What the law makes you able to show

About this documentUpdated 2026-09-20ShowHide

Sean McDermott, Co-Founder and CEO, UnGovr

Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.

Every law named here links to its summary page on lexlint.org, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.

© 2026 UnGovr, publishing as LexLint. The text and the figures are licensed under Creative Commons Attribution-ShareAlike 4.0: share and adapt them, including commercially, with credit to LexLint (UnGovr) and under the same licence. Please contact LexLint at hello@ungovr.org to discuss other terms. Logos and wordmarks belong to their owners.

Corpus figures as of 2026-09-21.

Legal information, not legal advice. This document describes the law as written and dated; it does not apply it to any system. The notice at the foot says what that means.

Nine things an operator can be made to produce after an agent has acted: the traces, who acted, what it could reach, where a person was, what it made, what was done about it, when, what was fixed, and how long all of it has to last. The last is the one the law states in periods, and the corpus carries them.

1What this document is

What the law makes you constrain is about the run: the eight places a duty can land on an AGENT while it is working. This document is about afterwards, when somebody asks what happened. The somebody is usually one of four: a regulator with a statutory power to ask, a customer whose systems or data were involved, a person whose data was in it, or a court. What each of them can require is set by law, and it is much narrower and much more specific than the record an engineer would want to have kept.

Nine classes follow. Eight are the kinds of evidence an incident makes relevant. The ninth is how long any of it has to last, which is the one the law answers in numbers rather than in kinds, and the corpus carries those numbers.

Two neighbours carry what this document deliberately leaves out. When a report is due, and to whom, is Incident reporting clocks, which draws every reporting deadline in the corpus on one time axis. What it has cost the organisations that could not answer is Does legal action really happen?.

2How to read a class

Reading the classes

Ours first
The nine classes are this section's own vocabulary, named for what somebody can make you produce. The document reads the same with every alignment note removed.
The count
A requirement line joins a class when its own wording speaks to that class. The test is words, not judgment, and it is applied to the line rather than to the instrument around it, so a count is a floor rather than a ceiling.
Small numbers
Several of these classes are thin, and the thinness is the finding rather than a failure of the reading. Binding law asks for an outcome and for a record of a decision; it very rarely asks for the run-time detail an incident responder needs.
A record, not a log
Where a statute does ask for a record, it usually asks for a record of processing, which is a register of what an organisation does with data, and not a trace of what a system did in a particular minute. The two words are worth keeping apart while reading.
The periods
The retention section lists every period in force the corpus states, read out of the sentence that states it, with that sentence beside it. A period is shown as a minimum or a maximum where the sentence says which, because a bare number does not.
A proposal, not a law
The note under each class quotes the SAFE proposal published by the OSAA, read 2026-09-20 from its request for comments. It is a voluntary undertaking among members and binds nobody.
Nine things an operator can be made to show Nine labelled cells, one per evidence class. Prompts, traces and tool calls: The record of what ran and what it did. Agent and workload identity: Which system acted, and on whose authority. Permissions and credentials at run time: What the run could reach while it ran. Human approval and intervention: Where a person was, and what they could do. Artefacts created or changed: What the run made, marked or moved. Detection, containment and recovery: What was noticed, stopped and put back. The incident timeline: When each of those things happened. Reproduction and remediation: What was fixed, and how that was shown. How long the record has to last: The one class the law states in periods. Prompts, traces and tool calls The record of what ran and what it did Agent and workload identity Which system acted, and on whose authority Permissions and credentials at run time What the run could reach while it ran Human approval and intervention Where a person was, and what they could do Artefacts created or changed What the run made, marked or moved Detection, containment and recovery What was noticed, stopped and put back The incident timeline When each of those things happened Reproduction and remediation What was fixed, and how that was shown How long the record has to last The one class the law states in periods
Figure 1. The nine classes, in the order the sections below take them: what ran, who ran it, what it could reach, where a person was, what it made, what was done, when, what was fixed, and how long all of it has to last.

3The nine classes

In order. Each section names the law first and shows the corpus second.

1 · Prompts, traces and tool calls

The record of what ran and what it did.

This is the class an incident responder cares about most and the one binding law says least about. What privacy law asks for is a record of processing: the purposes, the categories of people and data, the recipients, the transfers. That is an organisational register, and it can be complete while telling you nothing about what happened at eleven o'clock on Tuesday.

The first law in the corpus to ask for the other thing is the EU AI Act, and it is not in force yet. AI Act, Article 12 (record-keeping) requires automatic event logging to be built into a high-risk system so that it can record events over the system's lifetime, designed to support identifying an emerging risk, a substantial modification, and monitoring by the provider and the deployer; AI Act, Article 19 (automatically generated logs) and AI Act, Article 26(6) (deployer log-keeping) put the keeping duty on the provider and the deployer respectively; and AI Act, Article 21(2) (competent authority access to automatically generated logs) lets a competent authority ask for those logs on a reasoned request. All four apply from 2027-12-02, not yet in effect.

In force today, the nearest thing is sectoral: CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation requires an organisation's system logs to be enabled, retained securely within Indian jurisdiction on a rolling basis, and provided with an incident report or on the authority's direction.

44 requirement lines in force · 56 provisions · 45 jurisdictions · from: privacy 28 · AI 17 · cybersecurity 15 · scraping 5

The law behind the class Show 7 of the 44 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Keep a record of your processing operations, especially those based on legitimate interest, and name a person in charge (encarregado) whose identity and contact details you publish, preferably on your website.
Brazil Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance) Source as of 2026-09-19
Enable logs of all your ICT systems and retain them securely, within Indian jurisdiction, on a rolling 180-day basis, and provide them to CERT-In together with an incident report or when CERT-In orders or directs you to.
India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) Source as of 2026-09-12
Maintain written and electronic records of processing activities naming the controller, the purposes, the categories of data and recipients, any transfer outside Albania, and the envisaged erasure periods, and make the records available to the Commissioner on request.
Albania Law No. 124/2024 On the Protection of Personal Data, Law No. 124/2024 (Ligj Nr. 124/2024) On the Protection of Personal Data, Arts. 1-8, 11, 22-38, 43-46 (general provisions, lawful basis, consent, controller and processor obligations, and specific-purpose exceptions), in force 31 January 2025 Source as of 2026-09-19
Equip your service with devices capable of issuing an alert on an event or a request, and of sending a technical report on a compromised server, widely disseminated malicious code, a software vulnerability or anything an intrusion-detection system or event log identifies (Article 16(1)).
Keep a written record of processing activities under Article 32, covering the purposes, the categories of data subjects and data, the recipients, any transfer abroad, and the envisaged erasure periods, and make it available to the Agency on request.
Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, Law on the Protection of Personal Data, Official Gazette of Bosnia and Herzegovina No. 12/25, applicable 4 October 2025, arts. 1-9, 13, 26-34, 37-45, 52-65 (excluding 57a-57b), 75-85, 88-90 (general provisions, lawful basis, controller and processor duties, security, DPIA, DPO) Source as of 2026-09-19
Build data protection into the design of your processing and make it the default, and keep records of your processing activities.
Barbados Data Protection Act, 2019, Data Protection Act, 2019 (Act 2019-29), ss. 1-7, 29-62, 65-69 and 96-100 Source as of 2026-09-19
Identify in your register of processing activities every transfer of personal data to a third country or international organization, including that country's or organization's identity and, where relied on, the documents evidencing appropriate safeguards.
Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, transfert transfrontalier de données, Loi n°2017-20 du 20 avril 2018, Livre V, arts. 391-392 (transfert transfrontalier de données) Source as of 2026-09-19
The alliance's words for the same ground

Prompts, traces, tool calls, logs, configurations, model and safeguard versions and third-party dependencies

SAFE Evidence Preservation, read 2026-09-20.

2 · Agent and workload identity

Which system acted, and on whose authority.

An AGENT acting on behalf of a person raises a question the corpus barely asks: which system acted, and whose authority was it using? The identity duties in force are about people and organisations. Privacy law asks who the controller is and whether a unique identifier may be assigned to a person at all, which is the opposite question. Where an identity duty does reach a machine, it is usually the duty to say that a machine is what you are dealing with, which sits with the disclosure rules in Global AI law: 8 common threads rather than here.

This is the widest gap on the page between what a responder needs and what a statute requires, and it is worth stating plainly: if your record cannot say which agent, which version and which delegation chain produced an action, almost nothing in force today will have told you so. Jurisdiction in logs takes one part of the same problem, the jurisdiction a request was served under, and argues it as a field the record has to carry.

11 requirement lines in force · 13 provisions · 12 jurisdictions · from: privacy 5 · cybersecurity 4 · AI 3 · scraping 1

The law behind the class Show 8 of the 11 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Embed synthetically generated information with permanent metadata or another technical provenance mechanism, including a unique identifier, to the extent technically feasible, and do not enable removal, suppression or modification of that label or metadata.
India Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026) Source as of 2026-09-07
Obtain the Information Regulator's prior authorisation before linking data subjects' unique identifiers across responsible parties, processing criminal-behaviour or credit-reporting information, or transferring special personal information or a child's information to a country without adequate protection.
South Africa Protection of Personal Information Act 4 of 2013 (POPIA), Protection of Personal Information Act 4 of 2013 (POPIA), ss. 1-21, 36-38 and 55-59 (application, the general conditions for lawful processing, exemptions, the Information Officer and prior authorisation) Source as of 2026-09-19
Put in place technical mechanisms addressing threats to your systems' permanent availability, integrity, authentication, non-repudiation and data confidentiality, and to their physical security, and submit those mechanisms to the Agence Nationale de la Cybersécurité for approval.
Central African Republic Cybersecurity Law: Network and Information System Security Duty, Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité, Titre II, Chapitre III, Sections I et II (art. 16, 19, 20, 21, 23) Source as of 2026-09-20
The provision's own wording distinguishes genuine from non-genuine sexual acts with minors without requiring that a depiction involve or be traceable to a real minor, so do not produce, store, market, advertise, offer, show, pass on, make accessible, acquire or possess a pornographic depiction of a non-genuine sexual act with a minor, including a drawn, computer-generated or AI-generated depiction that does not involve a real minor.
Switzerland Swiss Criminal Code, Pornographic Depictions of Non-Genuine Sexual Acts with Minors, Swiss Criminal Code (StGB/CP/CP), SR 311.0, Art. 197 para. 4-5 Source as of 2026-09-06
Where you operate an Electronic Agent, an automated device that carries out an action on Electronic Information for a user without that user's direct intervention, such as an automated transaction or e-commerce system, additionally run a standard operating procedure meeting six security-control principles for user data and Electronic Transactions: confidentiality, integrity, availability, authenticity, authorization, and non-repudiation, and test a transacting user's identity and authorization before completing the transaction.
Indonesia Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty, Government Regulation No. 71 of 2019 (PP PSTE), Pasal 3, 23, 24(1)-(2), 31, 32, 39, 40 Source as of 2026-09-16
Carry in every direct marketing communication the identity of the sender and an address or other contact details the recipient can use to ask that the communication cease.
Jamaica Data Protection Act, 2020, rights of data subjects and automated decision-taking, Data Protection Act, 2020 (Act 7 of 2020), ss. 5-13 Source as of 2026-09-19
Ground the processing of a Norwegian national identity number (fodselsnummer) or other unique identifier on a legitimate need for secure identification, under Personal Data Act Section 12.
Norway Personal Data Act (personopplysningsloven), Lov om behandling av personopplysninger (personopplysningsloven), LOV-2018-06-15-38, in force 20 July 2018 Source as of 2026-08-24
Do not assign a unique identifier to an individual unless it is necessary to carry out your organisation's functions efficiently, and do not assign the same identifier already assigned by another agency except in limited circumstances.
New Zealand Privacy Act 2020, Information Privacy Principles and Extraterritorial Reach, Privacy Act 2020 (NZ), No 31, ss. 4, 22 (IPP 1, 2, 13) Source as of 2026-09-06
The alliance's words for the same ground

Agent and workload identities

SAFE Evidence Preservation, read 2026-09-20.

3 · Permissions and credentials at run time

What the run could reach while it ran.

What the run could reach while it ran is the difference between an incident and a catastrophe, and it is nearly absent from binding law as a record-keeping duty. Where it appears, it appears inside security regulations as a monitoring duty with a period attached rather than as evidence to be produced: an automatic mechanism that monitors access to a database's systems, with the record kept, is the shape.

The related duty that is everywhere is the control itself rather than the record of it, which is why this class is thin here and its counterpart is not: see the tools layer of What you must constrain.

10 requirement lines in force · 9 provisions · 8 jurisdictions · from: scraping 5 · cybersecurity 3 · privacy 2

The law behind the class Show 8 of the 10 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Preserve the intimacy, private life, honor, and image of the parties involved when retaining or disclosing connection records, application-access records, personal data, or the content of private communications.
Brazil Marco Civil da Internet, Protection of Records and Personal Data, Lei nº 12.965/2014 (Marco Civil da Internet), arts. 7º, 10, e 12 Source as of 2026-09-05
Do not possess, buy, receive, sell, exchange, facilitate, or traffic computer data, access credentials, or personal databases that you know or have reason to presume were obtained without the titleholder's consent or through a security breach or a computer offense.
Peru Decreto Legislativo 1700, illicit trafficking of computer data (art. 12-A of Ley 30096), Decreto Legislativo 1700 (24 January 2026), incorporating art. 12-A into Ley 30096, as amended by Decreto Legislativo 1741 (13 February 2026) Source as of 2026-09-05
Do not breach an automated data processing system's protective means, or access it without permission or by using rights granted to another person; Section 241 does not reach access to a page that carries no such protective means.
Latvia Krimināllikums Sections 241, 243, 244, Automated Data Processing System Offences, Krimināllikums, 241., 243. un 244. pants Source as of 2026-09-06
Adopt rules for handling data, log who has accessed it, and oversee the security of that data (Article 12).
Montenegro Law on Information Security, General Security Measures, Law on Information Security, Arts. 1 to 3, 7 to 15 and 18(1) to (3) Source as of 2026-09-18
Maintain a registry of every database you disclose to third parties, covering its legal basis, its contents, who receives it, retention periods and everyone who accessed it, and produce that registry to ANTAI on request.
Panama Ley 81 de 2019, Sobre Protección de Datos Personales, Ley No. 81 de 26 de marzo de 2019, Sobre Protección de Datos Personales, Gaceta Oficial No. 28743-A, arts. 1-4, 6-12, 14, 24-32, 44 and 47 (general provisions, lawful basis and accountability) Source as of 2026-09-19
Take all necessary precautions to secure personal data against unauthorized modification, alteration or consultation, including physical access controls, a log of who accessed the system and when, and secure backup copies.
Tunisia Organic Act on the Protection of Personal Data, Loi organique n° 2004-63 du 27 juillet 2004, portant sur la protection des données à caractère personnel, arts. 1-12, 16-26, 44-49, 53-61, 66-74, 104-105 (comprehensive regime) Source as of 2026-09-19
Do not knowingly possess, traffic in, publish, or control another person's access device, a credential or similar means of reaching an account or system, without the consent of its issuer, owner, or authorized user and with intent to use or distribute it; this can reach obtaining or trading in login credentials used to collect data from behind a login wall.
Arizona Unlawful possession of an access device, A.R.S. § 13-2316.01 Source as of 2026-09-06
Equip the connected device with reasonable security features appropriate to its nature, function and the information it may collect, store or transmit, satisfied by giving each device a unique preprogrammed authentication credential or by requiring the user to generate new credentials before first use, or by complying with an applicable federal security requirement for connected devices.
Oregon Security requirements for Internet-connected devices, ORS 646A.813 (added by 2019 c.193 (H.B. 2395-A) sec. 1; amending ORS 646.607) Source as of 2026-09-12
The alliance's words for the same ground

Permissions and credentials available during the run

SAFE Evidence Preservation, read 2026-09-20.

4 · Human approval and intervention

Where a person was, and what they could do.

Where a person was, and what they could do about the outcome, is the evidence question privacy law answers best. The right not to be subject to a solely automated decision produces a duty of meaningful human review before such a decision is finalised, and that review is a fact somebody can later be asked to show. The corpus holds it jurisdiction by jurisdiction, as a national reading of the data-subject rights chapter in Europe and as its own provision elsewhere.

For an AGENT the practical trap is that the review has to be real and has to be recorded as what it was. A person who clicked approve on a queue of four hundred items has not reviewed them, and a record that cannot distinguish that from a considered decision is evidence of the wrong thing.

48 requirement lines in force · 51 provisions · 50 jurisdictions · from: privacy 44 · AI 9

The law behind the class Show 8 of the 48 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in the EU.
European Union GDPR Articles 12-22, Data Subject Rights, Regulation (EU) 2016/679, Arts. 12-22 Source as of 2026-08-23
Let a consumer opt out of your use of ADMT to make a significant decision about them, unless you offer an appeal to a human reviewer with authority to overturn the decision or another exception listed in the regulation applies
California CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 Source as of 2026-09-08
Before finalizing a solely automated decision producing legal or similarly significant effects for a person in the United Kingdom, inform them in advance, and provide a meaningful human review and a right to contest the decision on request, under UK GDPR Articles 22A to 22D.
United Kingdom Data (Use and Access) Act 2025 Section 80, Automated Decision-Making, UK GDPR Articles 22A-22D, Data (Use and Access) Act 2025, c. 18, §80 (new UK GDPR Arts. 22A-22D); S.I. 2026/425 Source as of 2026-08-24
Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Germany, including a credit score generated for a third party's determinative use, under GDPR Article 22 and BDSG Section 31.
Germany GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany, Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37 Source as of 2026-08-24
Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Ireland, under GDPR Article 22.
Ireland GDPR Article 22, Automated Decision-Making in Ireland, Regulation (EU) 2016/679, Art. 22, as transposed by the Data Protection Act 2018 Source as of 2026-08-24
Give a person in Italy a path to obtain human intervention, express their view, and contest a decision made solely by automated processing that produces a legal or similarly significant effect on them.
Italy GDPR Article 22 and the Garante's OpenAI/ChatGPT Enforcement, Regulation (EU) 2016/679, Art. 22; Garante Provvedimento 30 marzo 2023 Source as of 2026-08-24
Give a person in France a path to obtain human intervention, express their view, and contest a decision made solely by automated processing, including profiling, that produces a legal or similarly significant effect on them.
France GDPR Article 22, Right Against Automated Individual Decision-Making, Regulation (EU) 2016/679, Art. 22 Source as of 2026-08-24
Give a person in the Netherlands a path to obtain human intervention, express their view, and contest a decision made solely by automated processing that produces a legal or similarly significant effect on them, subject to UAVG Article 40's exceptions.
Netherlands GDPR and UAVG Articles 40-43, Data-Subject Rights and Journalistic Exception, Regulation (EU) 2016/679, Arts. 12-23; UAVG, Arts. 40, 41, 43 Source as of 2026-08-24
The alliance's words for the same ground

Human approval and intervention events

SAFE Evidence Preservation, read 2026-09-20.

5 · Artefacts created or changed

What the run made, marked or moved.

What the run made, and what it changed. Two duties meet here. The first is marking: AI Act, Article 50 (transparency obligations for AI systems and synthetic content) (since 2026-08-02) requires synthetic content to be marked in a machine-readable way, and AI Framework Act, Article 31 (transparency obligations for AI outputs) requires the same of AI outputs in Korea, so the artefact itself carries part of the evidence. The second is integrity: a record that can be altered without trace is not evidence, and several security regimes say so in their own words.

An AGENT that writes files, posts content or edits records produces artefacts in other people's systems, which is where the COUNTERPARTY sits. Those artefacts are somebody else's evidence as much as yours.

29 requirement lines in force · 39 provisions · 38 jurisdictions · from: AI 20 · privacy 13 · scraping 7 · cybersecurity 2

The law behind the class Show 7 of the 29 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Use a machine-readable marking where feasible
European Union AI Act, Article 50 (transparency obligations for AI systems and synthetic content), Regulation (EU) 2024/1689, Article 50 Source as of 2026-08-14
Embed a latent disclosure of machine-readable provenance data in content the system creates
California California AI Transparency Act (SB 942, as amended by AB 853), Cal. Bus. and Prof. Code Sections 22757 to 22757.6 Source as of 2026-08-14
Place that disclosure at the start of an audio piece, or as a watermark label with audio description on a static image, or in both forms for a video or combined audio-video piece.
Brazil TSE Resolution, AI-Generated Content Disclosure Duty, Resolução TSE nº 23.610/2019, art. 9º-B (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) Source as of 2026-09-05
Embed synthetically generated information with permanent metadata or another technical provenance mechanism, including a unique identifier, to the extent technically feasible, and do not enable removal, suppression or modification of that label or metadata.
India Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026) Source as of 2026-09-07
Mark AI-generated audio, image, and video content in a machine-readable format under the Government's regulations.
Vietnam Law on Artificial Intelligence, transparency obligation, Law No. 134/2025/QH15, art. 11 Source as of 2026-09-06
Publish, before supply, the period including an end date for which the device will receive security updates, provide or supply the product with a statement of compliance with the security standard, and retain a copy of that statement for five years.
Australia Security Standards for Smart Devices, Cyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1 Source as of 2026-09-12
Give a data subject their data in a structured, commonly used, machine-readable format and transmit it to another controller on request where processing rests on consent or a contract and is automated.
Andorra LQPD, rights of the data subject, Llei 29/2021, arts. 15-26 (rights of the data subject) Source as of 2026-09-19
The alliance's words for the same ground

Files and external artifacts created or modified

SAFE Evidence Preservation, read 2026-09-20.

6 · Detection, containment and recovery

What was noticed, stopped and put back.

What was noticed, what was stopped, and what was put back. NIS2 Directive, Cybersecurity Risk-Management Measures names incident handling, business continuity including backup management, and crisis management among its minimum measures, so the existence of the capability is itself a duty. The evidence duty arrives through the notification rules: most breach and incident regimes in the corpus require the notification to describe the measures taken or proposed, which means the response has to be recorded as it happens rather than reconstructed afterwards.

67 requirement lines in force · 71 provisions · 61 jurisdictions · from: privacy 40 · cybersecurity 36 · scraping 4

The law behind the class Show 7 of the 67 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Take technical, operational and organisational measures appropriate to the risk your network and information systems face, covering at minimum a risk analysis and information-system-security policy, incident handling, business continuity and crisis management, supply chain security, and security in the acquisition, development and maintenance of your systems.
European Union NIS2 Directive, Cybersecurity Risk-Management Measures, Directive (EU) 2022/2555, Art. 21 Source as of 2026-09-08
At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved.
Vietnam Cybersecurity Law, Information System Classification and Protection Measures, Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10 Source as of 2026-09-16
Cover at least: risk analysis and information-security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluation of your measures' effectiveness; basic cyber-hygiene training; cryptography; personnel security and access control; and multi-factor or continuous authentication.
Germany BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities, BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38 Source as of 2026-09-12
As a relevant digital service provider, additionally take into account the security of your systems and facilities, incident handling, business continuity management, monitoring, auditing and testing, and compliance with international standards, and keep documentation sufficient for the competent authority to verify your compliance.
Ireland European Union (NIS) Regulations 2018, Security Requirements, S.I. No. 360/2018, Regs. 17 and 21 Source as of 2026-09-12
Cover at least: risk-analysis and information-system security policies; incident handling, including the procedures and tools to carry out the Article 25 and 26 notifications; business continuity, including backup management, disaster recovery and crisis management; and supply-chain security.
Italy Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures, D.Lgs. 4 settembre 2024, n. 138, Artt. 23 e 24 Source as of 2026-09-12
Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in acquiring, developing and maintaining your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.
Netherlands Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance, Cyberbeveiligingswet, Artt. 21 en 24 Source as of 2026-09-12
Give the Commission and every other relevant authority immediate information about a breach, whatever time you otherwise have, where that may help contain an imminent breach on a national scale, where containment may be needed nationally, sectorally or individually, or where the breach may affect the general public.
Nigeria Nigeria Data Protection Act, 2023, data breach notification, Nigeria Data Protection Act, 2023, data breach notification (s. 40; GAID 2025, art. 33) Source as of 2026-09-19
The alliance's words for the same ground

Detection, containment and recovery events

SAFE Evidence Preservation, read 2026-09-20.

7 · The incident timeline

When each of those things happened.

When each of those things happened is the most heavily regulated class on this page, because almost every reporting duty in the corpus is stated as a period running from a moment. That makes two facts legally significant that an engineer might not log at all: the moment the organisation became aware, and the moment the incident began.

Cyber Resilience Act, Manufacturer Reporting Obligations is the clearest example of a staged timeline: an early warning within 24 hours of becoming aware, a notification within 72, and a final report no later than fourteen days after a corrective measure becomes available. Every such deadline in the corpus, with the sentence it was read from, is drawn on one axis in Incident reporting clocks.

341 requirement lines in force · 252 provisions · 142 jurisdictions · from: privacy 259 · cybersecurity 121 · AI 29 · scraping 1

The law behind the class Show 7 of the 341 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Transmit the audit report and the audit implementation report to your Digital Services Coordinator of establishment and the Commission without undue delay, and make them public, with confidential information removed where necessary, within three months of receiving the audit report.
European Union Digital Services Act, Article 37 (independent audit of very large online platforms and search engines), Regulation (EU) 2022/2065, Article 37, supplemented by Commission Delegated Regulation (EU) 2024/436 Source as of 2026-09-15
Report a critical safety incident to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious injury
California Transparency in Frontier Artificial Intelligence Act (SB 53), Cal. Bus. and Prof. Code Sections 22757.10 to 22757.16 Source as of 2026-09-08
If you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred.
Colorado C.R.S. 6-1-716, Notification of Security Breach, C.R.S. section 6-1-716 Source as of 2026-08-23
If you own a website, application, or social media platform on which such material is disclosed, you are liable for damages if the depicted person requests removal and you fail to remove it, and known identical copies, within 72 hours.
Texas S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications, Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009 Source as of 2026-09-06
Notify the ICO without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in the United Kingdom, unless the breach is unlikely to risk their rights and freedoms.
United Kingdom UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom, UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025 Source as of 2026-08-24
Answer a confirmation-of-processing or access request immediately in simplified form, or within 15 days with a complete, clear statement of the data's origin, the criteria used, and the purpose of the processing.
Brazil LGPD, rights of the data subject, Lei nº 13.709, de 2018 (LGPD), arts. 17-22 (rights of the data subject) Source as of 2026-09-19
An app that detects a violation of Vietnam's personal data protection rules likely to cause harm to national defense and security, social order, or an individual's life, health, honor, dignity, or property must notify the agency in charge of personal data protection within 72 hours.
Vietnam Law on Personal Data Protection, breach notification, Law No. 91/2025/QH15, Article 23 Source as of 2026-08-29
The alliance's words for the same ground

A complete incident timeline

SAFE Evidence Preservation, read 2026-09-20.

8 · Reproduction and remediation

What was fixed, and how that was shown.

What was fixed, and how that was shown. The final-report duties are where this becomes evidence rather than engineering: NIS2 Directive, Reporting Obligations and Cyber Resilience Act, Manufacturer Reporting Obligations both end their staged sequence with a report, and AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk) requires a provider of a model with systemic risk to document and report corrective measures taken or planned. Elsewhere the same idea appears as a corrective-action duty attached to a regulator's finding.

Reproduction is the half the law does not ask for and an incident needs most. Nothing in the corpus requires an OPERATOR to be able to run the failing case again, which for a non-deterministic system is the difference between a fix and a hope.

58 requirement lines in force · 58 provisions · 49 jurisdictions · from: cybersecurity 54 · privacy 12 · AI 6

The law behind the class Show 7 of the 58 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Keep track of, document, and report to the AI Office, and as appropriate to national competent authorities, without undue delay, relevant information about serious incidents involving your model and any corrective measures you have taken or plan to take. The Regulation states no fixed number of days for this report and no explicit moment its clock starts from, only that it must be made without undue delay.
European Union AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk), Regulation (EU) 2024/1689, Article 55 Source as of 2026-09-20
Implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect that sensitive personal information from unlawful use or disclosure. The statute states no further content for what 'reasonable' requires beyond this general standard.
If a serious incident occurs in your AI system and you are its developer or provider, urgently apply technical measures to remedy, suspend, or recall the system, and at the same time notify the competent state authority of the incident.
Vietnam Law on Artificial Intelligence, incident management and reporting obligation, Law No. 134/2025/QH15, art. 12 Source as of 2026-09-20
Submit an intermediate report on the BSI's request, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
Germany BSI-Gesetz (BSIG), Incident Notification, BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32 Source as of 2026-09-12
Submit an intermediate report on CSIRT Italia's request, and a final report within one month of the notification (or, for an incident still ongoing at that point, a monthly progress report and a final report within one month of the incident's resolution).
Italy Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification, D.Lgs. 4 settembre 2024, n. 138, Art. 25 Source as of 2026-09-12
Submit a final report no later than one month after your notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border effects; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of resolution.
Netherlands Cyberbeveiligingswet, Significant-Incident Reporting Obligations, Cyberbeveiligingswet, Artt. 25-29 Source as of 2026-09-12
By April 15 of each year, submit to the Superintendent electronically either a written certification that you materially complied with this Part for the prior calendar year or a written acknowledgment identifying the sections you did not materially comply with and a remediation timeline, each signed by your highest-ranking executive and your Chief Information Security Officer.
The alliance's words for the same ground

Reproduction testing and remediation evidence

SAFE Evidence Preservation, read 2026-09-20.

9 · How long the record has to last

The one class the law states in periods.

How long any of it has to last is the one question the law answers in numbers. The corpus states the period as prose inside the obligation sentence, so the periods below are read out of those sentences when this page is built, by the rule in section 2, and each is shown with the sentence it came from.

What the corpus states

12 of the 128 requirement lines in force in this class state a period a record has to last. They run from 10 days to ten years, and they are not the same kind of number: some are the shortest you may keep something, others the longest.

ten years at least Article 4 also states three further common obligations this row does not flag as a security duty: retain connection and traffic data for at least ten years, install mechanisms to monitor your own network's data traffic, and, if you operate a cybercafé, install a video-surveillance system; these read as data-retention, surveillance-capability, and physical-security mandates rather than a duty over your systems' or services' own security posture.
Burundi Loi n° 1/10, Articles 3, 4(3) and 14: security-of-service duty and diligence penalty for network operators and service providers, Loi n° 1/10 du 16 mars 2022 portant prevention et repression de la cybercriminalite au Burundi, Arts. 3, 4(3), 14 Source as of 2026-09-19
ten years Retain your systems' connection and traffic data for ten years, and submit your networks and information systems to a mandatory, periodic security audit on terms a regulation sets.
Gabon Sécurité des systèmes d'information (dispositions communes), Loi N° 027/2023 du 11 juillet 2023, Titre III, Chapitre III, Section 2, arts. 28-35 Source as of 2026-09-18
7 years at most Retain a subscriber's information only for billing purposes, and for no longer than 7 years.
Nauru Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications, Communications and Broadcasting Act 2018 (No. 21 of 2018), ss. 48-49, 70-71 Source as of 2026-09-19
five years Publish, before supply, the period including an end date for which the device will receive security updates, provide or supply the product with a statement of compliance with the security standard, and retain a copy of that statement for five years.
Australia Security Standards for Smart Devices, Cyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1 Source as of 2026-09-12
five years If your own service is itself a data centre, a virtual private server provider, a cloud service provider, a virtual private network service, or a virtual asset (crypto) service provider, a narrower and heavier duty also applies: register and retain specified customer KYC information and financial-transaction records for five years. That narrower bound-party class is not one this profile's declared activities can identify on their own, so confirm applicability directly against the text if this describes your service.
India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) Source as of 2026-09-12
five years at most Do not retain personal data for longer than five years, or the term your contract with the data subject sets, once the data are no longer adequate, proportional, or necessary for their purpose.
Nicaragua Ley No. 787, Ley de Protección de Datos Personales, Ley No. 787, 29-Mar-2012, Gaceta Oficial No. 61, arts. 1-6, 9, 11-13, 19, 22-24, 27 Source as of 2026-09-19
five years at least Retain all documents relevant to each cybersecurity audit for at least five years, and give the audit report only to a member of executive management with direct responsibility for the cybersecurity program.
California CCPA Cybersecurity Audit Regulations, Cal. Code Regs. tit. 11, Sections 7120 to 7124 Source as of 2026-09-15
24 months at least At the medium or high tier, run an automatic mechanism monitoring access to the database's systems, retained at least 24 months, and appoint a data security officer where required.
Israel Privacy Protection Regulations (Data Security), information security programme, Privacy Protection Regulations (Data Security), 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement) Source as of 2026-09-18
24 months Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol.
Colorado HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313) Source as of 2026-08-23
one year Comply with the national cybersecurity authority's directives on retaining, for one year from generation, the technical data needed to identify a cybersecurity incident, including connection data, system logs, and the security-event traces your operating systems, applications and security products generate.
Morocco Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties, Loi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 26, 29, 32 et 34, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020) Source as of 2026-09-17
180-day Enable logs of all your ICT systems and retain them securely, within Indian jurisdiction, on a rolling 180-day basis, and provide them to CERT-In together with an incident report or when CERT-In orders or directs you to.
India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) Source as of 2026-09-12
10 days at most Obtain written consent before processing a person's biometric data in Russia, never condition service on that consent, and retain any biometric sample your organization holds only up to 10 days before deleting it, since the durable copy of record lives in the state system.
Russia Federal Law No. 572-FZ, Unified Biometric System for Identification and Authentication, Federal Law No. 572-FZ of 29 December 2022 "On the identification and/or authentication of individuals using biometric personal data" Source as of 2026-08-24

Two things this table does not show. Periods stated as a test rather than a number, no longer than is necessary for the purpose being the commonest of them, bind just as hard and cannot be drawn on a scale. And the period that will matter most to an agent is not here yet: AI Act, Article 19 (automatically generated logs) and AI Act, Article 26(6) (deployer log-keeping) require the automatically generated logs of a high-risk AI system to be kept for a period appropriate to the intended purpose and at least six months, and both apply from 2027-12-02, not yet in effect.

128 requirement lines in force · 139 provisions · 101 jurisdictions · from: privacy 112 · cybersecurity 22 · AI 11 · scraping 8

The law behind the class Show 7 of the 128 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Disclose at or before collection the categories of personal information you collect, your purpose for collecting it, and the retention period or the criteria you use to set it.
California California Consumer Privacy Act, as amended by the California Privacy Rights Act (Proposition 24), Cal. Civ. Code section 1798.100 et seq. (CCPA, as amended by the CPRA) Source as of 2026-08-23
Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol.
Colorado HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313) Source as of 2026-08-23
Destroy or arrange for the destruction of customer records containing sensitive personal information no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or indecipherable through any means.
Preserve the intimacy, private life, honor, and image of the parties involved when retaining or disclosing connection records, application-access records, personal data, or the content of private communications.
Brazil Marco Civil da Internet, Protection of Records and Personal Data, Lei nº 12.965/2014 (Marco Civil da Internet), arts. 7º, 10, e 12 Source as of 2026-09-05
Enable logs of all your ICT systems and retain them securely, within Indian jurisdiction, on a rolling 180-day basis, and provide them to CERT-In together with an incident report or when CERT-In orders or directs you to.
India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) Source as of 2026-09-12
A reproduction made under the research and non-commercial text-and-data-mining exception must be stored in a secure manner appropriate to the work and retained only as necessary for the purposes of the scientific research, including verification of results (s. 53A(3A)).
Ireland Text and Data Mining Exceptions, Copyright and Related Rights Act 2000 ss. 53A-53B, European Union (Copyright and Related Rights in the Digital Single Market) Regulations 2021 (S.I. No. 567 of 2021), regs. 3-4, inserting and amending ss. 53A and 53B of the Copyright and Related Rights Act 2000 Source as of 2026-09-06
Publish, before supply, the period including an end date for which the device will receive security updates, provide or supply the product with a statement of compliance with the security standard, and retain a copy of that statement for five years.
Australia Security Standards for Smart Devices, Cyber Security Act 2024 (Cth), No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1 Source as of 2026-09-12
The alliance's words for the same ground

None. The SAFE Evidence Preservation list says what to preserve and never for how long, which is the one question the corpus answers in numbers.

4The shape of the answer

Read across the nine sections and the law's priorities are plain, and they are not an incident responder's. The class with the most binding law behind it is the incident timeline (341 requirement lines in force). The class with the least is permissions and credentials at run time (10). What the law asks you to produce is mostly the what and the when of an event that has already been judged significant. What it almost never asks you to produce is the run-time detail that would let anyone work out why the system did it.

That asymmetry is the practical finding of this document. A record built only to the standard of what is legally demandable will satisfy a regulator and leave your own engineers unable to answer the first question they will be asked. The law is a floor here in a way it is not on What the law makes you constrain, where the duties bite directly.

5What this document does not claim

It does not say what to log. It says what binding law, as the corpus held it on the date in the byline, can make an organisation produce, and it counts how much of that corpus speaks to each class. A thin class is not permission to keep nothing: contract, sectoral regulation, a customer's own requirements and the ordinary duty to be able to defend yourself all reach past it.

It also does not adopt anyone's framework. The alliance's evidence list is quoted because a reader holding it should be able to find the same ground here with the law underneath, and because the one place our list and theirs differ, retention, is worth seeing rather than smoothing over. It is a proposal, it was open for comment when it was read, and it may be revised; the law beside it is dated on every line.