Legal information, not legal advice. Every jurisdiction page carries its verification status and sources.

All legal topicstechnology

Data Protection & Privacy

Data protection has become the most extraterritorial area of regulation: a company can owe duties in a jurisdiction it has never physically entered. Consent standards, transfer mechanisms and breach deadlines are the operative differences.

How 20 jurisdictions handle this

Reviewed· 2026-08-02

GDPR through the DSG, supervised by the Datenschutzbehörde

Data protection rests on the GDPR, supplemented by the Austrian Data Protection Act (DSG), which uniquely elevates a core right to data protection to constitutional rank. The Datenschutzbehörde is the single national supervisory authority for both the public and private sectors.

Key rules

  • Processing requires a GDPR lawful basis; the DSG adds national rules, including on employee and image data.
  • The DSG contains a constitutionally ranked fundamental right to data protection (§1).
  • Breaches presenting a risk must be notified to the Datenschutzbehörde, in principle within 72 hours.

Governing law

  • General Data Protection Regulation (Regulation (EU) 2016/679)
  • Data Protection Act (Datenschutzgesetz, DSG)National implementation; constitutional data-protection right

Consequences

  • GDPR fines up to EUR 20 million or 4% of worldwide annual turnover
  • Orders and processing bans from the Datenschutzbehörde

Austria's early practice favoured warnings over fines for first infringements, though enforcement has firmed up. The constitutional ranking of §1 DSG means a data-protection claim can, in principle, reach the Constitutional Court.

Full Austria portal
Reviewed· 2026-08-02

GDPR applied through the 2018 framework act and a Litigation Chamber

The GDPR applies directly, with the Act of 30 July 2018 filling in the margins the Regulation leaves to member states. The Data Protection Authority replaced the former Privacy Commission in 2018 and, unlike its predecessor, has a Litigation Chamber able to issue binding orders and fines.

Key rules

  • Children can consent to information-society services from the age of 13 in Belgium.
  • Public-sector bodies are largely exempt from administrative fines, which are instead directed at private controllers.
  • Federal public authorities must appoint a data protection officer.
  • Personal data breaches must be notified to the authority within 72 hours where the risk threshold is met.

Governing law

  • General Data Protection Regulation (Regulation (EU) 2016/679)
  • Act on the protection of natural persons with regard to the processing of personal data (30 July 2018)
  • Act establishing the Data Protection Authority (3 December 2017)

Consequences

  • Administrative fines up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher
  • Orders to bring processing into compliance, suspend transfers or erase data

Complaints must be in writing and in one of the national languages; the Litigation Chamber first tests admissibility and often closes cases through a settlement or a reprimand rather than a fine. A separate civil claim for damages goes to the ordinary courts, not the authority.

Full Belgium portal
Reviewed· 2026-08-03

LGPD, closely modelled on the GDPR

The Lei Geral de Proteção de Dados applies to processing connected to Brazil regardless of where the controller sits. The ANPD supervises and has been issuing sanctions since 2023.

Key rules

  • Ten lawful bases, including legitimate interest and protection of credit.
  • Data subjects have access, correction, portability, anonymisation and deletion rights.
  • A DPO (encarregado) must be appointed and publicly identified.

Governing law

  • Lei 13.709/2018 (LGPD)

Consequences

  • Up to 2% of Brazilian revenue capped at R$50 million per infraction

The ANPD's early enforcement has focused on small controllers with no DPO and no privacy notice, so the basics matter more than sophisticated documentation.

Full Brazil portal
Reviewed· 2026-08-03

The GDPR applied through the loi Informatique et Libertés, policed by the CNIL

France applies the GDPR alongside its pioneering 1978 Data Protection Act. The CNIL, the world's oldest data-protection regulator, supervises compliance and issues some of Europe's largest fines.

Key rules

  • The GDPR is directly applicable; the loi Informatique et Libertés fills national margins.
  • The CNIL can impose fines up to 4% of worldwide turnover.
  • Specific French rules govern health data and the numéro de sécurité sociale.

Governing law

  • Règlement général sur la protection des données (RGPD) (2016)
  • Loi Informatique et Libertés (1978)

Consequences

  • Administrative fines up to EUR 20m or 4% of global turnover
  • Formal notices and processing bans

The CNIL has led enforcement on cookies and advertising identifiers, so consent banners are a frequent audit target.

Full France portal
Gambia

Mixed (common law, customary law, Sharia)

Indexed· 2026-08-03

The Data Protection and Privacy Act 2023 created The Gambia's first general regime

The Data Protection and Privacy Act 2023 established a comprehensive framework and a Data Protection and Privacy Commission. It requires a lawful basis for processing, grants data subject rights, imposes security and breach obligations, and restricts cross-border transfers — replacing a prior position of no general statute.

Key rules

  • Jurisdiction — Data Protection and Privacy Commission; appeals to the High Court.

Governing law

  • Data Protection and Privacy Act, 2023 — First general regime; creates the Commission; transfer restrictions and breach notification.
  • Information and Communications Act, 2009 — Sectoral communications regulation.

Before 2023 The Gambia had no general data protection law, relying on constitutional privacy under s.23 and the Information and Communications Act 2009. The Data Protection and Privacy Act 2023 changed that, establishing the Data Protection and Privacy Commission as regulator with registration, investigation and enforcement functions. It sets processing principles of lawfulness, purpose limitation, minimisation, accuracy, storage limitation, integrity and accountability; recognises consent, contract, legal obligation, vital interests, public interest and legitimate interests as bases; grants rights of access, rectification, erasure, restriction, objection and portability; and imposes security measures and breach notification duties. Cross-border transfers require adequacy, appropriate safeguards or a statutory derogation. Because the Act is recent, subsidiary regulations and the Commission's operational capacity are still developing, so practitioners should verify the commencement and registration position for a given obligation.

Full Gambia portal
Reviewed· 2026-08-03

GDPR with strict German additions on employee data

The GDPR applies directly, supplemented by the BDSG. Germany layers on works-council involvement and a lower threshold for appointing a data protection officer.

Key rules

  • A DPO is mandatory where 20 or more people are regularly engaged in automated processing.
  • Employee monitoring generally requires a works agreement.
  • Sixteen state authorities plus the federal authority share supervision.

Governing law

  • Bundesdatenschutzgesetz
  • EU GDPR (Regulation 2016/679)

Consequences

  • Up to €20 million or 4% of global turnover

Because supervision is decentralised, the competent authority depends on the establishment's Land, and their published guidance is not always identical.

Full Germany portal
Ghana

Mixed (common law and customary law)

Reviewed· 2026-08-03

Data Protection Act 2012 with a registration duty for data controllers

The Data Protection Act 2012 (Act 843) establishes the Data Protection Commission and requires every data controller to register with it. Processing must satisfy statutory principles, data subjects have access and correction rights, and cross-border transfers require adequate protection at the destination.

Key rules

  • Jurisdiction — Data Protection Commission; appeals and prosecutions in the High Court.

Governing law

  • Data Protection Act, 2012 (Act 843) — Mandatory controller registration; eight principles; adequacy test for transfers.

Act 843 predates the GDPR and follows the earlier European model. It sets eight principles — accountability, lawfulness, specification of purpose, compatibility, quality, openness, security safeguards and data subject participation. Registration of data controllers with the Data Protection Commission is mandatory and renewable, and processing without registration is an offence, which distinguishes Ghana from jurisdictions where registration is risk-based. Consent is a principal basis, with exceptions for contract, legal obligation, vital interests and public functions. Sensitive personal data attracts stricter conditions. Section 18 restricts foreign transfers unless the recipient jurisdiction provides adequate protection. Enforcement powers include compliance notices and prosecution, though the Commission's practical capacity has been the subject of criticism, and there is no revenue-linked administrative fine of the GDPR type.

Full Ghana portal
India

Common law with personal-law pluralism

Reviewed· 2026-08-03

Digital Personal Data Protection Act 2023, phased into force

The DPDP Act replaces the earlier IT Rules framework with a consent-centred regime supervised by a Data Protection Board. Rules bringing provisions into force are being notified in stages.

Key rules

  • Consent notices must be available in English and the languages of the Eighth Schedule.
  • Significant data fiduciaries face additional audit and DPO obligations.
  • Transfers are permitted except to countries the government restricts by notification.

Governing law

  • Digital Personal Data Protection Act 2023
  • Information Technology Act 2000

Consequences

  • Up to ₹250 crore per breach of security safeguards

Because commencement is phased, the operative question for any given obligation is whether its rule has actually been notified yet.

Full India portal
Japan

Civil law with common-law influence

Reviewed· 2026-08-03

APPI with EU adequacy in both directions

The Act on the Protection of Personal Information is enforced by the Personal Information Protection Commission. Japan and the EU recognise each other as adequate, easing transfers.

Key rules

  • Leakage incidents likely to harm individual rights must be reported to the PPC.
  • Third-party transfers generally require consent, with an opt-out route for some business operators.
  • Pseudonymously processed information has a relaxed regime for internal analysis.

Governing law

  • Act on the Protection of Personal Information (Act No. 57 of 2003)

Consequences

  • Up to ¥100 million for corporations failing to comply with a PPC order

The PPC prefers guidance and corrective orders over fines, but the 2022 amendments materially raised corporate exposure.

Full Japan portal
Liberia

Mixed (American common law and customary law)

Indexed· 2026-08-03

No general data protection statute; constitutional privacy and sectoral rules only

Liberia has not enacted comprehensive data protection legislation and has no data protection authority. Privacy protection rests on article 16 of the Constitution, telecommunications regulation by the LTA, and confidentiality duties on financial institutions supervised by the Central Bank of Liberia.

Key rules

  • Jurisdiction — No dedicated authority; constitutional claims in the Civil Law Courts; LTA and CBL for their licensees.

Governing law

  • Constitution of Liberia, 1986, art 16 — Privacy of communications and the home.
  • Telecommunications Act, 2007 — LTA regulatory powers over licensees.

The material fact recorded here is absence. There is no statute establishing processing principles, lawful bases, data subject rights, breach notification or transfer restrictions, and no supervisory authority. Article 16 of the 1986 Constitution protects the privacy of communications and the home, enforceable in the courts. The Telecommunications Act 2007 gives the Liberia Telecommunications Authority regulatory powers over licensees including consumer protection and some subscriber information duties. The Financial Institutions Act and Central Bank regulations impose banking secrecy and know-your-customer obligations, which operate as data rules in the financial sector without generalising. Draft data protection and cybercrime bills have appeared in national ICT policy documents and been the subject of stakeholder consultation, but none is in force, so organisations processing Liberian personal data rely on contract, sectoral licence conditions and general tort principles.

Full Liberia portal
Reviewed· 2026-08-02

GDPR through the EEA, supervised by a national Data Protection Authority

As an EEA member, Liechtenstein applies the GDPR, incorporated through the EEA Agreement and implemented by a national Data Protection Act. The Data Protection Authority (Datenschutzstelle) supervises compliance and cooperates within the European data-protection framework.

Key rules

  • The GDPR applies via the EEA Agreement, supplemented by the national Data Protection Act.
  • High-risk breaches must be notified to the Datenschutzstelle in principle within 72 hours.
  • The Datenschutzstelle advises, investigates complaints and can order corrective measures.

Governing law

  • General Data Protection Regulation (Regulation (EU) 2016/679)Applicable via the EEA Agreement
  • Data Protection Act (Datenschutzgesetz)National implementation

Consequences

  • GDPR fines up to EUR 20 million or 4% of worldwide annual turnover
  • Corrective orders and processing restrictions from the Datenschutzstelle

Because Liechtenstein has a large financial and trust sector, data-protection and confidentiality duties interact closely with financial-services regulation. EEA membership keeps the regime aligned with the EU.

Full Liechtenstein portal
Reviewed· 2026-08-02

GDPR supervised by the CNPD, the regulator of a major data-hosting hub

Data protection follows the GDPR, with a national implementing law of 1 August 2018. The National Commission for Data Protection (CNPD) supervises compliance and matters especially because Luxembourg hosts significant EU data-processing and financial infrastructure.

Key rules

  • Processing requires a GDPR lawful basis and must respect transparency and data-minimisation duties.
  • High-risk breaches must be notified to the CNPD, in principle within 72 hours.
  • The CNPD investigates complaints, issues guidance and can impose GDPR fines.

Governing law

  • General Data Protection Regulation (Regulation (EU) 2016/679)
  • Law of 1 August 2018 on data protectionNational implementation of the GDPR

Consequences

  • GDPR fines up to EUR 20 million or 4% of worldwide annual turnover
  • Corrective orders and processing limitations from the CNPD

Because Luxembourg is a base for many EU financial and technology operations, the CNPD acts as lead supervisory authority in a number of cross-border cases. Public bodies are exempt from administrative fines under national law.

Full Luxembourg portal
Reviewed· 2026-08-02

A national data-protection law overseen by the APDP

As a non-EU state, Monaco does not apply the GDPR directly but has its own data-protection law, modernised to align with European standards. The Personal Data Protection Authority (APDP) supervises processing by both public and private bodies.

Key rules

  • Processing of personal data is governed by Monaco's national data-protection law, not the GDPR.
  • The APDP supervises compliance, handles complaints and can order corrective measures.
  • The law has been reformed to move Monaco closer to European (GDPR-equivalent) standards.

Governing law

  • Law on the protection of personal dataNational law overseen by the APDP

Consequences

  • Corrective orders and sanctions from the APDP
  • Liability for unlawful processing of personal data

Because Monaco is outside the EU, transfers to and from the Principality raise adequacy and safeguard questions that businesses must manage. Alignment with European standards is an ongoing policy goal.

Full Monaco portal
Reviewed· 2026-08-02

GDPR applied through the UAVG and supervised by the Autoriteit Persoonsgegevens

Data protection is governed directly by the EU General Data Protection Regulation, with the Dutch GDPR Implementation Act (UAVG) filling in national choices. The Autoriteit Persoonsgegevens supervises, investigates and fines, and was an early and active enforcer among EU regulators.

Key rules

  • Processing requires one of the six GDPR lawful bases; consent must be freely given, specific and revocable.
  • Personal data breaches must be notified to the Autoriteit Persoonsgegevens without undue delay, in principle within 72 hours.
  • Data subjects have rights of access, rectification, erasure, portability and objection, exercisable against the controller.

Governing law

  • General Data Protection Regulation (Regulation (EU) 2016/679)
  • GDPR Implementation Act (UAVG) (2018)National implementing choices under the GDPR

Consequences

  • Administrative fines up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher
  • Orders, reprimands and processing bans imposed by the Autoriteit Persoonsgegevens

The regulator publishes sector guidance and has fined both public bodies and large platforms. A Data Protection Officer is mandatory for public authorities and for controllers whose core activities involve large-scale monitoring.

Full Netherlands portal
Nigeria

Mixed (common law, customary law, Sharia)

Reviewed· 2026-08-03

The Nigeria Data Protection Act 2023 created a statutory commission and replaced the 2019 regulation

The NDPA 2023 is Nigeria's first primary data protection statute, superseding the NDPR 2019 issued by NITDA. It establishes the Nigeria Data Protection Commission, requires a lawful basis for processing, mandates data protection officers for higher-risk controllers, and provides for sanctions calculated on gross annual revenue.

Key rules

  • Jurisdiction — Nigeria Data Protection Commission; enforcement orders reviewable in the Federal High Court.

Governing law

  • Nigeria Data Protection Act, 2023 — Creates the NDP Commission; registration for controllers of major importance; revenue-based penalties.
  • Nigeria Data Protection Regulation, 2019 — Predecessor NITDA instrument.

Before 2023 Nigerian data protection rested on the Nigeria Data Protection Regulation 2019, a subsidiary instrument of NITDA whose legal foundation was contested. The Nigeria Data Protection Act 2023 puts the framework on a statutory footing and creates the Nigeria Data Protection Commission as an independent regulator with investigative and enforcement powers. It sets out lawful bases including consent, contract, legal obligation, vital interests and legitimate interests; requires that consent be freely given, specific and revocable; and grants data subject rights of access, rectification, erasure, restriction, objection and portability. Controllers of major importance must register with the Commission and appoint a data protection officer. Cross-border transfers require an adequate destination or an approved mechanism. Sanctions for data controllers of major importance can reach the greater of a fixed sum or 2% of gross annual revenue in the preceding year.

Full Nigeria portal
Sierra Leone

Mixed (common law and customary law)

Indexed· 2026-08-03

No comprehensive data protection statute; sectoral rules and a cybersecurity act apply

Sierra Leone has not enacted a general data protection law. Personal data is addressed indirectly through the Cybersecurity and Cybercrime Act 2021, the constitutional privacy guarantee, and sectoral banking and telecommunications rules, so there is no data protection authority or general lawful-basis requirement.

Key rules

  • Jurisdiction — No dedicated authority; High Court under s.28 for constitutional privacy claims; sector regulators for their licensees.

Governing law

  • Cybersecurity and Cybercrime Act, 2021 — Criminal offences and investigatory powers; not a data protection framework.
  • Constitution of Sierra Leone, 1991 (s.22 — Privacy of home and correspondence.)

The atlas records the absence of a general regime as the material fact. The Cybersecurity and Cybercrime Act 2021 criminalises unauthorised access, interception and data interference and creates investigatory powers, but it is a criminal statute rather than a data protection framework: it does not establish processing principles, data subject rights or a supervisory authority. Section 22 of the Constitution protects the privacy of home and property and correspondence, enforceable under s.28. The Bank of Sierra Leone imposes customer confidentiality duties on financial institutions, and NATCOM regulates telecommunications operators including some subscriber data obligations. Drafting of a comprehensive data protection bill has been reported in successive digital strategy documents but no Act is in force, so cross-border transfer restrictions and breach notification duties of the GDPR type do not apply.

Full Sierra Leone portal
Reviewed· 2026-08-03

PDPA with mandatory breach notification

The Personal Data Protection Act governs private-sector data use and is enforced by the PDPC. Amendments in 2020 introduced mandatory breach notification and a higher financial cap.

Key rules

  • Notifiable breaches must be reported to the PDPC within three calendar days of assessment.
  • The Do Not Call registry restricts marketing to Singapore telephone numbers.
  • Consent may be deemed or exempted for legitimate interests in defined situations.

Governing law

  • Personal Data Protection Act 2012

Consequences

  • Up to 10% of annual Singapore turnover or S$1 million, whichever is higher

The PDPC publishes detailed decisions, so its expectations on access controls and vendor management are unusually easy to research.

Full Singapore portal
Reviewed· 2026-08-02

A revised FADP since 2023, aligned with the GDPR but enforced without regulator fines

The totally revised Federal Act on Data Protection entered into force on 1 September 2023, modernising Swiss law and bringing it closer to the GDPR. The Federal Data Protection and Information Commissioner (FDPIC) supervises and can issue binding orders, but it cannot itself impose fines: penalties are criminal and pursued by the cantons against responsible individuals.

Key rules

  • Processing must be lawful, proportionate and transparent, with a duty to inform when personal data is collected.
  • Data breaches presenting a high risk must be reported to the FDPIC as soon as possible.
  • Enforcement is criminal: wilful breaches such as failing to inform or breaching due-diligence duties can lead to fines of up to CHF 250,000 imposed on the responsible individual.

Governing law

  • Federal Act on Data Protection (FADP / nFADP) (2023)Total revision in force 1 September 2023

Consequences

  • Fines up to CHF 250,000 imposed on responsible individuals for wilful breaches
  • Binding orders from the FDPIC (but no administrative fines by the regulator)

The Swiss model differs sharply from the GDPR in that the regulator cannot fine companies directly; liability targets individuals through the criminal route, which changes how compliance risk is assessed. An EU adequacy decision covers transfers to Switzerland.

Full Switzerland portal
Reviewed· 2026-08-03

UK GDPR plus the Data Protection Act 2018

The UK retained the GDPR framework after leaving the EU. The ICO supervises compliance and the regime remains recognised as adequate by the European Commission.

Key rules

  • Processing requires one of six lawful bases; consent must be freely given, specific and revocable.
  • Personal data breaches likely to risk individual rights must be reported to the ICO within 72 hours.
  • Data subject access requests must be answered within one month, extendable by two for complex cases.

Governing law

  • UK GDPR
  • Data Protection Act 2018

Consequences

  • Up to £17.5 million or 4% of global annual turnover, whichever is higher

The ICO publishes enforcement outcomes and tends to escalate through warnings and reprimands before fining, which makes documented remediation genuinely valuable.

Full United Kingdom portal
Reviewed· 2026-08-03

Sectoral federal rules plus comprehensive state statutes

There is no general federal privacy statute. Health data (HIPAA), financial data (GLBA) and children's data (COPPA) are regulated separately, while comprehensive obligations come from state law led by California.

Key rules

  • The CCPA/CPRA gives California residents access, deletion, correction and opt-out-of-sale rights.
  • The FTC polices unfair or deceptive privacy practices under Section 5 of the FTC Act.
  • Breach notification is governed by all 50 states, with differing deadlines and thresholds.

Governing law

  • California Consumer Privacy Act as amended by CPRA (Cal. Civ. Code § 1798.100)
  • HIPAA Privacy Rule (45 C.F.R. Part 164)

Consequences

  • Up to $7,500 per intentional CCPA violation
  • FTC consent decrees with 20-year compliance monitoring

Compliance is usually built to the strictest applicable state standard and then applied nationally, because maintaining fifty separate data flows is more expensive than levelling up.

Full United States portal

Related step-by-step procedures