Get privacy insights in your inbox.

Data Methodology

How the IQWorks Data Observatory collects, verifies, and maintains the data that powers our enforcement fines explorer, breach landscape, regulatory heatmap, and ransomware tracker.

Our Principles

Primary Sources First

We prioritize data from official regulatory publications, DPA press releases, and government gazettes over secondary reporting.

Verifiable Claims

Statistics we publish are derived from data you can inspect in our interactive explorers. Enforcement and breach records carry source URLs; where a record is not yet source-linked, we say so in the dataset notes below.

Periodic Updates

Datasets are refreshed periodically using automated ingestion pipelines with manual review; each dataset shows its last-updated date.

Transparent Limitations

We document known gaps, estimation methods, and coverage boundaries for each dataset.

Enforcement Fines

Coverage

415 actions from 2018-11-26 to 2026-02-22

Sources (26)

AEPD, AP, APD, Baden-Württemberg DPA (LfDI BW), Bavarian DPA (BayLDA), Berlin DPA (BlnBDI), CAC, CNIL, and 18 more

Enforcement action data is collected from official Data Protection Authority (DPA) publications across Europe, India, the United States, and other jurisdictions. Each action is recorded with the organization name, issuing authority, regulation violated, fine amount in the original currency and EUR equivalent, violation types, industry classification, and a severity score.

Fine amounts in non-EUR currencies are converted using the exchange rate at the date of issuance. Where fine amounts are expressed as a range, we record the upper bound. Severity scores (1-10) are computed based on fine magnitude relative to the issuing authority's typical range, the nature of violations, and whether the action involved repeat offenses.

Data Breaches

Coverage

953 breaches from 2007-07-12 to 2026-03-13

Primary Source

Have I Been Pwned (HIBP)

Breach data is sourced primarily from Have I Been Pwned (HIBP), supplemented with manually curated disclosures. Classification fields (industry, attack vector, affected data types) are enriched with AI assistance and reviewed manually.

Records affected counts reflect the number of accounts or records compromised as reported by the breached organization or verified through HIBP; where an organization later revised its figure, we use the revised number. Financial impact figures are recorded only where publicly reported; most breaches do not carry one.

Global Regulations

Coverage

174 countries and territories

Sources

Automated research, IQWorks Enforcement Fines Explorer, Manual verification, ITU Global Cybersecurity Index 2024, OECD AI Policy Observatory

Regulatory data covers privacy law status, cybersecurity law status, and AI governance status for 174 countries. Each country profile includes the law name, enactment year, DPA name, robustness assessment, breach notification requirements, DPO obligation status, cross-border transfer restrictions, and EU adequacy decisions.

Robustness assessments (heavy, moderate, limited, inadequate) are based on the scope of the law, enforcement mechanisms, individual rights granted, and international benchmarking. AI governance data is sourced from the OECD AI Policy Observatory and manual verification of national AI strategies and regulations. Country profiles are compiled with AI assistance; priority jurisdictions (India, the Gulf states, the EU, the US, the UK, Brazil, Singapore) have been verified field by field against primary sources, and verification of the remaining countries is ongoing. Per-country fine totals and action counts reflect what our enforcement explorer tracks, not every action ever issued.

Cybersecurity maturity tiers are taken directly from the ITU Global Cybersecurity Index 2024 (5th edition), which places each of the 194 ITU member states in one of five tiers: Role-modelling (95–100), Advancing (85–95), Establishing (55–85), Evolving (20–55), and Building (0–20). We publish the tier rather than a numeric score because the published report gives per-country tier placement and the band for each tier, not a per-country overall score. Territories that are not ITU member states — including Taiwan, Hong Kong, Macau, the Faroe Islands, Guernsey, the Isle of Man, and Jersey — carry no GCI rating and are shown as unrated rather than assigned a tier.

Ransomware & Cyber Incidents

Coverage

59 major incidents + 1551 CISA KEV CVEs

Sources

CISA KEV, LLM-curated historical incidents

CISA Known Exploited Vulnerabilities (KEV) data is sourced directly from the CISA catalog and cross-referenced with ransomware campaign attribution. The historical incident list is AI-curated from public reporting and is being source-verified incident by incident; the largest incidents (by ransom and impact) have been verified against public disclosures and investigative reporting.

Ransom demand and payment figures come from public disclosures, SEC filings, and investigative reporting. Treat per-incident figures in the historical list as indicative until the per-incident source work completes; the CISA KEV data carries no such caveat.

Questions about our data?

If you notice an error or have questions about our methodology, we want to hear from you.

Contact us