Legal and Regulatory Frameworks for Information Systems
Boris Kantsepolsky () and
Lev Topor ()
Additional contact information
Boris Kantsepolsky: The Academic College of Tel Aviv-Yaffo, School of Information Systems
Lev Topor: Institute for the Study of Global Antisemitism and Policy (ISGAP)
Chapter 5 in Managing Information Singularity, 2026, pp 93-134 from Springer
Abstract:
Abstract This chapter maps the legal and regulatory architecture that governs contemporary information systems (IS), showing how domestic statutes and international instruments co-evolve with rapidly advancing technologies. It contrasts national regimes of privacy, cybersecurity, sectoral and hardware rules with cross-border cooperation and conflict, explaining how sovereignty claims, data localization, and transfer restrictions shape cloud, platform, and enterprise architectures. Core frameworks surveyed include GDPR and Convention 108/108+, U.S. sectoral privacy (HIPAA/GLBA/CCPA), Canada’s PIPEDA, and China’s CSL/PIPL, alongside Russia’s localization regime; each illustrates different balances among privacy, security, trade, and state authority. The chapter also analyzes cybersecurity mandates and critical-infrastructure obligations (e.g., EU NIS/NIS2; U.S. FISMA), and the role of treaties and soft law (Budapest Convention, OECD guidelines) in enabling evidence sharing and incident response across jurisdictions. It links compliance to practice through standards and risk management (ISO/IEC 27001/27701, NIST CSF, PCI-DSS, COBIT), showing how organizations operationalize obligations via governance-by-design. The chapter further surfaces ethical and social commitments of fairness, transparency, dignity, and examines platform regulation (DSA/DMA) and hardware rules, export controls, and supply-chain security. Finally, it argues that emerging AI and QIS, among other technologies, intensify jurisdictional mismatches, creating “regulatory gaps” that demand interoperable, verifiable controls, global legal interoperability, and anticipatory governance. The concluding section outlines future directions like provenance and auditability, privacy-preserving computation, post-quantum transitions, and adaptive oversight, to align technological innovation with societal values and democratic integrity.
Keywords: IS Regulation; Cybersecurity Laws; Data Governance; Risk Management; Privacy; International Law; Sectoral Regulations; Digital Sovereignty; Cross-Border Data Flows (search for similar items in EconPapers)
Date: 2026
References: Add references at CitEc
Citations:
There are no downloads for this item, see the EconPapers FAQ for hints about obtaining it.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:sprchp:978-3-032-26223-3_5
Ordering information: This item can be ordered from
http://www.springer.com/9783032262233
DOI: 10.1007/978-3-032-26223-3_5
Access Statistics for this chapter
More chapters in Springer Books from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().