What is data privacy?
“Data is the new oil. It’s valuable, but if unrefined it cannot really be used. It has to be changed into gas, plastic, chemicals, etc to create a valuable entity that drives profitable activity; so must data be broken down, analyzed for it to have value.”
Clive Humby, British mathematician and Data Science Entrepreneur
European Union (EU) data privacy laws
General Data Protection Regulation (GDPR)
Who does GDPR apply to?
What is personal data under GDPR?
What are the key requirements under GDPR?

ePrivacy Directive
The ePrivacy Directive was amended and a new ePrivacy Regulation was proposed in 2017, but it was withdrawn in February 2025.
US data privacy laws
California Consumer Privacy Act (CCPA)
Who does CCPA/CPRA apply to?
The CCPA/CPRA applies to for-profit entities doing business in California or elsewhere that collect and process the personal information (PI) of California residents (consumers) and satisfy one of the following:
- More than $25 million gross revenue
- Buys, receives, or sell personal information of 100,000 or more California consumers, households, or devices
- Derives half of its annual revenue by selling the personal information of consumers
It defines personal information as any information that identifies or relates to, directly or indirectly, a consumer or household.
CCPA also grants consumers the right to know, delete, correct, opt-out of sharing/selling of personal data, non-discrimination, and to limit the use of sensitive personal information.
What are the key requirements/business obligations under CCPA/CPRA?
- Provide a privacy notice and notice at collection.
- Follow data minimization and purpose limitation principles.
- Facilitate convenient methods for consumers to exercise their data privacy rights
- Provide "Do not sell or share my personal information" and "Limit the use of sensitive personal information" options for consumers.
- Honour global privacy opt-out signals.
- Implement reasonable security measures to protect data
Fines for non-compliance can go up to $7500 per intentional violation and up to $2500 per unintentional violation. CCPA also provides a private right of action.
Colorado Privacy Act (CPA)
The CPA applies to businesses in Colorado or businesses elsewhere that target Colorado residents, and controls/processes: the personal data of:
- >100K consumers; or
- 25k consumers and generates at least 50% of revenue from the sale of personal data
Colorado privacy law provides similar rights as the CCPA, such as the right to access, correct, delete, and opt out of targeted advertising. Businesses must publish a privacy policy, provide opt-out choices, fulfil consumer rights, honour universal/global opt-out signals, and obtain consent for sensitive data.
Virginia Consumer Data Protection Act (VCDPA)
Virginia's privacy law went into effect in 2023 and shares the same applicability thresholds as Colorado privacy law.
Under VCDPA, businesses must be transparent about their data practices, respect and fulfil consumer requests promptly, implement security safeguards for data protection, and have a contractual relationship with processors.
Other US state privacy laws
- Connecticut (CDPA): July 1, 2023
- Indiana (INCDPA): Jan 1, 2026
- Kentucky (KCDPA): Jan 1, 2026
- Minnesota (MNCDPA): July 31, 2025
- Nebraska (NDPA): Jan 1, 2025
- New Jersey (NJDPA): Jan 15, 2025
- Rhode Island (RIDTPPA): Jan 1, 2026
- Texas (TDPSA): July 1, 2024
- Delaware (DPDPA): Jan 1, 2025
- Iowa (ICDPA): Jan 1, 2025
- Maryland (MODPA): Oct 1, 2025
- Montana (MCDPA): Oct 1, 2024
- New Hampshire (NHPA): Jan 1, 2025
- Oregon (OCPA): July 1, 2024
- Tennessee (TIPA): July 1, 2025
- Utah (UCPA): December 31, 2023
United Kingdom data privacy laws
ince Brexit, the UK has its own framework for data protection, separate from the EU’s GDPR. The regime is built on the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). In June 2025, the Data (Use and Access) Act brought reforms to modernise these rules.
Who does the UK GDPR and DPA apply to?
Any organization handling personal data in the UK, plus non-UK businesses offering goods or services to UK residents or tracking their behaviour.
Key business obligations under UK GDPR and DPA are:
- Process data lawfully, fairly, and transparently.
- Keep it accurate, secure, and only for as long as needed.
- Honour data subject requests.
- Get valid opt-in consent for cookies unless strictly necessary.
- Publish a privacy policy revealing how you process personal data.
UK residents get the right to access, correct, erase, object to processing, data portability and withdraw consent at any time.
Breaches can trigger penalties of up to £17.5 million or 4% of global turnover. Cookie compliance is under particular scrutiny, with regulators cracking down on misleading consent banners.
Brazil's data privacy law
he Lei Geral de Proteção de Dados (Brazil LGPD) draws a lot of inspiration from its European counterpart, the GDPR. The bill was passed in 2018 and came into force on September 18, 2020. It replaces over 40 personal data governing statutes for both online and offline.
Like other data privacy laws, it aims to protect the fundamental rights and data privacy of the people by encouraging innovation and economic and technological development.
Any natural person or entity will be subject to the LGPD if:
- it processes the personal data in Brazil,
- it processes the personal data of people located in Brazil, or
- it collects personal data of people, regardless of their nationality or current location when they were in Brazil.
Key LGPD requirements are:
- Collect and process data only for lawful purposes (10 legal bases similar to GDPR, e.g., consent, legal obligation, contract, legitimate interests).
- Provide clear notice of processing purposes (Privacy policy).
- Maintain security measures to protect personal data.
- Appoint a Data Protection Officer (DPO) in many cases.
- Report data breaches to the national authority (ANPD) within three days and, in some cases, to data subjects.
- Conduct impact assessments for high-risk processing.
- Ensure contracts with third parties (processors) include proper safeguards.
LGPD grants data subjects the following rights:
- Confirm whether their data is being processed.
- Access their personal data.
- Correct incomplete, inaccurate, or outdated data.
- Request anonymization, blocking, or deletion of unnecessary or excessive data.
- Portability of data to another service or provider.
- Comply with cross-border transfer rules.
- Deletion of personal data processed with consent.
- Information about entities with whom the controller has shared data.
- Refuse consent and be informed of its consequences.
- Revoke consent at any time.
Fines for non-compliance with LGPD could go up to 2% of a company’s revenue in Brazil, capped at 50 million Brazilian reais (about USD $10M) per violation.
Canada data privacy laws
Canada has a patchwork of privacy laws at the federal, provincial, and territorial levels. In the private sector, the most notable are:
- Personal Information Protection and Electronic Documents Act (PIPEDA)
- Alberta Personal Information Protection Act (Alberta PIPA)
- British Columbia Personal Information Protection Act (British Columbia PIPA)
- Act Respecting the Protection of Personal Information in the Private Sector (Québec)
Among these, PIPEDA is one of the most significant. While provincial laws like PIPAs govern organizations operating entirely within those provinces, PIPEDA remains the cornerstone federal legislation. It applies to organizations processing personal data of Canadians for commercial activities.
Key requirements under Canada PIPEDA are:
- Must have a designated person who oversees compliance with PIPEDA.
- Identify the specific purpose for processing prior to data collection.
- Obtain consent for data processing, unless the law explicitly requires not to.
- Practice data minimization and purpose limitation.
- Maintain the accuracy of the personal data you keep.
- Implement appropriate data security safeguards.
- Be transparent about your data practices (Privacy policy).
- Fulfil access requests promptly.
Fines for violations could reach $100,000 CAD per violation
UAE data privacy laws
Other data privacy laws
Argentina PDPL
Argentina's Personal Data Protection Law (PDPL) went into effect in 2000. It applies to organizations in the country or those outside that deal with the personal data of Argentine residents. Some of the law's key features include:
- Consent and contract are two of the most important legal bases under the law.
- Key requirements include maintaining accuracy, storage limitation, purpose limitation, data security implementation, etc.
- Gives its citizens the right to information, access, and correction.
There are ongoing proposals and discussions over amendments to the current PDPL.
Australia Privacy Act
The Privacy Act is the major data privacy law of the country. It applies to government agencies and organizations processing the personal data of Australian residents and has an annual turnover of more than 3 million AUD.
The law lays down 13 privacy principles that the organization must follow in order to be compliant.
Fines for non-compliance could reach up to:
- $50,000,000,
- Thrice the value of the benefit generated by the organization from the violation; or
- 30% of the annual turnover of the company during the period of breach.
China PIPL
he data privacy of the people of China is mostly regulated by three laws- the Personal Information Protection Law, Cyber Security Law and the Data Security Law.
The PIPL has extraterritorial scope, applying to the processing of personal data of individuals in China when:
- Products/services are offered to them,
- Their behavior is analyzed/assessed, or
- Other situations defined by law.
Key principles under China's PIPL are transparency, data minimization, purpose limitation, adherence to legal basis of processing, storage limitation, accuracy and accountability.
If found non-compliant, authorities may :
- order corrections, issue warnings, and confiscate illegal gains..
- issue fines up to RMB 1 million for organizations, and RMB 10,000 to RMB 100,000 for responsible individuals.
- in serious cases, issue fines up to RMB 50 million or 5% of annual turnover, along with suspension of business or even revocation of licenses.
Moreover, individuals in charge can also face fines of RMB 100,000 to RMB 1 million and may be barred from holding senior management or data protection roles for a certain period.




