In the case of, say, the GDPR, security requirements aren't prescriptive. You can read Article 32 yourself, but it comes down to being able to "ensure a level of security appropriate to the risk". Whether a company has met that standard is decided by data protection authorities and ultimately the courts.
Article 32, GPDR: https://gdpr-info.eu/art-32-gdpr/