{
  "schemaVersion": "1.0",
  "dataset": "ddos-regulations",
  "title": "Regulatory instruments with a DDoS dimension",
  "description": "Instruments bearing on availability, incident reporting or data location in a way that changes DDoS architecture. Rows exist only where the instrument could be reached and read.",
  "lastUpdated": "2026-08-15",
  "license": "Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.",
  "sources": [
    {
      "id": "eurlex-nis2",
      "title": "Directive (EU) 2022/2555 (NIS2)",
      "publisher": "EUR-Lex",
      "url": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj",
      "publishedDate": "2022-12-14",
      "accessedDate": "2026-08-15"
    },
    {
      "id": "eurlex-dora",
      "title": "Regulation (EU) 2022/2554 (DORA)",
      "publisher": "EUR-Lex",
      "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
      "publishedDate": "2022-12-14",
      "accessedDate": "2026-08-15"
    },
    {
      "id": "sdaia-pdpl",
      "title": "Personal Data Protection Law (English translation)",
      "publisher": "SDAIA",
      "url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf",
      "accessedDate": "2026-08-15"
    },
    {
      "id": "cst-saudi",
      "title": "Communications, Space & Technology Commission",
      "publisher": "CST",
      "url": "https://www.cst.gov.sa/en",
      "accessedDate": "2026-08-15"
    }
  ],
  "changelog": [
    {
      "date": "2026-08-15",
      "note": "Initial release: six instruments, four with verified primary links and two recorded without one."
    }
  ],
  "rowCount": 6,
  "data": [
    {
      "jurisdiction": "European Union",
      "instrument": "Directive (EU) 2022/2555 (NIS2)",
      "regulator": "National competent authorities per member state",
      "sector": "Essential and important entities across listed sectors",
      "ddosRelevance": "Availability risk on an all-hazards basis; supply-chain security applied to the mitigation supplier.",
      "incidentReporting": "Staged: early warning, fuller notification, final report",
      "bindingText": "Your member state’s transposing act, not the directive itself",
      "source": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj"
    },
    {
      "jurisdiction": "European Union",
      "instrument": "Regulation (EU) 2022/2554 (DORA)",
      "regulator": "European Supervisory Authorities and national financial regulators",
      "sector": "Financial entities and their ICT third-party providers",
      "ddosRelevance": "ICT risk management, resilience testing including an advanced regime, and third-party concentration.",
      "incidentReporting": "Major ICT-related incident reporting under the regulation",
      "bindingText": "The regulation applies directly; technical standards carry the detail",
      "source": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
    },
    {
      "jurisdiction": "Saudi Arabia",
      "instrument": "Personal Data Protection Law",
      "regulator": "SDAIA",
      "sector": "Any controller processing personal data",
      "ddosRelevance": "Where mitigation processes personal data — source addresses, headers, session data — cross-border processing becomes a compliance question rather than an implementation detail.",
      "incidentReporting": "not verified from a primary source for this dataset",
      "bindingText": "The Arabic text; the linked English version is published for reference",
      "source": "https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf"
    },
    {
      "jurisdiction": "Saudi Arabia",
      "instrument": "Telecommunications and IT licensing framework",
      "regulator": "Communications, Space & Technology Commission (CST)",
      "sector": "Licensed operators",
      "ddosRelevance": "Licence conditions bearing on service continuity and network security for licensed operators.",
      "incidentReporting": "not verified from a primary source for this dataset",
      "bindingText": "The licence instrument issued by the Commission",
      "source": "https://www.cst.gov.sa/en"
    },
    {
      "jurisdiction": "Türkiye",
      "instrument": "Personal Data Protection Law No. 6698 (KVKK)",
      "regulator": "Kişisel Verileri Koruma Kurumu",
      "sector": "Any data controller",
      "ddosRelevance": "Cross-border transfer rules bear on where mitigation may terminate sessions and hold telemetry.",
      "incidentReporting": "not verified from a primary source for this dataset",
      "bindingText": "The published Turkish text",
      "source": "not linked — the official portal could not be verified from this repository"
    },
    {
      "jurisdiction": "Türkiye",
      "instrument": "Law No. 5651 on internet publications",
      "regulator": "BTK",
      "sector": "Hosting and access providers",
      "ddosRelevance": "Log retention duties interact with what DDoS telemetry must be kept and for how long.",
      "incidentReporting": "not verified from a primary source for this dataset",
      "bindingText": "The published Turkish text",
      "source": "not linked — the official portal could not be verified from this repository"
    }
  ]
}