Compliance
Last Updated: May 8, 2026
This page documents the regulatory regimes the SwiftQuantum ecosystem
tracks, monitors, and complies with. It is informational and does not
constitute legal advice. The regulation data shown here is sourced
from the SwiftQuantum Legal API (api.swiftquantum.tech/api/v1/legal),
which scrapes 18+ government legal sources every 12 hours and
snapshots the result into this page at build time.
For binding legal advice on your own compliance posture, consult qualified counsel in your jurisdiction.
At a glance
| Indicator | Value |
|---|---|
| Jurisdictions tracked | 8 (US, KR, JP, ZH-diaspora, EU, DE, FR, ES) |
| Regulations in corpus | 55 |
| Regulation categories | 7 (R&D, export control, defense, cybersecurity, data privacy, IP / patent, general) |
| Government sources monitored | 18+ |
| Scrape cadence | every 12 hours |
| Privacy frameworks honored | GDPR, UK GDPR, CCPA / CPRA, APPI (JP), PIPA (KR), PIPEDA + Quebec Law 25, BDSG (DE), LGPD (BR), Australian Privacy Act 1988 |
| Export classification | ECCN 5D002 (encryption software) and applicable quantum-specific ECCNs |
| PQC migration target | aligned with NSA CNSA 2.0 timelines (full PQC by 2030–2033 windows) |
Geographic Scope and Targeted Distribution
Chinese-language regulation tracking is intended for the global Chinese-speaking diaspora (Chinese Americans, Singaporeans, Taiwanese, Hong Kong residents, Malaysians, and similar). We do not distribute Services in mainland China or Russia, and we do not represent compliance with mainland-China or Russian legal regimes. The "ZH" entry below tracks regulation that is materially relevant to the diaspora (Singapore, Hong Kong) for that audience.
Regulation Categories
| Category | Description |
|---|---|
r_and_d |
Research and development funding, national initiatives, public-private partnerships |
export_control |
EAR, ITAR, EU dual-use, Korean Industrial Technology Protection, etc. |
defense |
Military / dual-use restrictions specific to quantum applications |
cybersecurity |
NIST PQC standards, NIS2 transposition, sectoral cyber rules |
data_privacy |
GDPR, CCPA, APPI, PIPA, BDSG, LGPD, AU Privacy Act |
ip_patent |
Patent acts and IP regimes affecting quantum inventions |
general |
Cross-cutting frameworks not fitting the above |
Per-Jurisdiction Coverage
The full regulation list per jurisdiction is rendered from
/data/regulations.json at build time. Each entry includes the
regulation title (and native-language title where applicable),
category, enacted and last-amended dates, summary, key provisions,
quantum relevance, enforcement body, penalties, and a link to the
authoritative source.
The eight tracked jurisdictions are:
🇺🇸 United States — 8 regulations
National Quantum Initiative Act (2018, reauth bill 2026), Export Administration Regulations (EAR) with quantum ECCNs 4A906 / 4D906 / 3A901 / 3A904 / 3E901 / 4E906, ITAR USML Category XIII, NIST FIPS 203 / 204 / 205 / 206 (Post-Quantum Cryptography), Executive Order 14179 (2025, replacing revoked EO 14110), CHIPS and Science Act (2022), Quantum Computing Cybersecurity Preparedness Act (2022).
🇰🇷 South Korea (대한민국) — 7 regulations
Quantum Technology R&D and Industry Promotion Act (양자과학기술 및 양자산업 육성에 관한 법률), National Quantum Science and Technology Committee (국가 양자과학기술 위원회), MSIT Quantum Technology Development Strategy, Personal Information Protection Act (PIPA) quantum-cryptography clauses (개인정보보호법 양자암호 관련 조항), Framework Act on Telecommunications quantum communication clauses, National Cybersecurity Act quantum-security clauses, Industrial Technology Protection Act designating quantum as National Core Technology (산업기술의 유출방지 및 보호에 관한 법률).
🇯🇵 Japan (日本) — 7 regulations
Quantum Technology and Innovation Strategy (量子技術イノベーション 戦略), national quantum acts and implementing programs. The 2026 APPI amendment bill was approved by the Cabinet on 7 April 2026 and is pending Diet enactment; until then, the prior APPI regime applies.
🇸🇬 / 🇭🇰 / 🇹🇼 Chinese-speaking Regions (ZH diaspora) — 7 regulations
Singapore, Hong Kong, and Taiwan quantum-relevant frameworks. Not applicable to mainland China.
🇪🇺 European Union — 5 regulations
EU AI Act, EU Quantum Act (proposed), EU Cyber Resilience Act (CRA), EU PQC Transition Roadmap, EuroHPC Quantum Pillar.
🇩🇪 Germany (Deutschland) — 7 regulations
BSI standards including ML-KEM-768 / 1024 inclusion, C5:2025 with PQC, quantum-secure ID cards, BDSG, plus the 20+ EU Member State PQC joint statement.
🇫🇷 France — 7 regulations
National Quantum Plan (Plan Quantique National), Military Programming Law quantum-defense provisions, CNIL guidelines for quantum data processing, Intellectual Property Code quantum patents, SREN Act, NIS2 transposition (Loi Résilience), Intelligence Act communications provisions.
🇪🇸 Spain (España) — 7 regulations
Quantum Technologies Strategy 2025–2030 (Estrategia Española de Tecnologías Cuánticas), Organic Law on Data Protection quantum implications, National AI Strategy quantum AI provisions, NIS2 transposition (Ley de Coordinación y Gobernanza de la Ciberseguridad), Patent Act, EU Cyber Resilience Act Spanish implementation, Spain Digital Plan 2026.
Privacy frameworks
We honor the following privacy frameworks, with details in our Privacy Policy:
- GDPR (EU) and UK GDPR — Article 45 adequacy decision in effect for Korea since 17 December 2021, reviewed every four years (first review at three years).
- CCPA / CPRA (California) — no sale or sharing of personal information; rights honored within 45 days; non-discrimination guaranteed.
- APPI (Japan) — current regime; the 7 April 2026 Cabinet-approved amendment bill is pending Diet enactment.
- PIPA (Korea) — current regime; the 12 February 2026 / 10 March 2026 amendment takes effect on 11 September 2026 (10% revenue cap for specific high-severity violations; CEO/representative accountability; ISMS-P mandatory from 1 July 2027).
- PIPEDA (Canada) and Quebec Law 25 — French-language rights available on request.
- BDSG (Germany) — GDPR-aligned national supplements.
- LGPD (Brazil) and Australian Privacy Act 1988 — DPO and OAIC mechanisms documented.
Export control posture
- U.S. EAR: We classify our software under ECCN 5D002 for encryption-related items and apply applicable License Exception provisions. Quantum-specific ECCNs (4A906, 4D906, 3A901, 3A904, 3E901, 4E906) introduced in 2024–2025 are tracked; we follow worldwide NS / RS license requirements with License Exception IEC for allied nations.
- Korean Industrial Technology Protection Act: quantum technology is designated National Core Technology; we maintain documented controls for technology transfer reviews.
- EU dual-use: we apply the EU Cyber Resilience Act and dual-use regulation as transposed by Member States we operate in.
Post-Quantum Cryptography migration
We track and progressively adopt the NIST PQC standards:
| Standard | Algorithm | Status |
|---|---|---|
| FIPS 203 | ML-KEM (key encapsulation) | Finalized 13 Aug 2024 |
| FIPS 204 | ML-DSA (digital signature, lattice) | Finalized 13 Aug 2024 |
| FIPS 205 | SLH-DSA (stateless hash-based signature) | Finalized 13 Aug 2024 |
| FIPS 206 | FN-DSA / FALCON | Draft, in development |
| HQC (5th algorithm) | code-based KEM, ML-KEM backup | Selected Mar 2025; draft expected early 2026 |
We are migrating active web-service traffic to ML-KEM hybrid TLS during 2026 to align with NSA CNSA 2.0 timelines (software / firmware PQC by 2025, web / cloud PQC by 2025, exclusive use by 2030–2033).
Per-Jurisdiction Disclaimer
Each jurisdiction's regulation data is accompanied by a native-language
disclaimer rendered from /data/disclaimers.json. Common across all
jurisdictions:
"This information is provided for educational and reference purposes only. It does not constitute legal advice. Consult qualified legal counsel for compliance guidance. SwiftQuantum is not a law firm."
Native-language translations of the same disclaimer are available in Korean, Japanese, Chinese, German, French, and Spanish in the locale versions of this page.
Reporting a regulatory issue
If you believe we are out of compliance with a specific regulation or have noticed a regulation we should track, please contact legal@swiftquantum.tech. We aim to respond to substantive compliance reports within 14 days.
Operating entity
MQuantum (엠퀀텀) — sole proprietor, Republic of Korea Business Registration No. 309-96-05114 Representative: Park Eun Min (박은민) — IEEE Member, Designated Privacy Officer 39, Goryeodae-ro 10-gil, #206, Seongbuk-gu, Seoul, Republic of Korea Phone: +82 10-5369-1420