Global Data Protection

Privacy Laws Guide

How the major privacy regimes work, where they differ, and how to build one compliance program that satisfies GDPR, the US state laws, and the growing list of national frameworks.

The global landscape

Most of the world's economies now have comprehensive data protection laws, the large majority modeled to some degree on the GDPR. For a business, the practical consequence is that privacy obligations follow the data subject, not your headquarters: a US company with EU customers is subject to GDPR, one with California users to CCPA/CPRA, one processing Brazilian data to LGPD. Multinational operations routinely sit under a dozen regimes at once.

The regimes cluster into two design philosophies. GDPR-style laws are opt-in: processing needs an affirmative legal basis before it happens. The US state laws are opt-out: processing is generally allowed, but consumers get rights to access, delete, correct, and stop the sale or sharing of their data. Understanding which model applies is the first step in scoping any compliance program.

GDPR: the reference standard

The EU General Data Protection Regulation, applicable since May 2018, covers any organization processing personal data of people in the EU, wherever the organization is located, when it offers them goods or services or monitors their behavior. Its core mechanics:

  • Lawful basis: every processing activity needs one of six legal bases (consent, contract, legal obligation, vital interests, public task, legitimate interests), documented before processing starts
  • Data subject rights: access, rectification, erasure, restriction, portability, and objection, generally answered within one month
  • Accountability: records of processing, data protection impact assessments for high-risk processing, privacy by design, processor contracts, and a Data Protection Officer where required
  • Breach notification: to the supervisory authority within 72 hours where the breach risks individuals' rights
  • International transfers: data leaving the EU needs an adequacy decision (such as the EU-US Data Privacy Framework), standard contractual clauses, or another valid mechanism

Fines reach EUR 20 million or 4% of global annual turnover, whichever is higher, and enforcement is well past the theoretical stage: Meta was fined EUR 1.2 billion (2023) over unlawful EU-US transfers, and Amazon EUR 746 million (2021) over advertising consent. See the full GDPR guide for detail.

United States: a patchwork of state laws

There is no comprehensive federal privacy law; instead a growing roster of states (roughly twenty and counting) have enacted their own, alongside federal sectoral laws such as HIPAA (health), GLBA (financial), and COPPA (children). California leads with the CCPA as amended by the CPRA, which established a dedicated regulator (the California Privacy Protection Agency) and the strongest rights package:

  • Rights to know, delete, correct, and port personal information
  • Right to opt out of the sale and sharing of personal information, including for cross-context behavioral advertising, with mandatory honoring of the Global Privacy Control browser signal
  • Limits on the use of sensitive personal information
  • Non-discrimination against consumers who exercise their rights
  • Civil penalties per violation (higher for intentional violations and those involving minors), plus a private right of action for certain data breaches

Virginia, Colorado, Connecticut, Texas, Oregon, and the other state laws follow a broadly similar controller/processor model with variations in thresholds, sensitive-data consent, universal opt-out signals, and cure periods. None so far includes a general private right of action.

The practical approach is to build to the strictest common denominator (usually California plus Colorado) rather than tracking each state separately. See the US state privacy comparison.

Other major regimes

Law Jurisdiction Distinctive features
UK GDPR + DPA 2018 United Kingdom Mirrors EU GDPR post-Brexit with ICO enforcement; divergence is gradual
LGPD Brazil GDPR-like with ten legal bases; fines up to 2% of Brazilian revenue, capped at R$50M per violation
PIPL China Strict separate-consent requirements and heavily regulated cross-border transfers (security assessments, SCCs, certification)
DPDPA India Consent-centric "data fiduciary" model; phased implementation ongoing
PIPEDA + Quebec Law 25 Canada Federal baseline plus Quebec's stricter GDPR-style regime with mandatory privacy impact assessments
APPI Japan Mutual adequacy with the EU; notification-based model with transfer restrictions

The library covers each of these in depth, from LGPD and PIPL to India's DPDPA.

Building one program for many laws

  1. Map your data. Inventory what personal data you collect, where it lives, who it is shared with, and which jurisdictions' residents it covers. Every regime's obligations flow from this map.
  2. Pick a baseline. Most multinationals build to GDPR as the strictest general standard, then layer jurisdiction-specific deltas (GPC handling for California, separate consent for China, and so on).
  3. Operationalize rights requests. A single intake and fulfillment workflow with jurisdiction-aware deadlines beats per-law processes.
  4. Control the website layer. Trackers, consent banners, and privacy-policy accuracy are the most visible and most enforced surface; scan regularly.
  5. Govern transfers and vendors. Keep processor contracts, transfer mechanisms, and vendor inventories current; most fines involve a third party somewhere.
  6. Document everything. Regulators judge programs by their records: processing registers, DPIAs, consent logs, and training evidence.

Related guides

Find your compliance gaps

BD Emerson's scanner checks your site against GDPR, CCPA, and global requirements: undisclosed trackers, consent failures, and policy mismatches.