Law Data API
Query U.S. statutes and regulations through a modern, well-documented API. Federal, 50 states, D.C., and Puerto Rico — structured, current, and ready for production.
Law data, shaped for software
Every statute and regulation is parsed into a consistent JSON model with full hierarchy, citations, and metadata — so you can stop scraping PDFs and start building.
Walk the hierarchy
Every division — title, chapter, part, section — is addressable by a stable path and resolves to its parents and children. Walk the tree, follow cross-references, or jump straight to a citation.
Citations that resolve
Look up any Bluebook citation and get back the matching document as JSON and Markdown: the law's text, metadata, related documents. No regex, no per-jurisdiction parsing, no surprises when a state changes its numbering.
Always current
We harvest directly from authoritative state and federal sources, normalize the output, and publish updates as laws change. Effective dates, repeal status, and renumbering are first-class fields.
New York Codes, Rules and Regulations
§ 500.1: Definitions
For purposes of this Part only, the following definitions shall apply:
- a Affiliate means any person that controls, is controlled by or is under common control with another person. For purposes of this subdivision, control means the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a person, whether through the ownership of stock of such person or otherwise.
- b Authorized user means any employee, contractor, agent or other person that participates in the business operations of a covered entity and is authorized to access and use any information systems and data of the covered entity.
- c Chief information security officer or CISO means a qualified individual responsible for overseeing and implementing a covered entity’s cybersecurity program and enforcing its cybersecurity policy.
- d Class A company means a covered entity with at least $20,000,000 in gross annual revenue in each of the last two fiscal years from all business operations of the covered entity and the business operations in this State of the covered entity’s affiliates and:
- 1 over 2,000 employees averaged over the last two fiscal years, including employees of both the covered entity and all of its affiliates no matter where located; or
- 2 over $1,000,000,000 in gross annual revenue in each of the last two fiscal years from all business operations of the covered entity and all of its affiliates no matter where located.
- e Covered entity means any person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether the covered entity is also regulated by other government agencies.
- f Cybersecurity event means any act or attempt, successful or unsuccessful, to gain unauthorized access to, disrupt or misuse an information system or information stored on such information system.
- g Cybersecurity incident means a cybersecurity event that has occurred at the covered entity, its affiliates, or a third-party service provider that:
- 1 impacts the covered entity and requires the covered entity to notify any government body, self-regulatory agency or any other supervisory body;
- 2 has a reasonable likelihood of materially harming any material part of the normal operation(s) of the covered entity; or
- 3 results in the deployment of ransomware within a material part of the covered entity’s information systems.
- h Independent audit means an audit conducted by internal or external auditors free to make decisions not influenced by the covered entity being audited or by its owners, managers or employees.
- i Information system means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination or disposition of electronic information, as well as any specialized system such as industrial/process controls systems, telephone switching and private branch exchange systems, and environmental control systems.
- j Multi-factor authentication means authentication through verification of at least two of the following types of authentication factors:
- 1 knowledge factors, such as a password;
- 2 possession factors, such as a token; or
- 3 inherence factors, such as a biometric characteristic.
Ready to build with legal data?
Get started with the OpenLaws API today.