EU Privacy Law
-
AI Impact Assessments: Combining a GDPR DPIA with the AI Act's FRIA
How to run one assessment that satisfies both GDPR Article 35 DPIAs and the EU AI Act's Article 27 fundamental rights impact assessment for high-risk AI.
EU/EEA -
Automated Decision-Making: GDPR Article 22 Rules and the SCHUFA Judgment
When solely automated decisions are prohibited under GDPR Article 22, what the CJEU's SCHUFA ruling changed, and how the EU AI Act layers on top.
EU/EEA -
Consent Management Platforms: Selection, Configuration, and Audit Guide
How to choose and configure a CMP that produces legally valid consent: blocking behavior, TCF considerations, consent records, and the audit checklist.
EU/EEA and global -
Cookie Compliance in 2026: Country-by-Country Requirements Across the EU
How EU cookie consent rules differ by country: CNIL, Spanish AEPD, German TTDSG, Italian Garante and more, with the fines that defined each position.
EU/EEA -
Dark Patterns Are Now Illegal in the EU: DSA Article 25, GDPR, and What Enforcers Target
How the DSA's dark pattern ban, GDPR consent rules, and consumer law combine against deceptive design, with the EDPB's taxonomy and real enforcement examples.
EU/EEA -
Direct Marketing Compliance: Email, SMS, and Push Notification Rules by Jurisdiction
Opt-in and opt-out rules for email, SMS, and push marketing under the ePrivacy Directive, GDPR, UK PECR, CAN-SPAM, CASL, and TCPA, with the fines to know.
EU, UK, US, Canada -
DSA Algorithmic Transparency: Recommender Systems, Ad Repositories, and Researcher Access
The Digital Services Act's algorithm transparency duties: Article 27 recommender disclosures, Article 39 ad repositories, Article 40 researcher data access, and audits.
EU/EEA -
DSA Compliance for Platforms: Obligations by Tier and Where They Touch Privacy
Digital Services Act obligations for hosting services, online platforms, and VLOPs: notice-and-action, ad transparency, minors' protection, and enforcement so far.
EU/EEA -
ePrivacy Directive vs. GDPR: Where Cookie Law Meets Data Protection
How the ePrivacy Directive and GDPR fit together: which law governs cookies, consent standards, marketing rules, and who enforces what.
EU/EEA -
ePrivacy Regulation: What Changes Are Coming and How to Prepare Now
The status of the EU ePrivacy Regulation after the Commission withdrew the 2017 proposal in 2025, what remains in force, and how to prepare for what follows.
EU/EEA -
EU AI Act and GDPR: How the Two Regimes Apply to AI Systems Together
Where the EU AI Act and GDPR overlap for AI that processes personal data: risk tiers, prohibited practices, dual obligations, and the compliance sequence.
EU/EEA -
EU AI Act Transparency Rules: Disclosure Duties for Chatbots, Deepfakes, and AI Content
Article 50 of the EU AI Act explained: when users must be told they face an AI system, how AI-generated content must be marked, and the deadlines and fines.
EU/EEA -
GDPR Breach Notification: The 72-Hour Playbook for Controllers and Processors
GDPR Articles 33 and 34 explained: what counts as a breach, the 72-hour deadline, when individuals must be told, and how to document every incident.
EU/EEA -
GDPR and Children's Data: Age Verification and Parental Consent Requirements
GDPR Article 8 rules for children's data: consent age thresholds by country, parental verification, transparency for minors, and the TikTok and Instagram fines.
EU/EEA -
GDPR Consent Management: Building Lawful Consent Flows That Satisfy Regulators
What valid GDPR consent looks like under Articles 4(11) and 7, how regulators test consent banners, and how to build flows that hold up to scrutiny.
EU/EEA -
GDPR Controller vs. Processor: Obligations, Contracts, and Liability Allocation
How GDPR splits duties between controllers and processors, the mandatory Article 28 contract clauses, joint controllership, and who pays when things fail.
EU/EEA -
GDPR Cross-Border Transfers: SCCs, Transfer Impact Assessments, and Supplementary Measures
GDPR Chapter V transfer rules after Schrems II: adequacy decisions, the 2021 SCCs, transfer impact assessments, and the EU-US Data Privacy Framework.
EU/EEA -
GDPR Data Retention Policies: Building Defensible Schedules by Data Category
How GDPR storage limitation works in practice: setting retention periods per data category, legal holds, deletion mechanics, and documenting the schedule.
EU/EEA -
GDPR Data Subject Rights: Operationalizing Access, Erasure, and Portability
How to handle GDPR data subject requests under Articles 15 to 22: deadlines, identity checks, exemptions, and workflows that scale past manual email.
EU/EEA -
GDPR Data Protection Impact Assessment: When Required and How to Conduct One
When GDPR Article 35 makes a DPIA mandatory, the required content, and a step-by-step method for running assessments that stand up to regulator review.
EU/EEA -
GDPR Enforcement Tracker: Largest Fines, Trends, and Lessons for Compliance Teams
The biggest GDPR fines on record, what each was actually for, and the enforcement patterns that predict where regulators look next.
EU/EEA -
GDPR Data Protection Officer: When Mandatory, Role Definition, and Independence Requirements
When GDPR Articles 37 to 39 require a DPO, what the role must and must not do, independence rules, and how to appoint one without creating conflicts.
EU/EEA -
GDPR Lawful Basis Decision Tree: Which of the 6 Bases Applies?
How to choose and document the right GDPR Article 6 lawful basis: consent, contract, legal obligation, vital interests, public task, or legitimate interests.
EU/EEA -
Records of Processing Activities (ROPA): GDPR Template and Best Practices
What GDPR Article 30 records must contain for controllers and processors, who the under-250 exemption really covers, and how to keep a ROPA current.
EU/EEA -
GDPR for SMEs: Practical Compliance Without a Dedicated Privacy Team
What GDPR actually requires from small and mid-sized businesses, which obligations scale down, which do not, and a lean sequence for getting compliant.
EU/EEA -
GDPR Special Category Data: Processing Sensitive Personal Data Lawfully
GDPR Article 9 explained: the nine special categories, the ten conditions that permit processing, and the extra safeguards sensitive data demands.
EU/EEA -
Ultimate Guide to GDPR Compliance: 10-Step Roadmap
A practical 10-step GDPR compliance roadmap covering lawful basis, data subject rights, breach response, and transfers. Scan your site free today.
EU/EEA -
High-Risk AI Data Governance: Article 10 Requirements Under the EU AI Act
What EU AI Act Article 10 demands of training, validation, and testing data for high-risk AI: quality criteria, bias controls, documentation, and GDPR overlap.
EU/EEA
UK Privacy Law
-
ICO Enforcement Trends: What the UK Regulator Actually Fines
Analysis of ICO enforcement patterns: the biggest UK GDPR fines, the PECR fining machine, the public sector approach, and current regulatory priorities.
United Kingdom -
UK Children's Code: The 15 Age Appropriate Design Standards
What the ICO's Children's Code requires from online services likely to be accessed by under-18s: high privacy defaults, age assurance, and DPIAs.
United Kingdom -
Data (Use and Access) Act 2025: How the UK Reformed Its GDPR
What the DUAA 2025 changed in UK data protection: recognised legitimate interests, relaxed automated decision rules, and DSAR search limits.
United Kingdom -
UK GDPR vs. EU GDPR: What Actually Diverged After Brexit
The real differences between UK GDPR and EU GDPR: transfer mechanisms, representative duties, the DUAA 2025 reforms, and how to run dual compliance.
United Kingdom -
UK IDTA and Addendum: Restricted Transfers Explained
How to lawfully transfer personal data out of the UK: the IDTA, the UK Addendum to EU SCCs, transfer risk assessments, and the UK-US data bridge.
United Kingdom -
UK PECR Compliance: Cookie Consent and Marketing Rules
What PECR requires for cookies, email and SMS marketing, and the soft opt-in; how it interacts with UK GDPR; and the ICO's fining pattern.
United Kingdom
US Federal Law
-
Age Gating and Age Verification: Methods, Law, and Tradeoffs
Age assurance from neutral screens to ID verification: what COPPA, state social-media laws, and Free Speech Coalition v. Paxton require, and how to pick a proportionate method.
United States -
Consumer Reporting Agency Obligations Under the FCRA
What FCRA requires of CRAs and companies that become them: maximum possible accuracy, permissible purposes, dispute reinvestigation, and the data-broker line the CFPB has been probing.
United States -
COPPA Compliance Guide: The 2025 Amended Rule
COPPA after the 2025 amendments: who is covered, verifiable parental consent methods, the new opt-in for targeted advertising, data retention limits, and FTC penalty exposure.
United States -
COPPA Safe Harbor Programs: How They Work, When They Help
FTC-approved COPPA safe harbor programs: what certification covers, the approved programs, 2025 rule changes tightening oversight, and how to decide if membership is worth it.
United States -
COPPA vs State Minors' Privacy Laws: Mapping the Overlap
How COPPA interacts with state children's and teens' privacy laws: preemption limits, age-appropriate design codes, social media age laws, and building one program for all of them.
United States -
EO 14117 Bulk Data Rules: The DOJ Data Security Program
Executive Order 14117 and the DOJ's 28 CFR Part 202 rules: covered data categories, bulk thresholds, countries of concern, prohibited and restricted transactions, and compliance dates.
United States -
EO 14117 Vendor Diligence: Screening for the DSP
Vendor and counterparty diligence under the DOJ Data Security Program: covered-person screening, ownership-chain analysis, workforce-location attestations, and contract clauses that work.
United States -
EO 14117 for Tech Companies: SaaS, Cloud, and AI Impacts
How the DOJ Data Security Program hits tech companies: global engineering access, cloud and support models, AI training data, investment terms, and the restructuring patterns emerging.
United States -
FCRA for Employers: Background Checks Done Lawfully
FCRA background-check compliance for employers: the standalone disclosure, authorization, pre-adverse action process, state ban-the-box overlays, and the class-action patterns to avoid.
United States -
FERPA, COPPA, and CIPA Together: The School Privacy Stack
How FERPA, COPPA, and CIPA interact in K-12: school consent on parents' behalf, filtering and monitoring duties, and building one compliance posture for schools and their vendors.
United States -
FERPA for EdTech: School Official Exception, Vendor Duties
How FERPA governs edtech vendors: the school official exception, direct control requirements, metadata and product-improvement limits, and contract terms districts demand.
United States -
FERPA and State Student Privacy Laws: The Stricter Layer
How state student privacy laws (SOPIPA, New York Ed 2-d, and 100+ others) exceed FERPA: direct vendor liability, ad bans, security mandates, and building to the strictest state.
United States -
FTC Dark Patterns Enforcement: Design Choices as Violations
How the FTC prosecutes dark patterns: the Epic Games and Amazon cases, ROSCA and the Click-to-Cancel rule, consent-flow design standards, and state-law parallels.
United States -
FTC Data Security Expectations: What Orders Actually Require
The FTC's data security baseline distilled from consent orders and guidance: risk assessment, MFA, encryption, vendor oversight, incident response, and the unfairness theory behind it.
United States -
FTC Health Breach Notification Rule: Apps On the Clock
The HBNR after the 2024 amendments: which health apps are covered, why sharing data with advertisers is a 'breach', notification clocks, and the GoodRx and Premom precedents.
United States -
FTC Safeguards Rule: The Security Program GLBA Requires
The amended Safeguards Rule for non-bank financial institutions: nine required elements, the Qualified Individual, MFA and encryption mandates, and the 30-day breach notification.
United States -
FTC Section 5 Privacy: Unfair and Deceptive Data Practices
How the FTC polices privacy under Section 5: deception and unfairness doctrine, landmark data cases, consent decree mechanics, and the current enforcement agenda.
United States -
GLBA Information Security Program: Building to 16 CFR 314
How to build the written information security program GLBA requires: governance, risk assessment methodology, the eight safeguard domains, testing cadence, and the annual board report.
United States -
GLBA Privacy Notices: The Privacy Rule and Opt-Out Rights
GLBA Privacy Rule requirements: initial and annual notices, the model form safe harbor, opt-out rights for nonaffiliated sharing, and how state laws layer on top.
United States -
GLBA Vendor Management: Service Provider Oversight Under 314
Service provider oversight under the Safeguards Rule: selection diligence, mandatory contract terms, tiered periodic reassessment, and the fourth-party problem.
United States -
HIPAA Business Associate Agreements: Complete BAA Guide
When a BAA is required, the 45 CFR 164.504(e) mandatory terms, subcontractor flow-downs, the conduit exception's real limits, and BAA failures in OCR enforcement.
United States -
HIPAA Breach Response Playbook: Clocks, Assessments, Notices
Running a HIPAA breach: the four-factor risk assessment, 60-day individual notice, HHS and media notification, business associate timelines, and the documentation OCR checks.
United States -
HIPAA in the Cloud: CSP Rules, BAAs, Shared Responsibility
HIPAA cloud computing under OCR guidance: why encrypted no-key storage still makes a CSP a business associate, shared responsibility, and configuring eligible services.
United States -
HIPAA Compliance Roadmap: Building a Defensible Program
A step-by-step HIPAA compliance roadmap: scoping covered functions, the security risk analysis, policies, BAAs, training, breach readiness, and OCR audit survival.
United States -
HIPAA De-identification: Safe Harbor, Expert Determination
The two HIPAA de-identification methods under 45 CFR 164.514: the 18 Safe Harbor identifiers, expert determination standards, re-identification risk, and limited data sets.
United States -
HIPAA Minimum Necessary: Scoping Uses and Disclosures
The minimum necessary standard under 45 CFR 164.502(b): when it applies, the treatment exception, role-based access policies, and how OCR evaluates compliance.
United States -
HIPAA Security Risk Analysis: How to Do It Right
The 45 CFR 164.308(a)(1) risk analysis: scope, methodology, common failures OCR cites, the Risk Analysis Initiative, and how to keep the assessment current.
United States -
OCR HIPAA Enforcement Trends: What Gets Penalized Now
Current OCR enforcement patterns: the Risk Analysis Initiative, right-of-access actions, ransomware settlements, penalty tiers, and how investigations actually unfold.
United States -
Telehealth and HIPAA: Platforms, BAAs, and Post-PHE Rules
HIPAA requirements for telehealth after the COVID enforcement discretion ended: compliant platforms, BAAs, remote workforce safeguards, and website tracking risks.
United States
US State Law
-
California Age-Appropriate Design Code: Status and Duties
The CAADCA after NetChoice v. Bonta: what is enjoined, what survives in practice, and how to build age-appropriate design compliance that outlasts the litigation.
California, USA -
California Data Broker Registration: CPPA Registry Rules
Who must register as a data broker in California, annual disclosure requirements, CPPA sweep enforcement at $200 per day, and how the registry feeds the Delete Act.
California, USA -
California Delete Act: SB 362 and the DROP Explained
The Delete Act's one-stop deletion mechanism for data brokers: registration, the DROP platform, 2026 deadlines, audit duties, and CPPA enforcement.
California, USA -
CCPA and AdTech: Pixels, Sharing, and Opt-Out Mechanics
How the CCPA treats the advertising stack: why pixels are sales, cross-context behavioral advertising, GPC, and the enforcement actions built on ad-tech flows.
California, USA -
CCPA Complete Guide: California Privacy Law After the CPRA
The CCPA as amended by the CPRA: who is covered, consumer rights, sale and sharing rules, CPPA enforcement, and the fines and settlements shaping compliance.
California, USA -
CCPA Private Right of Action: Breach Lawsuits Explained
When California consumers can sue under Civ. Code 1798.150: statutory damages of $100-$750 per consumer, the reasonable-security trigger, and defense strategy.
California, USA -
CCPA Sensitive Personal Information: Categories and Duties
What counts as sensitive personal information under the CPRA, when the 'Limit' right applies, permitted uses, and how SPI differs from GDPR special categories.
California, USA -
CCPA Service Provider Agreements: Required Contract Terms
The contract clauses that keep a vendor a service provider instead of a third party under the CCPA: mandatory terms, contractor vs. third party, and audit duties.
California, USA -
CPPA Enforcement Priorities: What California Targets Next
The California Privacy Protection Agency's enforcement record and stated priorities: dark patterns, data brokers, connected vehicles, ADMT, and audit sweeps.
California, USA -
CPRA Risk Assessments: California's New Requirements
The CPPA's 2025 risk assessment regulations: which processing triggers them, required content, submission duties, ADMT overlap, and reuse of GDPR DPIAs.
California, USA -
Data Protection Assessments: State Requirements Guide
When state privacy laws require data protection assessments, what triggers them, what they must contain, Colorado's and California's depth, and one multistate template.
United States -
Unified DSAR Intake: One System for All State Laws
Building a single consumer-rights request pipeline across all US state privacy laws: intake, verification, routing, the 45-day clock, appeals, and evidence.
United States -
Multi-State Privacy Strategy: One Program, 20 Laws
How to run a single US privacy program across twenty state laws: the four anchor states, the union-list method, configuration deltas, and the maintenance cadence.
United States -
NYDFS Annual Certification: Section 500.17(b) Guide
The Part 500 annual compliance filing after the Second Amendment: certification vs acknowledgment, CISO and CEO signatures, the April 15 deadline, and the evidence file.
New York, USA -
NYDFS 23 NYCRR 500: Cybersecurity Regulation Guide
New York's financial-services cybersecurity regulation after the Second Amendment: who is covered, CISO and MFA duties, 72-hour reporting, class rules, and enforcement.
New York, USA -
NYDFS Third-Party Requirements: Section 500.11 Guide
Part 500's third-party service provider rules: written policies, due diligence, minimum contract terms, MFA and encryption for vendor access, and periodic reassessment.
New York, USA -
State Children's Privacy Laws: The COPPA-Plus Layer
How states extend past COPPA: teen ad-targeting consent, Maryland and design codes, Connecticut's duty of care, social-media laws, and the litigation reshaping them.
United States -
State Privacy Cure Periods: Tracker and Expiration Map
Which state privacy laws still offer cure periods, how long the windows run, which sunsets have expired, and how AGs actually use cure notices in enforcement.
United States -
B2B and Employee Data Under State Privacy Laws
How US state privacy laws treat B2B contact and employee data: California's full coverage, the consumer-context exemptions elsewhere, and what B2B companies still owe.
United States -
State Privacy Enforcement Tracker: Cases and Lessons
Attorney general and CPPA enforcement under state privacy laws: California's orders, Texas's lawsuits, Oregon's reports, the multistate consortium, and what gets checked first.
United States -
Sensitive Data Consent Rules: State-by-State Guide
How US state privacy laws define sensitive data differently, where opt-in consent is required, Maryland's sale ban, inferred data, and building one national consent flow.
United States -
Universal Opt-Out and GPC: State Requirements Compared
Global Privacy Control and universal opt-out mechanisms: which states mandate honoring them, Colorado's UOOM list, deadlines, and implementation architecture.
United States -
US State Privacy Law Comparison: 20 States Side by Side
Compare US state privacy laws on thresholds, sensitive data, GPC mandates, cure periods, and penalties, with the strict-tier states identified for baseline design.
United States
Canada
-
Bill C-27 Died: What's Next for Canadian Privacy Reform
Bill C-27's CPPA and AIDA died with prorogation in January 2025. What the bill would have done and how to prepare for the successor.
Canada -
AI Regulation in Canada After AIDA: What Applies Now
AIDA died with Bill C-27 in January 2025. What regulates AI in Canada now: PIPEDA, Quebec Law 25, and the voluntary code.
Canada -
OPC Enforcement: How Canada's Privacy Regulator Works
The OPC's enforcement toolkit under PIPEDA: investigations, compliance agreements, Federal Court, and the Facebook and Clearview findings.
Canada -
PIPEDA's 10 Fair Information Principles Explained
The ten fair information principles in PIPEDA Schedule 1, what each requires in practice, who enforces them, and the real penalty exposure.
Canada -
PIPEDA vs. GDPR: The Differences That Matter
A working comparison of PIPEDA and GDPR: consent models, penalties, breach rules, transfers, and what a dual-compliance program needs to add for each.
Canada / EU -
Quebec Biometric Registration: The CAI Disclosure Rule
Quebec requires disclosure to the CAI before creating a biometric database or verifying identity with biometrics. Who must file, and when.
Quebec, Canada -
Quebec Law 25: Canada's Strictest Privacy Law Explained
Law 25's obligations: privacy officer, consent, PIAs, breach reporting, portability, and fines up to 4% of worldwide turnover.
Quebec, Canada -
Quebec PIA Requirements Under Law 25 Explained
Law 25 requires PIAs for new information systems and before sending data outside Quebec. What triggers one and what it must contain.
Quebec, Canada -
Quebec Triple Compliance: Law 25, PIPEDA, and GDPR
How to build one privacy program covering Quebec Law 25, federal PIPEDA, and GDPR: which law applies when, where they diverge, and the strictest-rule map.
Quebec / Canada / EU
Latin America
-
Argentina EU Adequacy: Using and Keeping the Status
Argentina's EU adequacy decision (2003, reaffirmed 2024): what it lets you do with EU data, onward-transfer limits, and how it interacts with Law 25.326 duties.
Argentina / EU -
Argentina Data Protection Law 25.326: Compliance Guide
Argentina's Personal Data Protection Act: AAIP enforcement, registration duties, habeas data rights, sensitive-data rules, and the pending modernization bill.
Argentina -
Chile Data Protection Law 21.719: What Changes in 2026
Chile's new data protection law (Ley 21.719): the December 1, 2026 start date, the new Agency, GDPR-style duties, and fines up to 20,000 UTM, with a readiness plan.
Chile -
Colombia Data Protection: Law 1581 and SIC Enforcement
Colombia's habeas data regime: Law 1581 of 2012, Decree 1377, the RNBD registry, SIC enforcement with fines to 2,000 minimum wages, and transfer rules.
Colombia -
Brazil LGPD: Compliance Guide to Law 13.709/2018
Brazil's LGPD explained: who is covered, the ten lawful bases, data subject rights, ANPD enforcement including the Meta AI order, and fines up to 2% of Brazil revenue.
Brazil -
LGPD Compliance Roadmap: From Data Map to ANPD-Ready
A sequenced LGPD implementation plan: applicability, data mapping, lawful bases, notices, 15-day DSR pipeline, DPO, transfers, breach response, and RIPD assessments.
Brazil -
LGPD DPO (Encarregado): Appointment Rules and Duties
Brazil's encarregado requirement under ANPD Resolution 18/2024: who must appoint one, publication duties, permitted outsourcing, and small-business relief.
Brazil -
LGPD for US Companies: When Brazil's Law Reaches You
How Brazil's LGPD applies to US businesses with no Brazilian entity: extraterritorial triggers, the required DPO, transfer paperwork, and enforcement exposure.
Brazil -
LGPD International Transfers: Resolution 19/2024 Rules
Brazil's international data transfer regime: ANPD Resolution 19/2024, Brazilian SCCs and the adaptation deadline, adequacy, BCN global norms, and contract steps.
Brazil -
LGPD Lawful Bases: Brazil's 10 Legal Grounds Explained
The LGPD's ten lawful bases for processing personal data, how they differ from GDPR's six, the legitimate-interest balancing test, and sensitive-data rules.
Brazil -
LGPD vs GDPR: Key Differences That Change Compliance
Where Brazil's LGPD diverges from the GDPR: lawful bases, response deadlines, DPO rules, transfer mechanisms, fines, and what a GDPR program must add for Brazil.
Brazil / EU -
Mexico Cross-Border Data Transfers for US Companies
LFPDPPP transfer rules for US companies moving data out of Mexico: notice and consent mechanics, exceptions, processor remisiones, and the 2025 enforcement shift.
Mexico -
Mexico LFPDPPP 2025: Privacy Notices, Consent, ARCO Rights
Mexico's new LFPDPPP (March 2025): the aviso de privacidad, consent tiers, ARCO rights on 20-day clocks, and enforcement after INAI's dissolution.
Mexico
Asia-Pacific
-
Japan APPI Compliance Guide: Requirements After 2022
Japan's Act on the Protection of Personal Information: scope, purpose limitation, consent rules, breach reporting, pseudonymization, and PPC enforcement.
Japan -
APEC CBPR Certification: Cross-Border Privacy Rules Explained
The APEC Cross-Border Privacy Rules system and its Global CBPR successor: participating economies, accountability agents, certification steps, and what it buys.
APEC / Global -
APPI Cross-Border Transfers: Japan's Data Export Rules
Moving personal data out of Japan under APPI Article 28: consent with mandatory information, equivalent-standard countries, and continuous safeguard measures.
Japan -
APPI vs. GDPR: Japan and EU Privacy Law Compared
How Japan's APPI differs from GDPR: purpose-based processing vs lawful bases, opt-out sharing, criminal vs administrative penalties, and mutual adequacy.
Japan / EU -
Australia's Consumer Data Right: Open Banking and Beyond
The CDR regime: consumer-directed data sharing in banking, energy, and non-bank lending, accreditation, privacy safeguards, and how it interacts with the Privacy Act.
Australia -
Australia's NDB Scheme: Notifiable Data Breach Rules
The Notifiable Data Breaches scheme under the Privacy Act: eligible breaches, the 30-day assessment, OAIC notification, remedial-action exceptions, and statistics.
Australia -
Australia Privacy Act Reform: What Has Changed and What's Next
Australia's Privacy Act 1988 overhaul: AUD 50M penalties, the 2024 amendment act, the statutory privacy tort, doxxing offences, and the tranche-two agenda.
Australia -
CBPR vs. GDPR BCRs: Which Transfer Mechanism Fits?
APEC/Global CBPR certification against GDPR binding corporate rules: scope, cost, approval paths, legal effect, and when a multinational should run one or both.
APEC / EU -
China's DSL and PIPL: How the Two Data Laws Fit Together
How the Data Security Law and PIPL divide the field: data classification vs personal information, important data, state secrets, and overlapping export controls.
China -
DPDPA Children's Data Rules: Parental Consent to Age 18
India's DPDP Act sets the world's highest age for data consent: verifiable parental consent under 18, bans on tracking and targeted ads, and INR 200 crore penalties.
India -
DPDPA Data Fiduciary Duties: Standard and Significant
What India's DPDP Act requires of data fiduciaries: notice, consent, security, breach reporting, erasure, plus the extra DPO, audit, and DPIA duties for SDFs.
India -
India Data Localization: RBI Rules, DPDPA, and Sector Mandates
Where India actually requires local data storage: RBI payments localization, insurance and telecom rules, and the DPDPA's negative-list transfer model.
India -
India DPDPA Guide: The Digital Personal Data Protection Act
India's DPDP Act 2023: who it covers, consent and legitimate uses, data fiduciary duties, INR 250 crore penalties, and the phased rollout under the 2025 rules.
India -
DPDPA vs. GDPR: How India's Privacy Law Differs from the EU's
India's DPDP Act 2023 against the GDPR: lawful grounds, missing rights, children's rules, transfer models, penalties, and how to adapt an EU program for India.
India / EU -
Indonesia PDP Law: Compliance with Law No. 27 of 2022
Indonesia's Personal Data Protection Law: scope, GDPR-style bases, 3x24-hour breach notification, 2% revenue fines, criminal penalties, and the pending supervisory agency.
Indonesia -
Japan's My Number Act: Strict Rules for the National ID
The My Number Act's tight limits on Japan's 12-digit Individual Number: permitted uses, collection bans, security duties, and criminal penalties beyond APPI.
Japan -
Korea's Credit Information Act: Financial Data and MyData
The Credit Information Use and Protection Act: how Korea regulates financial personal data, pseudonymized data for research, and the MyData portability industry.
South Korea -
New Zealand Privacy Act 2020: IPPs, Breaches, Compliance
New Zealand's Privacy Act 2020: the 13 information privacy principles, notifiable breach rules, IPP 12 cross-border limits, and the Privacy Commissioner's powers.
New Zealand -
Philippines Data Privacy Act: RA 10173 Compliance Guide
The Philippine DPA: NPC registration, consent and criteria for lawful processing, 72-hour breach notification, criminal penalties, and the 2022 administrative fines.
Philippines -
Korea PIPA Data Transfers: Overseas Provision Rules
South Korea's cross-border transfer bases after the 2023 PIPA amendment: consent, contract necessity, certification, adequacy recognition, and PIPC stop orders.
South Korea -
PIPA vs. GDPR vs. APPI: Korea, EU, and Japan Compared
A three-way comparison of Korea's PIPA, the EU GDPR, and Japan's APPI: lawful bases, fines, breach clocks, transfers, and how to run one program across all three.
South Korea / EU / Japan -
South Korea PIPA: Personal Information Protection Act Guide
Korea's PIPA after the 2023 overhaul: scope, consent rules, revenue-based fines up to 3%, 72-hour breach reporting, and PIPC enforcement against Meta and others.
South Korea -
PIPL Compliance Roadmap: China's Privacy Law Step by Step
A practical sequence for PIPL compliance: scope analysis, consent rebuild, cross-border transfer filings, local representative, and CAC audit readiness.
China -
PIPL Consent Requirements: Separate Consent Explained
What valid consent looks like under China's PIPL: informed, voluntary, explicit, revocable, and 'separate' for sensitive data, sharing, disclosure, and exports.
China -
PIPL Cross-Border Transfers: Assessment, SCCs, Certification
China's three data export mechanisms under PIPL Article 38, the 2024 facilitation exemptions, thresholds, filings, and the separate-consent requirement.
China -
PIPL Handler Obligations: Duties of Personal Information Handlers
What PIPL demands of personal information handlers: security measures, protection officers, impact assessments, audits, breach response, and entrusted processing.
China -
PIPL Data Subject Rights: What Individuals Can Demand in China
The individual rights in PIPL Chapter IV: access, copy, correction, deletion, portability, explanation of automated decisions, and rights of the deceased's relatives.
China -
PIPL vs. GDPR: Consent, Localization, and State Access
Where China's PIPL and the EU GDPR genuinely differ: no legitimate interests, separate consent, gated cross-border transfers, localization, and enforcement style.
China / EU -
Singapore DPO Requirements: Who Needs One and What They Do
Every organization under Singapore's PDPA must appoint a data protection officer: the legal basis, duties, outsourcing options, and PDPC expectations.
Singapore -
PDPC Advisory Guidelines: Singapore PDPA in Practice
How Singapore's PDPC advisory guidelines turn the PDPA's principles into operational rules: key guidelines, selected topics, NRIC rules, and how to use them.
Singapore -
Singapore PDPA Guide: Obligations, Penalties, Enforcement
Singapore's Personal Data Protection Act after the 2020 amendment: eleven obligations, deemed consent, 10% turnover fines, breach notification, and the DNC registry.
Singapore -
Thailand PDPA Guide: Compliance with B.E. 2562 (2019)
Thailand's Personal Data Protection Act, fully effective June 2022: lawful bases, consent rules, 72-hour breach reporting, DPO triggers, and PDPC enforcement.
Thailand -
Thailand PDPA Cross-Border Transfers: The 2024 Rules
Transferring personal data out of Thailand: sections 28-29, the December 2023 PDPC notifications, contractual clauses, binding corporate rules, and exceptions.
Thailand -
Vietnam Decree 13 Compliance: PDPD Rules and the 2026 PDP Law
Vietnam's Decree 13/2023 on personal data protection: consent-first processing, impact dossiers, cross-border filings, MPS supervision, and the PDP Law arriving 2026.
Vietnam
Middle East & Africa
-
Bahrain PDPL: Law No. 30 of 2018 Compliance Guide
Bahrain's Personal Data Protection Law: PDPA enforcement, consent and lawful bases, data protection guardians, transfer rules, and criminal penalties up to BD 20,000.
Bahrain -
DIFC Data Protection Compliance: Implementation Guide
Building DIFC DP Law compliance step by step: portal notification, DPO analysis, notices, DSAR pipeline, breach response, DPIAs, and transfer instruments.
UAE (DIFC free zone) -
DIFC Data Protection Law No. 5 of 2020: Complete Guide
Dubai International Financial Centre's DP Law: who it covers, registration and DPO duties, data subject rights, adequacy-based transfers, and Commissioner enforcement.
UAE (DIFC free zone) -
Egypt PDPL: Law No. 151 of 2020 Compliance Guide
Egypt's Personal Data Protection Law: Data Protection Center licensing, consent rules, DPO duties, cross-border transfer permits, and criminal penalties up to EGP 5 million.
Egypt -
Israel Privacy Protection Law: Amendment 13 Changes Everything
Israel's Privacy Protection Law after Amendment 13 (effective August 2025): PPA enforcement powers, DPO duties, narrowed database registration, and NIS-scaled fines.
Israel -
Israel EU Adequacy: Paperless Transfers and Their Conditions
How Israel's EU adequacy decision works: the 2011 decision, the January 2024 reaffirmation, the EEA-origin data regulations, and what Israeli companies must maintain.
Israel / EU -
Kenya Data Protection Act 2019: ODPC Compliance Guide
Kenya's Data Protection Act: ODPC registration, lawful bases, data subject rights, transfer restrictions, active enforcement, and fines up to KES 5 million or 1% of turnover.
Kenya -
KVKK vs GDPR: What Changed in 2024 and What Still Differs
Turkey's KVKK compared with the GDPR after the 2024 amendments: consent defaults, VERBIS registration, transfer mechanics, fines, and the remaining compliance deltas.
Turkey / EU -
Nigeria NDPA Compliance: Data Protection Act 2023 Guide
Nigeria's Data Protection Act 2023: NDPC enforcement, lawful bases, data protection officers, DPCO audits, cross-border transfer rules, and fines up to 2% of revenue.
Nigeria -
Nigeria NDPA vs South Africa POPIA: Pan-African Compliance
Africa's two biggest privacy regimes compared: NDPA and POPIA scope, officers, registration, marketing rules, transfers, fines, and how to run one program across both.
Nigeria / South Africa -
Saudi PDPL: Complete Guide to the Personal Data Protection Law
Saudi Arabia's PDPL: SDAIA enforcement, consent and lawful bases, data subject rights, the 72-hour breach rule, transfer regulations, and criminal penalties.
Saudi Arabia -
POPIA Information Officer: Duties, Registration, Delegation
South Africa's information officer requirement: why the CEO holds it by default, deputy delegation, Regulator registration, the PAIA manual, and the compliance framework.
South Africa -
POPIA South Africa: Complete Compliance Guide
South Africa's Protection of Personal Information Act: Information Regulator enforcement, eight processing conditions, information officers, transfers, and R10 million fines.
South Africa -
POPIA vs GDPR: Key Differences for Compliance Teams
Where South Africa's POPIA diverges from the GDPR: juristic-person coverage, the CEO-default information officer, opt-in marketing, prior authorization, and fines.
South Africa / EU -
Saudi Data Localization and Transfers: PDPL and Sector Rules
Saudi Arabia's data transfer and localization stack: PDPL Transfer Regulations, SDAIA SCCs and risk assessments, plus SAMA, CST, and NCA sector localization rules.
Saudi Arabia -
Saudi PDPL Compliance Checklist: SDAIA-Ready in Nine Steps
An implementation sequence for Saudi Arabia's PDPL: registration, notices, consent records, DSR clocks, DPO triggers, DPIAs, 72-hour breach response, and transfers.
Saudi Arabia -
Saudi PDPL vs GDPR: The Differences That Matter
Where Saudi Arabia's PDPL diverges from the GDPR: consent-first design, criminal penalties, registration duties, Saudi transfer instruments, and enforcement posture.
Saudi Arabia / EU -
Turkey KVKK Compliance: Law No. 6698 and the 2024 Reforms
Turkey's data protection law: KVKK enforcement, VERBIS registration, explicit consent rules, the 2024 transfer reform with Turkish SCCs, and fines indexed annually.
Turkey -
UAE Data Localization and Cross-Border Transfer Rules
What must stay in the UAE and what can leave: ICT Health Law localization, federal PDPL transfer articles, DIFC and ADGM adequacy lists, and sector expectations.
United Arab Emirates -
UAE Data Protection Landscape: Federal, DIFC, ADGM, Sector
How the UAE's overlapping privacy regimes fit together: the federal PDPL, DIFC and ADGM free-zone laws, health and banking rules, and how to scope a multi-regime program.
United Arab Emirates -
UAE Federal PDPL: Data Protection Law No. 45 of 2021
The UAE's federal Personal Data Protection Law: scope and free-zone carve-outs, consent and lawful bases, data subject rights, and the pending executive regulations.
United Arab Emirates
International Standards
-
DPF Annual Recertification: Keeping Your Certification Alive
The DPF recertification cycle: deadlines, verification requirements, what lapses cost, privacy policy re-review, and how the FTC treats stale participation claims.
US / EU -
Schrems III Risk: Planning for a DPF Legal Challenge
How a future challenge to the EU-US Data Privacy Framework could unfold, what Latombe decided, the EO 14086 pressure points, and contingency planning that actually works.
US / EU -
UK Extension to the DPF: The UK-US Data Bridge
How the UK Extension to the EU-US Data Privacy Framework works: eligibility, the data bridge adequacy regulations, differences from EU flows, and certification mechanics.
US / UK -
DPF vs SCCs: Choosing Your EU-US Transfer Mechanism
Data Privacy Framework certification versus standard contractual clauses: cost, coverage, TIA burden, invalidation risk, and why mature programs run both in layers.
US / EU -
EU-US Data Privacy Framework: Self-Certification Guide
How to self-certify to the EU-US Data Privacy Framework: eligibility, the DPF Principles, privacy policy requirements, redress mechanics, and what FTC enforcement looks like.
US / EU -
ISO 27018 for Cloud Providers: PII Protection in Public Cloud
What ISO/IEC 27018 requires of public cloud PII processors: the control extensions, customer commitments, transparency duties, and how providers evidence conformance.
Global -
ISO 27018 Vendor Assessment: Testing Cloud PII Claims
How to assess cloud vendors against ISO 27018: reading certificate scopes, testing the annex commitments, DPA mirroring, subprocessor transparency, and red flags.
Global -
ISO 27701 Annex Mapping: Controls to Frameworks and Laws
Working with ISO 27701's mapping annexes: control correlations to ISO 29100, GDPR, ISO 27018, and how to build a crosswalk register that survives audits in multiple regimes.
Global -
ISO 27701 Certification Roadmap: From Scoping to Certificate
A phased roadmap to ISO 27701 certification: scoping and role determination, PII inventory, risk assessment, control build, internal audit, and the stage 1 and stage 2 audits.
Global -
ISO 27701 Gap Assessment: Sizing the Distance to a PIMS
How to run an ISO 27701 gap assessment: baseline scoping, clause-by-clause and control-by-control review, maturity scoring, and turning findings into a costed remediation backlog.
Global -
ISO 27701 to GDPR Mapping: One PIMS, Regulatory Evidence
How ISO 27701 controls map to GDPR articles: where the standard covers regulation, where it does not, and how to use a certified PIMS as accountability evidence.
EU / Global -
ISO 27701 Implementation: Building a Certifiable PIMS
How to implement ISO/IEC 27701: extending an ISMS into a privacy information management system, controller and processor controls, PII mapping, and the certification path.
Global -
ISO 27701 vs SOC 2 Privacy: Which Evidence Do Buyers Want?
ISO 27701 certification versus SOC 2 privacy attestation: structural differences, geographic buyer preferences, cost profiles, and when running both makes sense.
Global -
ISO 42001 and the EU AI Act: From AIMS to Act Readiness
How an ISO 42001 AIMS maps to EU AI Act obligations: the Article 17 quality management system, high-risk requirements, timelines, and what the standard does not cover.
EU / Global -
ISO 42001 Implementation: Building an AI Management System
How to implement ISO/IEC 42001: scoping the AIMS, AI impact assessments, the Annex A controls, lifecycle governance, and the path to certification.
Global -
ISO 42001 and Privacy: Governing Personal Data in AI Systems
Where ISO 42001 meets privacy law: training data governance, DPIAs versus AI impact assessments, automated decision rights, and composing an AIMS with a 27701 PIMS.
Global -
Integrated ISO Management Systems: 27001, 27701, 42001 Together
Running ISO 27001, 27701, and 42001 as one integrated management system: shared clauses, combined audits, one risk register, and the governance economics of the harmonized structure.
Global -
NIST Privacy Framework + CSF Integration: One Risk Program
Integrating the NIST Privacy Framework with Cybersecurity Framework 2.0: shared governance, the Protect-P overlap, typed risk registers, breach-response seams, and joint Profiles.
US / Global -
NIST Privacy Framework Guide: Core, Profiles, and Tiers
A working guide to the NIST Privacy Framework: the Core's five functions, building Current and Target Profiles, implementation tiers, and how it pairs with the Cybersecurity Framework.
US / Global -
NIST Privacy Framework Profiles: Building Current and Target
How to construct NIST Privacy Framework Profiles: selecting Core outcomes from legal and risk drivers, scoring the Current Profile honestly, and running the gap as a program roadmap.
US / Global -
SOC 2 + HIPAA Combined Reporting: One Audit for Health Data
Combining SOC 2 with HIPAA compliance evidence: SOC 2+ examinations mapped to the Security Rule, what a combined report proves to covered-entity customers, and BAA alignment.
US -
SOC 2 Privacy Criteria: What the Privacy Category Requires
The AICPA Trust Services privacy criteria explained: notice, choice and consent, collection, use and retention, access, disclosure, quality, and monitoring, and what examiners test.
US / Global -
SOC 2 Privacy for SaaS: Processor Realities and Design
How SaaS companies implement SOC 2's privacy category: the processor twist on commitments, system boundaries, subprocessor evidence, DSAR support controls, and period-proof design.
US / Global -
SOC 2 Privacy vs ISO 27701: Attestation or Certification?
Choosing between a SOC 2 privacy attestation and ISO 27701 certification: how the instruments differ, what each proves, buyer recognition by market, and the one-control-set strategy.
US / Global
Cross-Jurisdictional
-
AdTech and Marketing Privacy: Cookie Consent, Targeted Advertising, and Cross-Border Campaign Compliance
How advertising technology and digital marketing organizations must navigate cookie consent, targeted advertising restrictions, and data sharing rules across the EU, US, and global markets.
Global -
AI and Machine Learning Privacy: Training Data Governance, Automated Decisions, and Model Risk
Privacy compliance requirements for AI and machine learning systems covering training data sourcing, automated decision rules, model transparency, and bias audit obligations.
Global -
Breach Notification Rules Worldwide: Every Clock Compared
Global breach notification requirements side by side: GDPR's 72 hours, US state timelines and thresholds, HIPAA and SEC overlays, LGPD, PIPL, India's dual clocks, and how to run one response plan against all of them.
Global -
Incident Response and Breach Notification: A Multi-Jurisdictional Response Playbook
A tested multi-jurisdictional breach notification playbook covering triage, legal assessment, regulator notification, individual notification, and post-incident review across the GDPR, HIPAA, and state law requirements.
Global -
Children's Data Protection Worldwide: COPPA, Design Codes, and Beyond
How children's privacy law works globally: COPPA's verifiable parental consent and the 2025 amendments, GDPR age thresholds, the UK and California age-appropriate design codes, PIPL's under-14 rules, and age assurance.
Global -
Cookie and Tracker Rules Worldwide: Consent, Opt-Out, and the Space Between
How cookie and tracking law differs by jurisdiction: ePrivacy consent in the EU/UK, US opt-out and GPC mandates, Canada's implied-consent doctrine, Brazil, China, and how a global site should segment its banner logic.
Global -
Cross-Border Transfer Mechanisms: The Global Map
Every major transfer regime mapped: EU adequacy and SCCs post-Schrems II, the DPF, UK IDTA, China's CAC routes, LGPD's clauses, APEC CBPR and its Global CBPR successor, and the localization mandates no mechanism cures.
Global -
Data Mapping and Records of Processing: Tools, Methodologies, and Governance
How to build and maintain a defensible data map and records of processing activities across the enterprise, including tool selection, interview methodology, and governance cadence.
Global -
Data Retention Requirements Worldwide: Limits, Mandates, and the Schedule
How retention law works across jurisdictions: GDPR storage limitation, the maximum-limits regimes, the sectoral minimum-retention mandates that conflict with them, deletion engineering, and building a defensible retention schedule.
Global -
Data Subject Rights Across Jurisdictions: The Complete Matrix
Every major privacy regime's individual rights compared: access, deletion, correction, portability, objection, opt-outs, and ADM rights, with the deadlines, verification standards, and exceptions that configure a global fulfillment pipeline.
Global -
DPO Requirements Worldwide: When Mandatory, and How to Structure the Role
Which laws require a data protection officer or equivalent: GDPR's Article 37 triggers, Brazil's encarregado, PIPL's officer thresholds, Singapore's universal mandate, and how to build one DPO function that satisfies all of them.
Global -
Data Subject Rights Automation: Platforms, Workflows, and SLA Management
How to automate data subject access request intake, verification, routing, and fulfillment to meet regulatory response windows without manual overhead.
Global -
EdTech Privacy: FERPA, COPPA, State Student Laws, and International Student Data Requirements
How EdTech companies must navigate FERPA, COPPA, state student privacy laws, and international requirements including GDPR when handling student data globally.
Global -
Financial Services Privacy: GLBA, CCPA, GDPR, PSD2, and Open Banking Requirements
A comprehensive privacy compliance guide for financial institutions covering GLBA, CCPA, GDPR, PSD2, and open banking frameworks across the US, EU, and global markets.
Global -
Global Privacy Enforcement: The Cases That Define the Rules
The enforcement record that tells you what regulators actually punish: the billion-euro GDPR decisions, FTC and state actions, CNIL's cookie campaign, biometric class actions, and how to read enforcement as a compliance roadmap.
Global -
Building a Global Privacy Program That Actually Scales
How to build one privacy program for many laws: the highest-common-denominator strategy, governance and DPO structures, the control set that satisfies GDPR through PIPL, and the local-variation layer.
Global -
Healthcare Privacy Compliance: HIPAA, State Laws, GDPR, and Global Health Data Requirements
A multi-jurisdictional healthcare privacy compliance guide covering HIPAA, state health data laws, GDPR health data provisions, and requirements for global health organizations.
Global -
HR and Employee Privacy: Global Workforce Data Protection Across 30+ Countries
How multinational employers must handle employee personal data under GDPR, US state laws, PIPL, APPI, PIPA, and other frameworks covering the full employment lifecycle.
Global -
IoT and Connected Device Privacy: Data Collection, Consent, and Security by Design Requirements
Privacy compliance requirements for IoT manufacturers and service providers covering data collection transparency, consent mechanisms, over-the-air security, and retention limits.
Global -
Lawful Basis Around the World: Consent, Contract, and Everything Between
How processing gets justified across regimes: GDPR's six bases and legitimate interests balancing, PIPL's separate consent, the US opt-out model, LGPD's ten bases, and how to run one basis framework globally.
Global -
M&A Privacy Due Diligence: Evaluating Privacy Risk in Transactions Across Jurisdictions
How to conduct privacy due diligence in mergers and acquisitions including identifying regulatory liabilities, assessing breach history, and structuring representations and warranties.
Global -
The Master Privacy Crosswalk: Mapping GDPR to Everything Else
How the world's major privacy laws line up: scope, lawful basis, rights, breach clocks, transfers, and penalties compared across GDPR, CCPA/CPRA, PIPL, LGPD, APPI, PIPEDA, and more, and how to use a crosswalk without being misled by it.
Global -
Privacy Impact Assessment Requirements Worldwide: DPIA, PIA, PIPIA, and Peers
Where privacy impact assessments are mandatory and what each demands: GDPR DPIAs and prior consultation, US state data protection assessments, Quebec's PIAs, PIPL's PIPIA, LGPD's RIPD, and running one assessment pipeline for all.
Global -
Privacy Impact and Risk Assessment Library: Templates for DPIA, PIA, TIA, and AI Impact Assessments
A complete library of privacy assessment templates including GDPR DPIAs, general PIAs, transfer impact assessments, and AI impact assessment forms for global use.
Global -
Privacy by Design: Implementing the 7 Foundational Principles in Product Development
How to operationalize Ann Cavoukian's seven Privacy by Design principles in software development, product management, and data architecture decisions.
Global -
Privacy Metrics and Board Reporting: KPIs That Drive Executive Accountability
Which privacy program metrics matter to boards and regulators, how to measure them reliably, and how to present privacy risk clearly to non-technical executives.
Global -
Privacy Technology Stack: Selecting and Integrating OneTrust, BigID, TrustArc, and Other Privacy Tools
How to evaluate and select privacy management platforms, consent management tools, and data discovery solutions for building a scalable privacy operations stack.
Global -
Privacy Training Program Design: Role-Based Training for the Global Workforce
How to design effective role-based privacy training for engineers, marketers, HR teams, and executives that satisfies regulatory training obligations across multiple jurisdictions.
Global -
Retail and E-Commerce Privacy: Consumer Data, Loyalty Programs, and Cross-Border Sales Compliance
Privacy compliance requirements for retailers and e-commerce businesses covering consumer data collection, loyalty programs, behavioral targeting, and multi-jurisdictional selling.
Global -
SaaS and Cloud Privacy: Building Privacy-by-Design into Cloud Products and Services
How SaaS and cloud service providers must build privacy protections into product architecture, handle multi-tenant data, and satisfy customer privacy contractual requirements.
Global -
Sensitive Data Definitions Worldwide: One Word, Many Laws
What counts as sensitive data in each regime: GDPR's special categories, CPRA's sensitive personal information, PIPL's risk-based definition, biometric and health-data statutes, and how to run one classification system across all of them.
Global -
Vendor Privacy Assessment Program: Questionnaires, Risk Tiers, and Ongoing Monitoring
How to build a vendor privacy risk assessment program with tiered questionnaires, scoring methodology, contractual requirements, and periodic reassessment cadence.
Global
Global Privacy Law
-
Japan APPI Overview: Scope, Duties, and PPC Enforcement
Japan's APPI explained: covered data categories, consent and purpose rules, breach reporting, cross-border transfers, EU mutual adequacy, and PPC enforcement powers.
Japan -
Australia Privacy Act: APPs, NDB, and the 2024 Reforms
Australia's Privacy Act 1988 explained: the 13 Australian Privacy Principles, the Notifiable Data Breaches scheme, OAIC enforcement to AUD $50 million, and the 2024 reforms.
Australia -
EU GDPR Overview: Scope, Duties, Rights, and Enforcement
The GDPR in one page: who it reaches, lawful bases, data subject rights, controller and processor duties, transfers, breach rules, and the fines regulators actually impose.
European Union / EEA -
India DPDP Act and the Data Protection Board: How It Works
India's DPDP Act 2023 explained: consent-first processing, data fiduciary duties, the Data Protection Board, the 2025 draft rules, and penalties up to INR 250 crore.
India -
Singapore PDPA: Obligations, Consent, and PDPC Fines
Singapore's PDPA explained: the eleven obligations, consent and its alternatives, breach notification, the DNC registry, and PDPC fines up to 10% of local turnover.
Singapore -
PIPEDA Overview: Canada's Federal Private-Sector Privacy Law
How PIPEDA works: the ten fair information principles, valid consent, breach reporting with CAD $100,000 offenses, OPC enforcement, provincial substitutes, and Quebec's stricter Law 25.
Canada -
Quebec Law 25 Overview: Canada's Strictest Privacy Regime
Quebec's Law 25 explained: phased 2022-2024 obligations, mandatory PIAs, consent rules, confidentiality incidents, CAI enforcement, and fines to CAD $25 million or 4%.
Quebec, Canada -
UK GDPR Overview: The UK's Post-Brexit Privacy Regime
How the UK GDPR and Data Protection Act 2018 work: scope, ICO enforcement, divergences from the EU version, the DUAA 2025 reforms, transfers, and PECR's cookie rules.
United Kingdom
AI Regulation
-
AI Bias Audits: Legal Triggers, Methods, and Evidence
When AI bias audits are legally required and how to run them: NYC Local Law 144, Colorado's AI Act, EU obligations, disparate-impact metrics, and audit evidence that stands up.
US / EU -
Automated Decision-Making Opt-Outs: Profiling Rights by Law
How opt-out rights for automated decisions and profiling work across GDPR Article 22, US state privacy laws, and the CCPA ADMT regulations, and how to build one workflow.
US / EU -
Colorado AI Act: The First US Algorithmic Discrimination Law
Colorado's Artificial Intelligence Act (SB 24-205) explained: high-risk AI in consequential decisions, developer and deployer duties, impact assessments, and the delayed effective date.
Colorado, US -
EU AI Act Compliance: Risk Tiers, Duties, and Deadlines
What the EU AI Act requires: prohibited practices, high-risk obligations, GPAI rules, transparency duties, the staged 2025-2027 timeline, and fines up to 7% of turnover.
EU (extraterritorial reach)
Cloud Privacy Standard
-
Cookie Consent Implementation: Getting the Banner Right
How to implement cookie consent that survives regulator scrutiny: prior consent, equal reject options, granular categories, consent records, tag firing control, and CNIL/ICO enforcement lessons.
Global -
Cross-Border Data Transfers: Mechanisms That Hold Up
How to move personal data across borders lawfully: adequacy decisions, SCCs with transfer impact assessments, BCRs, the EU-US DPF, and the localization regimes that block transfers entirely.
Global -
Dark Patterns Compliance: Where Design Becomes Illegal
How regulators police manipulative design: FTC dark-patterns enforcement, GDPR and EDPB deceptive-design guidance, the DSA's outright ban, CCPA's consent-invalidation rule, and how to audit your UX.
US / EU -
Data Mapping and Inventory: The Substrate of Compliance
How to build and maintain a personal-data inventory: discovery methods, the schema that serves RoPA, DSAR, transfer, and retention duties at once, tooling options, and the maintenance problem that kills most maps.
Global -
DPIA Guidelines: When and How to Assess Privacy Risk
How data protection impact assessments work: GDPR Article 35 triggers, EDPB screening criteria, the assessment method, prior consultation, and the DPIA analogues in UK, state, and global law.
Global -
DSAR Automation: Scaling Rights Requests Without Risk
How to automate data subject requests safely: intake and identity verification, system orchestration, the deadlines across GDPR and state laws, what to automate versus review, and the metrics that matter.
Global -
Privacy Breach Incident Response: The First 72 Hours
How to run privacy-breach response: detection to containment, the risk assessment that drives notification, GDPR's 72-hour clock against the US state patchwork, evidence discipline, and the drills that matter.
Global -
ISO 27001 Certification: The ISMS Path Step by Step
How ISO/IEC 27001:2022 certification works: ISMS scope, risk assessment, Annex A controls, Stage 1 and 2 audits, the three-year cycle, and why it anchors privacy work.
Global -
ISO 27017 Cloud Security Controls: What the Code Adds
ISO/IEC 27017 explained: cloud-specific controls layered on ISO 27002, the seven cloud-only controls, shared-responsibility clarity, and how providers and customers use it.
Global -
ISO 27018: PII Protection in Public Clouds Explained
ISO/IEC 27018 explained: the code of practice for protecting PII in public clouds, the processor commitments it standardizes, and how it supports GDPR Article 28 diligence.
Global -
ISO 31000 Risk Management: The Framework Behind the Frameworks
ISO 31000 explained: the principles, framework, and process of enterprise risk management, how it underpins ISO 27001 and privacy risk assessments, and why it guides rather than certifies.
Global -
Privacy by Design Engineering: From Principle to Pipeline
How to engineer privacy by design and by default: GDPR Article 25's legal mandate, the seven foundational principles, ISO 31700, concrete patterns (minimization, pseudonymization, purpose binding), and the SDLC gates that make it real.
Global -
Records of Processing Activities: Article 30 Done Right
How to build and maintain a RoPA: GDPR Article 30's required fields for controllers and processors, the SME exemption's narrowness, generation from the data map, and what regulators check when they ask for it.
Global -
SOC 2 Privacy Criteria: What the Trust Category Covers
The SOC 2 privacy trust services category explained: the AICPA privacy criteria, how privacy differs from confidentiality, when to add it to your report scope, and how it maps to GDPR and ISO 27701.
Global (US-centric) -
Vendor Privacy Risk Assessments: Diligence That Works
How to assess vendor privacy risk: legal triggers from GDPR Article 28 to state service-provider rules, tiering and questionnaires, DPA terms that matter, continuous monitoring, and lessons from supply-chain breaches.
Global
US Privacy Law
-
Illinois BIPA: Biometric Privacy Law and Litigation Guide
The Biometric Information Privacy Act: consent and retention duties, $1,000/$5,000 statutory damages, Rosenbach, White Castle, the 2024 amendment, and defense strategy.
Illinois, USA -
CCPA Compliance Checklist: Requirements That Get Enforced
A practical CCPA/CPRA compliance checklist: applicability, notices, opt-out links, GPC, DSAR handling, vendor contracts, and the failures behind real fines.
California, USA -
COPPA Compliance: Children's Online Privacy Rules
COPPA after the 2025 rule amendments: who is covered, verifiable parental consent, the new opt-in for targeted ads, data retention limits, and FTC enforcement.
United States (Federal) -
Colorado Privacy Act (CPA): Requirements and Enforcement
The Colorado Privacy Act explained: applicability, consumer rights, universal opt-out mandate, data protection assessments, and AG enforcement with $20,000 penalties.
Colorado, USA -
Connecticut CTDPA: Data Privacy Act Requirements
Connecticut's CTDPA explained: thresholds, consumer rights, consent for sensitive data, minors' amendments, health-data expansion, and AG enforcement.
Connecticut, USA -
Delaware DPDPA: Personal Data Privacy Act Guide
Delaware's Personal Data Privacy Act: 35,000-consumer threshold, narrow exemptions, nonprofit coverage, sensitive-data consent, and DOJ enforcement at $10,000.
Delaware, USA -
Florida Digital Bill of Rights: Who It Actually Covers
Florida's FDBR explained: the $1 billion revenue threshold, big-tech targeting, $50,000 penalties tripled for minors' violations, and the broader provisions that hit everyone.
Florida, USA -
FERPA: Student Privacy Rules for Schools and Ed-Tech
FERPA's education-records rules: who is covered, directory information, the school-official exception ed-tech relies on, PPRA and state student-privacy laws, and enforcement.
United States (Federal) -
GLBA Privacy and Safeguards Rules: Compliance Guide
The Gramm-Leach-Bliley Act's Privacy Rule, the amended Safeguards Rule, the 2024 breach-reporting duty, who counts as a financial institution, and FTC enforcement.
United States (Federal) -
HIPAA Compliance for Websites and Digital Tools
How HIPAA applies to websites, portals, and tracking technologies: covered entities, the Privacy and Security Rules, the OCR tracking guidance fight, and penalty tiers.
United States (Federal) -
Montana MTCDPA: Consumer Data Privacy Act Guide
Montana's Consumer Data Privacy Act: low thresholds for a small state, GPC recognition, the 2025 amendments expanding minors' duties, and AG enforcement.
Montana, USA -
New Hampshire Privacy Act (SB 255): What It Requires
New Hampshire's privacy law: 35,000-consumer threshold, sensitive-data consent, GPC recognition from 2025, DOJ enforcement, and how it fits the New England stack.
New Hampshire, USA -
New Jersey NJDPA: Data Privacy Act Requirements
New Jersey's Data Privacy Act: no revenue threshold, financial data as sensitive, minors to 17, rulemaking authority, and Division of Consumer Affairs enforcement.
New Jersey, USA -
New York SHIELD Act: Data Security Requirements
The SHIELD Act's reasonable-safeguards program, expanded breach notification, AG enforcement with real settlements, and how it fits New York's wider privacy stack.
New York, USA -
Oregon OCDPA: Consumer Privacy Act Requirements
Oregon's OCDPA: the right to a list of specific third parties, no entity-level GLBA exemption, nonprofit coverage, sensitive-data consent, and AG enforcement.
Oregon, USA -
Texas TDPSA: Data Privacy and Security Act Guide
The Texas Data Privacy and Security Act: near-universal applicability, sensitive-data consent, GPC recognition, the AG's aggressive enforcement, and $7,500 penalties.
Texas, USA -
Utah UCPA: Consumer Privacy Act Explained
Utah's UCPA: the most business-friendly state privacy law. Dual thresholds with a revenue floor, opt-out rights, no assessments, and AG enforcement at $7,500.
Utah, USA -
Virginia VCDPA: Consumer Data Protection Act Guide
Virginia's VCDPA explained: thresholds, consumer rights, sensitive-data consent, data protection assessments, the permanent cure period, and AG enforcement.
Virginia, USA