Templates, forms and where to find help
The assessment templates and compliance forms regulators publish for free, the regulators themselves, and the organizations practitioners rely on — each linked to the issuing body's own copy.
Free LegisGate tools
The AI Regulatory Obligations Handbook
Seven chapters, three handouts and six worksheets on running the program. Free, no account.
Intelligence Library
What each AI and privacy law requires, by jurisdiction, with provisions cited to the source.
AI Tracker
AI bills, enforcement actions and key dates across US states and other jurisdictions.
EDPB Converter
Upload an existing DPIA and get it remapped into the structure of the EDPB's draft harmonised template. Free.
Data Protection Impact Assessment templates
Templates and tools published by data protection authorities for GDPR Article 35 and its equivalents.
- Official
Office of the Australian Information Commissioner · Australia · Word
- Guide — analyse d'impact relative à la protection des donnéesOfficial
DPIA screening guide
Autorité de protection des données · Belgium · PDF
Helps decide whether a DPIA is needed. Version 4.0, 2021.
- Modelo de Relatório de Impacto à Proteção de Dados Pessoais (RIPD)Official
Model data protection impact report
Secretaria de Governo Digital, Ministry of Management and Innovation · Brazil · PDF
Published for the federal public sector (July 2026). Brazil's data protection authority, ANPD, does not publish a model.
- Plantilla d'avaluació d'impacte relativa a la protecció de dadesOfficial
DPIA template (an offline DPIA app is also available)
Autoritat Catalana de Protecció de Dades (APDCAT) · Catalonia · PDF
- DPIA obrazacOfficial
DPIA form
AZOP · Croatia · Word
- Metodika obecného posouzení vlivu na ochranu osobních údajůOfficial
General DPIA methodology
Úřad pro ochranu osobních údajů (ÚOOÚ) · Czech Republic · PDF
Version 1.0, 2020.
- Skabelon til konsekvensanalyseOfficial
Impact assessment template
Datatilsynet · Denmark · Excel
- Skabelon til konsekvensanalyse ved AIOfficial
Impact assessment template for AI
Datatilsynet · Denmark · Excel
- MõjuhinnangOfficial
DPIA form
Andmekaitse Inspektsioon (AKI) · Estonia · PDF
July 2025.
- Consultation draft
European Data Protection Board · European Union · Word
Version 1.0, published for consultation. The EDPB has said it will finalise the template after the consultation.
- TVA-työkaluOfficial
DPIA tool
Office of the Data Protection Ombudsman · Finland · Excel
- Outil PIAOfficial
PIA software (open source, 20 languages)
CNIL · France · Online tool
Italy's Garante recommends the Italian version of this tool rather than publishing its own template.
- PIA — les modèlesOfficial
PIA templates
CNIL · France · PDF
- DSFA Muss-ListeOfficial
List of processing that requires a DPIA
Datenschutzkonferenz (DSK) · Germany · PDF
Version 1.1.
- Kurzpapier Nr. 5 — Datenschutz-FolgenabschätzungOfficial
Short paper no. 5: DPIA
Datenschutzkonferenz (DSK) · Germany · PDF
Office of the Privacy Commissioner for Personal Data · Hong Kong · PDF
Includes a risk assessment section for AI. June 2024.
- Official
Data Protection Commission · Ireland · PDF
November 2024.
- PIAの取組の促進についてOfficial
Promoting privacy impact assessment
Personal Information Protection Commission · Japan · PDF
June 2021.
Office of the Data Protection Commissioner · Kenya · PDF
- NIDA veikšanas veidlapaOfficial
DPIA form
Datu valsts inspekcija (DVI) · Latvia · Word
- Formulaire AIPD pour consultation préalableOfficial
Prior consultation form (GDPR Art. 36)
CNPD · Luxembourg · Word
For consulting the regulator when a DPIA shows high residual risk.
- Model DPIA RijksdienstOfficial
Model DPIA for central government
Ministry of the Interior (BZK) · Netherlands · PDF
August 2026.
- Rapportagemodel DPIA RijksdienstOfficial
DPIA report template for central government
Ministry of the Interior (BZK) · Netherlands · Word
Version 3.0.
Office of the Privacy Commissioner · New Zealand · Word
A short first-pass analysis to decide whether a full PIA is needed.
- Official
Office of the Privacy Commissioner · New Zealand · Word
Part of the 2024 PIA toolkit.
- Sjekkliste for vurdering av personvernkonsekvenserOfficial
DPIA checklist
Datatilsynet · Norway · PDF
A checklist for each phase, not a full template.
Information and Privacy Commissioner of Ontario · Ontario · PDF
November 2025. Worksheets are published alongside it.
National Privacy Commission · Philippines · PDF
National Privacy Commission · Philippines · PDF
- Modèle de rapport d'EFVPOfficial
Privacy impact assessment report template
Commission d'accès à l'information · Quebec · Word
Version 1.1, April 2024. The Commission describes it as a first version that will evolve.
- Réaliser une évaluation des facteurs relatifs à la vie privéeOfficial
Guide to privacy impact assessment
Commission d'accès à l'information · Quebec · PDF
Version 3.1, April 2024.
Personal Data Protection Commission · Singapore · PDF
Revised September 2021.
- Gestión del riesgo y evaluación de impacto en tratamientos de datos personalesOfficial
Risk management and impact assessment guide
AEPD · Spain · PDF
June 2021.
- Gestiona RGPDOfficial
Online risk and DPIA tool
AEPD · Spain · Online tool
- Modelo de informe de EIPD — administraciones públicasOfficial
DPIA report model — public administrations
AEPD · Spain · RTF
- Modelo de informe de EIPD — sector privadoOfficial
DPIA report model — private sector
AEPD · Spain · RTF
- Official
Integritetsskyddsmyndigheten (IMY) · Sweden · PDF
May 2025.
- Merkblatt zur Datenschutz-FolgenabschätzungOfficial
DPIA factsheet (FADP Arts. 22–23)
Federal Data Protection and Information Commissioner (FDPIC) · Switzerland · PDF
August 2023.
- Official
Information Commissioner's Office · United Kingdom · Word
The ICO says organisations may adapt its sample.
Fundamental Rights Impact Assessment
The EU AI Act Article 27 assessment, and the official methodologies available while the AI Office template is pending.
- Official
Autoritat Catalana de Protecció de Dades (APDCAT) · Catalonia · PDF
Published January 2025, in English.
- Official
Council of Europe · Council of Europe · PDF
Method for assessing an AI system's impact on human rights, democracy and the rule of law. Non-binding; provisional 2026 version.
- Not yet published
Fundamental Rights Impact Assessment template (AI Act Art. 27(5))
European AI Office · European Union
The Act requires the AI Office to publish a template questionnaire. It had not been published at our last check; the deployer duty applies from December 2, 2027.
European Center for Not-for-Profit Law and the Danish Institute for Human Rights · International · PDF
Includes a questionnaire template. December 2025.
Ministry of the Interior (BZK) · Netherlands · PDF
The English text of version 1. The Dutch version 2 (above) supersedes it.
- Impact Assessment Mensenrechten en Algoritmes (IAMA), versie 2Official
Human rights and algorithms impact assessment, version 2
Ministry of the Interior (BZK) · Netherlands · PDF
February 2026, aligned with AI Act Article 27.
US state privacy risk and data protection assessments
None of the state regulators we checked publishes a fill-in template. The law sets out what the assessment must contain, and these pages explain it.
- Official
California Privacy Protection Agency · California · Web page
No template. The regulations list what the risk assessment covers and what must be submitted to the Agency — first by April 1, 2028, for assessments from 2026 and 2027.
Colorado Attorney General · Colorado · Web page
No template. Part 8 of the Attorney General's rules sets out what a data protection assessment must contain and when it must be produced.
- Official
Connecticut Attorney General · Connecticut · Web page
No template. The Attorney General's FAQ describes what a data protection assessment must cover.
Oregon Department of Justice · Oregon · PDF
The Department states there is no set form to fill out, and explains what an assessment should cover.
EU AI Act — official templates and guidance
Templates, codes and guidelines published by the European Commission and the AI Office.
European Commission · European Union · Web page
Art. 50(2), (4) and (5). June 2026. Voluntary.
European Commission (AI Office) · European Union · Web page
Published for consultation in September 2025. No final version had been published at the time of our last check.
- Consultation draft
European Commission · European Union · Web page
Art. 6. Published for consultation in May 2026.
European Commission (AI Office) · European Union · Web page
Transparency, copyright, and safety and security chapters for Arts. 53 and 55. Voluntary.
European Commission · European Union · Web page
Art. 5. February 2025.
European Commission · European Union · Web page
Art. 3(1). February 2025.
European Commission · European Union · Web page
July 2025.
- Official
European Commission · European Union · Web page
Art. 50. July 2026.
European Commission (AI Act Service Desk) · European Union · Web page
When each part applies, as amended by the Digital Omnibus on AI.
- Official
European Commission (AI Office) · European Union · Word
Part of the Code's transparency chapter, for the documentation duties in Art. 53(1)(a)–(b).
European Commission (AI Office) · European Union · Web page
Art. 55(1)(c). Published November 2025.
European Commission (AI Office) · European Union · Web page
Required of general-purpose AI model providers under Art. 53(1)(d). Published July 2025, in 24 languages.
AI assessment and documentation tools from governments
Free assessment frameworks and toolkits published by government bodies.
Treasury Board of Canada Secretariat · Canada · Online tool
Required of Canadian federal institutions under the Directive on Automated Decision-Making.
NYC Department of Consumer and Worker Protection · New York City · Web page
Bias audit, published summary of results and candidate notice under Local Law 144. There is no official template; the rules and FAQ set out the required content.
- Official
AI Verify Foundation (IMDA) · Singapore · Online tool
Open-source AI testing toolkit. Voluntary.
PDPC and IMDA · Singapore · PDF
Voluntary. 2020.
Information Commissioner's Office · United Kingdom · Excel
Risk assessment for AI systems that process personal data. The ICO says this guidance is under review for the Data (Use and Access) Act.
NIST · United States · PDF
Voluntary. January 2023.
- Official
NIST · United States · Web page
Suggested actions for each part of the AI Risk Management Framework.
NIST · United States · PDF
Voluntary. July 2024.
International data transfers
Standard clauses and transfer tools approved by regulators.
- Official
European Commission · European Union · Web page
The countries the Commission has found to offer adequate protection (GDPR Art. 45).
European Data Protection Board · European Union · Web page
How to assess a transfer and choose supplementary measures after Schrems II.
European Commission · European Union · Web page
The Commission's page for both sets of clauses, with its questions and answers.
European Commission · European Union · Web page
Approved controller–processor contract terms under GDPR Art. 28(7).
- Official
European Commission · European Union · Web page
The Commission's approved clauses for transfers outside the EEA (GDPR Art. 46(2)(c)).
Federal Data Protection and Information Commissioner (FDPIC) · Switzerland · PDF
Using the EU clauses, with Swiss adaptations, under the Swiss FADP (updated February 2025).
Information Commissioner's Office · United Kingdom · PDF
Lets the EU clauses be used for transfers from the UK. Same 2026 update planned as the IDTA.
Information Commissioner's Office · United Kingdom · PDF
UK restricted transfers. The ICO has said it will update the IDTA in 2026 for the Data (Use and Access) Act; keep using the current version until then.
- Official
Information Commissioner's Office · United Kingdom · Word
The ICO's tool for assessing a restricted transfer (November 2022).
- Official
U.S. Department of Commerce · United States · Online tool
Check whether a US recipient is certified under the EU-US Data Privacy Framework.
Records of processing
Templates for the record of processing activities under GDPR Article 30.
- Exemple de registreOfficial
Example register
CNIL · France · PDF
- Modèle de registre simplifiéOfficial
Simplified register template
CNIL · France · OpenDocument spreadsheet
GDPR Art. 30 record of processing.
- Official
AEPD · Spain · Online tool
Generates the core GDPR documents, including the record of processing, for low-risk processing.
Information Commissioner's Office · United Kingdom · Excel
Record of processing activities for controllers (UK GDPR Art. 30(1)).
Information Commissioner's Office · United Kingdom · Excel
Record of processing activities for processors (UK GDPR Art. 30(2)).
Legitimate interests assessments
Templates for documenting the balancing test when relying on legitimate interests.
Information Commissioner's Office · United Kingdom · Word
Documents the three-part test for UK GDPR Art. 6(1)(f).
Breach notification
Official forms and portals for reporting a personal data breach to a regulator.
- Official
Office of the Australian Information Commissioner · Australia · Web page
Notifiable Data Breaches scheme, Privacy Act 1988 Part IIIC.
- Comunicação de Incidente de Segurança (CIS)Official
Security incident notification
ANPD · Brazil · Web page
LGPD Art. 48.
- Official
California Attorney General · California · Online form
A sample notice goes to the Attorney General when more than 500 California residents are notified (Civ. Code § 1798.82(f)).
European Data Protection Board · European Union · Web page
Worked examples of when to notify under GDPR Arts. 33–34.
- Notifier une violation de données personnellesOfficial
Notify a personal data breach
CNIL · France · Web page
GDPR Art. 33.
- Official
Data Protection Commission · Ireland · Web page
GDPR Art. 33.
- Official
Garante per la protezione dei dati personali · Italy · Web page
GDPR Art. 33.
- Meldformulier datalekkenOfficial
Data breach report form
Autoriteit Persoonsgegevens · Netherlands · Online form
GDPR Art. 33.
- Official
New York Attorney General · New York · Web page
General Business Law § 899-aa.
Personal Data Protection Commission · Singapore · Web page
PDPA s 26D.
- Guía para la notificación de brechas de datos personalesOfficial
Guide to personal data breach notification
AEPD · Spain · PDF
- Notificación de brechas de datos personalesOfficial
Personal data breach notification
AEPD · Spain · Online form
GDPR Art. 33.
- Official
Texas Attorney General · Texas · Web page
Business and Commerce Code § 521.053.
- Official
Information Commissioner's Office · United Kingdom · Web page
UK GDPR Art. 33.
Federal Trade Commission · United States · Online form
Health Breach Notification Rule, 16 CFR Part 318.
HHS Office for Civil Rights · United States · Web page
HIPAA breach notification, 45 CFR § 164.408.
Registration and DPO designation
Official forms for registering with a regulator and notifying it of your data protection officer.
- Désigner un DPO ou modifier une désignationOfficial
Designate a DPO or change a designation
CNIL · France · Web page
GDPR Art. 37(7). The page links to the online designation service.
- Official
Data Protection Commission · Ireland · Online form
GDPR Art. 37(7). No fee.
- Official
Information Commissioner's Office · United Kingdom · Web page
Registration with the ICO and the data protection fee, under the Data Protection (Charges and Information) Regulations 2018.
Data broker registration
Official registration portals for states with data broker registries.
California Privacy Protection Agency · California · Online tool
Registered data brokers began processing consumer deletion requests from August 1, 2026.
- Official
California Privacy Protection Agency · California · Web page
Annual registration under the Delete Act; the window is January 1–31.
- Official
Oregon Division of Financial Regulation · Oregon · Web page
Annual registration and fee.
- Official
Texas Secretary of State · Texas · Web page
Registration with Form 4001 and an annual fee.
- Official
Vermont Secretary of State · Vermont · Web page
Annual registration, January 1–31.
Organizations for further resources
Professional associations
- Health Care Compliance Association (HCCA)
United States, healthcare
Healthcare compliance education, publications and events.
- International Association of Privacy Professionals (IAPP)
Global
Resource library on privacy and AI law, legislation trackers and templates. Some resources are for members only.
- ISACA
Global
IT audit, risk and governance resources, including AI audit material.
- National Association of Attorneys General (NAAG)
US states and territories
The attorneys general's consumer protection work, which covers state privacy enforcement.
- Society of Corporate Compliance and Ethics (SCCE)
Global
Compliance and ethics publications and newsletters. Some are for members only.
Regulator networks
- Asia Pacific Privacy Authorities (APPA)
Asia-Pacific
Resources and communiqués from the region's privacy authorities.
- Common Thread Network
Commonwealth
The network of Commonwealth data protection authorities.
- European Data Protection Board (EDPB)
EU and EEA
GDPR guidelines, opinions and statements, searchable by topic.
- Global Privacy Assembly
Global
Resolutions, joint statements and working group reports from the world's privacy authorities.
- Red Iberoamericana de Protección de Datos (RIPD)
Ibero-America
Guides from Spanish- and Portuguese-speaking authorities, including on AI. Mostly in Spanish.
Intergovernmental bodies
- Council of Europe — Artificial intelligence
AI Framework Convention parties
The Framework Convention on AI and related resources.
- Council of Europe — Data protection
Convention 108 parties
Convention 108 and its committee's documents and resources.
- OECD — Privacy and data protection
OECD members
The OECD Privacy Guidelines and related policy work.
- OECD.AI Policy Observatory
Global
Catalogue of tools and metrics for trustworthy AI, and national AI policies.
- UNESCO — Ethics of artificial intelligence
Global
The UNESCO Recommendation on the Ethics of AI and its tools.
Government agencies
- AI Act Service Desk
European Union
The Commission's official information platform for the AI Act.
- AI Security Institute
United Kingdom
UK government research and evaluations of advanced AI.
- California Privacy Protection Agency
California
The CCPA and the Agency's regulations, including current rulemaking.
- CNIL — Artificial intelligence
France
The French regulator's AI and data protection material, in English.
- European AI Office
European Union
The Commission body implementing the AI Act, with links to its guidance and codes.
- European Data Protection Supervisor (EDPS)
EU institutions
EDPS guidelines, including on AI.
- European Union Agency for Cybersecurity (ENISA)
European Union
EU cybersecurity reports, guidance and threat landscape publications.
- Federal Trade Commission — Artificial intelligence
United States
FTC AI guidance, cases and statements.
- Federal Trade Commission — Privacy and security
United States
FTC business guidance on privacy and data security.
- Information Commissioner's Office — AI guidance
United Kingdom
The UK regulator's guidance on AI and data protection.
- NIST AI Resource Center
United States
The AI Risk Management Framework, its playbook and related resources.
- NIST Privacy Framework
United States
The NIST Privacy Framework and supporting resources.
- Personal Data Protection Commission
Singapore
PDPA advisory guidelines and regulatory guidance.
Research and policy non-profits
- Ada Lovelace Institute
United Kingdom and international
Research library on data and AI policy.
- AI Incident Database
Global
Searchable database of reported AI incidents.
- AI Standards Hub
United Kingdom and international
Tracks AI standards and related developments, with free e-learning.
- AI Verify Foundation
Singapore and international
Open-source AI testing tools and assurance resources.
- Brookings Institution — Artificial intelligence
United States
Policy research and commentary on AI.
- Center for Democracy & Technology
United States and EU
Research and policy work on privacy, data and AI.
- Future of Privacy Forum
Global
Privacy and AI policy analysis, reports and legislative comparisons.
- OWASP Gen AI Security Project
Global
Security guidance for LLM and generative AI applications, including the LLM Top 10.
- Partnership on AI
Global
Frameworks and guidance on responsible AI practice.
- Stanford HAI — AI Index
Global
Annual report with data on AI research, industry and policy.
Regulator contacts
335 authorities, by jurisdiction, with a link to each one's official website.
Abu Dhabi Global Market · 1
Alabama · 1
Andorra · 1
Angola · 1
Argentina · 1
Armenia · 1
Australia · 1
Australian Capital Territory · 1
Baden-Württemberg · 1
Barbados · 1
Basque Country · 1
Bavaria · 2
Beijing · 1
Bermuda · 1
Bosnia and Herzegovina · 1
Brandenburg · 1
British Columbia · 1
Burkina Faso · 1
Cabo Verde · 1
California · 6
- California Attorney General
- California Civil Rights Department (enforcement); the Civil Rights Council issued the regulations under Cal. Gov't Code § 12935(a). FEHA is also enforced by private civil action after exhaustion of CRD administrative remedies.
- California Department of Insurance
- California Office of Suicide Prevention (annual reporting); private right of action
- California Privacy Protection Agency
- Medical Board of California, Osteopathic Medical Board of California
Canada · 5
- Canadian Securities Administrators (CSA) — the council of Canada's provincial and territorial securities regulators; the Notice is staff guidance, and each member regulator enforces its own securities legislation
- Health Canada (Medical Devices Directorate)
- Office of the Privacy Commissioner of Canada — an ombudsperson regulator. The Commissioner investigates (ss. 12, 12.1), reports with recommendations (s. 13), audits (s. 18), may enter compliance agreements (s. 17.1) and may publish, but cannot issue orders and cannot impose an administrative monetary penalty; PIPEDA has no administrative penalty framework. Binding relief is by the Federal Court under s. 16 on an application under s. 14, and the only fines in the Act are the criminal fines in s. 28.
- Office of the Superintendent of Financial Institutions
- Treasury Board of Canada Secretariat
Catalonia · 1
Cayman Islands · 1
Chile · 1
China · 3
Colombia · 1
Congo (DRC) · 1
Connecticut · 1
Delaware · 1
Dubai International Financial Centre · 1
El Salvador · 1
Eswatini · 1
Ethiopia · 1
European Union · 16
- AI Office / market surveillance authorities / national competent authorities
- EU Member State supervisory authorities / EDPB
- European AI Office — voluntary code of practice under EU AI Act Chapter V; informs provider obligations for GPAI models.
- European Banking Authority
- European Commission — voluntary self-assessment tool; referenced in EU AI Act conformity and ethics guidance.
- European Commission (VLOPs/VLOSEs), national Digital Services Coordinators
- European Commission / National Competent Authorities
- European Commission, national competent authorities
- European Commission, national market surveillance authorities
- European Commission; national DPAs
- European Data Protection Board
- European Insurance and Occupational Pensions Authority
- European Securities and Markets Authority
- European Supervisory Authorities (EBA, EIOPA, ESMA) and national financial supervisors
- National competent authorities and CSIRTs
- National courts (civil liability); European Commission (transposition oversight)
Florida · 1
Georgia · 1
Georgia · 2
Ghana · 1
Guernsey · 1
Guyana · 1
Idaho · 1
Illinois · 5
- Illinois Attorney General; Illinois Emergency Management Agency and Office of Homeland Security (critical incidents)
- Illinois Department of Financial and Professional Regulation
- Illinois Department of Human Rights (charge intake and investigation) and the Illinois Human Rights Commission (adjudication); the Illinois Attorney General may bring pattern-and-practice actions under 775 ILCS 5/10-104, and a complainant may proceed in circuit court after opting out of the Department investigation under 775 ILCS 5/7A-102
- No enforcing agency is named in the Act (820 ILCS 42); the Illinois Department of Commerce and Economic Opportunity receives the section 20 demographic reports.
- Private right of action under 740 ILCS 14/20 — Illinois circuit court or supplemental claim in federal district court; the Act creates no administrative enforcer
Indonesia · 1
International · 21
- African Union Commission
- No Council of Europe-wide regulator. Art. 26: each Party must establish or designate one or more effective mechanisms to oversee compliance with the Convention's obligations, exercising their duties independently and impartially. The Conference of the Parties (Art. 23), convened by the CoE Secretary General, facilitates implementation and interpretation but does not itself enforce against a Party or a private organization.
- None as against a firm. IOSCO is the international policy forum and standard setter for securities regulation, and FR06/2021 is non-binding guidance addressed to IOSCO members rather than to market intermediaries or asset managers. IOSCO has no supervisory or enforcement power over a firm, imposes no penalty and provides no complaint route. Where one of the six measures binds an organisation, it binds because that organisation’s own securities regulator has adopted it into a national rule, and that regulator enforces its own rule.
- None. A political declaration with no enforcement mechanism and no supervisory body. France hosted the Summit and the Presidency of the French Republic publishes the text; it does not supervise adherence, and neither does any co-chair, signatory or international organisation named in the Statement. The prior record named France and India as the enforcement authority, which asserted a supervisory role that does not exist.
- None. A political declaration with no enforcement mechanism and no supervisory body. The United Kingdom hosted the summit and publishes the text; it does not supervise adherence.
- None. GPAI has no enforcement body, no penalty, no complaint route and no cause of action. The OECD hosts the GPAI Secretariat, which supports the Council, Plenary and Steering Group and publishes the partnership outputs; it supervises no organisation. Membership is held by countries and the European Union, so there is no organisation for the partnership to act against.
- None. IEEE Std 7000-2021 is a voluntary consensus standard: there is no enforcement body, no penalty, no complaint route and no cause of action. The IEEE Standards Association develops and publishes the standard; it does not supervise adopters. The standard has a Conformance clause in its published contents, but that clause text has not been read, so this record makes no statement about what conformance entails or who could assess it. Where the standard binds an organisation, it binds through a contract that requires it.
- None. ISO is a voluntary standards body; it certifies nobody under this document, holds no enforcement authority over any organization, and defines no legal cause of action. Prepared by ISO/IEC JTC 1/SC 40 and SC 42.
- None. ISO/IEC 23894:2023 is a voluntary International Standard: there is no enforcement body, no penalty, no complaint route and no cause of action. ISO and IEC develop and publish the standard through Joint Technical Committee ISO/IEC JTC 1, Subcommittee SC 42; neither supervises an adopter. The document is guidance rather than a management system specification, and no conformity criterion for it appears in any material ISO publishes free — the clauses that might address the point are behind the purchase gate and were not read, so this record makes no statement about them. Where the standard binds an organisation, it binds through a contract that requires it or through a regulator instrument that references it.
- None. The Global Digital Compact is annex I to General Assembly resolution 79/1, adopted 22 September 2024; a General Assembly resolution is a recommendation of the Assembly with no enforcement body, no penalty, no complaint route and no cause of action, and no organisation is bound by it. Follow-up is institutional and not supervisory: the Office for Digital and Emerging Technologies, established by the General Assembly with effect from 1 January 2025 as the UN system-wide focal point for digital issues, publishes the Compact's follow-up material and the voluntary endorsement list; the Secretary-General provides an implementation map (para. 71); the Independent International Scientific Panel on AI established by resolution 79/325 issues an annual non-prescriptive report; and a high-level review takes place during the eighty-second session (para. 74). Where a duty covering the same ground binds an organisation, it comes from the enacted law of the jurisdiction concerned, and that instrument is the citation.
- None. The International Medical Device Regulators Forum is a voluntary group of medical device regulators that publishes documents to promote international regulatory convergence. It is not a regulator: it grants no authorisation, conducts no assessment, imposes no penalty, offers no complaint route and provides no cause of action, and IMDRF/AIML WG/N88 FINAL:2025 creates no duty of its own. Its documents reach an organisation only where a member regulator has adopted an equivalent expectation in its own law or guidance, in which case that instrument is the citation and its wording governs. As at the IMDRF home page capture of 2026-09-07 the members are the Therapeutic Goods Administration (Australia), ANVISA (Brazil), Health Canada, the National Medical Products Administration (China), the European Commission Directorate-General for Health and Food Safety, the PMDA and MHLW (Japan), the Russian Ministry of Health, the Health Sciences Authority (Singapore), the Ministry of Food and Drug Safety (South Korea), the Medicines and Healthcare products Regulatory Agency (United Kingdom), the US Food and Drug Administration and Swissmedic (Switzerland); ANMAT (Argentina), the World Health Organization and the Saudi Food and Drug Authority are official observers. Each acts under its own law. This record makes no statement about what any of them requires.
- None. The MITRE Corporation publishes ATLAS; it does not enforce it and cannot. MITRE publishes no conformity criterion for the knowledge base, certifies no organisation, accredits no assessor, maintains no register and operates no complaint route, and it holds no supervisory relationship with anyone who uses it. ATLAS is licensed under the Apache License 2.0 and distributed on an as-is basis without warranties or conditions of any kind. Where a control it describes is required of an organisation, the requirement is imposed by a contract, a certification scheme or a security or privacy law, and that instrument is enforced by its own authority.
- None. The OECD is a standard-setting organisation and does not enforce its Recommendations. The OECD's own description of its legal instruments states that Recommendations are not legally binding and represent a political commitment to the principles they contain, with an expectation that Adherents will do their best to implement them. There is no conformity criterion, no certification, no accredited assessor, no register of compliant organisations and no complaint route, and the OECD holds no supervisory relationship with any organisation that applies the principles. The only mechanism the instrument creates is internal to the OECD: paragraph VIII instructs the Digital Policy Committee to report to Council on implementation, dissemination and continued relevance. Where a control described here is required of an organisation, the requirement comes from a national or regional instrument and is enforced by that instrument's own authority.
- None. The OWASP Foundation publishes the catalogue through the OWASP Gen AI Security Project; it does not enforce it and cannot. There is no conformity criterion, no certification, no accredited assessor, no register and no complaint route, and the Foundation holds no supervisory relationship with anyone who applies the list. The publication is licensed under Creative Commons Attribution-ShareAlike 4.0 and states in its own front matter that it does not constitute legal advice and is provided without warranty of accuracy. Where a control it describes is required of an organisation, the requirement is imposed by a contract, a procurement condition, a certification scheme or a statute, and that instrument is enforced by its own authority.
- None. The Recommendation is a UNESCO standard-setting instrument of the recommendation type, adopted by the General Conference on 23 November 2021 and applied by Member States on a voluntary basis under operative paragraph 2 of its adopting resolution; it creates no penalty, no complaint route and no supervisory body over organisations, and no organisation is bound by it. Monitoring under Section V is of Member States' policies, and UNESCO's Legal Affairs page records that monitoring of the Recommendation's implementation is the responsibility of UNESCO's Executive Board; UNESCO's readiness assessment and Ethical Impact Assessment methodologies (paras. 49 and 131) are tools offered to Member States, not certifications. Where a duty covering the same ground binds an organisation, it comes from the enacted law of the jurisdiction concerned, and that instrument is the citation.
- None. The Rome Call for AI Ethics is a voluntary call signed in Rome on 28 February 2020 and published by the Holy See. There is no enforcement body, no penalty, no complaint route and no cause of action; there is no register of compliance, no assessment and no certificate. The Pontifical Academy for Life convened the Call and was its first signatory, and the RenAIssance Foundation in Vatican City is its custodian, maintaining the text, the signatory listings and the events at which further organisations sign; neither supervises a signatory and neither has any power over one. Where an organisation is bound to the Call, it is bound because it signed, or because a contract, a procurement condition or an internal policy adopted it, and that document is the citation. Any legal duty covering the same ground — transparency, non-discrimination, security, privacy — comes from the law of the place concerned and is enforced by the authority that law names.
- None. The Seoul Declaration is a political declaration affirmed on 21 May 2024 by world leaders representing Australia, Canada, the European Union, France, Germany, Italy, Japan, the Republic of Korea, the Republic of Singapore, the United Kingdom, and the United States of America at the Leaders’ Session of the AI Seoul Summit, and published with its annex by the UK Department for Science, Innovation and Technology under Crown copyright and the Open Government Licence v3.0. It is not a treaty and not law: there is no enforcement body, no penalty, no complaint route, no cause of action, no register, no assessment and no certificate, and no organisation is an addressee of it. The Republic of Korea and the United Kingdom co-hosted the summit; neither supervises anyone under this Declaration. Paragraph 4 of the Declaration and the annex support the creation or expansion of AI safety institutes and other institutions "including supervisory bodies", but any power such a body has comes from the law of its own jurisdiction and not from this text. Where a duty covering the same ground binds an organisation, it comes from the enacted law of the place concerned and is enforced by the authority that law names.
- None. Voluntary G7 guidance with no enforcement body, no penalty and no complaint route. The Ministry of Internal Affairs and Communications of Japan publishes the documents as the 2023 G7 presidency; it does not supervise adherence.
- None. WHO issues this as ethics guidance and holds no enforcement authority over any government, health system, developer or company under this document. Any enforceable duty on the same subject matter comes from separate binding national or regional law (medical-device, clinical-safety, or data-protection authorities).
- PCI Security Standards Council
- U.S. Federal Trade Commission and U.S. Department of Transportation (compliance with the Principles, under 15 U.S.C. § 45 and 49 U.S.C. § 41712); U.S. Department of Commerce (Data Privacy Framework List administration); European Commission (adequacy monitoring under Art. 3); EU/EEA supervisory authorities (Art. 58 GDPR powers, preserved by Art. 2).
Iowa · 3
Isle of Man · 1
Israel · 1
Jamaica · 1
Japan · 2
Jordan · 1
Kentucky · 1
Kenya · 2
Kiribati · 1
Kosovo · 1
Lebanon · 1
Liechtenstein · 1
Louisiana · 1
Lower Saxony · 1
Malawi · 1
Marshall Islands · 1
Maryland · 2
Mauritius · 1
Mecklenburg-Vorpommern · 1
Minnesota · 1
Montana · 1
Morocco · 1
Nebraska · 1
Nevada · 3
- Division of Public and Behavioral Health of the Nevada Department of Health and Human Services — for Nev. Rev. Stat. § 433.567: it may investigate potential violations and may bring an action to recover a civil penalty of not more than $15,000 per violation (§ 433.567(4)(a), (4)(b) and (5)), and it must publish educational materials including recommended best practices on the use of artificial intelligence by a person seeking care (§ 433.567(4)(d)). The professional licensing board, agency or other entity by which a provider is licensed or certified — for Nev. Rev. Stat. § 629.610, a violation of which is unprofessional conduct subject to disciplinary action (§ 629.610(5)). Nevada Department of Education — owes the policy at § 391.297(2); the § 391.297(1) prohibition creates no penalty and names no authority to enforce it.
- Nevada Attorney General
- Public Utilities Commission of Nevada — for Nev. Rev. Stat. § 704.1833, under its general supervision of public utilities at Nev. Rev. Stat. § 703.150, the administrative fine at § 703.380 and the criminal fine at § 704.640. Nevada Office of Emergency Management — for the Nev. Rev. Stat. § 414.099 plan requirement, through its coordination of plan development under Nev. Rev. Stat. § 414.040(3) and (4); the section itself creates no penalty and names no enforcement authority.
New South Wales · 1
New Zealand · 1
Nicaragua · 1
Nigeria · 1
North Macedonia · 1
North Rhine-Westphalia · 1
Northern Territory · 1
Oklahoma · 1
Ontario · 2
- Information and Privacy Commissioner of Ontario
- Minister of Public and Business Service Delivery and Procurement (Ontario). The Act names no regulator and creates no offence, monetary penalty or order-making power; s. 12 establishes no private law duty of care and s. 13 preserves the validity of decisions taken in breach. Compliance runs through Ministerial directives under ss. 4 and 11, Ministerial technical standards under ss. 3, 8 and 10, and reporting to the Chief Information Security Officer of the Ministry under O. Reg. 51/26 ss. 4, 6 and 7. The Information and Privacy Commissioner of Ontario has no function under this Schedule.
Oregon · 2
- No administrative enforcement authority — private right of action only: an individual who suffers an ascertainable loss of money or property or other injury in fact may bring an action in a court of this state (Or. Laws 2026, ch. 85, § 2); the Oregon Judicial Department administers those courts
- Oregon Attorney General
Paraguay · 2
Peru · 2
- Autoridad Nacional de Protección de Datos Personales (ANPD), Dirección General de Transparencia, Acceso a la Información Pública y Protección de Datos Personales — Ministerio de Justicia y Derechos Humanos
- Secretariat of Government and Digital Transformation (SGTD), Presidency of the Council of Ministers
Philippines · 1
Queensland · 1
Rhineland-Palatinate · 1
Rhode Island · 3
Samoa · 1
San Marino · 1
São Tomé and Príncipe · 1
Saudi Arabia · 1
Saxony-Anhalt · 1
Schleswig-Holstein · 1
Serbia · 1
Seychelles · 1
Shenzhen · 1
Singapore · 2
Solomon Islands · 1
South Africa · 1
South Australia · 1
South Korea · 2
Sri Lanka · 1
Switzerland · 1
Tanzania · 1
Tasmania · 1
Tennessee · 2
- Tennessee Attorney General
- The act names no enforcement body. Tenn. Code Ann. § 33-1-205(b) makes a violation of § 33-1-205(a) a violation of the Tennessee Consumer Protection Act of 1977 and an unfair or deceptive act or practice affecting trade or commerce, "subject to the penalties and remedies provided in" that Act, with a civil penalty of five thousand dollars ($5,000) per violation notwithstanding that Act's own civil penalty limits; § 2 of the act adds violating § 33-1-205 to the enumerated list in § 47-18-104(b). The Tennessee Consumer Protection Act is administered by the Attorney General and Reporter: the office's own consumer protection page records that from 30 September 2019 the Division of Consumer Affairs has been housed within the Consumer Protection Division of the Attorney General's Office, and that "[t]he Attorney General has authority to enforce the Consumer Protection Act and other consumer protection related laws, both state and federal." The same page records that references to the Department of Commerce and Insurance on Division materials are historical. The act delegates no rulemaking to any agency. Who else, if anyone, may act on a violation is a question about Tenn. Code Ann. § 47-18-109 and is not answered by this act.
Texas · 5
- Texas Attorney General, exclusively — Tex. Bus. & Com. Code § 503.001(d) authorises the Attorney General to bring an action to recover the civil penalty and the statute creates no private right of action; since January 1, 2026 § 552.054(c) also channels every § 503.001 violation into Tex. Bus. & Com. Code ch. 552, enforced exclusively by the Attorney General under § 552.101
- Texas Attorney General, exclusively (Tex. Bus. & Com. Code § 541.151); no private right of action (§ 541.156)
- Texas Attorney General. Sec. 552.101(a) gives the attorney general exclusive authority to enforce ch. 552, except to the extent sec. 552.106 allows a licensing agency to sanction its own licensee after a sec. 552.105 finding and an attorney general recommendation. Sec. 552.101(b) forecloses a private right of action for a violation of the chapter or of any other law. Sec. 552.102 requires the attorney general to create and maintain an online complaint mechanism, and sec. 8 of the Act set 1 September 2026 as the deadline to post it. The chapter delegates no rulemaking to the attorney general. Chapter 553 is administered by the Texas Department of Information Resources, which has adopted no rule prescribing the sec. 553.052(b) application form.
- Texas Department of Insurance
- Texas Medical Board and Texas Attorney General
Thailand · 1
Tonga · 1
Trinidad and Tobago · 1
United Arab Emirates · 1
United Kingdom · 7
- Central Digital and Data Office
- Department for Science, Innovation and Technology; sector regulators (ICO, FCA, CMA, MHRA)
- Equality and Human Rights Commission (EHRC) and the UK courts
- Financial Conduct Authority
- Information Commissioner's Office
- Medicines and Healthcare products Regulatory Agency
- Solicitors Regulation Authority
United States · 50
- Actuarial Standards Board (issuer); Actuarial Board for Counseling and Discipline (peer discipline under the Code of Professional Conduct)
- AICPA — attestation standard, not enforcement. Required by enterprise procurement.
- American College of Emergency Physicians and eight partner emergency-medicine organizations (voluntary consensus statement; no disciplinary or enforcement mechanism of its own)
- American Medical Association (voluntary professional standard)
- Centers for Medicare & Medicaid Services
- Centers for Medicare & Medicaid Services (CMS)
- Centers for Medicare & Medicaid Services and state survey agencies
- CFPB, federal banking regulators, and the U.S. Department of Justice
- CFPB, FTC, and state attorneys general
- Consumer Financial Protection Bureau
- Department of Defense (CMMC PMO)
- EDUCAUSE / Higher Education Community
- Federal Communications Commission
- Federal Home Loan Mortgage Corporation (Freddie Mac)
- Federal Housing Finance Agency
- Federal National Mortgage Association (Fannie Mae)
- Federal Reserve, OCC (Bulletin 2011-12), FDIC (FIL-22-2017)
- Federal Reserve, Office of the Comptroller of the Currency (OCC), Federal Deposit Insurance Corporation (FDIC)
- Federal Trade Commission
- Federal Trade Commission (FTC)
- Financial Industry Regulatory Authority
- General Services Administration (FedRAMP PMO) and federal agencies
- HHS Office for Civil Rights
- HITRUST Alliance
- National Association of Insurance Commissioners (model; state DOI adoption)
- None for this guidance document itself. The Joint Commission is a real U.S. accreditation body with survey and enforcement authority over its own numbered accreditation standards (Requirements for Improvement, Conditional Accreditation, Preliminary Denial of Accreditation) and over certification programmes it administers (including the separate RUHD certification), but RUAIH is explicitly non-binding: it "is not intended to direct the development of AI tools or validate the effectiveness of AI tools themselves," creates no numbered accreditation standard, and is not scored in a Joint Commission accreditation survey as of the evidence date. The Coalition for Health AI (CHAI), the co-author, is a nonprofit coalition with no accreditation or enforcement authority of any kind.
- None in the legal sense. StateRAMP, Inc. dba GovRAMP is an Indiana nonprofit corporation formed exclusively within the meaning of section 501(c)(6) of the Internal Revenue Code (Bylaws art. I, § 1.2) and holds no supervisory, investigative or penal authority over any provider: the Security Assessment Framework creates no penalty, no complaint route and no cause of action. Its sanctions are program sanctions. The Program Management Office — Knowledge Services, operating under the PMO Charter (§ 1.3.3) — validates security packages and continuous monitoring submissions; the government Sponsoring Body or the Approvals Committee grants Authorized and Provisionally Authorized status (§§ 1.5.6, 1.5.7); under § 1.5.6 the PMO Director or appointed delegate may recommend revocation of a Provisionally Authorized status where identified issues are not remediated within the agreed timeframe; and under § 1.7.5 the government authorizing body and/or the PMO may revoke a status through the Continuous Monitoring Escalation Process, with the Authorized Product List updated accordingly. The Appeals Committee (§ 1.2.5) adjudicates conflict-of-interest claims, disagreements over status determination and requests for exceptions. Where a requirement to hold GovRAMP status binds a provider at all, it binds through the government customer's solicitation, contract or state policy, and the consequence is that contract's rather than this framework's.
- None. NIST is a non-regulatory federal agency; it certifies nobody under this document and holds no enforcement authority. Voluntary adoption; referenced by many sector regulators and contracts, which carry their own enforcement.
- None. NIST is a standards body with no supervisory authority over adopters; the Framework is voluntary and carries no penalty. Programme page: NIST Information Technology Laboratory.
- North American Electric Reliability Corporation (NERC)
- Office of Management and Budget
- Office of the National Coordinator for Health IT (ONC), HHS-OIG enforcement
- State bar disciplinary counsel / courts (this Opinion interprets the Model Rules; the ABA Standing Committee that issued it has no disciplinary power of its own)
- State bar disciplinary counsel / state supreme court (the ABA itself has no disciplinary authority over any lawyer)
- Substance Abuse and Mental Health Services Administration (SAMHSA) and HHS OCR
- The agency with jurisdiction over the institution under 15 U.S.C. § 6805(a): the federal banking agencies; the National Credit Union Administration Board for federally insured credit unions; the Securities and Exchange Commission for brokers, dealers, investment companies and registered investment advisers; state insurance authorities for insurers; the Federal Trade Commission for other financial institutions; and the Consumer Financial Protection Bureau within its jurisdiction, other than for the § 6801(b) safeguards standards.
- U.S. Copyright Office
- U.S. Department of Education, Student Privacy Policy Office
- U.S. Department of Health and Human Services, Office for Civil Rights (OCR)
- U.S. Department of Health and Human Services, Office for Civil Rights (OCR)
- U.S. Department of Housing and Urban Development (HUD), U.S. Department of Justice, state attorneys general, and private plaintiffs
- U.S. Department of Justice and qui tam relators
- U.S. Department of the Treasury
- U.S. Equal Employment Opportunity Commission
- U.S. Food and Drug Administration
- U.S. Food and Drug Administration
- U.S. Food and Drug Administration
- U.S. Food and Drug Administration
- U.S. Securities and Exchange Commission, Division of Examinations
- United States federal courts
Utah · 3
Uzbekistan · 2
- Ministry of Digital Technologies of the Republic of Uzbekistan (authorised state body under the amended Informatization Law art. 6); administrative liability under Code on Administrative Liability art. 462 part two follows that Code's general adjudication procedure (specific adjudicating body not independently confirmed this pass -- see evidence file).
- Personalization Agency under the Ministry of Justice of the Republic of Uzbekistan (reformed from the State Personalization Centre under the Cabinet of Ministers, effective 1 January 2023)
Vermont · 1
Victoria · 1
Vietnam · 2
Virginia · 1
Washington · 4
- Washington Attorney General, exclusively, for the Title 19 chapter (2026 Wash. Sess. Laws ch. 167, § 4(2)-(3)). The Title 42 chapter created by § 6 carries no enforcement provision.
- Washington courts (RCW 63.60 civil actions)
- Washington State Office of the Attorney General — RCW 19.373.090 makes a violation of the chapter a per se violation of the Consumer Protection Act, chapter 19.86 RCW, which the office enforces under RCW 19.86.080 and which a private claimant may enforce under RCW 19.86.090. The chapter creates no regulator of its own, delegates no rulemaking to any agency, and provides no notice or cure period before suit. RCW 44.28.819 puts the joint legislative audit and review committee on the enforcement record, reporting by September 30, 2030.
- Washington State Office of the Insurance Commissioner, with the Washington State Health Care Authority for health plans offered to public employees, retirees and their covered dependents under chapter 41.05 RCW. The act creates no penalty, no private right of action and no cure period. RCW 48.43.830(3)(b)(vi) makes a carrier's artificial-intelligence policies and procedures open to audit by the Commissioner under chapter 48.37 RCW, RCW 48.43.830(7) gives the Commissioner rulemaking power over that section, and RCW 41.05.845(7) gives the Health Care Authority the same power over the public employee plans. RCW 48.43.0161 makes the percentage of denials aided by artificial intelligence a reported and published figure.
Western Australia · 1
Every link goes to the issuing body's own site. Templates and forms change — check the source for the current version before you rely on one. Nothing here is legal advice.