Compliance Presets Reference Guide
Learn about all available compliance presets in piisafe.eu. Understand which framework to use for your industry, regulatory obligations, and data protection needs.
What Are Compliance Presets?
Curated entity selections aligned with regulatory frameworks
A compliance preset is a pre-configured selection of PII entity types designed to detect data categories mandated by specific privacy regulations. Instead of picking from all 58 entity types by hand, presets let you scan using a single framework.
GDPR Standard: 5 entity types, GDPR Full: 8
8 entity types for health data
3 entity types for card data
7 entity types for CA residents
The Instruments Behind the Presets
A preset is a shortcut into an entity list, not a legal position. Each one answers to a published instrument, and it helps to know which one you are invoking.
- GDPR — Regulation (EU) 2016/679, which replaced the 1995 Data Protection Directive and has applied across the EU since 25 May 2018. Article 9(1) marks health, biometric and similar data as special categories. Article 83(5) sets the upper fine band at €20 million or 4% of worldwide annual turnover, whichever is higher; Article 83(4) sets the lower band at €10 million or 2%. Article 33(1) allows 72 hours to notify a personal data breach to the supervisory authority. Germany layers its own BDSG, recast in 2018, on top.
US and Californian instruments
- HIPAA — the US Health Insurance Portability and Accountability Act of 1996. Its Safe Harbor de-identification method, at 45 CFR 164.514(b)(2), lists 18 identifiers that have to be removed. The Security Rule took effect in 2005; the Breach Notification Rule followed under the HITECH Act of 2009, and a breach affecting 500 or more individuals goes to the Department of Health and Human Services within 60 days.
- PCI DSS — the Payment Card Industry Data Security Standard, version 4.0, published in 2022. Requirement 3 governs stored account data and asks that the primary account number be rendered unreadable wherever it is kept. The previous version, v3.2.1, was retired in March 2024.
- CCPA — the California Consumer Privacy Act of 2018, effective 1 January 2020 and amended by the CPRA, whose provisions became operative on 1 January 2023.
Instruments that sit beside the GDPR
- EU AI Act — Regulation (EU) 2024/1689, in force since 2024. Article 99(3) sets fines up to €35 million or 7% of worldwide annual turnover for prohibited practices; Article 99(4) sets €15 million or 3% for most other breaches, and Article 99(5) sets €7.5 million or 1% for supplying incorrect information to authorities.
- NIS2 — Directive (EU) 2022/2555, which replaced the original NIS Directive of 2016 and had to be transposed by Member States by 17 October 2024. It adds security and incident-reporting duties for essential and important entities on top of the GDPR.
- ePrivacy — Directive 2002/58/EC, the rulebook for cookies and electronic communications, which sits beside the GDPR rather than inside it.
Where processing happens
One more instrument shapes where a scan may run at all: the Court of Justice invalidated the EU-US Privacy Shield in 2020 in Case C-311/18, Schrems II, which is why the location of processing matters as much as the entity list.
The scan itself is bounded, whichever preset you pick: at most 1,000 pages per run, at most 50,000 characters per call to the detection API, and 20 new scans per hour from one IP address. Findings live in server memory and nowhere else, and the sweep removes a finished session 35 minutes after the scan ends — so export before you close the tab.
Major Compliance Frameworks
The four most important regulatory frameworks with comprehensive PII detection
GDPR
EUROPEAN UNIONGeneral Data Protection Regulation covering all EU/EEA residents and anyone processing personal data in the EU.
Detects: PERSON, EMAIL_ADDRESS, PHONE_NUMBER, IP_ADDRESS and LOCATION. GDPR Full adds AGE, CREDIT_CARD and MEDICAL_RECORD_NUMBER.
HIPAA
HEALTHCARE (US)Health Insurance Portability and Accountability Act for healthcare providers, insurers, and business associates in the USA.
Detects: PERSON, PHONE_NUMBER, EMAIL_ADDRESS, US_SSN, MEDICAL_RECORD_NUMBER, IP_ADDRESS, VIN and URL. The API offers no insurance or health-plan identifier types.
PCI-DSS
PAYMENTSPayment Card Industry Data Security Standard for organizations processing credit/debit cards.
Detects: CREDIT_CARD, SWIFT_CODE and PERSON. The API offers no CVV, expiry-date or magnetic-stripe types.
CCPA
CALIFORNIACalifornia Consumer Privacy Act protecting privacy rights of California residents, with broader applicability to all similar state laws.
Detects: PERSON, EMAIL_ADDRESS, PHONE_NUMBER, US_SSN, US_DRIVER_LICENSE, CREDIT_CARD and IP_ADDRESS.
National Identifier Coverage by Country
14 countries have dedicated national identifier types. These are entity types, not presets. The 7 regional presets are Germany (BDSG), United States, United Kingdom, European Union, Australia, Canada (PIPEDA) and India.
Each type below was verified against the live detection API. Content from any other country is still covered by the universal types - names, e-mail addresses, phone numbers, IBANs, credit cards, locations and organisations - across all 48 supported languages.
🇬🇧 United Kingdom (UK)
UK_NINO, UK_NHS, UK_PASSPORT, UK_DRIVER_LICENSE
National Insurance and NHS numbers, passports and driving licences
🇺🇸 United States (US)
US_SSN, US_ITIN, US_PASSPORT, US_DRIVER_LICENSE, US_BANK_NUMBER
Social security and taxpayer numbers, passports, licences, bank routing numbers
🇧🇬 Bulgaria (BG)
BG_EGN
Uniform civil number
🇨🇿 Czechia (CZ)
CZ_RODNE_CISLO
Birth number
🇸🇰 Slovakia (SK)
SK_RODNE_CISLO
Birth number
🇪🇪 Estonia (EE)
EE_ID_CARD
Identity card number
🇱🇻 Latvia (LV)
LV_ID_CARD, LV_PERSONAS_KODS
Identity card number and personal identity code
🇹🇷 Turkey (TR)
TR_KIMLIK_NO, TR_DRIVER_LICENSE
National identification and driving licence numbers
🇮🇱 Israel (IL)
IL_ID_NUMBER
National identity number
🇮🇳 India (IN)
IN_AADHAAR, IN_PAN, IN_PASSPORT
Aadhaar, permanent account number, passport
🇦🇺 Australia (AU)
AU_TFN, AU_ABN, AU_ACN, AU_MEDICARE, AU_PASSPORT, AU_DRIVER_LICENSE
Tax file, business, company and Medicare numbers, passport and driving licence
🇳🇿 New Zealand (NZ)
NZ_PASSPORT, NZ_IRD, NZ_NHI, NZ_DRIVER_LICENSE
Passport, Inland Revenue tax number, National Health Index number and driving licence
🇨🇦 Canada (CA)
CA_SIN, CA_PASSPORT, CA_DRIVER_LICENSE
Social insurance number, passport and driving licence
🇸🇬 Singapore (SG)
SG_UEN, SG_PASSPORT
Unique entity number and passport
These are the countries with dedicated national identifier types, each verified against the live detection API. Content from any other country is still covered by the universal types (names, e-mail addresses, phone numbers, IBANs, credit cards, locations, organisations) across all 48 supported languages. Dedicated types for German, French, Spanish, Italian, Dutch, Austrian, Swiss, Polish, Portuguese and Swedish national identifiers are not currently offered.
Preset Comparison Matrix
Complete overview of entity coverage across major frameworks
| Entity Type | GDPR | HIPAA | PCI-DSS | CCPA |
|---|---|---|---|---|
| EMAIL_ADDRESS | ✓ | ✓ | – | ✓ |
| PHONE_NUMBER | ✓ | ✓ | – | ✓ |
| CREDIT_CARD | ✓ | – | ✓ | ✓ |
| IBAN_CODE | ✓ | – | – | – |
| US_SSN | – | – | – | ✓ |
| National IDs (UK_NINO, IN_AADHAAR, TR_KIMLIK_NO, …) | ✓ | – | – | ✓ |
| Tax IDs (US_ITIN, IN_PAN, AU_TFN) | ✓ | – | – | – |
| Passports (US_PASSPORT, UK_PASSPORT, CA_PASSPORT, IN_PASSPORT) | ✓ | – | – | ✓ |
| Driving licences (US_DRIVER_LICENSE, UK_DRIVER_LICENSE, TR_DRIVER_LICENSE) | ✓ | ✓ | – | ✓ |
| MEDICAL_RECORD_NUMBER | – | ✓ | – | – |
| LOCATION / ADDRESS | ✓ | ✓ | – | ✓ |
Note: Consult the anonym.legal API documentation for the complete entity list.
Which Preset for Your Industry?
Industry-specific guidance on selecting the right compliance framework
🏥 Healthcare & Pharmaceutical
Primary Presets: HIPAA Compliance + Healthcare, plus a regional preset for each country you treat patients in
Healthcare providers, insurers, and business associates must comply with HIPAA. If operating in EU, combine HIPAA with GDPR. Use anonym.legal's medical entity detection for diagnosis codes and prescription patterns.
Example: HIPAA Compliance + Healthcare + GDPR Full + Germany (BDSG)
🏦 Finance & Banking
Primary Presets: PCI-DSS + Financial Services, plus GDPR Full and CCPA (California) where those laws apply
Any organization handling payment cards must use PCI-DSS. Banks and fintech must also comply with GDPR (EU customers). Include CCPA if serving California or other US states with similar laws.
Example: PCI-DSS + Financial Services + GDPR Full + CCPA (California)
🛍️ E-Commerce & Retail
Primary Presets: E-Commerce + GDPR Standard (EU customers) + CCPA (California) (US customers), plus PCI-DSS if you process card payments
Retailers must balance EU (GDPR) and US (CCPA) compliance. If collecting payment information directly, PCI-DSS is mandatory. Many retailers use third-party payment processors (which handle PCI-DSS) but still need GDPR + CCPA for customer emails, phone numbers, etc.
Example: E-Commerce + GDPR Full + CCPA (California) + PCI-DSS
🏢 SaaS & Software
Primary Presets: Technology & IT + GDPR Full + CCPA (California), plus a regional preset per user market
SaaS platforms process user data across multiple regions. GDPR is essential for any EU users. Add CCPA for California users, and region-specific presets for each supported country. Consider HIPAA if any healthcare customers exist.
Example: Technology & IT + GDPR Full + United Kingdom + Germany (BDSG)
📰 Media & Publishing
Primary Presets: GDPR Standard + CCPA (California) + Contact Information
Publishers handling subscriber/reader data must comply with GDPR (EU readers) and CCPA (US readers). Be especially vigilant for data leakage in article metadata, author bios, and comment systems where PII can accidentally appear.
Example: GDPR Standard + CCPA (California) + Contact Information (author e-mail addresses and reader phone numbers)
🌍 Global/International
Primary Presets: GDPR Full as the baseline, plus every regional preset that matches your markets
Organizations operating globally must use GDPR as the baseline (most comprehensive), then add regional presets for each market. GDPR is often sufficient alone, but region-specific presets catch local ID formats and tax numbers you might otherwise miss.
Example: GDPR Full + European Union + United Kingdom + Germany (BDSG)
Customizing Presets
How to modify presets for your specific compliance needs
Step-by-Step Customization
-
1
Select Your Base Preset
Choose a primary framework (GDPR, HIPAA, PCI-DSS, CCPA) that best matches your main regulatory obligation. This ensures you cover mandatory entity types.
-
2
Add Regional Context
If operating in multiple regions, add the regional presets that exist - Germany (BDSG), United States, United Kingdom, European Union, Australia, Canada (PIPEDA) and India - to pick up the national identifier types those regions have.
-
3
Include Complementary Frameworks
Combine related presets: GDPR + HIPAA (healthcare in EU), PCI-DSS + GDPR (payments in EU), HIPAA + CCPA (healthcare in California).
-
4
Exclude Non-Relevant Types (Optional)
If a preset detects entities irrelevant to your business (e.g., IBAN detection for a US-only payment processor), you can manually exclude them via the scanner UI.
-
5
Set Detection Threshold
Adjust confidence thresholds: Strict (fewer false positives), Balanced (recommended), or Permissive (catch more potential matches). Export results for review.
-
6
Test & Document
Run a test scan on a sample page, review detected entities, adjust if needed. Document your custom preset selection for compliance audits.
💡 Tip: Multi-Preset Scanning
The scanner allows you to select multiple presets in a single scan. For example, you can check GDPR + PCI-DSS + CCPA simultaneously to verify compliance across all frameworks at once.
This is more efficient than running three separate scans and produces a consolidated report with all detected entities ranked by regulatory relevance.
API Provider Coverage
Presets supported by the anonym.legal detection API
anonym.legal
Presets (starter tier)
- ✓ All 4 major frameworks
- ✓ 7 regional presets
- ✓ 58 total entity types
- ✓ ML + regex hybrid detection
- ✓ Chrome extension support
All presets are available in piisafe.eu — the scanner loads the preset catalogue directly from the anonym.legal API.
Frequently Asked Questions
Common questions about compliance presets
What's the difference between presets and custom entity selection?
Presets are pre-configured, curated selections aligned with regulatory frameworks — they ensure you're checking for the right types of PII for your compliance obligations. Custom entity selection gives you granular control but requires expertise to know which entities are relevant to your regulation. For most users, presets are recommended.
Can I combine multiple presets in one scan?
Yes. You can select multiple presets simultaneously (e.g., GDPR + HIPAA + PCI-DSS). The scanner will check for all entity types across selected presets and generate a unified report showing which regulations each detected entity impacts.
Which preset is most comprehensive?
GDPR Full and HIPAA Compliance are the largest compliance presets, at 8 entity types each. However, the "most comprehensive" preset depends on your needs: use HIPAA for health data, PCI-DSS for payments, CCPA for consumer privacy. For maximum coverage, combine GDPR + HIPAA + PCI-DSS + CCPA.
Do I need to use every applicable preset?
Not necessarily. Start with your primary regulatory obligation (GDPR if EU-based, HIPAA if healthcare, PCI-DSS if payments). Add regional presets only if you operate in those regions or serve those customers. This focuses your scan on relevant data types and reduces false positives.
What if a preset detects false positives?
Adjust the detection threshold to "Strict" mode, which increases confidence requirements. Review false positives in your export (HTML, JSON, CSV) and note them for your compliance documentation. Some presets have optional entity types you can exclude if not relevant to your business.
Are presets legally binding for compliance?
Presets are designed to align with regulatory frameworks, but they're not a substitute for legal advice. A preset detects entities mandated by a regulation, but compliance is broader — it includes data handling, consent, retention, and security practices. Use presets as part of a comprehensive compliance program, not as the only requirement.
How often are presets updated?
Presets are updated when regulations change or new entity types are identified. piisafe.eu automatically uses the latest preset definitions from anonym.legal. You'll be notified if a preset's scope changes significantly.
Can I export my custom preset configuration?
Custom preset selections are saved in your browser's localStorage and can be re-used across scans. To share or document your configuration, export your scan results (which include selected presets) as JSON or CSV.
Infrastructure & Compliance Assurance
How piisafe.eu ensures compliance scanning integrity
🇩🇪 German Infrastructure
All scans are processed in Germany (Hetzner). Data never leaves EU infrastructure, ensuring GDPR Article 44 compliance (no third-country transfers).
🔒 ISO 27001-Certified Hosting
piisafe.eu runs in ISO 27001-certified data centres (Hetzner, Germany), whose information security management is independently audited.
💾 Zero Data Storage
Scan results are held in server memory only during your session and are never stored. This is no-storage architecture by design.
🎯 Deterministic Detection
Exact pattern recognisers for formatted identifiers, plus an NLP recogniser with fixed settings for names and places, give reproducible, consistent results—critical for compliance audits where you need provable, repeatable evidence.
📄 Audit-Ready Reports
Export results as HTML, JSON, or CSV with full preset and configuration details for documentation, regulators, and auditors.
🔄 Preset Versioning
Each scan records the preset version used, ensuring you can prove your compliance baseline was current at the time of scanning.
Start Your Compliance Scan Today
Select your regulatory preset, configure your scan, and get PII detection results in under 60 seconds. No registration, no credit card.
Open PII Scanner