The Future of Data Protection Beyond GDPR

The Future of Data Protection: Beyond GDPR

Updated: August 2026

GDPR reshaped data privacy from 2018 onward, but the field hasn’t stopped evolving. Other countries built their own GDPR-influenced privacy laws, the rules for moving data out of the EU changed after a major court ruling, and the EU AI Act has added a second layer of compliance on top of GDPR for any organisation building or deploying AI systems.

Key Takeaways

More than a dozen countries outside the EU, including the US, Brazil, South Africa, Canada, the UK, and India, have introduced their own GDPR-influenced privacy laws, though the details vary by jurisdiction.

The Schrems II ruling reshaped EU-US data transfers, and its replacement mechanism, the EU-US Data Privacy Framework, is itself facing legal challenges that organisations relying on it should keep watching.

The EU AI Act is now partly in force, with prohibited practices and AI literacy duties active since February 2025 and GPAI model rules active since August 2025, while the deadline for high-risk AI system obligations was pushed back to December 2027 under a 2026 amendment.

The Evolution of International Privacy Laws

As data privacy concerns grow, countries worldwide are enacting their own privacy laws to protect citizens’ personal information. These international privacy laws are guided by five global privacy principles:

international privacy laws
International Privacy Laws

1. Notice: Informing users about the policies and measures in place to protect their personal information.

2. Choice and consent: Giving individuals control over the collection, use, and storage of their data.

3. Access and participation: Ensuring that data is accessed and used by authorised individuals within secure protocols.

4. Integrity and security: Implementing measures to protect data from unauthorised access and maintaining its integrity.

5. Enforcement: Enforcing compliance with regulations and holding organisations accountable for data protection.

The GDPR emphasised the need for data protection, focusing on mitigating risks, fraud, and compromise while protecting individuals’ rights.

Which Countries Have Adopted GDPR-Style Privacy Laws?

Outside the EU, several major economies have introduced privacy laws that borrow heavily from GDPR’s structure, even where the details differ.

What Privacy Laws Exist in the United States?

The US still has no comprehensive federal privacy law. Instead, individual states have filled the gap. California’s CCPA was the first major state privacy law and remains one of the most closely watched, but it’s no longer unusual. As of early 2026, 20 states have comprehensive consumer privacy laws in effect, including Virginia, Colorado, Connecticut, Utah, Texas, and, more recently, Indiana, Kentucky, and Rhode Island. Several of these laws now include specific protections for minors’ data, such as Connecticut’s and Oregon’s age-related restrictions on selling a minor’s personal data.

What Is Brazil’s LGPD?

Brazil’s General Data Protection Law (LGPD) consolidated dozens of earlier data privacy rules into one framework and requires many organisations to appoint a data protection officer. Brazil’s data protection authority, the ANPD, has shifted from an educational posture to active enforcement in 2025 and 2026. Fines can reach 2% of the controller’s Brazilian revenue from the prior fiscal year, capped at BRL 50 million per infraction, and the ANPD has already used that ceiling in cases against major platforms, including a R$153.7 million sanction in August 2026 over failures in handling children’s and adolescents’ data.

What Is South Africa’s POPIA?

South Africa’s Protection of Personal Information Act (POPIA) has been in force since 1 July 2021 and is overseen by the Information Regulator. Its standards for lawful processing, consent, and data subject rights are broadly comparable to GDPR’s.

What Is Canada’s Privacy Law Reform?

Canada’s private sector currently operates under the Personal Information Protection and Electronic Documents Act (PIPEDA), which shares GDPR’s core principles. Federal reform has stalled twice: the previous reform bill, Bill C-27, died when Parliament was prorogued in January 2025. The government introduced a replacement, Bill C-36 (the Protecting Privacy and Consumer Data Act), in June 2026, but it hadn’t passed as of this writing, so PIPEDA remains the operative law.

What Is the UK’s Data Protection Framework?

The UK operated under EU GDPR until the end of the Brexit transition period, when the Data Protection Act 2018 and related regulations converted GDPR’s requirements into a UK-specific regime known as UK GDPR. The Data (Use and Access) Act 2025 has since updated that framework, receiving royal assent in June 2025. It introduces a new “recognised legitimate interests” lawful basis that skips the usual balancing assessment for certain processing activities, and it changed subject access request handling from February 2026 onward, confirming that controllers only need to carry out a reasonable and proportionate search when responding to a request. Organisations that need a UK GDPR representative should factor these changes into their compliance documentation.

What Is India’s Data Protection Law?

India’s data protection law has moved well past the bill stage. The Digital Personal Data Protection Act was passed in 2023, and the government notified its implementing rules in November 2025, alongside the creation of the Data Protection Board of India as the enforcement authority. Compliance duties are being phased in through an 18-month rollout running to mid-2027, so organisations handling Indian personal data should expect obligations to keep coming into force through 2026 and into 2027.

What Other Countries Have Introduced Privacy Laws?

Bahrain’s Data Protection Law was the first of its kind in the Gulf region, and the Philippines’ Data Privacy Act of 2012 closely follows the older EU Data Protection Directive. Australia, Nigeria, Israel, and several other jurisdictions have introduced their own frameworks too, each with its own scope and enforcement body, so a GDPR-based compliance approach needs to be checked against the specific law in each country an organisation operates in.

What Happened After the Schrems II Ruling?

The 2020 Schrems II ruling struck down the EU-US Privacy Shield, the mechanism that had previously let organisations transfer personal data from the EU to the US. It required organisations to assess whether a recipient country’s laws offered protection equivalent to GDPR, and to add safeguards such as standard contractual clauses where they didn’t.

The European Commission adopted a replacement mechanism, the EU-US Data Privacy Framework, in July 2023. It has already faced its first legal test: the EU General Court dismissed a challenge to the framework in September 2025, though that ruling was appealed to the Court of Justice of the EU in October 2025 and remains pending. Separately, privacy campaigner Max Schrems has signalled that a further challenge to the framework may be coming, and questions have been raised about the framework’s oversight body, the US Privacy and Civil Liberties Oversight Board, after it lost quorum in January 2025. None of this has invalidated the framework so far, but organisations relying on it for EU-US transfers should watch how these cases develop rather than treat the current adequacy decision as permanent.

What Does the EU AI Act Mean for Data Protection?

The EU AI Act is the most significant addition to the European compliance landscape since GDPR, and it sits on top of GDPR rather than replacing it. Many of the AI systems the Act regulates process personal data, so an organisation may face AI Act and GDPR obligations covering the same system at the same time.

What Is the Timeline for EU AI Act Compliance?

The Act entered into force on 1 August 2024, but its requirements are phasing in over several years rather than all at once:

• 2 February 2025: bans on prohibited AI practices and AI literacy requirements began applying.

• 2 August 2025: rules on general-purpose AI (GPAI) models, governance structures, confidentiality, and penalties began applying.

• 2 December 2026: the deadline for transparency obligations covering AI-generated content, including watermarking, is now due (pushed back from August 2026 by three months).

• 2 December 2027: high-risk AI systems covering use cases like biometrics, employment decisions, credit and insurance risk scoring, and access to education now have this deadline instead of August 2026, a 16-month postponement agreed in 2026.

• 2 August 2028: high-risk AI systems embedded in already-regulated products, such as medical devices and machinery, now have this deadline instead of August 2027, a 12-month postponement.

The EU moved these deadlines because it reached political agreement in May 2026 on a “Digital Omnibus” package amending the AI Act, which entered into force on 27 July 2026. The delay gives organisations more time to prepare for high-risk system obligations, but it doesn’t change the rules already in force.

What Are the Penalties Under the EU AI Act?

The most serious violations, such as deploying a prohibited AI practice, can draw fines of up to €35 million or 7% of global annual turnover, whichever is higher. That’s a higher ceiling than GDPR’s maximum of €20 million or 4% of turnover, which is worth noting for any organisation weighing the relative risk of AI Act versus GDPR non-compliance.

How Should Organisations Prepare for What’s Next?

The organisations managing this landscape well tend to do a few things consistently: they map where personal data crosses borders and check that mechanism still holds up against current case law, they track which of their AI systems fall into the AI Act’s high-risk categories rather than assuming the December 2027 deadline means AI Act work can wait, and they treat new privacy laws in the countries they operate in as a live compliance question rather than a one-off legal check.

Conclusion

GDPR set the template, but the compliance picture has kept moving since 2018: more countries with their own privacy laws, a replacement transfer mechanism for EU-US data that’s still being tested in court, and now a second EU regulation in the AI Act that overlaps with GDPR wherever AI systems touch personal data. Staying current means tracking all of these threads together alongside the original regulation.

GDPRLocal can help you work out where GDPR and EU AI Act obligations overlap for your organisation.

Frequently Asked Questions

Is GDPR still the strictest data protection law?

GDPR remains one of the strictest and most influential frameworks, but the EU AI Act now carries a higher maximum fine (up to €35 million or 7% of global turnover, against GDPR’s €20 million or 4%) for the AI practices it covers.

Does the EU AI Act replace GDPR for AI systems?

No. The AI Act adds obligations specific to how AI systems are built, tested, and deployed, on top of GDPR’s existing rules on how personal data is processed. An AI system that processes personal data needs to meet both sets of requirements.

Is the EU-US Data Privacy Framework still valid?

Yes, as of this writing. It survived its first legal challenge at the EU General Court in September 2025, though that decision has been appealed to the Court of Justice of the EU and further challenges have been signalled. Organisations relying on it for transfers should monitor the case law rather than assume it’s settled long-term.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It is not a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.