Sample — TRESTLE Regulatory Radar™

The privacy law map for U.S. life sciences.

This is a static, illustrative sample. It shows the categories, coverage, and format of the live Regulatory Radar™ but is not maintained and does not reflect current requirements. The live, monthly-refreshed Radar — with the full 63-record register, jurisdiction map, timeline, filters, and export — is available to subscribers.

The subscriber service tracks 63 requirements across 28 jurisdictions — spanning comprehensive state privacy, HIPAA / 42 CFR Part 2, AI governance (U.S. + EU), cybersecurity & device, FTC enforcement & adtech, consumer health data, genetic & biometric, research & clinical trials, and cross-border data transfer.
Sample below shows 8 of the 63. Verified as of Aug 2026 · this page is not refreshed.
This is a static, illustrative sample. Verified as of Aug 2026 — this page is not maintained and does not reflect current requirements. The live, monthly-refreshed Radar is available to subscribers.
Request a demo → Subscribe →
Sample records · 8 of 63

A representative slice of what the live Radar tracks.

One row per category, chosen to show the range of exposure the full register covers: from headline state privacy statutes to the highest-consequence federal cross-border rule. The full subscriber service adds status filters, jurisdiction map with click-to-filter, chronological timeline, monthly change log, CSV/XLSX export, and the full plain-English record for each requirement.

CA Effective Comprehensive State Privacy Effective Jan 1, 2023

California CCPA / CPRA

CCPA/CPRA is unique in covering employee (HR) and B2B contact data, and it treats precise geolocation and health inferences as "sensitive personal information." PHI handled under HIPAA is exempt, but marketing, HR,…

Subscribers see: What it is · Actions we take with clients · Compliance functions engaged · Penalties · Client-ready talking point · Official sources
FED Effective HIPAA / 42 CFR Part 2 Effective Apr 14, 2003

HIPAA Privacy Rule

Pharma, device, and patient-services companies are usually business associates (or hybrid covered entities via patient-assistance and copay programs). The de-identification safe harbor (§164.514) and the limited data…

Subscribers see: What it is · Actions we take with clients · Compliance functions engaged · Penalties · Client-ready talking point · Official sources
FED Partially Effective AI Governance Effective Aug 2, 2026

EU AI Act (Extraterritorial)

For U.S. life-sciences companies the practical effect is a longer runway, not a smaller obligation. Transparency duties under Article 50 are live now and apply to any AI a patient, investigator, or HCP interacts with in…

Subscribers see: What it is · Actions we take with clients · Compliance functions engaged · Penalties · Client-ready talking point · Official sources
WA Effective Consumer Health Data Effective Mar 31, 2024

Washington My Health My Data Act (MHMDA)

MHMDA is the highest-risk state health-privacy law because of its broad definition (any data linked to health status, including inferences) plus a private right of action that fuels class litigation. HIPAA-covered data…

Subscribers see: What it is · Actions we take with clients · Compliance functions engaged · Penalties · Client-ready talking point · Official sources
IL Effective Genetic / Biometric Effective Oct 3, 2008

Illinois BIPA

BIPA is the most-litigated biometric law in the U.S.; life-sciences exposure comes from lab access controls, clinical-trial identity verification, and timekeeping systems. The 2024 amendment caps repeated-scan damages,…

Subscribers see: What it is · Actions we take with clients · Compliance functions engaged · Penalties · Client-ready talking point · Official sources
FED Partially Vacated FTC Enforcement / Adtech Effective Jun 20, 2024

HIPAA Online Tracking Technologies (OCR Bulletin, as narrowed)

The vacatur is routinely over-read as ending the exposure. It does not. It removed one HIPAA theory on one class of page while leaving authenticated-page exposure intact and leaving every non-HIPAA theory untouched.…

Subscribers see: What it is · Actions we take with clients · Compliance functions engaged · Penalties · Client-ready talking point · Official sources
FED Effective Cross-Border Data Transfer Effective Apr 8, 2025

DOJ Data Security Program (28 CFR Part 202 / EO 14117)

This is the highest-consequence and least-tooled obligation currently facing life-sciences data operations. There is no exemption for anonymised, pseudonymised, de-identified, or encrypted data, so the de-identification…

Subscribers see: What it is · Actions we take with clients · Compliance functions engaged · Penalties · Client-ready talking point · Official sources
NY Effective Cybersecurity / Device Effective Mar 21, 2020

New York SHIELD Act

The SHIELD Act imposes an affirmative "reasonable safeguards" duty on any company holding NY residents’ private information—covering life-sciences HR, clinical, and commercial data even without a NY office. It is a…

Subscribers see: What it is · Actions we take with clients · Compliance functions engaged · Penalties · Client-ready talking point · Official sources
Primary source: NY AG — SHIELD Act
Subscriber service

The live Radar — 63 requirements, 28 jurisdictions, refreshed monthly.

Interactive jurisdiction map. Filter by status, category, and function. Chronological timeline. Full plain-English record for every requirement, including the client-ready talking point. CSV / XLSX export. Monthly change log with source citations. Available standalone or bundled with TRESTLE Privacy Console™, AI Integrity Test™, AI Integrity Framework™, and Praxis™.

Request a demo → Subscribe →
Or email svincze@trestlecompliance.com

Delivered as consulting by default; attorney engagement on request at higher rates. Signed by L. Stephan Vincze — attorney-client privileged when retained by a GC or outside counsel. This sample is a compliance-awareness illustration only and does not constitute legal advice; verify current requirements against primary sources and counsel.