Cross-Jurisdictional Global

The Master Privacy Crosswalk: Mapping GDPR to Everything Else

How the world's major privacy laws line up: scope, lawful basis, rights, breach clocks, transfers, and penalties compared across GDPR, CCPA/CPRA, PIPL, LGPD, APPI, PIPEDA, and more, and how to use a crosswalk without being misled by it.

Regulation

GDPR and UK GDPR, CCPA/CPRA and the US state laws, PIPL, LGPD, APPI, PIPEDA and Quebec Law 25, Australia's Privacy Act, PDPA Singapore, DPDP Act India, and the wider roster

Max Penalty

Regime-specific and cumulative: GDPR to 4% of worldwide turnover, PIPL to 5% of prior-year revenue, LGPD to 2% of Brazil revenue capped at 50 million BRL per violation, CCPA to $7,500 per intentional violation

Enforcing Authority

Each regime's own regulator; no global authority harmonizes them, which is precisely why organizations build crosswalks

Official Source

www.edpb.europa.eu

Executive Summary

  • The major regimes share a recognizable skeleton (notice, basis or opt-out, rights, security, breach, transfers, accountability) descended from the same fair-information-practice ancestry, which is what makes crosswalking possible.
  • The deep structural split is consent architecture: GDPR-family laws require a lawful basis before processing; the US state family permits processing and grants opt-outs; PIPL demands separate consent for specific acts.
  • Rights converge on access, deletion, and correction everywhere, then diverge at the edges: portability, objection, ADM rights, and the US opt-outs of sale and targeted advertising.
  • Breach clocks range from 72 hours (GDPR, and now several peers) to 30-day state caps to LGPD's flexible standard, and one incident typically triggers several simultaneously.
  • A crosswalk is a control-design tool, not a compliance conclusion: it shows where one control serves many laws and flags the deltas that need jurisdiction-specific engineering.

Comparative privacy law rewards structural thinking: beneath the surface variety, nearly every modern regime is a rearrangement of the same components, notice, permission, rights, security, breach, transfers, accountability, inherited from the OECD fair-information tradition and stress-tested by the GDPR’s decade of enforcement. That shared skeleton is why one well-built program can serve dozens of statutes, and the crosswalk is the document where the sharing gets proven control by control. Its value lies equally in what it refuses to blur: the permission-architecture split between basis-first Europe and opt-out America, PIPL’s separate-consent regime, the false-friend vocabulary where identical words carry different law. Read as a map of convergence with honestly marked divergences, the crosswalk is the multinational program’s most load-bearing artifact; read as a claim that the laws are basically the same, it is how global programs quietly become GDPR programs with translation errors.

ConvergesNotice, access/deletion/correction, security, vendor contracts, breach process, records, assessments
DivergesPermission model (basis vs opt-out vs separate consent), transfers, sensitive-data definitions, ADM rights
False friends”Consent,” “sensitive,” “sale,” “deidentified” mean different things per regime
Format that worksControl x regime matrix with citations and last-verified dates, refreshed quarterly
Reference hubEuropean Data Protection Board

Using the crosswalk

Drill into the permission split. Lawful basis comparison covers the basis-versus-opt-out divide in depth.

Configure the pipelines. The data subject rights matrix and global breach notification rules parameterize the two clock-driven machines.

Handle the corridors. Cross-border data transfers turns the transfer column into per-corridor decisions.

Run it as one program. Building a global privacy program is the operating model the crosswalk feeds.

See how your own website’s practices measure against the converged baseline with a free scan.

Frequently Asked Questions

Where do the major regimes actually align closely enough for one control to serve all?

Seven areas of real convergence. Transparency: every regime requires a notice describing categories collected, purposes, recipients, rights, and contact routes (GDPR Articles 13-14 being the most prescriptive, so a GDPR-grade layered notice, localized, satisfies the family). Data subject access, deletion, and correction: present in GDPR, all US state laws, PIPL, LGPD, APPI (with its 2020-amendment strengthening), PIPEDA, and the DPDP Act; one fulfillment pipeline with per-regime deadline and verification parameters covers them. Security obligations: universally phrased as reasonable/appropriate measures scaled to risk (GDPR Article 32, CCPA's reasonable security via its private right of action, PIPL Article 51, LGPD Article 46), so one security program with evidence serves all. Processor/vendor contracts: GDPR Article 28's term set is the superset; contracts written to it satisfy state-law service-provider requirements, LGPD operator arrangements, and APPI supervision duties. Breach response existence: every regime requires a process and some notification; the clocks differ but the machine is one. Accountability records: Article 30 records, LGPD Article 37, PIPL's processing records, and the documentation the state AGs request in sweeps are the same inventory rendered differently. Impact assessments: GDPR DPIAs, state data protection assessments (Colorado and Connecticut make them mandatory for targeted advertising, sale, profiling, and sensitive data), Quebec PIAs, PIPL's PIPIA, and LGPD's RIPD are one analytical exercise with different paper outputs; run once, render per regime. The practical upshot: roughly 70-80% of program machinery is genuinely shared, which is the entire economic argument for a unified program over per-country silos.

What is the deep split between the GDPR family and the US model?

Permission architecture, and it changes system design. The GDPR family (EU/UK, and structurally LGPD, PIPL, Korea's PIPA, Quebec's regime): processing personal data is prohibited unless justified by a lawful basis, consent, contract, legal obligation, vital interests, public task, or legitimate interests under GDPR Article 6, with the basis chosen and documented before processing begins, special categories requiring an additional Article 9 gate, and consent when used carrying the strict Article 7 standard (freely given, specific, informed, withdrawable). The US model (CCPA/CPRA and the state family): processing is generally permitted with notice; the individual's power is the opt-out, of sale, of sharing/targeted advertising, of profiling in significant decisions, plus opt-in only for narrow zones (sensitive data in some states, minors, financial incentives); enforcement then polices the notice's truthfulness (FTC deception doctrine) and the opt-out's functionality (the Sephora settlement over ignored GPC signals). Engineering consequences of the split: a GDPR system needs basis metadata on processing activities and consent state that gates collection; a US system needs sale/share classification on data flows and opt-out signals that propagate to downstream recipients, including automatic honoring of the Global Privacy Control in California, Colorado, and a growing list; a global system needs both, keyed by user jurisdiction. PIPL's third way deserves its own note: nominally consent-based like the GDPR but stricter in kind, requiring separate (not bundled) consent for sensitive processing, cross-border transfers, public disclosure, and provision to other handlers, with fewer alternative bases (no legitimate-interests equivalent), which is why 'GDPR-compliant' consent flows routinely fail PIPL review. The crosswalk lesson: notice and rights crosswalk cleanly across the split; the permission layer does not, and pretending it does is the most common crosswalk error.

How do the rights catalogs compare regime by regime?

The universal core: access (what data, plus purpose/recipient metadata in the GDPR family), deletion (with regime-specific exception lists, legal obligations and claims everywhere, CCPA's longer enumerated list), and correction (GDPR Article 16, every state law, APPI, PIPEDA's accuracy principle). The strong-but-not-universal tier: portability (GDPR Article 20's structured machine-readable right, mirrored in CCPA's access format requirement, LGPD, and Quebec's Law 25 portability which took effect July 2024); objection and restriction (GDPR Articles 21 and 18, including the absolute direct-marketing objection, with weaker analogues elsewhere, APPI's cease-of-use rights strengthened in 2022, PIPEDA's consent-withdrawal); and automated-decision rights (GDPR Article 22's right not to be subject to solely automated significant decisions, state-law profiling opt-outs in Colorado, Connecticut, Virginia and peers, CCPA's arriving ADMT regulations, PIPL Article 24's explanation-and-refusal right). The US-specific layer: opt-out of sale (CCPA's original innovation), of sharing for cross-context behavioral advertising (CPRA), of targeted advertising (Virginia/Colorado formulation), each with universal-signal mechanics that have no GDPR equivalent (GDPR handles adtech through the consent gate instead). The mechanical differences that trip fulfillment teams: clocks (one month GDPR extendable, 45 days most US states extendable, 15 days LGPD, 'promptly' in APPI), verification standards (proportionality doctrine in Europe, tiered verification and agent-request rules in the CCPA regulations), fee rules (free first copy nearly everywhere, manifestly-excessive exceptions), and scope of 'personal information' itself (household data in CCPA, inferences explicitly included, publicly-available-data carve-outs that vary). A rights matrix keyed on right x regime x parameter (deadline, verification tier, exceptions, format) is the single most-used artifact a crosswalk produces, because it configures the DSAR pipeline directly.

How do breach notification and transfer rules compare?

Breach: the GDPR set the 72-hour authority standard (Article 33, with Article 34 individual notice for high risk), and the world has been converging toward it, LGPD requires ANPD and subject notice within a reasonable period that ANPD regulation has firmed toward 3 working days, PIPL requires immediate remedial action and notification, India's DPDP and its rules point to tight reporting to the Data Protection Board plus CERT-In's separate 6-hour cyber-incident rule, Australia's NDB scheme runs on 'as soon as practicable' assessment within 30 days, Quebec requires CAI and individual notice for serious injury risk, and the US states run from 'without unreasonable delay' to hard 30-day (Colorado, Florida) and 45-day caps with AG thresholds, while HIPAA's 60 days and the SEC's four-business-day materiality disclosure overlay by sector and listing status. Design consequence: one incident-response plan with a jurisdiction-matrix step, not per-country plans. Transfers: the GDPR's Chapter V architecture (adequacy, SCCs with transfer impact assessments post-Schrems II, BCRs, the EU-US DPF for certified importers) is the reference model; the UK mirrors it with the IDTA/Addendum and its own DPF extension; LGPD copies the structure (adequacy, clauses, ANPD's 2024 SCC regulation); PIPL is materially stricter, CAC security assessment for CIIOs and volume thresholds, Chinese SCCs with filing, or certification, plus separate consent, with the 2024 facilitation rules easing low-volume cases; APPI requires consent or equivalent-protection arrangements with disclosure about the destination regime; PIPEDA runs on accountability-through-contract rather than transfer approval; and localization mandates (Russia, Chinese CIIO data, sectoral rules in India, Indonesia, Vietnam) sit outside any crosswalk cell as hard constraints. The transfer crosswalk's practical form is a corridor table: origin regime x destination x mechanism x paperwork, attached to the vendor register, because transfers are where 'roughly equivalent' regimes stop being interchangeable.

How should a crosswalk be built and used without it becoming misleading?

Build it at the control level, not the statute level: rows are your controls and obligations (notice content, basis/opt-out handling, each right, breach clock, vendor terms, assessment triggers, transfer mechanism, records), columns are regimes, cells record the requirement's parameters and cite the provision; this orientation answers the operative question, 'does our control satisfy this regime,' where statute-oriented summaries only answer 'what does this law say.' Source it from primary text and regulator guidance, dated: crosswalks decay fast (the CPRA regulations, PIPL's transfer facilitation, Quebec's phased dates, India's commencement, and the EU AI Act's staged application have each invalidated older comparison tables), so every cell carries a citation and a last-verified date, and a quarterly refresh owned by counsel is part of the artifact's definition. Respect the false-friend problem, the crosswalk's characteristic failure: terms that look equivalent and are not, 'consent' (GDPR's granular standard versus PIPEDA's implied-consent doctrine versus PIPL's separate consent), 'sensitive data' (Article 9's closed list versus CPRA's category including geolocation and account credentials versus PIPL's risk-based definition covering finance and location), 'sale' (CCPA's broad valuable-consideration definition catching adtech flows that no other regime labels a sale), 'deidentified' (HIPAA's safe harbor versus GDPR's anonymization threshold, which is far stricter); good crosswalks mark these cells loudly rather than letting the table's grid imply equivalence. Use ISO 27701's annex mappings and the NIST Privacy Framework's crosswalks as scaffolding (both publish regime mappings that save construction effort), then localize. And keep the artifact honest about its role: it identifies where one control serves many regimes and where deltas need engineering or legal judgment, it does not conclude compliance, the cell says 'Article 28 terms satisfy Colorado's processor requirements,' and a lawyer confirmed that once, for your facts, on a date the cell records.

Regulatory Crosswalk

GDPRCCPA/CPRAPIPLLGPDAPPIPIPEDAISO/IEC 27701

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.