Data Protection & Privacy — 304 Nodes
- 16 CFR Part 312 - Children's Online Privacy Protection Rule (Coppa Rule)
This rule imposes requirements on operators of websites or online services directed to children under 13, or those with actual knowledge of collecting personal information from a child, concerning the collection, use,… - Abu Dhabi Global Market (ADGM) Data Protection Regulations 2021
The ADGM Data Protection Regulations 2021 impose a comprehensive data protection framework on Controllers and Processors within the ADGM financial free zone, closely mirroring the EU GDPR. It mandates adherence to core… - Act on the Protection of Personal Information (Act No. 57 of 2003, as amended 2022)
The 2022 amended APPI mandates that businesses report specific data breaches to Japan's Personal Information Protection Commission (PPC) and notify affected individuals, generally within 72 hours for the preliminary… - Act on the Protection of Personal Information (APPI) as amended in 2022
The amended Japanese APPI imposes stricter obligations on businesses handling personal information of Japanese residents, including mandatory data breach reporting to the Personal Information Protection Commission (PPC)… - Åland Islands - EU GDPR and Finnish Data Protection Ombudsman Supervisory Framework
The Åland Islands (Ahvenanmaa in Finnish) is an autonomous, demilitarized, and monolingually Swedish-speaking province of Finland located in the Baltic Sea. As an autonomous province of an EU member state, Åland is… - Albania Law on Protection of Personal Data No. 9887 of 2008 - IDPC
Albania's Law on Protection of Personal Data No. 9887 - adopted by the Assembly of the Republic of Albania on 10 March 2008 and amended significantly through subsequent legislation (including the 2012 amendments on Law… - American Data Privacy and Protection Act (ADPPA)
The American Data Privacy and Protection Act (ADPPA) establishes a comprehensive national data privacy framework for the U.S., requiring covered entities to adhere to data minimization principles (Sec. 101), obtain… - Argentina Law 25.326 Personal Data Protection Act 2000 AAIP Data Subject Rights Cross-Border Transfer and Registration of Databases Framework
Argentina Law 25.326 Personal Data Protection Act (Ley de Protección de los Datos Personales) enacted on 4 October 2000 administered by the Agencia de Acceso a la Información Pública (AAIP) establishes the comprehensive… - Argentina Ley 25.326 de Proteccion de los Datos Personales (Personal Data Protection Act)
Ley 25.326 de Proteccion de los Datos Personales (Argentine Personal Data Protection Act) was sancionada on 4 October 2000 and partially promulgada on 30 October 2000 by Decreto 995/2000. The Act gives constitutional… - Argentina Personal Data Protection Act 25,326/2000 - AAIP (Agencia de Acceso a la Información Pública) Oversight, Sensitive Data, Public Registers, Automated Decisions, Cross-Border Transfer Only to Adequate Countries, Data Owner Rights and 2024 Draft Reform toward GDPR Standards
This regulation establishes comprehensive data protection obligations for entities processing personal data in Argentina, including requirements for lawful processing, data subject rights, sensitive data handling, and… - Australia Privacy Act 1988 - Australian Privacy Principles (APPs) and Notifiable Data Breaches (NDB) Scheme
The Privacy Act 1988 (Cth) binds Australian Government agencies and APP entities (organisations with annual turnover >$3M plus specified smaller organisations) to 13 Australian Privacy Principles governing collection,… - Australia Privacy Act 1988 (2024 Reform - Privacy and Other Legislation Amendment Act)
The Australia Privacy Act 1988, as amended, regulates the handling of personal information through the 13 Australian Privacy Principles (APPs) in Schedule 1. It applies to most Australian Government agencies and private… - Australia Privacy Act 1988 and the Privacy Act Review Report 2022 Proposals
The Australian Government's 2022 Privacy Act Review proposes significant reforms, including a GDPR-style right to erasure (Proposal 18.2), an unqualified right to object to direct marketing (Proposal 19.3), mandatory… - Australia Trusted Digital Identity Framework TDIF Accreditation Rules Identity Proofing Authentication Federation and Fraud Control for Identity Service Providers
The Australian Government Trusted Digital Identity Framework (TDIF) administered by the Department of Finance through the Digital Transformation Agency establishes a voluntary federated accreditation scheme for digital… - Belgium Data Protection Act 2018 (Loi du 30 juillet 2018) - GDPR National Implementation
Belgium's Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data (Loi du 30 juillet 2018 relative à la protection des personnes physiques à l'égard des traitements de… - Biobanking & Genomic Data Governance under GDPR & Global Standards (2026)
Biobanks and genomic data repositories must comply with GDPR Article 9 (special category data), Article 89 (research exemptions), strict purpose limitation, data minimisation, pseudonymisation/anonymisation techniques,… - Bosnia and Herzegovina Law on Protection of Personal Data No. 49/06 - AZLP
Bosnia and Herzegovina's Law on Protection of Personal Data (Zakon o zaštiti ličnih podataka / Zakon o zaštiti osobnih podataka), adopted by the Parliamentary Assembly of Bosnia and Herzegovina in 2006 (Official Gazette… - Brazil ANPD Resolution CD/ANPD No. 15 - Security Incident Notification under the LGPD
Controllers of personal data subject to the Lei Geral de Protecao de Dados (LGPD) in Brazil must apply Resolution CD/ANPD No. 15 to the communication of security incidents involving personal data, including notification… - Brazil ANVISA & LGPD - Processing of Health Data and Medical Device Regulation (2026)
ANVISA regulates medical devices and SaMD under RDC 751/2022 while LGPD (Law 13.709/2018) imposes strict rules for processing sensitive health data. Requirements include explicit consent or legal basis, data… - Brazil General Personal Data Protection Law 2018 (Lei Geral de Proteção de Dados Pessoais - LGPD, Law No. 13,709 of 14 August 2018)
The LGPD (Lei Geral de Proteção de Dados Pessoais - General Personal Data Protection Law, Law No. 13,709 of 14 August 2018, as amended by Law No. 13,853 of 8 July 2019 and Law No. 14,010 of 10 June 2020) is Brazil's… - Brazil gov.br Platform Digital Identity under LGPD and Digital Government Initiatives
Brazil's national digital identity platform is gov.br, operated by the Ministry of Management and Innovation in Public Services (MGI) with technical operations by the Federal Data Processing Service (Serpro). The gov.br… - Brazil Lei 15.352/2026: ANPD Becomes the Agencia Nacional de Protecao de Dados (Regulatory Agency)
Lei No. 15.352 of 25 February 2026 (conversion of Medida Provisoria 1.317/2025) amends the LGPD (Lei 13.709/2018) to establish the Agencia Nacional de Protecao de Dados (ANPD). New Article 55-A of the LGPD creates the… - Brazil LGPD (Lei Geral de Protecao de Dados) - Data Protection Principles and Subject Rights
Brazil's Lei Geral de Protecao de Dados Pessoais (LGPD, Law 13,709/2018) establishes 10 lawful bases for processing personal data, grants data subjects rights of access, correction, deletion and portability, requires… - Brazil LGPD Compliance
Lei Geral de Proteção de Dados (LGPD) is Brazil's comprehensive data protection law (Law No. 13,709/2018), modeled after GDPR but with distinct governance requirements for the ANPD (National Data Protection Authority)… - Brazil LGPD Direct Marketing Requirements - ANPD Guidance: Consent as Lawful Basis for Marketing, Legitimate Interest for B2B, Data Subject Rights in Marketing Context, Children's Marketing Prohibition, Opt-Out Mechanisms and ANPD Enforcement Actions
The LGPD, as interpreted by the ANPD, requires express consent for direct marketing to individuals, prohibits marketing directed at children and adolescents in digital environments under the ECA Digital framework, and… - British Virgin Islands Data Protection Act 2021
The British Virgin Islands enacted the Data Protection Act, 2021 (No. 3 of 2021), a comprehensive statute aligned with UK and EU data protection standards. Administered by the BVI Information Commissioner, the Act… - Bulgaria Personal Data Protection Act (ZZLD) - GDPR National Implementation
Bulgaria's Закон за защита на личните данни (ZZLD - Personal Data Protection Act), as substantially amended by Darzhaven Vestnik (Official Gazette) Act SG 17/2019 of 26 February 2019 to align with the EU General Data… - California AB 1008 (2024) - CCPA Amendment: AI Systems and Abstract Digital Formats of Personal Information
California Assembly Bill 1008 (Bauer-Kahan), Chapter 802 of the 2024 Statutes, amends California Civil Code Section 1798.140 - the definitions section of the California Consumer Privacy Act (CCPA) as amended by the… - California AB 1949 (2024) - CCPA Amendments for Consumers Under 18 (Children's Data Privacy)
California AB 1949 (chaptered September 2024) amends the California Consumer Privacy Act to strengthen protections for personal information of consumers under 18. The Act amends Civil Code Section 1798.100 to prohibit a… - California Age-Appropriate Design Code Act (CAADCA) - Data Protection Impact Assessments for Services Likely to be Accessed by Children
The California Age-Appropriate Design Code Act (CAADCA) requires businesses providing online services likely to be accessed by children to complete, review, and document a Data Protection Impact Assessment (DPIA) before… - California Civil Code § 1798.100. General Duties of Businesses that Collect Personal Information
This article requires businesses to inform consumers at or before the point of collection about the categories of personal information collected, the purposes for its use, and retention periods, and mandates specific… - California SB 976 (2024) - Protecting Our Kids from Social Media Addiction Act
California SB 976 (chaptered September 20 2024) adds Chapter 24 (Sections 27000-27007) to Division 20 of the California Health and Safety Code creating the Protecting Our Kids from Social Media Addiction Act. The Act… - California Telehealth Requirements & CCPA Health Data Amendments 2026
California requires in-state licensure for physicians providing telehealth to CA patients. CCPA 2026 amendments strengthen protections for sensitive health data, including stricter consent for sharing, automated… - Canada Anti-Spam Legislation CASL 2014 - Commercial Electronic Message Consent, Unsubscribe Requirements and CRTC Enforcement
Canada's Anti-Spam Legislation (CASL, S.C. 2010 c. 23, in force 1 July 2014) is one of the world's strictest anti-spam regimes, applying to Commercial Electronic Messages (CEMs) sent to or from Canada via email, SMS,… - Canada Criminal Code Part VI (Invasion of Privacy): Definitions of Private Communication and Intercept, Interception Offence, Bodily Harm and Exceptional Circumstances Exceptions, Judicial Authorisation, and Disclosure Restrictions
Part VI of the Canadian Criminal Code, R.S.C. 1985, c. C-46, titled Invasion of Privacy, is the principal federal framework governing the interception of private communications in Canada, including wiretapping and… - Canada PIPEDA (Personal Information Protection and Electronic Documents Act) - SC 2000, c. 5 Private Sector Data Protection Obligations
PIPEDA (SC 2000, c. 5) governs collection, use, and disclosure of personal information in the course of commercial activities across Canada (except in provinces with substantially similar legislation - Alberta, British… - Canada Privacy Act - Collection, Use, Disclosure and Access for Government Institutions
Canada's Privacy Act (R.S.C. 1985, c. P-21) governs personal information held by federal government institutions. Section 4 bars collection unless the information relates directly to an operating program or activity;… - Caribbean Netherlands (Bonaire, Sint Eustatius, Saba) - Personal Data Protection Act BES (Wbp BES) Framework
The Caribbean Netherlands - comprising the islands of Bonaire, Sint Eustatius, and Saba (collectively known as the BES Islands) - are special municipalities of the Netherlands located in the Caribbean Sea. Since 10… - CCPA/CPRA - California Consumer Privacy Rights
The California Consumer Privacy Act (CCPA, effective January 1, 2020) as substantially amended by the California Privacy Rights Act (CPRA, enforceable from March 29, 2024 following litigation delays; original date July… - CCPA/CPRA (Opt-out Sale)
California Civil Code § 1798.120 establishes a consumer's fundamental right to direct a business to stop selling or sharing their personal information. Fulfilling this obligation, as detailed in California Civil Code §… - CCPA/CPRA Enforcement
The California Consumer Privacy Act (CCPA), as significantly enhanced by the California Privacy Rights Act (CPRA), provides comprehensive privacy rights to California residents. It introduces the CPPA (California… - CCPA/CPRA Privacy Enterprise Compliance Standard v22
The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) establish comprehensive privacy rights for California residents. Key requirements include the right to know what personal… - CCPA/CPRA Privacy Enterprise Compliance Standard v7
The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) establish comprehensive privacy rights for California residents. Key requirements include the right to know what personal data is… - Children’s Online Privacy Protection Rule (COPPA Rule) - 2023 Notice of Proposed Rulemaking
The FTC's proposed update to the COPPA Rule (16 C.F.R. Part 312) expands protections by requiring separate, verifiable parental consent for disclosing personal information to third parties for advertising, including for… - Chile Law 21.719 on the Protection of Personal Data 2024 - GDPR-Aligned Reform with Personal Data Protection Agency, Full Effectiveness 1 December 2026
Data controllers and processors operating in Chile or directing services at Chile must apply Law 21.719 on the Protection of Personal Data (approved by Congress on 26 August 2024, published on 13 December 2024, full… - Chile Ley 21.719/2024 - New Data Protection Framework and GDPR Alignment
Chile's Ley 21.719 (enacted December 2024, effective December 2026) replaces the 1999 PDPA with a GDPR-aligned framework: 8 lawful bases including legitimate interests, data subject rights of… - China Network Data Security Management Regulations 2024 - State Council Decree Effective 1 January 2025
Network data processors operating in China, including domestic and foreign-based entities that process data related to individuals or organizations in China when offering products or services, analysing or evaluating… - China Personal Information Protection Law 2021
China's Personal Information Protection Law establishes a comprehensive personal data protection framework modelled partly on GDPR, requiring consent for processing, separate explicit consent for sensitive personal… - Civil Code § 1798.110: Consumers’ Right to Know What Personal Information is Being Collected. Right to Access Personal Information
This article requires businesses to disclose to consumers, upon a verifiable request, the categories and specific pieces of personal information collected about them, the sources of that information, the business… - Civil Code § 1798.121. Consumers’ Right to Limit Use and Disclosure of Sensitive Personal Information
Organizations must provide consumers with the right to limit the use and disclosure of their sensitive personal information to purposes necessary for providing requested goods or services and must cease other uses upon… - Colombia Ley 1581/2012 - Habeas Data and Personal Data Protection (ARCO Rights)
Colombia's Ley Estatutaria 1581/2012 establishes fundamental ARCO data rights (Access, Rectification, Suppression, Opposition), requires prior authorisation (consent) before personal data collection, mandates SIC… - Colombia SIC Directive 002 of 2024 - Processing of Personal Data in the Use of Artificial Intelligence, Issued 21 August 2024
Data controllers, data processors, and users that develop or use AI based on information containing personal data in Colombia must comply with Directive 002 of 2024 issued by the Superintendence of Industry and Commerce… - Colorado Privacy Act (CPA) of 2021
The Colorado Privacy Act (CPA) grants Colorado residents rights over their personal data, including access, correction, deletion, and opt-out of targeted advertising, sale of personal data, or profiling. It imposes… - Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679
Establishes binding contractual obligations for data transfers from EU controllers to processors and sub-processors outside the EEA, including cloud providers. Applies to all organizations processing EU personal data… - Connecticut Data Privacy Act (CTDPA) - Public Act No. 22-15
The Connecticut Data Privacy Act (CTDPA) grants Connecticut residents rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of the processing of personal data for targeted… - Cook Islands Privacy Act 2014
The Cook Islands enacted the Privacy Act 2014, a privacy and personal information protection statute aligned with New Zealand privacy law standards given the Cook Islands' free association status with New Zealand. The… - COPPA (Marketing to Kids)
This operator's online service is explicitly designated as a child-directed service, thereby triggering stringent obligations under the Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501-6506. While a neutral… - Croatia GDPR Implementation Act 2018 (NN 42/2018) - National Data Protection Implementation
Croatia's Zakon o provedbi Opće uredbe o zaštiti podataka (GDPR Implementation Act - Act on the Implementation of the General Data Protection Regulation), published in the Croatian Official Gazette (Narodne novine No.… - Data Protection Act 2018 Section 14: Automated individual decision-making, including profiling
Organizations must not make decisions based solely on automated processing that have legal or similarly significant effects on individuals, unless specific conditions are met, and must provide safeguards including the… - Data Protection Act 2018 Section 172: Re-identification of de-identified personal data
This section establishes a criminal offence for knowingly or recklessly re-identifying personal data that has been de-identified, without the consent of the controller who performed the de-identification. - Data Protection Act 2018, PART 3 - Law Enforcement Processing
Establishes a data protection framework for competent authorities processing personal data for law enforcement purposes, including principles for processing, data subject rights, and controller obligations. - Data Protection Act, 2012 (Act 843) - General Data Protection Principles
Organizations must comply with Ghana's eight data protection principles, including accountability, lawfulness, purpose specification, data quality, security safeguards, and data subject participation, and must register… - Data Protection Law DIFC Law No. 5 of 2020
This law requires data Controllers and Processors operating within the Dubai International Financial Centre (DIFC) to implement and demonstrate a comprehensive data protection program under the accountability principle… - Data Protection Regulations 2021
These regulations apply to Data Controllers and Processors within the Qatar Financial Centre (QFC), mandating registration with the QFCRA (Article 10) and adherence to core data processing principles (Article 6). They… - Delaware Personal Data Privacy Act (House Bill 154)
The Delaware Personal Data Privacy Act (DPDPA) establishes rights for consumers to access, correct, delete, and opt-out of the sale of their personal data, and imposes duties on data controllers who conduct business in… - Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India, requiring lawful consent, protection of children's data through parental consent, and establishment of the Data… - Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime
This Directive regulates the transfer by air carriers of passenger name record (PNR) data of extra-EU flights and its processing by Member States for the prevention, detection, investigation and prosecution of terrorist… - Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)
The EU ePrivacy Directive 2002/58/EC requires prior opt-in consent for electronic direct marketing via email, SMS, or automated calls, with a limited 'soft opt-in' exception for existing customers under Article 13(1).… - Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)
This directive, often called the 'Cookie Law,' requires providers of electronic communications services to obtain prior, informed consent from users before storing or accessing information on their terminal equipment… - EDPB Guidelines on GDPR in Educational Institutions - Lawful Basis, Parental Consent, Learning Management Systems and Data Minimisation
Educational institutions must establish a valid lawful basis under GDPR Article 6 for processing student data, which is typically 'public task' rather than consent. For children under the age specified by Member State… - Egypt Personal Data Protection Law 151 of 2020 Executive Regulations - Ministerial Decree 816 of 2025, Full Enforcement October 2026
Data controllers and processors operating in Egypt must apply the Executive Regulations of the Personal Data Protection Law 151 of 2020, issued by the Minister of Communications and Information Technology as Ministerial… - Egypt Personal Data Protection Law No. 151 of 2020 and its Executive Regulations
Egypt's Law No. 151 of 2020 establishes a comprehensive framework for personal data protection, requiring data controllers and processors to adhere to specific processing principles, obtain explicit consent for… - ePrivacy (Cookie Directive)
Compliance with the ePrivacy Directive mandates a strict consent-first framework for accessing or storing information on user terminal equipment, directly reflecting Article 5(3) of Directive 2002/58/EC. This node… - EU Data Act Regulation 2023/2854 - IoT Data Access, Business-to-Business Fairness, and Cloud Switching Rights, Applicable 12 September 2025
Manufacturers of connected products and providers of related digital services placed on the EU market, plus IaaS, PaaS, and SaaS providers, must comply with the EU Data Act (Regulation (EU) 2023/2854) which entered into… - EU GDPR - Research and Education Exemptions (Articles 85-91)
GDPR Articles 85-91 establish member-state derogation authority for journalistic, academic, artistic, and research processing; scientific and historical research processing is permitted under Article 89 subject to… - EU GDPR (Regulation 2016/679) Article 8 - Children's Consent and Parental Authorization for Online Services
GDPR Article 8 requires parental or guardian consent for processing personal data of children under 16 (or lower member state threshold) using information society services - applicable to apps, games, social media, and… - EU GDPR Article 30 - Records of Processing Activities: Mandatory Documentation Requirements for Controllers and Processors
Under Article 30 of the GDPR, data controllers and processors must maintain a detailed, written record of their data processing activities (RoPA). This obligation applies to all organizations, with a limited exemption… - EU GDPR Article 46 - International Data Transfer Mechanisms: SCCs, BCRs, Codes of Conduct and Certification
In the absence of an adequacy decision under Article 45, GDPR Article 46 permits the transfer of personal data to a third country or international organization only if the controller or processor provides appropriate… - EU GDPR Article 89 - Research, Scientific, and Statistical Processing Exemptions
GDPR Article 89 permits Member States to provide derogations from certain data subject rights (access, rectification, restriction, objection) for scientific research, statistical purposes, and public interest archiving,… - EU General Data Protection Regulation (GDPR) 2016/679 Article 22 - Automated Individual Decision-Making Including Profiling: Right Not to Be Subject to Solely Automated Decisions
Organizations deploying automated decision systems that produce legal or similarly significant effects on individuals must either invoke a valid Article 22(2) exception (contract necessity, legal authorization, or… - EU General Data Protection Regulation (GDPR) Article 6 and Recital 47 - Lawful Basis for Processing Personal Data for Direct Marketing
Under GDPR Article 6(1), processing personal data for marketing is only lawful if a valid basis is established, typically either explicit consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)). Recital 47… - EU-US Data Privacy Framework 2023 - Adequacy Decision and Executive Order 14086
The EU-US Data Privacy Framework (DPF) is the third successor to Safe Harbor (invalidated by Schrems I in 2015) and Privacy Shield (invalidated by Schrems II in 2020), comprising Executive Order 14086 (Enhancing… - Family Educational Rights and Privacy Act (FERPA) - Education Records, Parental Rights, Directory Information and Disclosure Conditions
The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law that protects the privacy of student education records and applies to all schools that receive funds under an applicable program of the U.S.… - Federal Law on Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares - LFPDPPP)
The LFPDPPP establishes the legal framework for the protection of personal data processed by private parties in Mexico. It mandates the implementation of privacy notices (Aviso de Privacidad), requires explicit consent… - Financial Transaction Reports Act 1988 - Part II Transaction reports and Part III Accounts
This Act requires cash dealers, solicitors, and other entities to report significant cash transactions, international currency transfers, and suspect transactions to AUSTRAC, and to maintain identification and… - French Guiana - EU General Data Protection Regulation (GDPR) and CNIL Supervisory Framework
French Guiana is a French overseas department and an EU outermost region located on the northeastern coast of South America, forming an integral part of the French Republic and the European Union. As an EU outermost… - GDPR (Hospitality Specifics)
Significant compliance deficiencies exist regarding the lawful basis for processing personal data within a hospitality context. Current configuration confirms `guest_consent_marketing_obtained` is false, violating GDPR… - GDPR Art 21 (Opt-out)
GDPR Article 21 grants data subjects an absolute right to object to the processing of their personal data for direct marketing purposes. When a `data_subject_objected` flag is triggered within a context where… - GDPR Article 22 - Automated Decision-Making in Customer Experience: Individual Rights, Profiling Restrictions, Meaningful Human Review, Safeguards for Sensitive Categories and Controller Transparency Obligations
Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them. This right applies under Article… - GDPR Article 22 - Automated Individual Decision-Making in Workflows: Prohibition, Exceptions, Safeguards, Right to Human Review and Controller Obligations
Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. This prohibition under Article 22 GDPR applies… - GDPR Article 89 - Safeguards and Derogations Relating to Processing for Archiving Purposes in the Public Interest, Scientific or Historical Research Purposes or Statistical Purposes
This regulation requires that personal data processed for archiving in the public interest, scientific or historical research, or statistical purposes must be subject to appropriate safeguards ensuring data minimisation… - GDPR Binding Corporate Rules (BCR) Framework - Articles 46-47 and EDPB Guidelines on BCRs
Binding Corporate Rules (BCRs) are legally binding internal rules and policies for data protection within a corporate group, allowing for the transfer of personal data internationally to members in countries without an… - GDPR Data Processing Agreement (DPA) Checklist
A compliant Data Processing Agreement establishes a legally binding contract defining the processor's obligations, consistent with European Data Protection Board Guidelines 07/2020. The processor must act exclusively… - GDPR Data Processing Enterprise Compliance Standard v17
The General Data Protection Regulation (GDPR) mandates strict guidelines for the processing of personal data within the European Union. Organizations must ensure lawful processing, obtain explicit consent from data… - GDPR Data Processing Enterprise Compliance Standard v2
The General Data Protection Regulation (GDPR) mandates strict guidelines for the processing of personal data within the European Union (EU) and the European Economic Area (EEA). Organizations must ensure lawful… - GDPR DPO Requirements
The EU GDPR (General Data Protection Regulation) requires certain organizations to designate a Data Protection Officer (DPO) (Article 37). The DPO acts as an independent compliance champion, advising the organization on… - GDPR Health Data (EU)
The EU GDPR 2016/679 (General Data Protection Regulation) classifies health data as a 'special category' of personal data. Article 9 generally prohibits the processing of such data unless a specific legal exemption is… - GDPR: Health Data (Art. 9)
GDPR Article 9 establishes a general prohibition on processing special categories of personal data, with 'data concerning health' (including mental health, genetic data, and biometric data used for identification)… - General Data Protection Regulation (EU) 2016/679 - Article 4 Definitions for Online Gaming Data Protection
GDPR Art. 4 defines personal data, processing, profiling and related concepts; any online gaming controller or processor handling player data in the EU must treat such data as personal data and comply with the… - General Data Protection Regulation (GDPR) - Article 10: Processing of personal data relating to criminal convictions and offences
Organizations must only process personal data on criminal convictions and offences if it is under the control of an official authority or authorized by Union or Member State law with appropriate safeguards. - General Data Protection Regulation (GDPR) - Article 13: Information to be provided where personal data are collected from the data subject
Controllers must provide data subjects with specific information about the processing of their personal data at the time of collection. - General Data Protection Regulation (GDPR) - Article 45: Transfers on the basis of an adequacy decision
Under GDPR Article 45, personal data may be transferred from the EU/EEA to a third country or international organization without specific authorization if the European Commission has formally decided that the recipient… - General Data Protection Regulation (GDPR) - Article 48: Transfers or disclosures not authorised by Union law
A judgment from a third-country court or a decision from a third-country administrative authority requiring data transfer is only recognizable or enforceable if it is based on an international agreement, such as a… - General Data Protection Regulation (GDPR) - Article 9: Processing of special categories of personal data
Organizations are prohibited from processing personal data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique… - General Data Protection Regulation (GDPR) - Safeguards and Derogations Relating to Processing for Archiving Purposes in the Public Interest, Scientific or Historical Research Purposes or Statistical Purposes
This regulation requires educational institutions processing personal data for scientific research, historical research, or statistical purposes to implement appropriate safeguards, including data minimisation and… - General Data Protection Regulation (GDPR) Article 11: Processing which does not require identification
Organizations are not required to obtain or maintain identifying information on data subjects solely to comply with the GDPR if their processing purposes do not otherwise require such identification. - General Data Protection Regulation (GDPR) Article 6 - Lawfulness of processing
Processing of personal data is only lawful if and to the extent that at least one of six specific legal bases applies under the General Data Protection Regulation (GDPR), such as consent, performance of a contract,… - Ghana Data Protection Act 2012 (Act 843) - Data Controller Registration with Data Protection Commission, Sensitive Data Categories, Data Subject Rights, Transborder Data Flow Restrictions, Commissioner Enforcement Powers and Criminal Liability Provisions
All data controllers and processors in Ghana must register with the Data Protection Commission (DPC) and comply with data protection principles under the Data Protection Act, 2012 (Act 843), including lawfulness,… - Ghana Data Protection Act Health Sector Guidelines 2026
Data Protection Commission guidelines require explicit consent, security certifications, and DPIAs for electronic health records and telemedicine platforms operating in Ghana. - Global Anti-Spam Legislation Comparison Framework - CASL (Canada), CAN-SPAM (US), PECR (UK), GDPR Article 6 Email (EU), SPAM Act (Australia) and India IT Rules: Consent Standards, Opt-Out Windows, Penalties and B2B Exemption Variations
This framework compares core email marketing compliance obligations across major jurisdictions, focusing on consent requirements (e.g., GDPR Article 6, CASL Section 6), opt-out enforcement (CAN-SPAM 15 U.S.C. §… - Guadeloupe - GDPR and French Data Protection Law (Loi Informatique et Libertés)
Guadeloupe, as an outermost region of France and the European Union under the TFEU outermost regions framework, is fully subject to the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et… - HIPAA Privacy Rule
The HIPAA Privacy Rule establishes national standards governing the use and disclosure of protected health information (PHI) by covered entities and their business associates. General rules articulated within 45 CFR §… - Hong Kong PCPD Model Personal Data Protection Framework for AI 2024 and Generative AI Employee Use Checklist 2025
Hong Kong organisations that procure, implement or use AI systems including predictive AI and generative AI, processing personal data in their operation or customisation of an AI system, must apply the PCPD Model… - IAB CCPA Compliance Framework - US Privacy Technical Specification: Global Privacy Control (GPC) Signal Honouring, Opt-Out of Sale/Sharing, Privacy Signal Pass-Through in RTB Auctions, CCPA/CPRA String and Publisher Liability Protections
This regulation establishes a standardized contractual and technical framework for honoring consumer privacy rights under U.S. state privacy laws, particularly regarding opt-out of sale/sharing of personal information… - IAB Europe Transparency and Consent Framework v2.2 - GDPR Consent for Digital Advertising: CMP Requirements, Vendor List, TC String Encoding, Legitimate Interest Assertions, Special Feature Opt-Ins and Belgian DPA Audit Requirements
This regulation establishes technical and policy requirements for obtaining, recording, and transmitting user consent and legitimate interest signals in digital advertising under the GDPR, specifically mandating… - India Aadhaar Act 2016 and Digital Personal Data Protection Act 2023 as the UIDAI Digital Identity Framework
India's national digital identity framework is anchored in two statutes administered by the Ministry of Electronics and Information Technology (MeitY) through the Unique Identification Authority of India (UIDAI). The… - India Digital Personal Data Protection Act 2023 - Data Principal Rights and Fiduciary Obligations
India's Digital Personal Data Protection Act 2023 (DPDP Act) establishes a rights-based framework for digital personal data: lawful consent and deemed consent bases, data principal rights of access, correction, erasure,… - India Digital Personal Data Protection Act 2023 (DPDP Act, Act No. 22 of 2023)
The Digital Personal Data Protection Act 2023 (DPDP Act, Act No. 22 of 2023) is India's first comprehensive data protection legislation, receiving Presidential assent on 11 August 2023 and administered by the Data… - India Digital Personal Data Protection Rules 2025 - MeitY Gazette G.S.R. 846(E) of 13 November 2025
Data Fiduciaries in India must implement the Digital Personal Data Protection Rules, 2025, notified by MeitY via Gazette Notification G.S.R. 846(E) on 13 November 2025, in a phased manner over 18 months culminating on… - India DPDP Act 2023
The Digital Personal Data Protection (DPDP) Act of 2023 is India's principal statute for digital personal data, prioritizing individual rights and organizational obligations. It introduces the role of Consent Managers… - India DPDP Rules 2025 - Consent Manager Registration, Significant Data Fiduciary (SDF) Criteria (Data Volume/Sensitivity/National Security Risk), Data Localisation for Critical Data, Children's Processing Age Verification and DPBI Appeal Procedures
The India DPDP Rules 2025 establish obligations for data fiduciaries processing personal data, including mandatory registration of Consent Managers, enhanced compliance for Significant Data Fiduciaries based on data… - Iowa Consumer Data Protection Act (SF 262)
The Iowa Consumer Data Protection Act (ICDPA) grants Iowa residents rights to access, delete, and obtain a copy of their personal data, and to opt out of the sale of their data or its use for targeted advertising. The… - Ireland Data Protection Act 2018 - GDPR National Implementation and Lead EU DPA for Big Tech
Ireland's Data Protection Act 2018 (Acts of the Oireachtas 2018, No. 7), signed into law on 24 May 2018, is Ireland's primary national legislation supplementing the EU General Data Protection Regulation (GDPR -… - Israel Privacy Protection Law Amendment 13 of 2024 - GDPR-Aligned Reforms in Force 14 August 2025
Organisations subject to the Israeli Privacy Protection Law must, from 14 August 2025, comply with the sweeping reforms in Amendment 13, including appointment of a qualified Privacy Protection Officer where thresholds… - Japan Act on Protection of Personal Information (APPI) - Act No. 57 of 2003 as Amended 2020/2021 - PPC Obligations and Cross-Border Transfer Rules
Japan's APPI (Act No. 57 of 2003, with major 2015 and 2020 amendments effective April 2022) requires personal information handling businesses to specify and limit use of personal information to notified purposes, obtain… - Japan APPI Amended Order and Rules 2024 - Two-Stage Breach Reporting to PPC and Triennial Review Interim Report of 27 June 2024
Business operators subject to Japan's Act on the Protection of Personal Information (APPI) must, under the amended Order and Rules, report data breaches and notify affected individuals where the breach involves… - Jordan Personal Data Protection Law 2023
Personal Data Protection Law No. (24) of 2023 establishes a comprehensive framework for the protection of personal data in Jordan, requiring data controllers to obtain informed consent, implement appropriate security… - Kenya ODPC Sector-Specific Guidance Notes 2024-2025 - Communication, Education, Public Sector, Private Security, and Biometric Data
Data controllers and processors operating in Kenya should apply the sector-specific Guidance Notes issued by the Office of the Data Protection Commissioner (ODPC) during 2024 and 2025 under the Data Protection Act 2019,… - Kuwait Data Privacy Protection Regulation No. 42 of 2021 - CITRA (Communications and Information Technology Regulatory Authority) Oversight, Processing Conditions, Sensitive Data, Cross-Border Transfer Rules, Security Measures, 72-Hour Breach Notification and Fines up to KWD 50,000
The CITRA Data Privacy Protection Regulation No. 42 of 2021 establishes data protection obligations for entities processing personal data in Kuwait, including requirements for lawful processing, data subject rights,… - Law No. 18,331 of 2008 on Personal Data Protection
Uruguay's Law 18,331/2008 establishes a comprehensive framework for the protection of personal data, requiring data controllers to ensure lawfulness, fairness, transparency, purpose limitation, data minimization,… - Lei Geral de Proteção de Dados Pessoais (LGPD) - Article 18: Rights of the Data Subject
This article establishes the fundamental right of data subjects to obtain information from the data controller about their personal data being processed, at any time and upon request. - Lei Geral de Proteção de Dados Pessoais (LGPD) - Article 41: Data Protection Officer
Organizations acting as data controllers must appoint a Data Protection Officer (encarregado) and publicly disclose their contact information, with this officer being responsible for handling communications from data… - Lei Geral de Proteção de Dados Pessoais (LGPD) - Article 48
The controller must notify the national authority and the data subject of any security incident that could result in significant risk or harm to the data subjects. - Lei Geral de Proteção de Dados Pessoais (LGPD) - Article 7: Lawful Bases for Processing Personal Data
Organizations must ensure that any processing of personal data is conducted only under one of the lawful bases specified in the regulation, such as obtaining consent from the data subject. - Lei Geral de Proteção de Dados Pessoais (LGPD) - Lei nº 13.709, de 14 de Agosto de 2018
This law governs the processing of personal data in Brazil, applying to any natural or legal person conducting data processing operations within Brazilian territory or targeting individuals located in Brazil, as defined… - Lei Nº 13.709, de 14 de Agosto de 2018 (General Personal Data Protection Law - LGPD) - Chapter I: Preliminary Provisions
This regulation establishes the territorial and material scope of Brazil's data protection law, defining which data processing activities are covered and outlining specific exemptions for purposes such as journalism,… - Lei Nº 13.709, de 14 de Agosto de 2018 (Lei Geral de Proteção de Dados Pessoais - LGPD) - Chapter III Rights of the Data Subject
Chapter III of Brazil's data protection law guarantees data subjects nine enumerated rights against controllers, including confirmation of processing, access, correction, anonymization, blocking or deletion,… - Lei Nº 13.709, de 14 de Agosto de 2018 (Lei Geral de Proteção de Dados Pessoais - LGPD), Capítulo VIII, Da Fiscalização, Seção I, Das Sanções Administrativas (Artigos 52-54)
Chapter VIII, Section I of Brazil's LGPD establishes the administrative sanctions regime enforced by the national data protection authority (ANPD): Article 52 lists the sanctions (warning with corrective deadline,… - Lei Nº 13.709, de 14 de Agosto de 2018 (Lei Geral de Proteção de Dados Pessoais - LGPD), Chapter VII (Articles 46-51)
Chapter VII of Brazil's General Data Protection Law (LGPD), titled Security and Good Practices (Articles 46 to 51), obliges processing agents to adopt technical and administrative security measures from product… - Lei Nº 13.709/2018 (Lei Geral de Proteção de Dados Pessoais - LGPD) - Article 5: Definitions
This article establishes the official legal definitions for key terms used throughout the LGPD, such as personal data, sensitive data, controller, processor, and consent, which organizations must use to classify data… - Ley Chile - Biblioteca del Congreso Nacional Ley Chile - Biblioteca del Congreso Nacional Ley Chile Este proceso demora demasiado, es probable que su conexión esté muy lenta o que su navegador no sea compatible con nuestra aplicación
Chile's 2024 personal data protection reform (Ley que regula la proteccion y el tratamiento de los datos personales y crea la Agencia de Proteccion de Datos Personales) updates Law 19.628 with lawful bases for… - Ley de Protección de los Datos Personales N° 25.326
Argentina's Personal Data Protection Law establishes the principles for processing personal data in public and private databases, requiring data controllers to obtain prior, express, and informed consent from the data… - Macao Personal Data Protection Act 2005 (Law No. 8/2005)
The Macao Special Administrative Region (SAR) of the People's Republic of China enacted the Personal Data Protection Act, Law No. 8/2005 of 22 August 2005. The Act is administered by the Office for Personal Data… - Maine An Act To Protect the Privacy of Online Consumer Information 2019
Maine LD 946 signed June 6, 2019 effective July 1, 2020 requires broadband internet service providers to obtain explicit opt-in consent before using, selling, or disclosing a customer's personal information, prohibits… - Malaysia Personal Data Protection (Amendment) Act 2024 - Three-Phase Rollout, Mandatory DPO, Breach Notification, and Removal of Whitelist System
Data controllers and data processors operating in Malaysia must comply with the Personal Data Protection (Amendment) Act 2024, rolled out in three phases: from 1 January 2025 expanded sensitive personal data definition… - Malaysia Personal Data Protection Act 2010 (Act 709) - PDPA
The Personal Data Protection Act 2010 (PDPA, Act 709) is Malaysia's primary legislation governing the processing of personal data in commercial transactions. The PDPA was enacted on 2 June 2010 and came into force on 15… - Maldives Data Protection: Data Protection Act 2017 (in force) and the draft Privacy and Personal Data Protection Bill (pending)
The Maldives has not enacted a comprehensive 'Personal Data Protection Act 2021'. The only enacted instrument is the limited Data Protection Act 2017 (in force since 15 January 2018), which sets out basic principles for… - Martinique - GDPR and French Data Protection Law (Loi Informatique et Libertés)
Martinique, as an outermost region of France and the European Union under the TFEU outermost regions framework, is fully subject to the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et… - Maryland Online Data Privacy Act 2024 (MODPA)
Maryland MODPA signed May 9, 2024 effective October 1, 2025 prohibits controllers from collecting sensitive personal data beyond what is strictly necessary to provide the requested service, extends children's privacy… - Maryland Online Data Privacy Act of 2024
The Maryland Online Data Privacy Act of 2024 requires controllers to limit personal data collection to what is adequate, relevant, and reasonably necessary for disclosed purposes (data minimization and purpose… - Mayotte - GDPR and French Data Protection Law (Loi Informatique et Libertés)
Mayotte, as a French overseas department and outermost region of the European Union since its departmentalisation in 2011 and EU outermost region status confirmed in 2014, is fully subject to the EU General Data… - Measures for the Standard Contract for the Outbound Transfer of Personal Information & CAC Security Assessment Triggers
Under China's Personal Information Protection Law (PIPL), organizations transferring personal information outside mainland China must use one of three mechanisms: a mandatory Cyberspace Administration of China (CAC)… - Mental Health Data Privacy & Special Category Protections (Global 2026)
Mental health data is treated as highly sensitive special category data across major jurisdictions. Strict rules apply to collection, processing, sharing, and secondary use, with heightened consent standards, enhanced… - Mexico Federal Law for the Protection of Personal Data Held by Private Parties 2025 - SABG as Regulator after INAI Suppression, Effective 21 May 2025
Private sector data controllers processing personal data in Mexico must comply with the new Federal Law for the Protection of Personal Data Held by Private Parties enacted 20 March 2025 and entered into effect 21 May… - Mexico LFPDPPP 2010 - Personal Data Protection in the Private Sector (ARCO Rights)
Mexico's Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (LFPDPPP, 2010) establishes ARCO rights (Access, Rectification, Cancellation, Opposition), requires a Privacy Notice before data… - Minnesota Consumer Data Privacy Act (MCDPA)
The Minnesota Consumer Data Privacy Act (MCDPA) grants Minnesota residents rights over their personal data, including access, correction, deletion, and opt-out of sale, profiling, or targeted advertising. Effective July… - Montana Consumer Data Privacy Act
The Montana Consumer Data Privacy Act (MCDPA) establishes rights for Montana residents to control their personal data and imposes obligations on data controllers and processors. It applies to entities conducting… - Montenegro Law on Personal Data Protection No. 79/2017 - AZLP ME
Montenegro's Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti), adopted by the Parliament of Montenegro in 2017 as Official Gazette of Montenegro No. 79/2017 and significantly amended in 2021… - Nebraska Data Privacy Act (LB 1294)
The Nebraska Data Privacy Act (NDPA) grants Nebraska residents rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of the sale of personal data, targeted advertising, and certain… - Nepal Individual Privacy Act 2018 - Ministry of Home Affairs
Nepal's Individual Privacy Act 2018 (Byaktigat Gupta Raakhne Sambandhi Ain, 2075 B.S.), enacted by the Federal Parliament of Nepal and authenticated by the President of Nepal, is Nepal's primary legislation protecting… - Netherlands GDPR Implementation Act 2018 (Uitvoeringswet Algemene verordening gegevensbescherming - UAVG)
The UAVG (Uitvoeringswet Algemene verordening gegevensbescherming - Implementation Act for the General Data Protection Regulation) is the Netherlands' national statute implementing and supplementing the EU General Data… - Nevada SB 220 (2019) and SB 260 (2021) - Sale of Covered Information Opt-Out Requirements for Operators of Websites
This law requires operators of websites or online services who collect 'covered information' from Nevada consumers to provide a designated request address for consumers to opt-out of the 'sale' of their information, as… - New Hampshire Privacy Act (SB 255-FN)
The New Hampshire Privacy Act establishes rights for consumers to access, correct, delete, and obtain a copy of their personal data, and to opt out of the processing of their data for targeted advertising, sale, or… - New Hampshire Privacy Act 2024 (SB 255)
New Hampshire SB 255 signed March 6, 2024 effective January 1, 2025 grants consumers rights to access, correct, delete, and port their personal data, requires opt-in consent for sensitive data processing, and provides a… - New Jersey Data Privacy Act (P.L.2023, c.266)
The New Jersey Data Privacy Act (NJDPA) applies to controllers conducting business in NJ or targeting NJ residents who control or process personal data of at least 100,000 consumers, or 25,000 consumers if they derive… - New York Health Information Privacy & SHIELD Act (2026)
New York’s SHIELD Act and health-specific privacy rules require reasonable security safeguards for private information (including health data), mandatory breach notification to the NY Attorney General and affected… - New York SAFE for Kids Act (S.7694-A 2023-24) - Stop Addictive Feeds Exploitation
The New York Stop Addictive Feeds Exploitation (SAFE) for Kids Act, S.7694-A in the 2023-24 legislative session, adds Article 45 (Sections 1500-1508) to the New York General Business Law. The Act defines an addictive… - New Zealand Privacy Act 2020
The New Zealand Privacy Act 2020 regulates how public and private sector agencies handle personal information through 13 Information Privacy Principles (IPPs) outlined in Section 22. It mandates the notification of… - New Zealand Privacy Amendment Act 2025 - Information Privacy Principle 3A on Indirect Collection Notification, In Force 1 May 2026
Agencies that collect personal information about an individual from a source other than the individual themselves in New Zealand must, from 1 May 2026, comply with the new Information Privacy Principle 3A (IPP 3A)… - Nigeria Data Protection Act 2023 - Data Processing Principles and Controller Obligations
Nigeria's Data Protection Act 2023 (NDPA) establishes a comprehensive GDPR-inspired framework: 7 lawful bases for processing, data subject rights including access, rectification, deletion, portability and objection,… - Nigeria Data Protection Regulation 2019
The Nigeria Data Protection Regulation (NDPR) governs the processing of personal data of Nigerian citizens and residents, requiring Data Controllers to process data lawfully, securely, and transparently. As per Article… - North Macedonia Law on Personal Data Protection 2020 - DZLP
North Macedonia's Law on Personal Data Protection (Закон за заштита на личните податоци - ZZLP) - adopted by the Assembly of the Republic of North Macedonia in early 2020 and published in the Official Gazette of the… - Oman Personal Data Protection Law 2022 - Ministry of Transport, Communications and Information Technology (MTCIT) Oversight, Data Controller and Processor Obligations, Sensitive Data Categories, Data Subject Rights, Cross-Border Transfer Conditions, 72-Hour Breach Notification and Fines up to OMR 500,000
This regulation establishes comprehensive obligations for data controllers and processors in Oman regarding the lawful processing of personal data, including requirements for consent, data subject rights, sensitive data… - Oregon Consumer Privacy Act (SB 619) - Data Protection Assessments, Profiling Restrictions and Non-Discrimination Obligation
The Oregon Consumer Privacy Act (OCPA) requires controllers to conduct and document a Data Protection Assessment (DPA) for any processing that presents a heightened risk of harm to a consumer, including profiling, as… - Personal Data Protection Act (Republic of China, Taiwan) as amended on December 30, 2015
The Taiwan Personal Data Protection Act (PDPA) governs the collection, processing, and use of personal data by government and non-government agencies, requiring a specific purpose and consent for most activities… - Personal Data Protection Act 2010 (Act 709)
The Malaysia Personal Data Protection Act 2010 (PDPA) governs the processing of personal data in commercial transactions, requiring organizations ('data users') to comply with seven core Data Protection Principles. The… - Personal Data Protection Act 2012 - Part 3 General Rules with Respect to Protection of and Accountability for Personal Data
Organizations must implement policies and practices to comply with the Act's requirements for collecting, using, disclosing, protecting, and retaining personal data, including obtaining consent and notifying individuals… - Personal Data Protection Act 2012 - Part 6A Notification of Data Breaches
Organizations must assess data breaches to determine if they are notifiable and subsequently notify the Personal Data Protection Commission and affected individuals of any notifiable data breach. - Personal Data Protection Act 2012 - Section 13 Consent required
An organisation must obtain consent from an individual before collecting, using, or disclosing their personal data for a specified purpose. - Personal Data Protection Act 2012 - Section 26D Duty to notify occurrence of notifiable data breach
Organizations have a mandatory duty to assess data breaches and notify the Personal Data Protection Commission and affected individuals if the breach is deemed notifiable. - Personal Data Protection Act 2012 (2021 Amendment)
The Singapore Personal Data Protection Act (PDPA) establishes a baseline standard of protection for personal data in Singapore by governing its collection, use, disclosure, and care by private sector organisations.… - Personal Data Protection Act 2012 (No. 26 of 2012) as amended by the Personal Data Protection (Amendment) Act 2020
The Singapore PDPA, as amended in 2020, mandates that organizations notify the Personal Data Protection Commission (PDPC) of a data breach within 3 calendar days (Part VIA, Section 26C) and introduces a data portability… - Personal Data Protection Act B.E. 2562 (2019)
Thailand's PDPA regulates the collection, use, and disclosure of personal data for organizations inside Thailand and those outside who process data of Thai residents. As per Section 19, data processing is prohibited… - Personal Data Protection Act B.E. 2562 (2019)
Thailand's Personal Data Protection Act (PDPA) governs the collection, use, and disclosure of personal data by data controllers and processors within Thailand, and certain entities outside Thailand processing data of… - Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5)
Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information during commercial activities. The Act requires organizations to obtain an individual's consent for… - Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 - Part 1, Interpretation
This act defines key terms governing the protection of personal information in the private sector, establishing foundational concepts for compliance, including the definition of a security breach which implies a… - Personal Information Protection and Electronic Documents Act, Section 7
Organizations may collect, use, or disclose personal information without an individual's knowledge or consent only under specific, legally defined circumstances such as for investigations, emergencies, debt collection,… - Personal Information Protection Law of the People's Republic of China - Direct Marketing Obligations, Article 23-29: Opt-In Consent for Personalised Ads, Automated Decision-Making Transparency, Separate Consent for Sensitive Data, Right to Opt Out of Personalised Recommendations and Minor Protection Rules
The PIPL requires entities conducting direct marketing in China to obtain separate, explicit opt-in consent before processing personal information for personalized advertising or automated decision-making, including… - Personal Information Protection Law of the People's Republic of China (PIPL)
The China Personal Information Protection Law (PIPL) establishes a comprehensive data protection framework for organizations processing the personal information of individuals within the PRC, mandating a clear lawful… - Philippines NPC Advisory No. 2024-04 - Guidelines on Artificial Intelligence Systems Processing Personal Data, Issued 19 December 2024
Personal Information Controllers (PICs) and Personal Information Processors (PIPs) in the Philippines developing, testing, training, or deploying AI technologies must comply with NPC Advisory No. 2024-04 issued by the… - Philippines Republic Act 10173 - Data Privacy Act of 2012
Republic Act No. 10173, the Data Privacy Act of 2012, is the principal Philippine personal data protection statute. The Act was approved on 15 August 2012 and entered into force on 8 September 2012. The Act is organised… - Privacy Act 2020
The New Zealand Privacy Act 2020 governs the collection, use, and disclosure of personal information by agencies, establishing 13 Information Privacy Principles (IPPs) under Section 22. It mandates notification to the… - Proposal for a Regulation of the European Parliament and of the Council concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications)
The proposed ePrivacy Regulation strengthens the confidentiality of electronic communications and modernizes rules for tracking technologies, requiring user consent for processing communications data and for using… - Protection of Personal Information Act (Act 4 of 2013): Section 19 - Security measures on integrity and confidentiality of personal information
A responsible party must secure the integrity and confidentiality of personal information by implementing appropriate, reasonable technical and organisational measures to prevent its loss, damage, destruction, or… - Protection of Personal Information Act (Act 4 of 2013): Section 22 - Notification of security compromises
Organizations must notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering a security compromise involving personal information. - Protection of Personal Information Act (POPIA), 2013 - Section 11: Consent, justification and objection
This section establishes the legal grounds under which a responsible party may lawfully process personal information, requiring at least one of six specific justifications to be met for any processing activity. - Protection of Personal Information Act (POPIA), 2013 - Section 57: Duties and responsibilities of information officer
This section outlines the core duties and responsibilities of the designated Information Officer, including developing a compliance framework, conducting impact assessments, and ensuring the organization lawfully… - Protection of Personal Information Act 4 of 2013 (POPIA)
The Protection of Personal Information Act (POPIA) establishes eight mandatory conditions for the lawful processing of personal information by public and private bodies in South Africa. As outlined in Chapter 3, any… - Qatar Personal Data Privacy Protection Law No. 13 of 2016
This law establishes comprehensive data protection obligations for entities processing personal data in Qatar, including requirements for lawful processing, data subject rights, sensitive data handling, cross-border… - REAL ID Act 2005 - Public Law 109-13
The REAL ID Act of 2005 (Public Law 109-13 Division B, enacted 11 May 2005) established federal minimum security standards for state-issued driver's licences and identification cards required for federal purposes…
+ 104 more nodes in this pillar — see the full registry at /intelligence or the discovery index at /api/v1/nodes/index.json.