Skip to guide
DIAMOND BRIGHTCyberGuard™

THE BUSINESS OWNER’S FIELD GUIDE

Compliance,
in plain English.

Know which rules may apply, what’s at stake, and where to start. A practical overview of data security and privacy for your business.

Sources checked September 23, 2026 · U.S. focus, with Illinois and EU coverage

This is an educational overview, not legal advice or a complete compliance determination. Requirements, exemptions, and deadlines vary. Use the official sources and qualified legal or compliance advice for your situation. A security scan alone does not establish compliance.

UNDERSTAND THE DIFFERENCE

“Noncompliance” doesn’t have one price tag.

Dollar amounts below have context. A statutory maximum, a lawsuit’s damages, and a payment-provider fee are different things.

01 / REGULATORS

Fines & orders

Laws can authorize monetary penalties, corrective action, or limits on data processing.

02 / CIVIL CLAIMS

Damages & lawsuits

Some laws allow people to sue. Available damages and legal fees depend on the statute and facts.

03 / CONTRACTS

Business consequences

Payment agreements and customer or government contracts can carry their own requirements.

04 / ASSURANCE

Standards & frameworks

SOC 2, ISO 27001, and NIST serve different purposes. They are not universal legal clearance.

EXPLORE 11 COMMON TOPICS

Which rules belong on your radar?

Open a topic for coverage, practical requirements, possible consequences, and official sources. Categories help you browse; they do not determine whether a law applies.

11 topics · Select a heading to read more

Federal law

HIPAA / HITECH

Health information and patient privacyCivil penalties and corrective actionCoverage, requirements & sources

Who it may cover

Covered health plans, clearinghouses, qualifying healthcare providers, and their business associates. A dental or medical office may be covered; handling any health-related data does not automatically make every business subject to HIPAA.

What to put in place

  • Assess risks to all electronic protected health information and document how you reduce them.
  • Implement appropriate access controls, audit logging, workforce training, physical safeguards, and contingency plans.
  • Maintain required business associate agreements, privacy procedures, and breach-notification processes.

Potential penalties & consequences

HIPAA civil penalties depend on the violation and level of culpability; amounts are adjusted for inflation. HHS announced a $1.5 million civil penalty against Warby Parker in February 2025. That is an enforcement example, not a standard fine or a maximum for every case.

Evidence to keep

Risk analysis, remediation records, policies, training records, agreements, and incident documentation.

Federal rule

GLBA / FTC Safeguards Rule

Customer financial informationEnforcement orders and oversightCoverage, requirements & sources

Who it may cover

Financial institutions under FTC jurisdiction, including many tax preparers, mortgage brokers, and auto dealers that arrange financing. Coverage depends on business activities; other financial regulators have their own requirements.

What to put in place

  • Assign a qualified individual and maintain a written security program based on a risk assessment.
  • Protect customer data with access controls, encryption and MFA, subject to the rule’s alternatives; train staff and oversee vendors.
  • Test safeguards, plan incident response, and report to leadership. Certain provisions have a limited exemption for institutions with fewer than 5,000 consumers.

Potential penalties & consequences

FTC enforcement can require security improvements and independent oversight. Monetary exposure depends on the legal authority and conduct; there is no single universal “Safeguards Rule fine” for every business.

Evidence to keep

Security program, risk assessment, vendor reviews, testing results, and leadership reports. Certain breaches involving at least 500 consumers require FTC notice within 30 days of discovery.

Payment industry standard

PCI DSS

Businesses that accept card paymentsPayment-brand or contractual penaltiesCoverage, requirements & sources

Who it may cover

Merchants and service providers that store, process, or transmit payment card data, or can affect its security. Small transaction volume does not automatically exempt a merchant.

What to put in place

  • Map how card data moves through your business and confirm your validation requirements with your acquiring bank or processor.
  • Minimize stored card data; secure payment systems, access, software, networks, and third-party services.
  • Complete the appropriate self-assessment or assessment, scans, and other testing required for your environment.

Potential penalties & consequences

PCI DSS is an industry standard, not a government fine schedule. Payment brands define noncompliance penalties; your acquiring bank or processor can explain your contractual exposure. PCI SSC does not publish one universal monthly fine for all merchants.

Evidence to keep

Applicable assessment and attestation, scan results, service-provider compliance evidence, and remediation records. Outsourcing payment processing can reduce scope but does not remove all responsibilities.

California law

CCPA / CPRA

California consumer privacy rightsUp to $2,663 or $7,988 per violationCoverage, requirements & sources

Who it may cover

Qualifying for-profit businesses doing business in California. Thresholds include over $26.625 million in prior-year gross revenue; annually buying, selling, or sharing data of at least 100,000 California residents or households; or deriving at least 50% of revenue from selling or sharing residents’ personal information. Exemptions need separate review.

What to put in place

  • Map personal data and publish accurate notices and a privacy policy.
  • Handle applicable access, deletion, correction, sale/share opt-out, and sensitive-information requests; honor applicable opt-out preference signals.
  • Apply data minimization, retention limits, reasonable security, and required vendor terms. Check newer audit, risk-assessment, and automated-decision rules for phased obligations.

Potential penalties & consequences

Effective January 1, 2025, administrative fines can reach $2,663 per violation, or $7,988 for intentional violations and specified violations involving consumers known to be under 16. These are maximums, not automatic charges. A limited private right of action also exists for certain security breaches.

Evidence to keep

Data inventory, notices, request logs, vendor agreements, retention rules, and evidence of security controls.

European Union law

EU GDPR

Personal data with an EU connectionHigher tier: €20 million or 4%Coverage, requirements & sources

Who it may cover

Organizations established in the EU, plus certain organizations outside it that offer goods or services to people in the EU or monitor their behavior there. Merely having a website accessible from Europe is not the whole test.

What to put in place

  • Identify lawful grounds, explain your processing, minimize data, and respect people’s rights.
  • Use appropriate security, processor contracts, retention rules, and lawful international-transfer arrangements.
  • Assess high-risk processing and evaluate breach notification promptly; supervisory-authority notice may be required within 72 hours of awareness.

Potential penalties & consequences

For specified serious infringements, the ceiling is €20 million or 4% of the preceding year’s worldwide annual turnover, whichever is higher. The lower tier is €10 million or 2%, also whichever is higher. Actual fines are case-specific; authorities can also restrict processing.

Evidence to keep

Processing records, lawful-basis decisions, contracts, risk assessments, and rights-request and incident logs. UK GDPR is a separate regime.

Illinois law

Illinois PIPA

Personal information and breach responseConsumer-protection enforcementCoverage, requirements & sources

Who it may cover

Data collectors handling covered personal information about Illinois residents. Similar duties may apply under other states’ laws based on where affected people live.

What to put in place

  • Maintain reasonable security measures for covered records and required security terms in data-sharing contracts.
  • Keep a response plan that identifies affected data, residents, service providers, and notification duties.
  • Provide required breach notices without unreasonable delay, subject to the law’s exceptions. Attorney General notice may also apply; healthcare entities have special provisions.

Potential penalties & consequences

A PIPA violation is an unlawful practice under Illinois consumer-protection law. Exposure depends on the facts and enforcement provisions, rather than one automatic dollar amount for every breach.

Evidence to keep

Security policies, vendor terms, incident timeline, notification analysis, and copies of required notices.

Illinois law

Illinois BIPA

Fingerprints, face geometry, and other biometrics$1,000 / $5,000 statutory damagesCoverage, requirements & sources

Who it may cover

Private entities collecting or using covered biometric identifiers or information, subject to statutory exclusions. Biometric time clocks and access systems deserve review before deployment.

What to put in place

  • Provide required written notice and obtain a written release before collecting covered biometrics.
  • Publish and follow a retention and destruction policy; limit disclosure and protect the data.
  • Review the vendor’s collection, storage, and sharing practices alongside your own.

Potential penalties & consequences

A prevailing claimant may recover $1,000 for a negligent violation or $5,000 for an intentional or reckless violation, or actual damages if greater, plus fees and other relief. These are civil damages, not automatic government fines. The 2024 amendment limits repeated same-person, same-method collection and specified repeated disclosures to a single recovery; do not multiply by every time-clock scan.

Evidence to keep

Notices, releases, retention and destruction records, security controls, and vendor agreements.

Contract requirement

CMMC / defense contracts

Protecting federal contract informationContract eligibility at riskCoverage, requirements & sources

Who it may cover

Defense contractors and subcontractors whose applicable contracts require a CMMC level for systems handling federal contract information (FCI) or controlled unclassified information (CUI). Contract terms and rollout phase matter.

What to put in place

  • Identify the required level and the systems, people, and service providers in scope.
  • Implement the applicable safeguarding requirements and assemble evidence of how controls operate.
  • Complete the required assessment and affirmation process, and maintain the required status.

Potential penalties & consequences

CMMC is not a simple per-record fine schedule. Required CMMC status can be a condition of contract award; missing it can prevent eligibility. Other contractual or legal consequences require a separate review.

Evidence to keep

System scope, security plans, control evidence, assessment results, and required affirmations. A general vulnerability scan is not a CMMC assessment.

Read the official sources

Defense Department: CMMC overview ↗
Independent assurance

SOC 2

Demonstrating controls to business customersCustomer and contract expectationsCoverage, requirements & sources

Who it may cover

Service organizations whose customers want independent assurance about relevant security, availability, processing integrity, confidentiality, or privacy controls.

What to put in place

  • Agree on the system and trust-services categories in scope with your independent CPA firm.
  • Document controls and retain evidence of operation, including access reviews, change management, and incident handling.
  • Choose the appropriate report: Type 1 addresses a point in time; Type 2 also evaluates operation over a period.

Potential penalties & consequences

SOC 2 itself does not impose government fines. It is an examination and report, not a law or a universal compliance certificate. Gaps may affect customer due diligence or contractual commitments.

Evidence to keep

Control descriptions, policies, review records, and evidence for the agreed examination scope and period.

Management-system standard

ISO/IEC 27001

An organized information security programCertification and contract impactCoverage, requirements & sources

Who it may cover

Organizations choosing an information security management system, or whose customers require certification within a defined scope.

What to put in place

  • Define scope, leadership responsibilities, information-security risks, and a risk-treatment plan.
  • Operate and document the management system, including suitable controls, internal audits, and management review.
  • If certification is needed, use an independent certification body and maintain the system over time.

Potential penalties & consequences

ISO/IEC 27001 itself does not levy statutory fines. Certification is optional unless required by a contract or other obligation. A certificate applies to its stated scope and does not establish compliance with every privacy law.

Evidence to keep

Risk assessments, treatment decisions, policies, audit findings, corrective actions, and management reviews.

Read the official sources

ISO: ISO/IEC 27001 overview ↗
Risk-management framework

NIST Cybersecurity Framework

A practical starting point for most businessesNo automatic framework fineCoverage, requirements & sources

Who it may cover

Organizations of any size looking to organize cybersecurity risk management. The framework may also be referenced in customer or regulatory expectations.

What to put in place

  • Use the six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
  • Compare your current practices with a target profile and prioritize the gaps that matter most.
  • Assign owners, track improvements, and revisit the plan as the business changes.

Potential penalties & consequences

The framework is guidance, not a stand-alone penalty law. Using it can help organize a security program, but does not by itself satisfy every legal, contractual, or industry requirement.

Evidence to keep

A current and target profile, prioritized action plan, assigned owners, and evidence of progress.

A USEFUL START FOR ANY BUSINESS

Build the basics.
Then check the details.

This starter list helps organize the work. It is not a certification checklist or proof that every applicable requirement is met.

FTC small-business security resources ↗

  1. Map your data and responsibilities.List sensitive information, systems, vendors, customer locations, and relevant contracts.
  2. Assign an accountable owner.Identify the requirements, document risks, and build a prioritized action plan.
  3. Put safeguards into daily use.Use strong access controls, MFA, updates, suitable encryption, and tested backups.
  4. Train people and review vendors.Explain safe handling, reporting, and approved tools. Document third-party responsibilities.
  5. Practice incident response.Know who will investigate, preserve evidence, restore systems, and evaluate notification duties.
  6. Keep evidence and revisit the plan.Record testing, fixes, access reviews, training, and business changes.

COMMON QUESTIONS

A few things worth clearing up.

Does a small business get a free pass?

Not automatically. Coverage depends on the particular law, data, activities, thresholds, and exemptions. PCI guidance includes small merchants; the FTC Safeguards Rule has only limited small-institution exemptions. Check the topic’s official sources.

Will one scan make us compliant?

No. A scan can identify certain technical weaknesses. Compliance can also require policies, contracts, privacy notices, training, operational controls, ongoing evidence, and formal assessment. Fixes and follow-up matter.

Do we need every standard listed here?

No. Start with your actual legal and contractual duties, then choose supporting frameworks or assurance work. An independent SOC 2 examination, ISO certification, and a CMMC assessment are different engagements.

Is this every compliance law?

No. This guide focuses on common data-security and privacy topics. Other state privacy laws, children’s privacy, education records, sector rules, employment obligations, and international laws can also apply. It does not cover all workplace, tax, environmental, or licensing requirements.

TURN AWARENESS INTO ACTION

Find the security gaps you can act on.

DiamondGuards can help identify technical weaknesses and provide findings for your improvement plan. Legal advice, formal certification, and regulator approval are separate from a security scan.