Updated: July 2026
144 countries now have data protection or privacy laws in effect. Cumulative GDPR fines since 2018 have passed €7.1 billion. Twenty US states have enacted their own comprehensive privacy rules, and India’s Digital Personal Data Protection Act began rolling out in late 2025.
If your business processes personal data (and almost every business does), the question is which of these laws apply to you, and how many.
This guide covers every major framework, what each one requires, and how to build a compliance programme that holds up across jurisdictions.
Global data privacy regulations are legally binding frameworks that govern how organisations collect, store, process, share and delete personal information. They establish rights for individuals over their own data and create enforceable obligations for any organisation that handles it.
The term covers a broad range of instruments: comprehensive omnibus laws such as the EU’s GDPR, sector-specific rules such as the US HIPAA for health data, state-level statutes, and regional frameworks spanning multiple countries. They vary in scope, enforcement mechanism and territorial reach, but share a common purpose: giving people meaningful control over their personal information.
The complexity comes from how far these laws reach. The GDPR applies to any organisation serving EU residents, regardless of where that organisation is based. China’s PIPL applies to cross-border processing of Chinese citizens’ data. A mid-sized SaaS company with customers in Europe, the US and India can be subject to five or six distinct legal regimes simultaneously.
Compliance has a financial case, separate from the legal one. The cost of getting it wrong consistently outweighs the cost of getting it right.

Here are the four numbers every business leader should have front of mind:
144 countries have data protection laws in effect. According to the IAPP, 144 countries now have data protection and privacy laws in force, up from roughly 100 a decade ago. For any company operating internationally, the question is which frameworks apply.
€7.1 billion in cumulative GDPR fines. European regulators issued €1.2 billion in GDPR penalties in 2025 alone, and cumulative fines since enforcement began in May 2018 now exceed €7.1 billion. Ireland’s Data Protection Commission accounts for €4.04 billion of that total; the largest cases involved Meta, WhatsApp and LinkedIn.
$10.22 million: the average cost of a US data breach. IBM’s annual cost-of-a-breach research puts the average cost of a data breach in the US at USD 10.22 million in 2025. Non-compliance adds a further $174,538 to that figure, in addition to regulatory fines.
95% of organisations report more benefits than costs. A study across 3,000+ organisations found that 95% reported a net positive return on their privacy investment, with an average payback ratio of 1.6x. The benefits include fewer breaches, reduced legal exposure and stronger customer retention.
81% of consumers factor trust into purchasing decisions. Organisations that can demonstrate how they protect data convert more, retain more, and spend less on defending against complaints.
The EU now has four main instruments in its data protection system: GDPR, the EU AI Act, the Digital Services Act and the Digital Markets Act. Each adds obligations for different types of organisations.
The GDPR came into force on 25 May 2018. Every major privacy law passed since has been compared to it. It applies to any organisation that processes the personal data of EU residents, regardless of where the organisation is headquartered.

What it covers. Personal data under the GDPR is broadly defined as any information relating to an identified or identifiable natural person. This includes names, email addresses, IP addresses, location data, cookie identifiers and health records. Special category data – covering health, race, religion, biometric data and more – requires explicit consent or another specific legal basis for processing.
Six lawful bases. Processing personal data is only permitted under one of six lawful bases: consent, contract, legal obligation, vital interests, public task or legitimate interests. Legitimate interests requires a balancing test. Most supervisory authorities have taken enforcement action against organisations that claimed legitimate interests without properly completing the balancing test.
Individual rights. Data subjects hold a set of statutory rights: access (subject access requests), rectification, erasure (“right to be forgotten”), restriction of processing, data portability and the right to object. Organisations must respond to most of these requests within one calendar month.
Accountability obligations. Controllers must maintain records of processing activities (Article 30), conduct Data Protection Impact Assessments for high-risk processing (Article 35) and appoint a Data Protection Officer where required (Articles 37-39). Cross-border transfers outside the EEA require appropriate safeguards: adequacy decisions, Standard Contractual Clauses or Binding Corporate Rules.
Fines. The GDPR has a two-tier fine structure. Less severe violations attract fines of up to €10 million or 2% of global annual turnover. The most serious breaches – violations of core principles, failure to obtain valid consent, or breaching data subject rights – can reach €20 million or 4% of global annual turnover, whichever is higher.
Breach notification. Data controllers must notify their supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to pose a risk to individuals. Affected individuals must be notified without undue delay when the breach is likely to pose a high risk.
Need help with GDPR compliance? GDPRLocal’s Compliance Hub provides ad hoc support, implementation programmes, audits, SAR management, and breach notification services. Talk to our team →
The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. It uses a risk-based approach, categorising AI systems by the level of risk they pose.
Timeline. The AI Act entered into force on 12 July 2024. Provisions phase in across four dates. The prohibition on unacceptable-risk AI applications (the eight banned practices) became enforceable on 2 February 2025. Obligations for general-purpose AI model providers (including large language models) applied from 2 August 2025, at which point non-EU providers must also appoint an Authorised AI Representative within the EU. High-risk AI system requirements – covering risk management, technical documentation, data governance and human oversight – are expected to apply from late 2026 to early 2027. Full enforcement, with national authorities and the European AI Office empowered to investigate and penalise, is expected from mid to late 2027.
What it prohibits. Eight categories of AI systems are banned outright, including social scoring by public authorities, real-time remote biometric identification in public spaces (with limited law enforcement exceptions), AI that exploits vulnerabilities related to age or disability, and systems designed to manipulate people subliminally.
High-risk AI. Systems used in recruitment, credit scoring, education assessment, access to essential services and law enforcement fall into the high-risk category. Deployers must conduct fundamental rights impact assessments, maintain logs, ensure human oversight and register systems in the EU database.
The GDPR intersection. The AI Act and GDPR both apply wherever AI processes personal data. DPIAs under GDPR and conformity assessments under the AI Act often examine the same activities. Organisations building or deploying AI systems should run these assessments in parallel.
Fines. Violations of the prohibited AI system rules carry fines of up to €35 million or 7% of global turnover. Non-compliance with other provisions may result in a fine of €15 million or 3% of global turnover.
These two regulations target online platforms and large digital gatekeepers rather than data processing in general, but their privacy implications are real.
The DSA required the largest platforms (designated Very Large Online Platforms and Very Large Online Search Engines, those with more than 45 million EU users per month) to comply as of 25 August 2023. All other platforms came into scope from 17 February 2024, with micro and small enterprises remaining exempt. The DSA requires transparency in algorithmic recommendation systems, prohibits targeting advertising based on sensitive data and bans targeted advertising directed at minors. Platforms must give users meaningful options to opt out of personalised recommendations.
The DMA covers large “gatekeeper” platforms: Google, Meta, Apple, Amazon, Microsoft and others designated by the Commission. It restricts combining personal data across services without explicit consent.
Since the UK left the EU, it has maintained a data protection regime that closely mirrors GDPR but operates independently. The UK received an EU adequacy decision in 2021, permitting free data flows from the EEA, a status currently under periodic review.
The UK GDPR applies alongside the Data Protection Act 2018 (DPA 2018). The structure mirrors EU GDPR closely: the same six lawful bases, the same individual rights, the same obligation to notify the Information Commissioner’s Office (ICO) within 72 hours of a breach and the same two-tier fine structure (up to £17.5 million or 4% of global turnover at the highest level).
Where the UK diverges from the EU:
• The UK has issued its own adequacy decisions, including the UK-US Data Bridge adopted in 2023.
• The ICO issues fewer large fines than the Irish DPC or French CNIL and has publicly stated it takes an outcomes-based approach to enforcement.
• The UK’s Data (Use and Access) Act 2024 covers smart data schemes, digital identity and data intermediaries, though core GDPR protections remain unchanged.
Organisations that previously used EU Standard Contractual Clauses for transfers from the EU to the UK should have migrated to the UK’s International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.
PECR governs electronic marketing, cookies and public electronic communications services. It works alongside UK GDPR and imposes specific requirements:
• Organisations must obtain prior consent before placing non-essential cookies or similar tracking technologies.
• Electronic marketing by email, SMS or automated calls requires prior opt-in consent (with a soft opt-in exception for existing customers).
• The ICO can fine organisations up to £500,000 for PECR breaches, in addition to UK GDPR penalties.
A reform of PECR has been discussed for several years. Any update is expected to align with the DUA Act timeline.
The United States has no federal comprehensive consumer privacy law. What exists instead is 20 state-level statutes, a patchwork of sector-specific federal laws and a Federal Trade Commission that uses its unfair and deceptive practices authority to enforce basic data protection principles.

The FTC Act prohibits unfair or deceptive practices, which regulators have applied to data protection since the early 2000s. Companies that make privacy representations they don’t honour or implement unreasonably weak security face FTC enforcement. The FTC has issued consent orders against Google, Facebook, Twitter/X and hundreds of smaller companies.
The FTC’s Health Breach Notification Rule was expanded in 2024 to cover health apps and wearables, closing a significant gap in US health data protection.
California’s California Consumer Privacy Act (CCPA), as significantly amended by the California Privacy Rights Act (CPRA), is the most robust US state privacy law. The CPRA took full effect on 1 January 2023, establishing the California Privacy Protection Agency (CPPA) as a dedicated enforcement body.
Consumer rights under CPRA: know what data is collected and how it is used; access the data; correct inaccuracies; delete data; opt out of the sale or sharing of personal information; limit the use of sensitive personal information; non-discrimination for exercising rights.
Sensitive personal information is a CPRA addition modelled on GDPR’s special categories. It covers Social Security numbers, financial account credentials, health data, precise geolocation, racial or ethnic origin, religious beliefs, union membership and the contents of private communications.
The CPPA has initiated several enforcement proceedings, with a particular focus on dark patterns in consent interfaces and compliance with opt-out mechanisms.
Following California, 19 other states have enacted comprehensive privacy laws. The wave accelerated sharply after 2022. As of June 2026:
In effect:
• Virginia – Consumer Data Protection Act (CDPA), effective 1 January 2023
• Colorado – Colorado Privacy Act (CPA), effective 1 July 2023
• Connecticut – Data Privacy Act (CTDPA), effective 1 July 2023
• Utah – Consumer Privacy Act (UCPA), effective 31 December 2023
• Texas – Data Privacy and Security Act (TDPSA), effective 1 July 2024
• Oregon – Consumer Privacy Act (OCPA), effective 1 July 2024
• Montana – Consumer Data Privacy Act (MTCDPA), effective 1 October 2024
• Iowa – Consumer Data Protection Act (ICDPA), effective 1 January 2025
• Delaware – Personal Data Privacy Act (DPDPA), effective 1 January 2025
• Nebraska – Data Privacy Act (NDPA), effective 1 January 2025
• New Hampshire – Privacy Act (NHPA), effective 1 January 2025
• New Jersey – Data Privacy Act (NJDPA), effective 15 January 2025
• Tennessee – Information Protection Act (TIPA), effective 1 July 2025
• Minnesota – Consumer Data Privacy Act (MCDPA), effective 31 July 2025
• Maryland – Online Data Privacy Act (MODPA), effective 1 October 2025
• Indiana – Consumer Data Protection Act (INCDPA), effective 1 January 2026
• Kentucky – Consumer Data Protection Act (KCDPA), effective 1 January 2026
• Rhode Island – Data Transparency and Privacy Protection Act (RIDTPPA), effective 1 January 2026
• Oklahoma – SB 546, signed March 2026
These laws share a common architecture: consumer rights, a controller/processor distinction and data minimisation principles. The differences still matter for compliance. Maryland’s MODPA takes a stricter approach to data minimisation than California’s. Minnesota includes a right to question automated decision-making. Vermont and Massachusetts have legislation in progress.
Sector-specific federal laws that still apply everywhere:
• HIPAA – health information held by covered entities and business associates
• FERPA – student education records
• COPPA – data collected from children under 13
• GLBA – financial data held by financial institutions
• FCRA – consumer credit information
Brazil, India and China have each enacted comprehensive data protection frameworks in recent years. Together they cover over 3 billion people. Cross-border transfers involving any of the three require careful legal planning.
Brazil’s LGPD entered into force in 2020, consolidating over 40 existing laws into a single framework. In January 2026, Brazil received EU adequacy status, confirming that LGPD provides a level of data protection essentially equivalent to GDPR.
Scope. The LGPD applies to any organisation that processes personal data in Brazil, offers goods or services to Brazilian individuals, or processes data collected in Brazil, regardless of the organisation’s location.
Processing principles. The LGPD establishes ten principles including purpose limitation, necessity, free access, data quality, transparency, security, prevention of harm, non-discrimination and accountability. The principles closely follow GDPR, with two notable additions: an explicit “prevention of harm” principle and enforcement handled by Brazil’s dedicated ANPD rather than existing regulators.
Legal bases. The LGPD provides ten legal bases for processing, including consent, compliance with legal obligations, legitimate interests and the protection of life. Consent must be specific, informed and free. Children’s data requires parental consent.
Individual rights. Data subjects have rights to confirmation of processing, access, correction, anonymisation or blocking, deletion, portability, information about sharing, information about refusal to consent and revocation of consent.
Penalties. The National Data Protection Authority (ANPD) can impose fines of up to 2% of revenue in Brazil in the prior financial year, capped at R$50 million per violation.
India’s DPDP Act received presidential assent in August 2023 and is the country’s first standalone data protection law. Implementing rules were notified by Parliament on 13 November 2025, triggering a phased rollout that continued into 2026.
Scope. The DPDP Act applies to the processing of digital personal data within India and to processing outside India where it relates to offering goods or services to individuals in India.
Consent-first model. The Act is built around consent as the primary legal basis. Consent must be free, specific, informed, unconditional and unambiguous. A “Consent Manager” mechanism allows individuals to manage consent through a registered intermediary.
Data fiduciaries and processors. The Act uses the terms “Data Fiduciary” (equivalent to “controller”) and “Data Processor”. “Significant Data Fiduciaries” – entities designated by the government based on volume, sensitivity, or risk – face additional obligations, including Data Protection Impact Assessments, the appointment of a Data Protection Officer, and audits.
Data localisation. The Act grants the government powers to restrict cross-border transfers to specified countries. Notifications on approved transfer destinations are anticipated through 2026.
Children’s data. Verifiable parental consent is required before processing data of anyone under 18. No behavioural monitoring or targeted advertising targeting children is permitted.
Penalties. The DPDP Act contains a penalty schedule with fines up to ₹250 crore (approximately $30 million USD) for the most serious violations.
China’s PIPL came into force in November 2021, alongside the Data Security Law (DSL) and Cybersecurity Law (CSL) to create a layered data governance regime.
Scope. The PIPL applies to any organisation that processes the personal information of individuals in China, as well as to processing outside China that relates to providing products or services to Chinese individuals or analysing their behaviour.
Lawful bases. PIPL provides several lawful bases, including consent, contract necessity, legal obligation, vital interests and legitimate interests. Consent is the most commonly used, and it must be separate and explicit for sensitive personal information.
Sensitive personal information. Sensitive data under PIPL includes biometrics, religion, medical health data, financial accounts, location tracking and the personal information of minors. Processing requires explicit consent and a prior Personal Information Protection Impact Assessment (PIPIA).
Cross-border transfers. Transfers require one of three mechanisms: (a) a security assessment approved by the Cyberspace Administration of China (CAC) for critical information infrastructure operators or those above volume thresholds; (b) a Personal Information Protection Certification; or (c) a Standard Contract filed with the CAC. As of January 2026, China has completed its cross-border transfer certification framework, providing organisations with more structured pathways.
Penalties. Fines under PIPL reach up to 50 million yuan (approximately $7 million) or 5% of annual revenue for serious violations. Responsible individuals can also face personal liability.
Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) has governed private sector data handling at the federal level since 2000. It applies to organisations that collect, use, or disclose personal information in the course of commercial activities.
PIPEDA is built on ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access and challenging compliance.
Canada’s federal privacy reform effort stalled sharply in January 2025, when Parliament was prorogued and Bill C-27 – which contained both the proposed Consumer Privacy Protection Act (CPPA) and an AI regulation component – died on the order paper without a vote. A federal election in April 2025 pushed reform further back. The government has since confirmed the bill won’t return in its original form; the AI component has been set aside entirely. Canada continues to operate under PIPEDA, which was enacted in 2000. Watch for a new, separate privacy reform bill in the coming parliamentary session, but there is no confirmed timeline as of mid-2026.
Quebec’s Law 25 (An Act Respecting the Protection of Personal Information in the Private Sector), which was fully phased in by September 2023, is the most GDPR-aligned framework of any Canadian jurisdiction. It requires privacy impact assessments, data portability, breach notification and the appointment of a Privacy Officer.
Australia’s Privacy Act 1988 applies to Australian Government agencies and private-sector organisations with annual turnover above AUD 3 million, as well as health service providers, regardless of size.
The Act includes 13 Australian Privacy Principles (APPs) governing collection, use, disclosure, quality, security, access and correction of personal information.
The Notifiable Data Breaches (NDB) Scheme requires organisations to notify the Australian Information Commissioner and affected individuals where a data breach is likely to result in serious harm.
Australia’s Privacy and Other Legislation Amendment Act 2024, passed in November 2024, significantly increased the maximum penalty for serious or repeated interference with privacy to AUD 50 million (or three times the benefit obtained or 30% of annual turnover, whichever is higher) and strengthened the OAIC’s enforcement powers. A second tranche of reforms – expected in 2026 or 2027 – is anticipated to remove the small business exemption and introduce a direct right of action for individuals. These changes have not yet been enacted; the current AUD 3 million turnover threshold still applies.
Japan’s Act on the Protection of Personal Information (APPI) was substantially amended in 2022, with the amendments taking effect on 1 April 2022. It covers organisations that handle personal information of Japanese residents, with a record retention limit for anonymised data and a mandatory breach notification requirement. Where a reportable breach occurs, organisations must file a preliminary report with the Personal Information Protection Commission (PPC) within 3 to 5 days of recognising the incident, and a final report within 30 days (60 days where the breach involved malicious activity such as a cyberattack). Notification is triggered when more than 1,000 data subjects are affected, or when the breach involves sensitive personal information or data stolen for improper purposes, regardless of the number of people affected.
South Korea’s PIPA (Personal Information Protection Act) is among the strictest in Asia-Pacific, with an opt-in consent requirement as the default lawful basis, strict data localisation provisions for sensitive data and substantial fines. South Korea received EU adequacy in December 2021.
South Africa’s POPIA (Protection of Personal Information Act) became fully enforceable in July 2021. It established the Information Regulator and introduced eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
A compliance programme needs to do two things: identify which laws apply, and operationalise the requirements across every jurisdiction where you process data.
The eight steps below apply whether you’re starting from scratch or auditing an existing programme.

You can’t protect data you don’t know you have. A data mapping exercise (sometimes called a data inventory or Record of Processing Activities under GDPR Article 30) documents:
• What personal data you hold
• Where it came from
• What it is used for
• Who has access to it
• Where it is stored (and in which country)
• How long it is retained
• Who it is shared with
This mapping exercise is the foundation of everything else in your compliance programme. It also directly satisfies the accountability obligation under Article 30 of the GDPR.
Start with your highest-risk processing – HR data, customer databases, marketing platforms – before moving to lower-risk systems.
Once you know what data you process and where, you can determine which legal frameworks apply. The key questions are:
• Where are the individuals whose data you process located?
• Where is your business established?
• What sector does your data relate to (health, finance, children)?
• What is your company’s annual turnover (relevant for Australia, PIPEDA exemptions)?
A company processing data of EU, UK, Brazilian, and California residents is simultaneously subject to the EU GDPR, UK GDPR, LGPD, and the CPRA/CCPA. Each requires a separate compliance assessment, though many obligations overlap.
Someone in your organisation must own privacy compliance. The options depend on your size and risk profile:
• In-house Data Protection Officer (DPO): Required under GDPR for public authorities, organisations engaged in large-scale systematic monitoring, or large-scale processing of special category data. Good practice for any organisation that processes substantial data.
• Outsourced DPO: An experienced third-party DPO gives you senior expertise without a full-time hire. GDPRLocal’s DPO Prime service provides a named consultant who takes accountability for your compliance programme and attends supervisory authority meetings on your behalf.
• Article 27 Representative: If you are based outside the EU or UK but process data of residents there, you are legally required to appoint a local representative. This is a distinct role from a DPO.
Not sure whether you need a DPO or a representative? Our team can assess your obligations in 30 minutes. Book a call.

Every personal data processing activity needs a documented lawful basis. Review each activity in your data map and assign one. Be specific: “legitimate interests” covers a lot of ground, but it requires a documented balancing test showing that your interests don’t override the rights and freedoms of data subjects.
Where consent is your chosen basis – particularly for marketing, cookies or non-essential processing – review whether your current consent mechanisms meet the bar: freely given, specific, informed, unambiguous and easily withdrawable.
Your privacy policy should be an honest, readable account of how you process data. Most organisations have policies that are too long, too vague or out of date.
A compliant privacy notice under GDPR should cover: the identity of the controller; the contact details of the DPO (if applicable); the purposes and legal basis for each type of processing; any third-party recipients; details of international transfers; retention periods; individual rights and how to exercise them; and the right to lodge a complaint with a supervisory authority.
Cookie consent banners must give users a genuine choice to accept or decline non-essential cookies, with equal prominence for both options. Pre-ticked boxes don’t constitute valid consent.
The GDPR, LGPD, PIPL and almost every other data protection framework require “appropriate technical and organisational security measures.” What’s appropriate depends on the nature and volume of data you process, the state of the art in security technology, the cost of implementation and the risk level.
For most organisations, the baseline should include: encryption of personal data at rest and in transit; pseudonymisation where feasible; role-based access controls; regular security testing; staff training; vendor security assessments; and incident detection and response procedures.
ISO 27001 or SOC 2 certification can demonstrate compliance with security requirements and reassure enterprise clients.
Every data protection law requires some form of breach notification, and the timescales are tight. GDPR and UK GDPR require notification to the supervisory authority within 72 hours of becoming aware. Brazil’s ANPD expects notification within a reasonable timeframe, with guidance suggesting 2 to 3 business days. India’s DPDP Act requires notification to both the Data Protection Board and affected individuals.
A documented incident response plan should cover: how to detect and assess a breach; who within the organisation decides whether notification is required; which authorities to notify and in what format; how to notify affected individuals; and how to document the breach and your response.
Running a breach simulation exercise once a year is good practice and demonstrates the “accountability” principle to regulators.
Data protection compliance is ongoing. Regulations change, your organisation’s data processing evolves, new products launch, new vendors are onboarded, and new jurisdictions become relevant.
Build in regular review cycles: a full compliance audit at least annually, a DPA/DPO review of new processing activities before they launch (not after), and ongoing monitoring of regulatory developments. Supervisory authorities issue guidance, case decisions and enforcement actions that effectively interpret the law; tracking these keeps your programme current.
The regulatory landscape is moving faster than at any point since GDPR’s introduction. Five trends define the compliance agenda for the rest of 2026 and into 2027.
The EU AI Act is in active rollout. Eight categories of AI practice were banned outright from 2 February 2025, including social scoring; real-time remote biometric identification in publicly accessible spaces (with narrow law-enforcement exceptions); AI designed to manipulate people subliminally; and systems that exploit vulnerabilities related to age, disability, or socioeconomic status. General-purpose AI model providers faced their compliance deadline on 2 August 2025. High-risk AI system requirements – including fundamental rights impact assessments, mandatory logging and human oversight – are expected to apply from late 2026 to early 2027, with full enforcement powers for national authorities from mid to late 2027. Organisations deploying AI in recruitment, credit decisions, medical diagnostics or law enforcement are in scope and should be preparing documentation and governance processes now.
Wherever AI processes personal data, obligations stack. A hiring algorithm that uses biometric assessments is subject to the GDPR (biometric data as a special category), the EU AI Act (prohibited or high-risk system depending on use), and potentially member-state employment law. Running a joint DPIA and AI conformity assessment is now the practical standard.
In the US, Colorado’s story shows how fast this space moves. The state passed a comprehensive AI Act (SB 24-205) in 2024, delayed its effective date from February to June 2026, and then, in May 2026, the legislature repealed it entirely and replaced it with a much lighter disclosure-based framework (SB 189). Other states – including Texas and California – have enacted narrower transparency and training data requirements. The US state-level picture on AI is still forming.
Regulators across Europe have made consent management their top enforcement priority for 2025-2026. The Irish DPC, the French CNIL, the Dutch AP and the German state DPAs have all issued guidance or enforcement actions targeting:
• Cookie banners where “reject” is harder to find than “accept”
• Consent obtained through a series of nudges or pre-selected options
• Consent being required for access to a service when it isn’t genuinely necessary
• Inadequate withdrawal mechanisms
If your cookie banner or consent interface was built in 2021-2022, it probably needs a review. The standard has risen significantly since then.
The 2023 EU-US Data Privacy Framework replaced the invalidated Privacy Shield, but the political environment around transatlantic data flows remains unstable. The EU-US DPF’s adequacy decision is subject to legal challenge and periodic review. Organisations that rely solely on the DPF should maintain Standard Contractual Clauses as a backup.
India’s DPDP transfer restrictions and China’s CAC security assessment requirement create real operational friction for global businesses. Data mapping must now reflect not only where data is stored but which transfer mechanism covers each flow, and whether that mechanism is current.
The UK’s Age Appropriate Design Code (Children’s Code) set the pace, and regulators in other jurisdictions have followed. The CPPA in California has designated children’s data as a priority enforcement area. India’s DPDP Act contains some of the strictest children’s data provisions globally, requiring verifiable parental consent for under-18s and prohibiting behavioural tracking of minors entirely.
For any service that might be accessed by people under 18, this means age verification or assurance processes, default privacy settings set to high and no behavioural advertising unless the service can demonstrate users are adults.
Forward-looking organisations now treat privacy as part of product design, vendor selection and procurement contracts. The compliance team reviews new processing activities before launch, not after a complaint is filed. Privacy impact assessments happen at the design stage, not when regulators ask.
Cisco’s 2025 Privacy Benchmark Study found that 99% of respondents expect to redirect some budget from privacy to AI governance. The practical question is whether that creates a compliance gap or whether privacy and AI governance are treated as a single function, as regulators increasingly expect.
A data controller is the organisation that determines the purposes and means of processing personal data. A data processor processes data on behalf of the controller, under instruction. The distinction matters because controllers bear the primary compliance obligations and liability. At the same time, processors have specific duties (particularly around security, sub-processing and breach notification) and must operate under a written contract with the controller. The same organisation can be a controller for some activities and a processor for others.
Yes. GDPR applies to any organisation that processes the personal data of individuals in the EU, regardless of where the organisation is based. If you run a website accessible to EU users, offer goods or services to people in the EU or monitor their behaviour, you fall within GDPR’s scope. Non-EU organisations without an EU establishment are also required to appoint an Article 27 Representative in an EU member state.
Since Brexit, the UK and EU operate separate but closely aligned frameworks. UK GDPR is the retained version of EU GDPR, modified by the Data Protection Act 2018 and subsequent UK legislation. The substantive rights and obligations are nearly identical. Still, they’re enforced by different regulators (ICO in the UK, national supervisory authorities in EU member states), and the UK has issued its own adequacy decisions and transfer mechanisms. Organisations operating in both markets need to comply with both frameworks and maintain separate legal bases where applicable.
Under GDPR and UK GDPR, a DPO is mandatory for: (a) public authorities; (b) organisations whose core activities require large-scale, regular and systematic monitoring of individuals; and (c) organisations whose core activities involve large-scale processing of special category data or criminal offence data. Even where not mandatory, many organisations appoint a DPO voluntarily, or use an outsourced DPO service. The DPO must be operationally independent and can’t be instructed on how to exercise their compliance duties.
A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Not every breach requires notification: the GDPR threshold for notifying a supervisory authority is whether the breach is “likely to result in a risk to the rights and freedoms of natural persons.” Breaches that are unlikely to cause harm to individuals can be documented internally without external notification. Where there is a high risk to individuals, they must also be notified directly.
Standard Contractual Clauses are pre-approved contract clauses published by the European Commission (and separately, the UK ICO) that provide a legal mechanism for transferring personal data from the EEA to third countries without an adequacy decision. Organisations using SCCs must carry out a Transfer Impact Assessment (TIA) to determine whether the legal environment in the recipient country undermines the protection the SCCs provide. The current EU SCCs were updated in June 2021; legacy contracts were required to migrate by December 2022.
The CCPA/CPRA and GDPR share broad goals (consumer rights, transparency, accountability) but differ in important ways. CCPA gives consumers a right to opt out of the “sale” of their data rather than requiring an opt-in lawful basis for most processing. GDPR requires a positive legal basis before any processing begins. CPRA’s sensitive personal information provisions are closer in spirit to GDPR’s special category rules, but the GDPR’s opt-in requirement for special categories is stricter than CPRA’s opt-out model. GDPR applies to all organisations regardless of size; CCPA has revenue and volume thresholds.
Data minimisation means collecting only the personal data that is adequate, relevant and necessary for the stated purpose. In practice: don’t collect fields “just in case” they might be useful later; build forms that ask only what the process genuinely requires; set retention periods so data is deleted when it’s no longer needed; and periodically review whether historical data still serves a legitimate purpose. Regulators increasingly scrutinise organisations that hold extensive personal data beyond their operational needs.
A DSAR is a request from an individual to receive a copy of the personal data you hold about them, along with supplementary information about how it is processed. The steps are: (1) verify the identity of the requester; (2) acknowledge receipt; (3) search across all systems and records for data relating to that individual; (4) consider any exemptions (e.g. legal professional privilege, third-party data); (5) provide the response within one calendar month (extendable by two months for complex requests with notice). Maintaining a DSAR procedure and a request log is an accountability best practice.
A DPIA is a structured assessment of the privacy risks associated with a specific high-risk processing activity before it begins. Under GDPR Article 35, DPIAs are mandatory for processing that is “likely to result in a high risk” to individuals, including systematic profiling, large-scale processing of special category data, and public area monitoring. The DPIA process identifies the nature and purpose of processing, assesses necessity and proportionality, identifies risks and mitigation measures and determines whether residual risks are acceptable. Where the DPIA identifies high risks that can’t be mitigated, prior consultation with the supervisory authority is required.
Yes, GDPR applies to organisations of all sizes. There is a limited exemption for organisations with fewer than 250 employees from the obligation to maintain written records of processing activities, but only where processing is unlikely to pose a risk to individuals’ rights, is not occasional, or does not involve special category data. Most small businesses won’t qualify for this exemption in practice. The ICO and other supervisory authorities have produced extensive guidance for small organisations, and fines are expected to be proportionate, but the obligations still apply.
International transfers of personal data from the EU or the UK without a valid legal mechanism (an adequacy decision, SCCs, BCRs, or another approved safeguard) constitute a violation of the GDPR or the UK GDPR. This is one of the most consistently enforced areas, with significant fines issued against Meta, LinkedIn and others for inadequate transfer safeguards. Regulators also have the power to issue orders prohibiting transfers entirely until adequate measures are in place.
What Is a Data Protection Officer – and Do You Need One? Covers the statutory DPO requirement, voluntary appointments, and what an outsourced DPO service delivers.
GDPR Breach Reporting: Notifiable Data Breaches and the Intricacies of Breach Notification. A detailed walkthrough of the 72-hour notification requirement, what constitutes a reportable breach, and how to structure your incident response.
GDPR at 10: A Decade of Data Protection. How GDPR reshaped global privacy law over the past 10 years, the fines that defined enforcement, and what comes next.
Need support building your compliance programme? GDPRLocal’s team of certified data protection consultants works with organisations of all sizes across every major jurisdiction. From Article 27 representation to full DPO services and compliance audits, we provide practical, accountable support.
The statistics, regulatory citations and legal references in this article are drawn from the following primary and secondary sources:
1. Data protection and privacy laws now in effect in 144 countries – IAPP
2. GDPR Enforcement Tracker Report 2025/2026: Numbers and Figures – CMS Law / GDPR Enforcement Tracker
3. GDPR Fines Hit €7.1 Billion: Data Privacy Enforcement Trends in 2026 – Kiteworks
4. 20 State Privacy Laws in Effect in 2026: Key Dates & Changes – MultiState
5. US State Comprehensive Privacy Laws Report 2025 – IAPP
6. Data Privacy Statistics 2026: 51+ Laws, Fines & Trends – StationX
7. Global Data Privacy Laws 2026: Cross-Jurisdiction Compliance Guide – Kiteworks
8. Global Data Protection Laws in 2026 – Forcepoint
9. Data Privacy in 2026: What Every Business Leader Needs to Know – Vantage Point
10. Over 150 Data Privacy Statistics Companies Need to Know About in 2026 – Usercentrics
11. The 5 Trends Shaping Global Privacy and Enforcement in 2026 – OneTrust
12. Data Privacy Trends 2026: Essential Guide for Business Leaders – SecurePrivacy
13. Privacy Laws 2026: Global Changes, Enforcement & Compliance Guide – SecurePrivacy
14. Data Privacy Laws by Country 2026 – World Population Review
15. Data Protection and Privacy Legislation Worldwide – UNCTAD
16. Privacy and Cybersecurity 2025-2026: Insights, Challenges and Trends Ahead – White & Case
17. Data Privacy, Cybersecurity and AI Developments Shaping 2026 – Nixon Peabody
18. GDPR text – EUR-Lex – Official Journal of the European Union
19. UK GDPR guidance – ICO
20. EU AI Act – full text – European Commission
21. EU AI Act implementation timeline – official dates – European Commission AI Act Service Desk
22. EU AI Act Article 5: Prohibited AI Practices – EU AI Act resource
23. Digital Services Act: now fully applicable from 17 February 2024 – Osborne Clarke
24. Japan APPI breach notification requirements – Baker McKenzie Global Data Handbook
25. Canada Bill C-27 died on order paper – prorogation impact – Fasken
26. Australia Privacy and Other Legislation Amendment Act 2024 – Kennedys Law
27. Colorado AI Act SB 24-205 repealed and replaced by SB 189 – Troutman Pepper Privacy + Cyber + AI
GDPRLocal provides data protection representation and compliance services for organisations operating in the EU, UK and beyond. This article is for informational purposes and does not constitute legal advice. For advice specific to your organisation, contact our team.
About the Author
Ana Mishova
Sales and Business Development Consultant — GDPRLocal
Ana focuses on helping organisations understand their compliance obligations and find the right data protection solutions. At GDPRLocal she works closely with businesses of all sizes, making GDPR and privacy compliance clear, practical, and accessible.