Where do the major regimes actually align closely enough for one control to serve all?
Seven areas of real convergence. Transparency: every regime requires a notice describing categories collected, purposes, recipients, rights, and contact routes (GDPR Articles 13-14 being the most prescriptive, so a GDPR-grade layered notice, localized, satisfies the family). Data subject access, deletion, and correction: present in GDPR, all US state laws, PIPL, LGPD, APPI (with its 2020-amendment strengthening), PIPEDA, and the DPDP Act; one fulfillment pipeline with per-regime deadline and verification parameters covers them. Security obligations: universally phrased as reasonable/appropriate measures scaled to risk (GDPR Article 32, CCPA's reasonable security via its private right of action, PIPL Article 51, LGPD Article 46), so one security program with evidence serves all. Processor/vendor contracts: GDPR Article 28's term set is the superset; contracts written to it satisfy state-law service-provider requirements, LGPD operator arrangements, and APPI supervision duties. Breach response existence: every regime requires a process and some notification; the clocks differ but the machine is one. Accountability records: Article 30 records, LGPD Article 37, PIPL's processing records, and the documentation the state AGs request in sweeps are the same inventory rendered differently. Impact assessments: GDPR DPIAs, state data protection assessments (Colorado and Connecticut make them mandatory for targeted advertising, sale, profiling, and sensitive data), Quebec PIAs, PIPL's PIPIA, and LGPD's RIPD are one analytical exercise with different paper outputs; run once, render per regime. The practical upshot: roughly 70-80% of program machinery is genuinely shared, which is the entire economic argument for a unified program over per-country silos.
What is the deep split between the GDPR family and the US model?
Permission architecture, and it changes system design. The GDPR family (EU/UK, and structurally LGPD, PIPL, Korea's PIPA, Quebec's regime): processing personal data is prohibited unless justified by a lawful basis, consent, contract, legal obligation, vital interests, public task, or legitimate interests under GDPR Article 6, with the basis chosen and documented before processing begins, special categories requiring an additional Article 9 gate, and consent when used carrying the strict Article 7 standard (freely given, specific, informed, withdrawable). The US model (CCPA/CPRA and the state family): processing is generally permitted with notice; the individual's power is the opt-out, of sale, of sharing/targeted advertising, of profiling in significant decisions, plus opt-in only for narrow zones (sensitive data in some states, minors, financial incentives); enforcement then polices the notice's truthfulness (FTC deception doctrine) and the opt-out's functionality (the Sephora settlement over ignored GPC signals). Engineering consequences of the split: a GDPR system needs basis metadata on processing activities and consent state that gates collection; a US system needs sale/share classification on data flows and opt-out signals that propagate to downstream recipients, including automatic honoring of the Global Privacy Control in California, Colorado, and a growing list; a global system needs both, keyed by user jurisdiction. PIPL's third way deserves its own note: nominally consent-based like the GDPR but stricter in kind, requiring separate (not bundled) consent for sensitive processing, cross-border transfers, public disclosure, and provision to other handlers, with fewer alternative bases (no legitimate-interests equivalent), which is why 'GDPR-compliant' consent flows routinely fail PIPL review. The crosswalk lesson: notice and rights crosswalk cleanly across the split; the permission layer does not, and pretending it does is the most common crosswalk error.
How do the rights catalogs compare regime by regime?
The universal core: access (what data, plus purpose/recipient metadata in the GDPR family), deletion (with regime-specific exception lists, legal obligations and claims everywhere, CCPA's longer enumerated list), and correction (GDPR Article 16, every state law, APPI, PIPEDA's accuracy principle). The strong-but-not-universal tier: portability (GDPR Article 20's structured machine-readable right, mirrored in CCPA's access format requirement, LGPD, and Quebec's Law 25 portability which took effect July 2024); objection and restriction (GDPR Articles 21 and 18, including the absolute direct-marketing objection, with weaker analogues elsewhere, APPI's cease-of-use rights strengthened in 2022, PIPEDA's consent-withdrawal); and automated-decision rights (GDPR Article 22's right not to be subject to solely automated significant decisions, state-law profiling opt-outs in Colorado, Connecticut, Virginia and peers, CCPA's arriving ADMT regulations, PIPL Article 24's explanation-and-refusal right). The US-specific layer: opt-out of sale (CCPA's original innovation), of sharing for cross-context behavioral advertising (CPRA), of targeted advertising (Virginia/Colorado formulation), each with universal-signal mechanics that have no GDPR equivalent (GDPR handles adtech through the consent gate instead). The mechanical differences that trip fulfillment teams: clocks (one month GDPR extendable, 45 days most US states extendable, 15 days LGPD, 'promptly' in APPI), verification standards (proportionality doctrine in Europe, tiered verification and agent-request rules in the CCPA regulations), fee rules (free first copy nearly everywhere, manifestly-excessive exceptions), and scope of 'personal information' itself (household data in CCPA, inferences explicitly included, publicly-available-data carve-outs that vary). A rights matrix keyed on right x regime x parameter (deadline, verification tier, exceptions, format) is the single most-used artifact a crosswalk produces, because it configures the DSAR pipeline directly.
How do breach notification and transfer rules compare?
Breach: the GDPR set the 72-hour authority standard (Article 33, with Article 34 individual notice for high risk), and the world has been converging toward it, LGPD requires ANPD and subject notice within a reasonable period that ANPD regulation has firmed toward 3 working days, PIPL requires immediate remedial action and notification, India's DPDP and its rules point to tight reporting to the Data Protection Board plus CERT-In's separate 6-hour cyber-incident rule, Australia's NDB scheme runs on 'as soon as practicable' assessment within 30 days, Quebec requires CAI and individual notice for serious injury risk, and the US states run from 'without unreasonable delay' to hard 30-day (Colorado, Florida) and 45-day caps with AG thresholds, while HIPAA's 60 days and the SEC's four-business-day materiality disclosure overlay by sector and listing status. Design consequence: one incident-response plan with a jurisdiction-matrix step, not per-country plans. Transfers: the GDPR's Chapter V architecture (adequacy, SCCs with transfer impact assessments post-Schrems II, BCRs, the EU-US DPF for certified importers) is the reference model; the UK mirrors it with the IDTA/Addendum and its own DPF extension; LGPD copies the structure (adequacy, clauses, ANPD's 2024 SCC regulation); PIPL is materially stricter, CAC security assessment for CIIOs and volume thresholds, Chinese SCCs with filing, or certification, plus separate consent, with the 2024 facilitation rules easing low-volume cases; APPI requires consent or equivalent-protection arrangements with disclosure about the destination regime; PIPEDA runs on accountability-through-contract rather than transfer approval; and localization mandates (Russia, Chinese CIIO data, sectoral rules in India, Indonesia, Vietnam) sit outside any crosswalk cell as hard constraints. The transfer crosswalk's practical form is a corridor table: origin regime x destination x mechanism x paperwork, attached to the vendor register, because transfers are where 'roughly equivalent' regimes stop being interchangeable.
How should a crosswalk be built and used without it becoming misleading?
Build it at the control level, not the statute level: rows are your controls and obligations (notice content, basis/opt-out handling, each right, breach clock, vendor terms, assessment triggers, transfer mechanism, records), columns are regimes, cells record the requirement's parameters and cite the provision; this orientation answers the operative question, 'does our control satisfy this regime,' where statute-oriented summaries only answer 'what does this law say.' Source it from primary text and regulator guidance, dated: crosswalks decay fast (the CPRA regulations, PIPL's transfer facilitation, Quebec's phased dates, India's commencement, and the EU AI Act's staged application have each invalidated older comparison tables), so every cell carries a citation and a last-verified date, and a quarterly refresh owned by counsel is part of the artifact's definition. Respect the false-friend problem, the crosswalk's characteristic failure: terms that look equivalent and are not, 'consent' (GDPR's granular standard versus PIPEDA's implied-consent doctrine versus PIPL's separate consent), 'sensitive data' (Article 9's closed list versus CPRA's category including geolocation and account credentials versus PIPL's risk-based definition covering finance and location), 'sale' (CCPA's broad valuable-consideration definition catching adtech flows that no other regime labels a sale), 'deidentified' (HIPAA's safe harbor versus GDPR's anonymization threshold, which is far stricter); good crosswalks mark these cells loudly rather than letting the table's grid imply equivalence. Use ISO 27701's annex mappings and the NIST Privacy Framework's crosswalks as scaffolding (both publish regime mappings that save construction effort), then localize. And keep the artifact honest about its role: it identifies where one control serves many regimes and where deltas need engineering or legal judgment, it does not conclude compliance, the cell says 'Article 28 terms satisfy Colorado's processor requirements,' and a lawyer confirmed that once, for your facts, on a date the cell records.