GDPR

Data Protection Laws Around the World: A Practical Guide

  • Data Protection
  • Data Governance
  • Privacy

Data protection laws now cover most of the world’s major economies, and almost all of them were written in the last decade. That recency is the problem. They borrow from each other heavily enough to look interchangeable, and differ enough in the details that treating them as interchangeable will cost you.

This guide sets out what is actually in force, region by region. It is written for people scoping work across several jurisdictions rather than complying with one, and it links out to more detailed treatments where a region needs them.

Last reviewed: September 2026.

The three families of data protection law

Almost every regime in the world belongs to one of three groups, and knowing which one you are dealing with tells you more than any individual provision.

Comprehensive, GDPR-descended. One statute covering all sectors, built on controllers and processors, lawful bases, data subject rights and breach notification. The EU, the UK, Brazil, Thailand, Korea, Saudi Arabia and most laws written after 2016 sit here.

Sectoral and fragmented. No single national law. Rules attach to industries or, in the US case, to states. The United States is the only major economy still working this way.

Principle-based and older. Comprehensive but structured around numbered principles rather than articles, usually predating the GDPR. Australia is the clearest example.

The practical consequence: moving between two laws in the same family is a gap analysis. Moving between families is a redesign.

The GDPR, and why everything else is measured against it

The EU’s General Data Protection Regulation has applied since 25 May 2018. Three structural features explain its influence.

It is a regulation, not a directive. It applies directly across every member state without each one passing its own version. Nothing else in this guide works that way. Every other law here is a national statute, which is why national variation is the norm outside the EU.

It has six lawful bases, not one. Consent, contract, legal obligation, vital interests, public task and legitimate interests. Most laws written since have started consent-only and then added bases, because a consent-only regime turns out to be unworkable for employment data, fraud prevention and security.

It reaches beyond the EU. Article 3 applies the Regulation to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour there. This is the provision every subsequent law copied, and it is why a company in Singapore or Nepal can be subject to European law.

Penalties run to the higher of EUR 20 million or 4% of global annual turnover. That percentage-of-turnover model has since appeared, in various forms, in Singapore, Australia and Korea.

The concepts that travel furthest from the GDPR are the controller and processor roles. Getting that distinction right is the foundation of nearly every compliance programme in this guide, and I have covered it separately in controller or processor: your role depends on what you do.

Europe beyond the GDPR

The United Kingdom retained the GDPR after leaving the EU. The regime is now the UK GDPR read together with the Data Protection Act 2018, enforced by the Information Commissioner’s Office. The substance remains close to the EU version, with ongoing divergence in specific areas. If you comply with one, you are most of the way to the other, but they are two separate laws and adequacy is not permanent.

Switzerland is outside the EU and runs its own revised Federal Act on Data Protection, in force since 1 September 2023. It is close to the GDPR in substance without being identical.

The United States has no national privacy law

This is the most commonly misunderstood point in the entire field. There is no federal comprehensive privacy statute in the United States. Proposed bills have repeatedly failed to pass.

What exists instead is two layers.

Federal law, organised by sector. HIPAA covers health information, GLBA covers financial institutions, COPPA covers children’s data online, FERPA covers education records. Each protects a category of data or a type of institution, not the population generally. The Federal Trade Commission enforces against deceptive data practices under its general consumer protection authority, which fills some of the gap but is not a privacy law.

State law, and expanding. Around 20 states have a comprehensive consumer privacy law in effect as of 2026, with Indiana, Kentucky and Rhode Island joining on 1 January 2026. Several more have been enacted with effective dates in 2027. Counts published by different trackers vary depending on whether they count laws enacted or laws in force, so treat any specific number as needing a check against the IAPP US State Privacy Legislation Tracker.

California is the outlier within the outlier. The CCPA, as amended by the CPRA, created the only dedicated state privacy regulator in the country, the California Privacy Protection Agency. It is the only comprehensive state law with a private right of action, and that right is limited to certain data breaches rather than general violations. It is also the only one that covers employees, job applicants and business contacts rather than consumers alone.

For anyone building a US programme: the working assumption most practitioners use is that complying with California, Colorado, Connecticut and Texas gets you most of the way to a national baseline, with the remaining states adding specific requirements rather than new architecture.

Australia

The Privacy Act 1988 is built on 13 Australian Privacy Principles rather than numbered articles, and is enforced by the Office of the Australian Information Commissioner. It predates the GDPR by thirty years, and the architecture reflects that.

Recent changes matter more than the base statute:

  • The Notifiable Data Breaches scheme has since 2018 required notification to the OAIC and to affected individuals where a breach is likely to result in serious harm.
  • Following the Optus and Medibank breaches, the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 raised maximum penalties for serious or repeated breaches to the greater of AUD 50 million, three times the value of the benefit obtained, or 30% of adjusted turnover.
  • The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024, with most provisions commencing that day.
  • A statutory tort for serious invasion of privacy commenced on 10 June 2025, inserted as Schedule 2 of the Privacy Act. Individuals can now sue directly, without going through the OAIC, for intrusion upon seclusion or misuse of information relating to them. Australia spent most of a century without an enforceable personal right to privacy, so this is a genuine shift rather than a technical amendment.
  • Automated decision-making transparency obligations take effect on 10 December 2026, requiring privacy policies to disclose where computer programs make or substantially influence decisions affecting an individual’s rights or interests. A Children’s Online Privacy Code is due to be registered by the same date.

One quirk that catches foreign organisations out: businesses with annual turnover of AUD 3 million or less are generally exempt unless they handle health information, trade in personal information, or fall into other specified categories. The exemption has been under review for years without being removed.

Asia-Pacific

The region contains statutes drafted decades apart, using at least six different names for the same category of law, enforced by bodies with very different powers.

The headline points:

  • China’s Personal Information Protection Law has applied since 1 November 2021, sitting on top of the Cybersecurity Law and the Data Security Law.
  • India’s Digital Personal Data Protection Act, 2023 had its Rules notified in November 2025, with substantive obligations taking effect on 14 May 2027.
  • Japan’s Act on the Protection of Personal Information is the oldest comprehensive law in the region, with the 2020 amendments in force since 1 April 2022.
  • South Korea’s PIPA underwent a major overhaul in force from 15 September 2023, shifting emphasis from criminal sanctions to administrative penalties calculated against total revenue.
  • Singapore, Malaysia, Thailand, Taiwan and Sri Lanka each have a statute called the Personal Data Protection Act, and they are not the same law. I have set out what each requires in what is PDPA.
  • Vietnam’s Law No. 91/2025/QH15 took effect on 1 January 2026 and is unusual in recognising three roles rather than two.

The full country-by-country picture, with dates and regulators, is in APAC privacy laws: a country-by-country guide.

The Middle East

The Gulf and wider MENA region has built out quickly, mostly under the name Personal Data Protection Law.

Qatar was first in the GCC with Law No. 13 of 2016. Bahrain followed with the first comprehensive standalone statute in the bloc, in force from 1 August 2019. Saudi Arabia’s PDPL has been fully enforceable since 14 September 2024 and is the most actively enforced in the region. Oman, Jordan, the UAE, Turkiye and Egypt all have laws in place, and the DIFC and ADGM in the UAE operate separate regimes that the federal law does not displace.

The detail, including which country’s law people mean when they say “PDPL,” is in what is PDPL.

Latin America and Africa

Brazil’s LGPD is the most GDPR-like law outside Europe, enforced by the ANPD. Canada operates PIPEDA federally, with Quebec’s Law 25 setting a stricter, more GDPR-aligned standard provincially. South Africa’s POPIA and Nigeria’s Data Protection Act 2023 are the two most significant African regimes.

What actually differs between them

Six axes account for most of the divergence. If you are building a multi-jurisdiction programme, these are the points where a single template breaks:

1. Is consent the default, or one basis among several? The GDPR, Thailand and Malaysia offer a range of lawful bases. Saudi Arabia and China lean much harder on consent. Singapore was consent-centric until 2020 and has since added legitimate interests. This single question changes how you design data collection.

2. The breach clock, and what starts it. The 72-hour standard from the GDPR has been widely copied, including in Thailand and Saudi Arabia. Singapore requires notification within three calendar days of assessing that a notifiable breach occurred, which is both shorter and anchored differently. Malaysia requires notification as soon as practicable. Australia’s trigger is likely serious harm.

3. Whether you have to register. Saudi Arabia requires controllers to register with SDAIA. Bahrain requires DPOs to be accredited on a register. The GDPR abolished general registration in 2018. Organisations arriving from a GDPR programme routinely miss registration requirements because their home regime does not have one.

4. DPO thresholds. Some jurisdictions require appointment above a processing threshold, some require notification to the regulator, some require formal accreditation, and some require it only of specific sectors.

5. Cross-border transfer mechanisms. Adequacy decisions, standard contractual clauses, consent-based transfer, regulator approval and country whitelists all appear in different combinations. Malaysia abandoned its whitelist in 2025 for an adequacy-style assessment.

6. Terminology. Controller, data user, data fiduciary, personal information handler, organisation and APP entity all describe roughly the same role. Mapping the vocabulary is the first step in any regional gap analysis, and it is where most programmes go wrong quietly.

What this means in practice

The failure mode is predictable: an organisation builds a GDPR programme, assumes it covers everything, and discovers three years later that it never registered in Saudi Arabia, its Singapore breach procedure runs to the wrong deadline, and its processor contracts do not contain the clauses Malaysian law requires.

The alternative is not maintaining ten separate programmes. It is a common core with jurisdiction-specific overlays.

The common core is the same everywhere. Know what personal data you hold and why. Document which role you occupy in each processing activity. Be able to produce a regulator notification quickly. Have contracts that reflect what your processors actually do. Maintain records of processing. That work supports every statute in this guide.

The overlay is what each law adds on top: the exact notification deadline, the registration requirement, the DPO threshold, the transfer mechanism, the specific contract clauses.

Building the core first is what makes the overlays cheap. Organisations that skip it end up with parallel programmes that drift apart, which is expensive and produces exactly the governance gaps regulators are now fining people for. A working data governance framework does more for multi-jurisdiction privacy compliance than a stack of country-specific policies ever will.

Frequently asked questions

How many countries have data protection laws?

Most of the world’s major economies now have a comprehensive statute in force or commenced. The number changes frequently as new laws are enacted and existing ones commence in phases, so any specific figure needs checking against a current tracker.

Does the GDPR apply outside the EU?

Yes. Article 3 extends it to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour there. It does not displace local law, so an organisation can be subject to both.

Does the United States have a data protection law?

Not a comprehensive federal one. It has sectoral federal laws covering health, financial, children’s and education data, and around 20 state comprehensive privacy laws in effect as of 2026, with more taking effect in 2027.

Which data protection law is the strictest?

The question is less useful than it sounds, because strictness varies by dimension. The GDPR has the highest headline penalty as a percentage of turnover. Korea’s PIPA has demanding sensitive-data rules. Saudi Arabia’s PDPL adds registration duties the GDPR does not have. Australia now allows individuals to sue directly. The right question is which obligations apply to your specific processing.

What is the difference between GDPR, PDPA and PDPL?

The GDPR is the EU’s regulation. PDPA stands for Personal Data Protection Act and is the name used in Singapore, Malaysia, Thailand, Taiwan and Sri Lanka. PDPL stands for Personal Data Protection Law and is used in Saudi Arabia, Bahrain, Oman, Jordan, the UAE and Vietnam. Different laws, different regulators, shared vocabulary.

If I comply with GDPR, am I compliant everywhere?

No, though you are much closer than if you started from nothing. The concepts transfer. The specifics - registration, notification deadlines, DPO thresholds, contract content - do not.


Sources

  • Regulation (EU) 2016/679 (General Data Protection Regulation)
  • UK Data Protection Act 2018 and the UK GDPR
  • Australia Privacy Act 1988 (Cth); Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022; Privacy and Other Legislation Amendment Act 2024 (Cth); OAIC guidance on the statutory tort for serious invasions of privacy
  • California Consumer Privacy Act as amended by the California Privacy Rights Act; IAPP US State Privacy Legislation Tracker
  • Individual national statutes as cited in the linked regional guides