The global landscape
Most of the world's economies now have comprehensive data protection laws, the large majority modeled to some degree on the GDPR. For a business, the practical consequence is that privacy obligations follow the data subject, not your headquarters: a US company with EU customers is subject to GDPR, one with California users to CCPA/CPRA, one processing Brazilian data to LGPD. Multinational operations routinely sit under a dozen regimes at once.
The regimes cluster into two design philosophies. GDPR-style laws are opt-in: processing needs an affirmative legal basis before it happens. The US state laws are opt-out: processing is generally allowed, but consumers get rights to access, delete, correct, and stop the sale or sharing of their data. Understanding which model applies is the first step in scoping any compliance program.
GDPR: the reference standard
The EU General Data Protection Regulation, applicable since May 2018, covers any organization processing personal data of people in the EU, wherever the organization is located, when it offers them goods or services or monitors their behavior. Its core mechanics:
- Lawful basis: every processing activity needs one of six legal bases (consent, contract, legal obligation, vital interests, public task, legitimate interests), documented before processing starts
- Data subject rights: access, rectification, erasure, restriction, portability, and objection, generally answered within one month
- Accountability: records of processing, data protection impact assessments for high-risk processing, privacy by design, processor contracts, and a Data Protection Officer where required
- Breach notification: to the supervisory authority within 72 hours where the breach risks individuals' rights
- International transfers: data leaving the EU needs an adequacy decision (such as the EU-US Data Privacy Framework), standard contractual clauses, or another valid mechanism
Fines reach EUR 20 million or 4% of global annual turnover, whichever is higher, and enforcement is well past the theoretical stage: Meta was fined EUR 1.2 billion (2023) over unlawful EU-US transfers, and Amazon EUR 746 million (2021) over advertising consent. See the full GDPR guide for detail.
United States: a patchwork of state laws
There is no comprehensive federal privacy law; instead a growing roster of states (roughly twenty and counting) have enacted their own, alongside federal sectoral laws such as HIPAA (health), GLBA (financial), and COPPA (children). California leads with the CCPA as amended by the CPRA, which established a dedicated regulator (the California Privacy Protection Agency) and the strongest rights package:
- Rights to know, delete, correct, and port personal information
- Right to opt out of the sale and sharing of personal information, including for cross-context behavioral advertising, with mandatory honoring of the Global Privacy Control browser signal
- Limits on the use of sensitive personal information
- Non-discrimination against consumers who exercise their rights
- Civil penalties per violation (higher for intentional violations and those involving minors), plus a private right of action for certain data breaches
Virginia, Colorado, Connecticut, Texas, Oregon, and the other state laws follow a broadly similar controller/processor model with variations in thresholds, sensitive-data consent, universal opt-out signals, and cure periods. None so far includes a general private right of action.
The practical approach is to build to the strictest common denominator (usually California plus Colorado) rather than tracking each state separately. See the US state privacy comparison.
Other major regimes
| Law | Jurisdiction | Distinctive features |
|---|---|---|
| UK GDPR + DPA 2018 | United Kingdom | Mirrors EU GDPR post-Brexit with ICO enforcement; divergence is gradual |
| LGPD | Brazil | GDPR-like with ten legal bases; fines up to 2% of Brazilian revenue, capped at R$50M per violation |
| PIPL | China | Strict separate-consent requirements and heavily regulated cross-border transfers (security assessments, SCCs, certification) |
| DPDPA | India | Consent-centric "data fiduciary" model; phased implementation ongoing |
| PIPEDA + Quebec Law 25 | Canada | Federal baseline plus Quebec's stricter GDPR-style regime with mandatory privacy impact assessments |
| APPI | Japan | Mutual adequacy with the EU; notification-based model with transfer restrictions |
The library covers each of these in depth, from LGPD and PIPL to India's DPDPA.
Building one program for many laws
- Map your data. Inventory what personal data you collect, where it lives, who it is shared with, and which jurisdictions' residents it covers. Every regime's obligations flow from this map.
- Pick a baseline. Most multinationals build to GDPR as the strictest general standard, then layer jurisdiction-specific deltas (GPC handling for California, separate consent for China, and so on).
- Operationalize rights requests. A single intake and fulfillment workflow with jurisdiction-aware deadlines beats per-law processes.
- Control the website layer. Trackers, consent banners, and privacy-policy accuracy are the most visible and most enforced surface; scan regularly.
- Govern transfers and vendors. Keep processor contracts, transfer mechanisms, and vendor inventories current; most fines involve a third party somewhere.
- Document everything. Regulators judge programs by their records: processing registers, DPIAs, consent logs, and training evidence.
Related guides
Find your compliance gaps
BD Emerson's scanner checks your site against GDPR, CCPA, and global requirements: undisclosed trackers, consent failures, and policy mismatches.