Regulations

30 regulations covered · GDPR, CCPA, HIPAA, and more

Privacy & Data Protection

(4)
GDPR

General Data Protection Regulation

European Union

Prove a lawful, transparent, and secure basis for each personal-data use.

5 requirements · 10 implementation steps
CCPA/CPRA

California Consumer Privacy Act / California Privacy Rights Act

California, USA

Disclose data practices and support California privacy choices.

5 requirements · 8 implementation steps
PIPEDA

Personal Information Protection and Electronic Documents Act

Canada

Be accountable for fair, consent-based collection, use, retention, and access.

5 requirements · 6 implementation steps
Breach Laws

State Data Breach Notification Laws

United States (Multi-State)

Detect, assess, notify, and remediate quickly under state-specific deadlines.

5 requirements · 4 implementation steps

Email & Outreach

(3)
CASL

Canada's Anti-Spam Legislation

Canada

Send commercial electronic messages only with consent, identification, and unsubscribe controls.

5 requirements · 2 implementation steps
CAN-SPAM

Controlling the Assault of Non-Solicited Pornography And Marketing Act

United States

Make outbound emails truthful, identifiable, and easy to opt out of.

4 requirements · 1 implementation steps
TCPA

Telephone Consumer Protection Act

United States

Do not call or text unless the consent trail supports the outreach method.

4 requirements · 2 implementation steps

Children & Minors

(1)
COPPA

Children's Online Privacy Protection Act

United States

Screen out under-13 respondents unless a study is built for parental notice, consent, and controls.

5 requirements · 2 implementation steps

Health & Biometric

(2)
HIPAA

Health Insurance Portability and Accountability Act

United States

Do not accept PHI unless the legal basis, contract, and safeguards are set first.

5 requirements · 3 implementation steps
Biometric Laws

Biometric Privacy Laws (BIPA / Texas / Washington)

Illinois, Texas, Washington (USA)

Collect verification clips only with explicit notice, narrow purpose, strict retention, and controlled client access.

5 requirements · 3 implementation steps

Consumer Protection

(1)
FTC Act

Federal Trade Commission Act — Section 5

United States

Do not make privacy, security, AI, or quality promises unless operations can prove them.

4 requirements · 3 implementation steps

Financial Services

(12)
GLBA

Gramm-Leach-Bliley Act

United States

Use nonpublic personal information only to perform the bank-authorized service and protect it under bank-grade safeguards.

3 requirements · 1 implementation steps
ECOA

Equal Credit Opportunity Act

United States

Make research representative and explainable without enabling discrimination in credit access or terms.

3 requirements · 1 implementation steps
UDAAP

Unfair, Deceptive, or Abusive Acts or Practices

United States

Do not let research create misleading, coercive, unsupported, or unfair consumer outcomes for the bank.

4 requirements · 1 implementation steps
TILA

Truth in Lending Act

United States

Do not draft, simplify, or change credit-cost claims unless the bank has approved the disclosure and advertising treatment.

3 requirements · 1 implementation steps
FCRA

Fair Credit Reporting Act

United States

Use credit and eligibility data only for the bank-approved research purpose and keep it out of ordinary deliverables.

3 requirements · 1 implementation steps
CLA

Consumer Leasing Act

United States

Present lease cost, term, and obligation information only in the form the bank has approved under Regulation M.

3 requirements · 1 implementation steps
EFTA

Electronic Fund Transfer Act

United States

Present EFT rights, error-resolution procedures, and liability disclosures only in bank-approved form — never substitute or paraphrase Reg E language.

4 requirements · 2 implementation steps
FCBA

Fair Credit Billing Act

United States

Use only bank-approved billing error and dispute language in stimuli — never paraphrase a consumer's statutory dispute rights.

3 requirements · 1 implementation steps
FDCPA

Fair Debt Collection Practices Act

United States

Ensure no research material, script, or concept mimics, tests, or recommends a communication that would constitute a prohibited debt collection practice.

5 requirements · 2 implementation steps
FDIA § 43

Federal Deposit Insurance Act — Section 43

United States

Ensure research materials do not blur the distinction between FDIC-insured deposits and non-deposit products sold at bank locations.

3 requirements · 1 implementation steps
TISA

Truth in Savings Act

United States

Present deposit account rates, yields, and fees only in the form the bank has approved under Regulation DD — never independently simplify or restate APY.

4 requirements · 1 implementation steps
OAA § 626

Omnibus Appropriations Act — Section 626

United States

Apply heightened care and additional disclosure review to any research touching servicemember credit, allotments, or financial well-being.

3 requirements · 1 implementation steps

Mortgage & Lending

(7)
AMTPA

Alternative Mortgage Transaction Parity Act

United States

Only test alternative mortgage disclosures and concepts using bank-approved, federally pre-empted terms — never draft or simplify them independently.

3 requirements · 1 implementation steps
HOPA

Home Owners Protection Act

United States

Use only bank-approved PMI cancellation and termination language in research stimuli — never state PMI rights independently.

3 requirements · 1 implementation steps
HMDA

Home Mortgage Disclosure Act

United States

Handle HMDA data only for the approved fair-lending or market-research purpose; surface disparate patterns and flag them to the bank.

4 requirements · 2 implementation steps
HOEPA

Home Ownership and Equity Protection Act

United States

Only test high-cost mortgage disclosures using bank-approved copy; never independently characterize whether a loan is high-cost.

3 requirements · 1 implementation steps
RESPA

Real Estate Settlement Procedures Act

United States

Use only bank-approved TRID disclosure copy in research stimuli and never draft or simplify Loan Estimate or Closing Disclosure language independently.

4 requirements · 2 implementation steps
SAFE Act

S.A.F.E. Mortgage Licensing Act

United States

Do not facilitate or simulate unlicensed mortgage origination activity in research; validate MLO respondent credentials when studies depend on them.

3 requirements · 1 implementation steps
ILSFDA

Interstate Land Sales Full Disclosure Act

United States

Do not substitute research stimuli for required ILSFDA property reports or let concept-test materials misstate material land or development facts.

3 requirements · 1 implementation steps