Risk & impact assessments
Obligations to assess an AI or data-processing system's risks before or during deployment — impact assessments, DPIAs, conformity assessments, and formal risk-management programs.
Europe & Central Asia18 laws
Albania Law 124/2024
Republic of Albania
Processing of personal data in Albania or targeting Albanian data subjects by controllers and processors.
Law · Partially In Force
BlnDSG
Berlin, Germany
Personal data processed by an authority or other public body of the Land Berlin or of a Land corporation, institution or foundation of public law (§ 2 Abs. 1), by a private-law association performing public-administration tasks in which Berlin holds an absolute majority or by a non-public body performing sovereign tasks (§ 2 Abs. 2), or by a processor acting for one of them. Teil 3 applies instead of Teil 2 where the processing serves the prevention, investigation, detection, prosecution or punishment of criminal or administrative offences (§ 2 Abs. 4, § 30). § 19 additionally reaches non-public bodies processing for journalistic, artistic or literary purposes (§ 2 Abs. 7).
Law · In Force
Brandenburgisches Datenschutzgesetz (BbgDSG)
Brandenburg, Germany
Processing of personal data by an authority, institution or other public body of the Land Brandenburg, by a municipality or association of municipalities, by a legal person of public law under their supervision, by a non-public body performing sovereign tasks of a Land public body, or by a processor acting for any of them; and, for §§ 29 Absatz 1 and 2, by any body processing for journalistic, artistic or literary purposes.
Law · In Force
Datenschutzgesetz (DSG), LGBl. 2018 Nr. 272 (Liechtenstein) — EEA GDPR implementation
Principality of Liechtenstein
Processing of personal data in Liechtenstein; EEA GDPR applies directly with DSG as national implementing law.
Law · In Force
Guernsey DP Law 2017
Bailiwick of Guernsey
Processing of personal data in the Bailiwick of Guernsey or by controllers established in the Bailiwick.
Law · In Force
ICO Children's Code (Age Appropriate Design Code)
United Kingdom
A relevant information society service (DPA 2018 s. 123(7): provided for remuneration, at a distance, by electronic means, at the individual request of a recipient, excluding preventive or counselling services) likely to be accessed by children under 18 in the United Kingdom.
Guidance · In Force
Law No. 06/L-082 on Protection of Personal Data
Republic of Kosovo
Processing by public and private bodies in Kosovo; limited extraterritorial reach for equipment in Kosovo.
Law · In Force
Law of Georgia on Personal Data Protection
Georgia
Processing of personal data in Georgia or using technical means in Georgia; extraterritorial reach for Georgian data subjects.
Law · In Force
Law of Ukraine On Protection of Personal Data (Law No. 2297-VI)
Ukraine
Processing of personal data in Ukraine or of Ukrainian data subjects by controllers and processors.
Law · In Force
Law on Personal Data
Republic of Azerbaijan
Collection or processing of personal data about a natural person in the Republic of Azerbaijan by a state or local self-government body or by a legal or natural person, other than collection and processing by a natural person exclusively for personal and family needs (art. 3.3) and the national-security and state-secret cases left to other legislation by art. 3.2.
Law · In Force
Law on Personal Data Protection (Official Gazette MK 42/20, 294/21)
Republic of North Macedonia
Processing of personal data in North Macedonia or targeting North Macedonian data subjects.
Law · In Force
Law on Personal Data Protection (Serbia) (Zakon o zaštiti podataka o ličnosti)
Republic of Serbia
Processing of personal data in Serbia or targeting Serbian data subjects; GDPR-aligned controller and processor obligations.
Law · In Force
Law on the Protection of Personal Data (Bosnia and Herzegovina)
Bosnia and Herzegovina
Processing of personal data in BiH or of BiH data subjects; foreign controllers must appoint local representative where required.
Law · In Force
LDSG RP
Rhineland-Palatinate, Germany
Public-sector personal data processing in Rhineland-Palatinate including AI.
Law · In Force
Llei 29/2021, del 28 d'octubre, qualificada de protecció de dades personals (Andorra)
Principality of Andorra
Processing of personal data in Andorra or by controllers/processors subject to Andorran law, including extraterritorial targeting of Andorran data subjects.
Law · In Force
Moldova Law 195/2024
Republic of Moldova
Processing of personal data in Moldova or by controllers subject to Moldovan law after August 23, 2026.
Law · In Force
Monaco Law 1.565
Principality of Monaco
Processing by controllers/processors in Monaco or targeting data subjects in Monaco (GDPR-style territorial and extraterritorial scope).
Law · In Force
San Marino Law 171/2018
Republic of San Marino
Processing of personal data in San Marino or by controllers established in San Marino, including automated and filing-system processing.
Law · In Force
US States9 laws
APDPA
United States — Alabama
Law · Pending
Cal. Bus. & Prof. Code Ch. 25.1 (Transparency in Frontier Artificial Intelligence Act)
State of California
Frontier developers training or deploying foundation models meeting the 10^26 FLOP threshold; large frontier developers with >$500M annual gross revenue (with affiliates).
Law · In Force
Cal. Code Regs. tit. 11 (CPPA — automated decisionmaking technology and risk assessments)
State of California
CCPA-covered businesses that use ADMT to make significant decisions about California consumers.
Regulation · Partially In Force
California Age-Appropriate Design Code Act (Cal. Civ. Code Tit. 1.81.47)
State of California
Online products or services likely to be accessed by children and offered to California consumers.
Law · Partially In Force
Ind. Code § 24-15
United States — Indiana
Law · In Force
Iowa Code ch. 715D
United States — Iowa
Controllers or processors conducting business in Iowa, or targeting products/services to Iowa residents, that meet the § 715D.2(1) consumer-volume/revenue thresholds (100,000 consumers, or 25,000 consumers with 50%+ revenue from data sales).
Law · In Force
Ky. Rev. Stat. § 367.3611 et seq.
United States — Kentucky
Law · In Force
Tex. Bus. & Com. Code ch. 552
State of Texas
Applies to a person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an artificial intelligence system in Texas (sec. 551.002). There is no revenue, headcount, data-volume or consumer-count threshold anywhere in the Act. Three duties are narrower than the Act: sec. 552.051(b) binds a governmental agency, and secs. 552.053 and 552.054(b) bind a governmental entity as sec. 552.001(3) defines it. One is narrower the other way: sec. 552.051(f) binds the provider of a health care service or treatment.
Law · In Force
Utah Code tit. 13, ch. 61
United States — Utah
Law · In Force
Middle East & Africa7 laws
ADGM Data Protection Regulations 2021
Abu Dhabi Global Market
Processing personal data by ADGM-established controllers or processors.
Law · In Force
Code du numérique du Bénin — Livre V
Republic of Benin
Processing of personal data in the context of the activities of a controller or processor on Beninese territory, or of persons who are in Benin where the activities relate to offering them goods or services or to monitoring their behaviour in Benin (art. 381).
Law · In Force
Data Protection Act, 2012 (Act 843) (Ghana)
Republic of Ghana
Controllers and processors collecting or processing personal data in Ghana.
Law · In Force
Data Protection Act, 2024 (Botswana)
Republic of Botswana
Automated or non-automated filing-system processing by a controller or processor established in Botswana; or, where not established there, processing where the activities of an establishment are in Botswana, or the activities relate to offering goods or services to data subjects in Botswana or to monitoring their behaviour there (s. 4).
Law · In Force
Lei n.º 133/V/2001 (Cabo Verde)
Republic of Cabo Verde
Processing of personal data by wholly or partly automated means, or non-automated processing of data in a filing system, in the context of an establishment of a controller or processor situated in Cabo Verde whatever the place of processing; or outside the territory where Cabo Verdean law applies by public international law; or by a controller or processor not established in Cabo Verde where the activities relate to offering goods or services to data subjects in Cabo Verde or to monitoring their behaviour there (art. 2.º).
Law · In Force
Loi n° 1/03 du 10 mars 2026 (Burundi)
Burundi
{"scope_basis":"jurisdiction","jurisdictions":["BI"],"regions":["Middle East & Africa"],"requires_ai":false}
Regulation · In Force
Loi n° 29-2019 (République du Congo)
Republic of the Congo
Collection, processing, transmission, storage or use of personal data by a natural person, by the State, by decentralised administrative entities or by legal persons of public or private law; processing implemented by a controller on the territory of the Republic of the Congo or in any place where the law of that country applies; or processing implemented by a controller, established in Congo or not, which has recourse to means of processing situated on Congolese territory, excluding means used only for transit (art. 2).
Law · In Force
EU & EEA6 laws
Assessment List for Trustworthy Artificial Intelligence (ALTAI) — EU High-Level Expert Group on AI
European Union
Organisations self-assessing AI trustworthiness in the EU; especially relevant for high-risk and limited-risk AI under the EU AI Act.
Framework · In Force
EDPB DPIA template (2026, v1.0)
European Union
Guidance · Pending
EU Digital Services Act
European Union & EEA
Intermediary services offered in the EU, especially VLOPs and VLOSEs using recommender systems and content moderation AI.
Regulation · In Force
Regulation (EU) 2016/679 (General Data Protection Regulation)
European Union & EEA
Any organisation that offers goods or services to, or monitors the behaviour of, individuals in the EU/EEA — regardless of where the controller or processor is established.
Regulation · In Force
Regulation (EU) 2024/1689 (Artificial Intelligence Act)
European Union & EEA
Providers placing AI on the EU market, deployers in the EU, and providers or deployers established in third countries whose AI system output is used in the EU.
Regulation · Partially In Force
Regulation (EU) 2024/2847
European Union & EEA
Manufacturers placing products with digital elements on the EU market, including standalone AI software.
Regulation · Partially In Force
Global & Voluntary6 laws
Global Digital Compact
United Nations
Surfaced wherever an AI system is designed, developed, deployed or used, in any sector, for civilian purposes: para. 4 scopes the Compact to the non-military domain and it names no sector, size or entity class. It creates no duty on anyone — its commitments are what Governments will do; its paragraphs addressed to companies, developers and platforms (22, 25, 32, 36) are calls; and endorsement (66) is voluntary. Two rows are conditioned on hosting user-generated content (32 (d), 36 (b)) and one on generating synthetic content (36 (c)), because those paragraphs are addressed to platforms and to content generators respectively.
Guidance · In Force
IEEE 7010
International
Surfaced as voluntary standards context wherever an autonomous or intelligent system is deployed. IEEE Std 7010-2020 creates no duty of its own; where an organisation is bound to it, the binding instrument is a contract, and the contract governs scope.
Standard · In Force
ISO/IEC 42001
International (voluntary)
Surfaced as voluntary standards context wherever an organisation provides or uses a product or service that utilizes an AI system. ISO/IEC 42001 creates no duty of its own; where an organisation is bound to it, the binding instrument is a contract, a tender condition, an internal policy, a maintained certificate or a regulator instrument that references it, and that document governs scope.
Standard · In Force
ISO/IEC 42005
International (voluntary)
Surfaced as voluntary standards context wherever an organisation develops, provides or uses an AI system. ISO/IEC 42005 creates no duty of its own; where an organisation is bound to it, the binding instrument is a contract, a tender condition, an internal policy or a regulator instrument that references it, and that document governs scope.
Standard · In Force
UNESCO Recommendation on the Ethics of AI
United Nations (UNESCO)
Surfaced wherever an AI system is designed, developed, deployed or used, in any sector and for any purpose: para. 2 (b) defines AI actors as any natural or legal person involved in any stage of the life cycle, para. 4 offers ethical guidance to all AI actors including the private sector, and the Recommendation carves out no domain. It creates no duty on anyone — Member States apply it voluntarily and AI actors receive guidance. Three rows carry the condition their paragraph turns on: decisions about people (para. 38, decision limb) and the provider role (paras. 51, last sentence, and 120, last sentence).
Guidance · In Force
WHO AI Ethics for Health
International (WHO)
Surfaced for any AI system used in health-care delivery, diagnostics, health research, or population/public health, consistent with the guidance's own stated scope (Executive Summary; §5, chapeau).
Guidance · In Force
Americas5 laws
Barbados DPA
Barbados
Processing of personal data in the context of the activities of a data controller or data processor established in Barbados (s. 3 (1) (a)), or processing of personal data of data subjects in Barbados by a controller or processor not established in Barbados where the processing relates to the offering of goods or services to data subjects in Barbados (s. 3 (1) (b)).
Law · Partially In Force
Canada ADM Directive
Canada (Federal)
An institution subject to the Policy on Service and Digital — a department within the meaning of s. 2 of the Financial Administration Act — using an automated decision system in production to make an administrative decision or a related assessment about a client (Directive, ss. 5.1 and 8.1). Systems used solely for research and experimentation and those in test environments are out of scope (s. 5.2). The instrument reaches systems developed or procured after 1 April 2020, and systems predating that date once significantly modified (s. 1.2).
Guidance · In Force
Data Protection Act, 2021 (Act No. 45 of 2021) (Belize)
Belize
Processing of personal data in Belize by public or private controllers subject to the Act.
Law · Pending
Ley N.º 7593/2025 (Paraguay)
Republic of Paraguay
Law · Pending
Ley Orgánica de Protección de Datos Personales (Ecuador)
Republic of Ecuador
Processing of personal data in Ecuador or targeting Ecuadorian data subjects.
Law · In Force
Asia Pacific5 laws
Data Protection Act 2025 (Kiribati)
Republic of Kiribati
Processing of personal data by controllers and processors in Kiribati — lawful basis, consent, data-subject rights, security and breach notification, data protection impact assessments, cross-border transfer standards; phased application for non–major-importance controllers.
Law · Pending
GB/T 45654—2025
China
Providing a generative artificial intelligence service in mainland China (clause 1). No revenue, headcount or sector threshold. Adoption is voluntary: the standard is a recommended national standard and creates no legal duty of its own.
Standard · In Force
Law No. 91/2025/QH15 on Personal Data Protection (Viet Nam)
Socialist Republic of Viet Nam
Vietnamese and foreign agencies, organisations, and individuals processing personal data in Vietnam or related to Vietnamese citizens.
Law · In Force
PIPL Standard Contract Measures
China (National)
Cross-border transfer of personal information from China under PIPL standard contracts or security assessment.
Regulation · In Force
Sri Lanka PDPA
Democratic Socialist Republic of Sri Lanka
Recorded for footprint mapping only. Section 2, which supplies the Act’s application, is not in operation until 1 January 2027. From that date it reaches processing wholly or partly in Sri Lanka, and a controller or processor domiciled or ordinarily resident in Sri Lanka, incorporated under Sri Lankan law, offering goods or services to data subjects in Sri Lanka, or specifically monitoring their behaviour in Sri Lanka including profiling with the intention of making decisions about it.
Law · Partially In Force
United Kingdom2 laws
ICO DPIA guidance
United Kingdom
Guidance · In Force
UK GDPR (assimilated Regulation (EU) 2016/679)
United Kingdom
Organisations established in the UK and those that offer goods or services to, or monitor, individuals in the UK from outside.
Regulation · In Force
Switzerland1 law
revFADP (SR 235.1)
Switzerland
Processing of personal data of individuals in Switzerland, regardless of where the controller is established.
Law · In Force
Sourced from the LegisGate™ intelligence library — our single source of truth (SSOT). Theme membership is computed deterministically from curated library text; run a LegisGate™ report to see how these obligations apply to your specific AI tool.
