Question Libraries
Legal questions derived from actual regulatory text. Open source and community maintained.
HIPAA — Health Insurance Portability and Accountability Act
HHS / OCR · United States · 10 questions
| ID | Legal Question | Citation | Status |
Propose a new question for HIPAA
SOC 2 — System and Organization Controls
AICPA · International · 10 questions
| ID | Legal Question | Citation | Status |
Propose a new question for SOC 2
PCI-DSS — Payment Card Industry Data Security Standard
PCI SSC · International · 10 questions
| ID | Legal Question | Citation | Status |
Propose a new question for PCI-DSS
GDPR — General Data Protection Regulation
EU DPAs · European Union · 10 questions
| ID | Legal Question | Citation | Status |
Propose a new question for GDPR
TCPA — Telephone Consumer Protection Act
FCC · United States · 8 questions
| ID | Legal Question | Citation | Status |
Propose a new question for TCPA
SOX — Sarbanes-Oxley Act
SEC / PCAOB · United States · 8 questions
| ID | Legal Question | Citation | Status |
Propose a new question for SOX
CCPA/CPRA — California Consumer Privacy Act
California Privacy Protection Agency · California, US · 10 questions
| ID | Legal Question | Citation | Status |
|---|
Propose a new question for CCPA
COPPA — Children's Online Privacy Protection Act
FTC · United States · 8 questions
| ID | Legal Question | Citation | Status |
|---|
Propose a new question for COPPA
FERPA — Family Educational Rights and Privacy Act
U.S. Department of Education · United States · 8 questions
| ID | Legal Question | Citation | Status |
|---|
Propose a new question for FERPA
GLBA — Gramm-Leach-Bliley Act
FTC / Federal Banking Regulators · United States · 8 questions
| ID | Legal Question | Citation | Status |
|---|
Propose a new question for GLBA
How questions get validated
- Submit via GitHub issue using the question proposal template
- Cite the exact regulation section (e.g., "45 CFR §164.312(a)(1)")
- A reviewer matches it against the source regulatory text
- If accurate and not duplicated, it gets merged into the YAML library
- The question enters Active status and is used in future scans
All questions include regulatory citations. Proposed questions are reviewed against source regulatory text before being merged.
View YAML source files on GitHub