Updated: August 2026
GDPR reshaped data privacy from 2018 onward, but the field hasn’t stopped evolving. Other countries built their own GDPR-influenced privacy laws, the rules for moving data out of the EU changed after a major court ruling, and the EU AI Act has added a second layer of compliance on top of GDPR for any organisation building or deploying AI systems.
• More than a dozen countries outside the EU, including the US, Brazil, South Africa, Canada, the UK, and India, have introduced their own GDPR-influenced privacy laws, though the details vary by jurisdiction.
• The Schrems II ruling reshaped EU-US data transfers, and its replacement mechanism, the EU-US Data Privacy Framework, is itself facing legal challenges that organisations relying on it should keep watching.
• The EU AI Act is now partly in force, with prohibited practices and AI literacy duties active since February 2025 and GPAI model rules active since August 2025, while the deadline for high-risk AI system obligations was pushed back to December 2027 under a 2026 amendment.
As data privacy concerns grow, countries worldwide are enacting their own privacy laws to protect citizens’ personal information. These international privacy laws are guided by five global privacy principles:

1. Notice: Informing users about the policies and measures in place to protect their personal information.
2. Choice and consent: Giving individuals control over the collection, use, and storage of their data.
3. Access and participation: Ensuring that data is accessed and used by authorised individuals within secure protocols.
4. Integrity and security: Implementing measures to protect data from unauthorised access and maintaining its integrity.
5. Enforcement: Enforcing compliance with regulations and holding organisations accountable for data protection.
The GDPR emphasised the need for data protection, focusing on mitigating risks, fraud, and compromise while protecting individuals’ rights.
Outside the EU, several major economies have introduced privacy laws that borrow heavily from GDPR’s structure, even where the details differ.
The US still has no comprehensive federal privacy law. Instead, individual states have filled the gap. California’s CCPA was the first major state privacy law and remains one of the most closely watched, but it’s no longer unusual. As of early 2026, 20 states have comprehensive consumer privacy laws in effect, including Virginia, Colorado, Connecticut, Utah, Texas, and, more recently, Indiana, Kentucky, and Rhode Island. Several of these laws now include specific protections for minors’ data, such as Connecticut’s and Oregon’s age-related restrictions on selling a minor’s personal data.
Brazil’s General Data Protection Law (LGPD) consolidated dozens of earlier data privacy rules into one framework and requires many organisations to appoint a data protection officer. Brazil’s data protection authority, the ANPD, has shifted from an educational posture to active enforcement in 2025 and 2026. Fines can reach 2% of the controller’s Brazilian revenue from the prior fiscal year, capped at BRL 50 million per infraction, and the ANPD has already used that ceiling in cases against major platforms, including a R$153.7 million sanction in August 2026 over failures in handling children’s and adolescents’ data.
South Africa’s Protection of Personal Information Act (POPIA) has been in force since 1 July 2021 and is overseen by the Information Regulator. Its standards for lawful processing, consent, and data subject rights are broadly comparable to GDPR’s.
Canada’s private sector currently operates under the Personal Information Protection and Electronic Documents Act (PIPEDA), which shares GDPR’s core principles. Federal reform has stalled twice: the previous reform bill, Bill C-27, died when Parliament was prorogued in January 2025. The government introduced a replacement, Bill C-36 (the Protecting Privacy and Consumer Data Act), in June 2026, but it hadn’t passed as of this writing, so PIPEDA remains the operative law.
The UK operated under EU GDPR until the end of the Brexit transition period, when the Data Protection Act 2018 and related regulations converted GDPR’s requirements into a UK-specific regime known as UK GDPR. The Data (Use and Access) Act 2025 has since updated that framework, receiving royal assent in June 2025. It introduces a new “recognised legitimate interests” lawful basis that skips the usual balancing assessment for certain processing activities, and it changed subject access request handling from February 2026 onward, confirming that controllers only need to carry out a reasonable and proportionate search when responding to a request. Organisations that need a UK GDPR representative should factor these changes into their compliance documentation.
India’s data protection law has moved well past the bill stage. The Digital Personal Data Protection Act was passed in 2023, and the government notified its implementing rules in November 2025, alongside the creation of the Data Protection Board of India as the enforcement authority. Compliance duties are being phased in through an 18-month rollout running to mid-2027, so organisations handling Indian personal data should expect obligations to keep coming into force through 2026 and into 2027.
Bahrain’s Data Protection Law was the first of its kind in the Gulf region, and the Philippines’ Data Privacy Act of 2012 closely follows the older EU Data Protection Directive. Australia, Nigeria, Israel, and several other jurisdictions have introduced their own frameworks too, each with its own scope and enforcement body, so a GDPR-based compliance approach needs to be checked against the specific law in each country an organisation operates in.
The 2020 Schrems II ruling struck down the EU-US Privacy Shield, the mechanism that had previously let organisations transfer personal data from the EU to the US. It required organisations to assess whether a recipient country’s laws offered protection equivalent to GDPR, and to add safeguards such as standard contractual clauses where they didn’t.
The European Commission adopted a replacement mechanism, the EU-US Data Privacy Framework, in July 2023. It has already faced its first legal test: the EU General Court dismissed a challenge to the framework in September 2025, though that ruling was appealed to the Court of Justice of the EU in October 2025 and remains pending. Separately, privacy campaigner Max Schrems has signalled that a further challenge to the framework may be coming, and questions have been raised about the framework’s oversight body, the US Privacy and Civil Liberties Oversight Board, after it lost quorum in January 2025. None of this has invalidated the framework so far, but organisations relying on it for EU-US transfers should watch how these cases develop rather than treat the current adequacy decision as permanent.
The EU AI Act is the most significant addition to the European compliance landscape since GDPR, and it sits on top of GDPR rather than replacing it. Many of the AI systems the Act regulates process personal data, so an organisation may face AI Act and GDPR obligations covering the same system at the same time.
The Act entered into force on 1 August 2024, but its requirements are phasing in over several years rather than all at once:
• 2 February 2025: bans on prohibited AI practices and AI literacy requirements began applying.
• 2 August 2025: rules on general-purpose AI (GPAI) models, governance structures, confidentiality, and penalties began applying.
• 2 December 2026: the deadline for transparency obligations covering AI-generated content, including watermarking, is now due (pushed back from August 2026 by three months).
• 2 December 2027: high-risk AI systems covering use cases like biometrics, employment decisions, credit and insurance risk scoring, and access to education now have this deadline instead of August 2026, a 16-month postponement agreed in 2026.
• 2 August 2028: high-risk AI systems embedded in already-regulated products, such as medical devices and machinery, now have this deadline instead of August 2027, a 12-month postponement.
The EU moved these deadlines because it reached political agreement in May 2026 on a “Digital Omnibus” package amending the AI Act, which entered into force on 27 July 2026. The delay gives organisations more time to prepare for high-risk system obligations, but it doesn’t change the rules already in force.
The most serious violations, such as deploying a prohibited AI practice, can draw fines of up to €35 million or 7% of global annual turnover, whichever is higher. That’s a higher ceiling than GDPR’s maximum of €20 million or 4% of turnover, which is worth noting for any organisation weighing the relative risk of AI Act versus GDPR non-compliance.
The organisations managing this landscape well tend to do a few things consistently: they map where personal data crosses borders and check that mechanism still holds up against current case law, they track which of their AI systems fall into the AI Act’s high-risk categories rather than assuming the December 2027 deadline means AI Act work can wait, and they treat new privacy laws in the countries they operate in as a live compliance question rather than a one-off legal check.
GDPR set the template, but the compliance picture has kept moving since 2018: more countries with their own privacy laws, a replacement transfer mechanism for EU-US data that’s still being tested in court, and now a second EU regulation in the AI Act that overlaps with GDPR wherever AI systems touch personal data. Staying current means tracking all of these threads together alongside the original regulation.
GDPRLocal can help you work out where GDPR and EU AI Act obligations overlap for your organisation.
GDPR remains one of the strictest and most influential frameworks, but the EU AI Act now carries a higher maximum fine (up to €35 million or 7% of global turnover, against GDPR’s €20 million or 4%) for the AI practices it covers.
No. The AI Act adds obligations specific to how AI systems are built, tested, and deployed, on top of GDPR’s existing rules on how personal data is processed. An AI system that processes personal data needs to meet both sets of requirements.
Yes, as of this writing. It survived its first legal challenge at the EU General Court in September 2025, though that decision has been appealed to the Court of Justice of the EU and further challenges have been signalled. Organisations relying on it for transfers should monitor the case law rather than assume it’s settled long-term.
Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It is not a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.