers. A descriptive study of what software security programmes do. It measures activities, has no pass mark, and defines nothing about data.

Enforced by Nobody. It is an observational study, not a standard to be met.

Treating a descriptive model as a compliance target is a common category error. A low score is information, not a finding.

BSIMMas at 2026-08
SPD-5

US Space Policy Directive 5 - Cybersecurity Principles for Space Systems

United StatesSpace / Satellite

A voluntary standard. No regulator enforces it.

No enforcement mechanism. Principles, which agencies then write into contracts and licences

Space Policy Directive 5 sets cybersecurity principles for space systems and directs agencies to consider them. It creates no obligation on a commercial operator by itself. Where it bites is downstream, in the licence conditions and contract clauses agencies subsequently adopt.

Covers. A set of PRINCIPLES directed at US agencies. It names no data category, and reaches an operator only through whatever licence or contract adopts it.

Enforced by Nobody directly. It is a policy directive to federal agencies, not a rule binding operators.

Check the licence or contract that governs your mission; that is where any enforceable version of these principles will be.

ISO/IEC 42001

ISO/IEC 42001 Artificial Intelligence Management System

GlobalAI Systems

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction. The certificate is suspended or withdrawn

ISO/IEC 42001 certifies an AI management system. Nobody can sanction you for lacking one. It is increasingly asked for in procurement, and it is a credible way to evidence the governance the AI Act expects, but the standard and the Regulation are separate things.

Covers. Governs an AI management SYSTEM. It defers to whichever data protection regime applies for what the data actually is.

Enforced by Your certification body, at surveillance and recertification audits.

A 42001 certificate is not a conformity assessment under the AI Act and does not substitute for one.

ISO/IEC 42001as at 2026-08
ISA/IEC 62443

ISA/IEC 62443 Industrial Automation and Control Systems Security

GlobalManufacturing / Industrial

A voluntary standard. No regulator enforces it.

No regulator and no statutory sanction of its own

ISA/IEC 62443 is the reference standard for industrial automation and control system security. It is voluntary in itself, and it is heavily referenced: EU product regulation, national critical infrastructure rules, and asset-owner procurement all point at it, and those are what carry consequences.

Covers. Governs industrial automation and control SYSTEMS, organised by zones, conduits and security levels rather than by data class.

Enforced by Certification bodies where certification is sought; otherwise nobody.

Where a regulation adopts 62443 by reference, the obligation and the penalty belong to that regulation.

ISA/IEC 62443as at 2026-08
Bill C-27 CPPA

Canada Consumer Privacy Protection Act (Digital Charter)

CanadaAll Industries / Agriculture

Not in force. Nothing here is currently enforceable.

No enforcement mechanism, because there is no statute

Bill C-27 would have replaced the commercial provisions of PIPEDA with the Consumer Privacy Protection Act, a new Tribunal, and the Artificial Intelligence and Data Act. It died on the Order Paper in January 2025 when Parliament was prorogued, before reaching a vote. Canada continues to run on PIPEDA, a statute written in 2000.

Covers. Not in force. Bill C-27 died on the Order Paper in January 2025, so PIPEDA’s definition of personal information still governs in Canada.

Enforced by None. There is no authority, because there is no statute.

Any figure you see quoted for CPPA penalties describes a bill that never became law. Federal privacy reform has been signalled but no replacement has been enacted.

What evidence these frameworks
actually ask for.

Across the whole corpus, 57 frameworks cite 228 requirements between them — and they resolve to nine capabilities, not 57 programmes. That overlap is the argument for running compliance, security, and incident management off one continuously-classified inventory instead of three.

One collector, one inventory, three jobs. The classification that finds the regulated data is the same classification that ranks the vulnerabilities and attributes the file changes, which is why it cannot go stale without something visibly breaking.

What this does not do

  • It does not tell you whether an instrument applies to you. Scope turns on facts twelve checkboxes cannot see — corporate structure, contracts, designations, where processing physically happens. What it does is narrow 57 down to a shortlist worth taking to someone who can answer properly.
  • It does not tell you what you would pay.Every figure here is a published ceiling. Enforcement is discretionary, tiered, and in most regimes lands well below the maximum.
  • It does not assess whether you meet any of these requirements. DB Audit produces evidence — it records, detects, attributes, and proves. Whether that evidence satisfies an auditor is the auditor's call, and compliance is an organisational property no tool can confer.
  • It does not write your policies. Where a mandate is organisational — a cryptography policy, a documented procedure, a training programme — the services layer maps the gap, builds the roadmap, and assembles the auditor-ready pack. Drafting and owning the policy stays with you.
  • It is not legal advice. No part of this page creates a professional relationship or substitutes for counsel who knows your business.

Now check it against the actual estate

A shortlist is the easy half. The hard half is which of those requirements you can already prove today, from the databases you actually have. A fixed-fee gap assessment answers that one — and your answers above come with the enquiry, so nobody has to ask twice.

Enforcement data reviewed August 2026. Several figures — HIPAA, CCPA, and NERC CIP among them — are indexed annually and move. Each card carries its own date.