Solutions by Regulation

Continuous testing for the privacy laws that drive enforcement

Each law asks something different of your tags, pixels, and SDKs. Vault JS tests your properties against the specific requirements of each one and documents the result, so you can show regulators and courts what actually happened.

Gradient glow shape

Choose a regulation

CCPA / CPRA

Verify that GPC and GPP signals are honored, that Do Not Sell or Share actually stops sharing, and that dark patterns are not in play.

CIPA and ECPA

Detect session replay, chat, and keystroke capture that create wiretap exposure under California and federal law.

GDPR, UK GDPR, and ePrivacy

Test consent enforcement, cookies, fingerprinting, and ID syncing across EU and UK properties.

HIPAA and MHMD

Detect health data leaking through pixels, SDKs, and third parties on patient-facing web and mobile properties.

Quebec Law 25

Verify bilingual consent, cross-border data flows, and region-specific tracking under Quebec’s privacy law.

VPPA

Detect pixels that share video-viewing data with third parties and check consent before identifiers are disclosed.

Browse every privacy law we track

All 45 laws are on one page: privacy laws by state and country. Each has a plain-English summary: who it applies to, what it requires, who enforces it and the penalties, with the articles we have published on it.

Prefer a map? See the US state privacy laws map or the global privacy laws map.

Stay ahead of changing privacy laws