Skip to main content

What Are Compliance Presets?

Curated entity selections aligned with regulatory frameworks

A compliance preset is a pre-configured selection of PII entity types designed to detect data categories mandated by specific privacy regulations. Instead of picking from all 58 entity types by hand, presets let you scan using a single framework.

GDPR (EU)

GDPR Standard: 5 entity types, GDPR Full: 8

HIPAA (Healthcare)

8 entity types for health data

PCI-DSS (Payments)

3 entity types for card data

CCPA (California)

7 entity types for CA residents

The Instruments Behind the Presets

A preset is a shortcut into an entity list, not a legal position. Each one answers to a published instrument, and it helps to know which one you are invoking.

  • GDPR — Regulation (EU) 2016/679, which replaced the 1995 Data Protection Directive and has applied across the EU since 25 May 2018. Article 9(1) marks health, biometric and similar data as special categories. Article 83(5) sets the upper fine band at €20 million or 4% of worldwide annual turnover, whichever is higher; Article 83(4) sets the lower band at €10 million or 2%. Article 33(1) allows 72 hours to notify a personal data breach to the supervisory authority. Germany layers its own BDSG, recast in 2018, on top.

US and Californian instruments

  • HIPAA — the US Health Insurance Portability and Accountability Act of 1996. Its Safe Harbor de-identification method, at 45 CFR 164.514(b)(2), lists 18 identifiers that have to be removed. The Security Rule took effect in 2005; the Breach Notification Rule followed under the HITECH Act of 2009, and a breach affecting 500 or more individuals goes to the Department of Health and Human Services within 60 days.
  • PCI DSS — the Payment Card Industry Data Security Standard, version 4.0, published in 2022. Requirement 3 governs stored account data and asks that the primary account number be rendered unreadable wherever it is kept. The previous version, v3.2.1, was retired in March 2024.
  • CCPA — the California Consumer Privacy Act of 2018, effective 1 January 2020 and amended by the CPRA, whose provisions became operative on 1 January 2023.

Instruments that sit beside the GDPR

  • EU AI Act — Regulation (EU) 2024/1689, in force since 2024. Article 99(3) sets fines up to €35 million or 7% of worldwide annual turnover for prohibited practices; Article 99(4) sets €15 million or 3% for most other breaches, and Article 99(5) sets €7.5 million or 1% for supplying incorrect information to authorities.
  • NIS2 — Directive (EU) 2022/2555, which replaced the original NIS Directive of 2016 and had to be transposed by Member States by 17 October 2024. It adds security and incident-reporting duties for essential and important entities on top of the GDPR.
  • ePrivacy — Directive 2002/58/EC, the rulebook for cookies and electronic communications, which sits beside the GDPR rather than inside it.

Where processing happens

One more instrument shapes where a scan may run at all: the Court of Justice invalidated the EU-US Privacy Shield in 2020 in Case C-311/18, Schrems II, which is why the location of processing matters as much as the entity list.

The scan itself is bounded, whichever preset you pick: at most 1,000 pages per run, at most 50,000 characters per call to the detection API, and 20 new scans per hour from one IP address. Findings live in server memory and nowhere else, and the sweep removes a finished session 35 minutes after the scan ends — so export before you close the tab.

Major Compliance Frameworks

The four most important regulatory frameworks with comprehensive PII detection

🇪🇺 GDPR

EUROPEAN UNION

General Data Protection Regulation covering all EU/EEA residents and anyone processing personal data in the EU.

Entity Types 5 (Standard) / 8 (Full)
Applicable To 27 EU/EEA
Recommended For All EU users

Detects: PERSON, EMAIL_ADDRESS, PHONE_NUMBER, IP_ADDRESS and LOCATION. GDPR Full adds AGE, CREDIT_CARD and MEDICAL_RECORD_NUMBER.

🏥 HIPAA

HEALTHCARE (US)

Health Insurance Portability and Accountability Act for healthcare providers, insurers, and business associates in the USA.

Entity Types 8
Focus Areas Health data
Use With PCI-DSS (if billing)

Detects: PERSON, PHONE_NUMBER, EMAIL_ADDRESS, US_SSN, MEDICAL_RECORD_NUMBER, IP_ADDRESS, VIN and URL. The API offers no insurance or health-plan identifier types.

💳 PCI-DSS

PAYMENTS

Payment Card Industry Data Security Standard for organizations processing credit/debit cards.

Entity Types 3
Critical Entities CREDIT_CARD, SWIFT_CODE
Compliance Level Mandatory

Detects: CREDIT_CARD, SWIFT_CODE and PERSON. The API offers no CVV, expiry-date or magnetic-stripe types.

🇺🇸 CCPA

CALIFORNIA

California Consumer Privacy Act protecting privacy rights of California residents, with broader applicability to all similar state laws.

Entity Types 7
Covers 9+ US states
Scope Consumer data

Detects: PERSON, EMAIL_ADDRESS, PHONE_NUMBER, US_SSN, US_DRIVER_LICENSE, CREDIT_CARD and IP_ADDRESS.

National Identifier Coverage by Country

14 countries have dedicated national identifier types. These are entity types, not presets. The 7 regional presets are Germany (BDSG), United States, United Kingdom, European Union, Australia, Canada (PIPEDA) and India.

Each type below was verified against the live detection API. Content from any other country is still covered by the universal types - names, e-mail addresses, phone numbers, IBANs, credit cards, locations and organisations - across all 48 supported languages.

🇬🇧 United Kingdom (UK)

UK_NINO, UK_NHS, UK_PASSPORT, UK_DRIVER_LICENSE

National Insurance and NHS numbers, passports and driving licences

🇺🇸 United States (US)

US_SSN, US_ITIN, US_PASSPORT, US_DRIVER_LICENSE, US_BANK_NUMBER

Social security and taxpayer numbers, passports, licences, bank routing numbers

🇧🇬 Bulgaria (BG)

BG_EGN

Uniform civil number

🇨🇿 Czechia (CZ)

CZ_RODNE_CISLO

Birth number

🇸🇰 Slovakia (SK)

SK_RODNE_CISLO

Birth number

🇪🇪 Estonia (EE)

EE_ID_CARD

Identity card number

🇱🇻 Latvia (LV)

LV_ID_CARD, LV_PERSONAS_KODS

Identity card number and personal identity code

🇹🇷 Turkey (TR)

TR_KIMLIK_NO, TR_DRIVER_LICENSE

National identification and driving licence numbers

🇮🇱 Israel (IL)

IL_ID_NUMBER

National identity number

🇮🇳 India (IN)

IN_AADHAAR, IN_PAN, IN_PASSPORT

Aadhaar, permanent account number, passport

🇦🇺 Australia (AU)

AU_TFN, AU_ABN, AU_ACN, AU_MEDICARE, AU_PASSPORT, AU_DRIVER_LICENSE

Tax file, business, company and Medicare numbers, passport and driving licence

🇳🇿 New Zealand (NZ)

NZ_PASSPORT, NZ_IRD, NZ_NHI, NZ_DRIVER_LICENSE

Passport, Inland Revenue tax number, National Health Index number and driving licence

🇨🇦 Canada (CA)

CA_SIN, CA_PASSPORT, CA_DRIVER_LICENSE

Social insurance number, passport and driving licence

🇸🇬 Singapore (SG)

SG_UEN, SG_PASSPORT

Unique entity number and passport

These are the countries with dedicated national identifier types, each verified against the live detection API. Content from any other country is still covered by the universal types (names, e-mail addresses, phone numbers, IBANs, credit cards, locations, organisations) across all 48 supported languages. Dedicated types for German, French, Spanish, Italian, Dutch, Austrian, Swiss, Polish, Portuguese and Swedish national identifiers are not currently offered.

Preset Comparison Matrix

Complete overview of entity coverage across major frameworks

Entity Type GDPR HIPAA PCI-DSS CCPA
EMAIL_ADDRESS
PHONE_NUMBER
CREDIT_CARD
IBAN_CODE
US_SSN
National IDs (UK_NINO, IN_AADHAAR, TR_KIMLIK_NO, …)
Tax IDs (US_ITIN, IN_PAN, AU_TFN)
Passports (US_PASSPORT, UK_PASSPORT, CA_PASSPORT, IN_PASSPORT)
Driving licences (US_DRIVER_LICENSE, UK_DRIVER_LICENSE, TR_DRIVER_LICENSE)
MEDICAL_RECORD_NUMBER
LOCATION / ADDRESS

Note: Consult the anonym.legal API documentation for the complete entity list.

Which Preset for Your Industry?

Industry-specific guidance on selecting the right compliance framework

🏥 Healthcare & Pharmaceutical

Primary Presets: HIPAA Compliance + Healthcare, plus a regional preset for each country you treat patients in

Healthcare providers, insurers, and business associates must comply with HIPAA. If operating in EU, combine HIPAA with GDPR. Use anonym.legal's medical entity detection for diagnosis codes and prescription patterns.

Example: HIPAA Compliance + Healthcare + GDPR Full + Germany (BDSG)

🏦 Finance & Banking

Primary Presets: PCI-DSS + Financial Services, plus GDPR Full and CCPA (California) where those laws apply

Any organization handling payment cards must use PCI-DSS. Banks and fintech must also comply with GDPR (EU customers). Include CCPA if serving California or other US states with similar laws.

Example: PCI-DSS + Financial Services + GDPR Full + CCPA (California)

🛍️ E-Commerce & Retail

Primary Presets: E-Commerce + GDPR Standard (EU customers) + CCPA (California) (US customers), plus PCI-DSS if you process card payments

Retailers must balance EU (GDPR) and US (CCPA) compliance. If collecting payment information directly, PCI-DSS is mandatory. Many retailers use third-party payment processors (which handle PCI-DSS) but still need GDPR + CCPA for customer emails, phone numbers, etc.

Example: E-Commerce + GDPR Full + CCPA (California) + PCI-DSS

🏢 SaaS & Software

Primary Presets: Technology & IT + GDPR Full + CCPA (California), plus a regional preset per user market

SaaS platforms process user data across multiple regions. GDPR is essential for any EU users. Add CCPA for California users, and region-specific presets for each supported country. Consider HIPAA if any healthcare customers exist.

Example: Technology & IT + GDPR Full + United Kingdom + Germany (BDSG)

📰 Media & Publishing

Primary Presets: GDPR Standard + CCPA (California) + Contact Information

Publishers handling subscriber/reader data must comply with GDPR (EU readers) and CCPA (US readers). Be especially vigilant for data leakage in article metadata, author bios, and comment systems where PII can accidentally appear.

Example: GDPR Standard + CCPA (California) + Contact Information (author e-mail addresses and reader phone numbers)

🌍 Global/International

Primary Presets: GDPR Full as the baseline, plus every regional preset that matches your markets

Organizations operating globally must use GDPR as the baseline (most comprehensive), then add regional presets for each market. GDPR is often sufficient alone, but region-specific presets catch local ID formats and tax numbers you might otherwise miss.

Example: GDPR Full + European Union + United Kingdom + Germany (BDSG)

Customizing Presets

How to modify presets for your specific compliance needs

Step-by-Step Customization

  1. 1

    Select Your Base Preset

    Choose a primary framework (GDPR, HIPAA, PCI-DSS, CCPA) that best matches your main regulatory obligation. This ensures you cover mandatory entity types.

  2. 2

    Add Regional Context

    If operating in multiple regions, add the regional presets that exist - Germany (BDSG), United States, United Kingdom, European Union, Australia, Canada (PIPEDA) and India - to pick up the national identifier types those regions have.

  3. 3

    Include Complementary Frameworks

    Combine related presets: GDPR + HIPAA (healthcare in EU), PCI-DSS + GDPR (payments in EU), HIPAA + CCPA (healthcare in California).

  4. 4

    Exclude Non-Relevant Types (Optional)

    If a preset detects entities irrelevant to your business (e.g., IBAN detection for a US-only payment processor), you can manually exclude them via the scanner UI.

  5. 5

    Set Detection Threshold

    Adjust confidence thresholds: Strict (fewer false positives), Balanced (recommended), or Permissive (catch more potential matches). Export results for review.

  6. 6

    Test & Document

    Run a test scan on a sample page, review detected entities, adjust if needed. Document your custom preset selection for compliance audits.

💡 Tip: Multi-Preset Scanning

The scanner allows you to select multiple presets in a single scan. For example, you can check GDPR + PCI-DSS + CCPA simultaneously to verify compliance across all frameworks at once.

This is more efficient than running three separate scans and produces a consolidated report with all detected entities ranked by regulatory relevance.

API Provider Coverage

Presets supported by the anonym.legal detection API

24

Presets (starter tier)

  • ✓ All 4 major frameworks
  • ✓ 7 regional presets
  • ✓ 58 total entity types
  • ✓ ML + regex hybrid detection
  • ✓ Chrome extension support

All presets are available in piisafe.eu — the scanner loads the preset catalogue directly from the anonym.legal API.

Frequently Asked Questions

Common questions about compliance presets

What's the difference between presets and custom entity selection?

Presets are pre-configured, curated selections aligned with regulatory frameworks — they ensure you're checking for the right types of PII for your compliance obligations. Custom entity selection gives you granular control but requires expertise to know which entities are relevant to your regulation. For most users, presets are recommended.

Can I combine multiple presets in one scan?

Yes. You can select multiple presets simultaneously (e.g., GDPR + HIPAA + PCI-DSS). The scanner will check for all entity types across selected presets and generate a unified report showing which regulations each detected entity impacts.

Which preset is most comprehensive?

GDPR Full and HIPAA Compliance are the largest compliance presets, at 8 entity types each. However, the "most comprehensive" preset depends on your needs: use HIPAA for health data, PCI-DSS for payments, CCPA for consumer privacy. For maximum coverage, combine GDPR + HIPAA + PCI-DSS + CCPA.

Do I need to use every applicable preset?

Not necessarily. Start with your primary regulatory obligation (GDPR if EU-based, HIPAA if healthcare, PCI-DSS if payments). Add regional presets only if you operate in those regions or serve those customers. This focuses your scan on relevant data types and reduces false positives.

What if a preset detects false positives?

Adjust the detection threshold to "Strict" mode, which increases confidence requirements. Review false positives in your export (HTML, JSON, CSV) and note them for your compliance documentation. Some presets have optional entity types you can exclude if not relevant to your business.

Are presets legally binding for compliance?

Presets are designed to align with regulatory frameworks, but they're not a substitute for legal advice. A preset detects entities mandated by a regulation, but compliance is broader — it includes data handling, consent, retention, and security practices. Use presets as part of a comprehensive compliance program, not as the only requirement.

How often are presets updated?

Presets are updated when regulations change or new entity types are identified. piisafe.eu automatically uses the latest preset definitions from anonym.legal. You'll be notified if a preset's scope changes significantly.

Can I export my custom preset configuration?

Custom preset selections are saved in your browser's localStorage and can be re-used across scans. To share or document your configuration, export your scan results (which include selected presets) as JSON or CSV.

Infrastructure & Compliance Assurance

How piisafe.eu ensures compliance scanning integrity

🇩🇪 German Infrastructure

All scans are processed in Germany (Hetzner). Data never leaves EU infrastructure, ensuring GDPR Article 44 compliance (no third-country transfers).

🔒 ISO 27001-Certified Hosting

piisafe.eu runs in ISO 27001-certified data centres (Hetzner, Germany), whose information security management is independently audited.

💾 Zero Data Storage

Scan results are held in server memory only during your session and are never stored. This is no-storage architecture by design.

🎯 Deterministic Detection

Exact pattern recognisers for formatted identifiers, plus an NLP recogniser with fixed settings for names and places, give reproducible, consistent results—critical for compliance audits where you need provable, repeatable evidence.

📄 Audit-Ready Reports

Export results as HTML, JSON, or CSV with full preset and configuration details for documentation, regulators, and auditors.

🔄 Preset Versioning

Each scan records the preset version used, ensuring you can prove your compliance baseline was current at the time of scanning.

Start Your Compliance Scan Today

Select your regulatory preset, configure your scan, and get PII detection results in under 60 seconds. No registration, no credit card.

Open PII Scanner