Privacy & Data Protection
Comprehensive guide to global privacy and data protection frameworks including GDPR, CCPA, and 20+ international privacy laws.
GDPR
GDPR: The Complete Guide to Compliance
The GDPR is the world's most influential data protection law, setting the standard for how organizations collect, process, and protect personal data of individuals in the EU and EEA. This guide covers lawful bases, data subject rights, breach notification, and practical compliance steps.
Learn moreADGM DPR
ADGM Data Protection Regulations: The Complete Guide
The ADGM Data Protection Regulations provide a GDPR-aligned framework governing personal data processing within Abu Dhabi's international financial free zone, establishing comprehensive data subject rights and controller obligations.
Learn moreAPPI
APPI: The Complete Guide to Japan's Data Protection Law
Japan's APPI is one of Asia's longest-standing data protection laws, recently strengthened with enhanced cross-border transfer rules, mandatory breach reporting, and expanded individual rights. The EU has recognized Japan as providing adequate protection.
Learn morePrivacy Act 1988
Australia Privacy Act 1988: The Complete Guide to Compliance
Australia's Privacy Act 1988 and its 13 Australian Privacy Principles govern how organizations collect, use, disclose, and store personal information. The Act includes the Notifiable Data Breaches scheme and is undergoing significant reform proposals.
Learn moreCCPA
CCPA: The Complete Guide to Compliance
The CCPA is California's landmark consumer privacy law granting residents the right to know, delete, and opt out of the sale of their personal information. This guide covers applicability thresholds, consumer rights, and practical compliance steps.
Learn moreCPA
CPA: The Complete Guide to Colorado Privacy Act Compliance
The Colorado Privacy Act grants residents rights over personal data and requires businesses to honor universal opt-out mechanisms, conduct data protection assessments, and obtain consent for sensitive data processing.
Learn moreCPRA
CPRA: The Complete Guide to Compliance
The CPRA amends and expands the CCPA, introducing new consumer rights, the concept of sensitive personal information, the California Privacy Protection Agency, and mandatory cybersecurity audits for high-risk businesses.
Learn moreCTDPA
CTDPA: The Complete Guide to Connecticut Data Privacy Act Compliance
The CTDPA is Connecticut's comprehensive data privacy law, closely modeled on the VCDPA and CPA, with additional provisions for universal opt-out mechanisms and loyalty program disclosures.
Learn moreDIFC DP Law
DIFC Data Protection Law: The Complete Guide to Compliance
The DIFC Data Protection Law is a GDPR-aligned framework governing the processing of personal data within Dubai's premier financial free zone. It applies to all entities operating in the DIFC and sets a high bar for data protection in the Middle East.
Learn moreDPDPA
DPDPA: The Complete Guide to India's Digital Personal Data Protection Act
India's DPDPA establishes a consent-driven framework for digital personal data protection, introducing the Data Protection Board of India for enforcement and imposing significant obligations on Data Fiduciaries processing the data of Indian residents.
Learn moreFADP (nDSG)
FADP: The Complete Guide to Switzerland's Data Protection Law
Switzerland's revised FADP modernizes the country's data protection framework to align closely with the GDPR, introducing enhanced transparency obligations, breach notification requirements, and significant personal liability for violations.
Learn moreKenya DPA
Kenya DPA: The Complete Guide to Kenya's Data Protection Act
Kenya's Data Protection Act establishes a comprehensive framework for personal data protection, creating the Office of the Data Protection Commissioner and granting individuals extensive rights over their personal data.
Learn moreKVKK
KVKK: The Complete Guide to Turkey's Data Protection Law
Turkey's KVKK is the country's comprehensive data protection law modeled on the EU Data Protection Directive, requiring consent-based processing, VERBIS registration, data subject rights, and supervised cross-border transfers.
Learn moreLGPD
LGPD: The Complete Guide to Brazil's Data Protection Law
Brazil's LGPD is a comprehensive data protection law closely modeled on the GDPR, establishing rights for data subjects, obligations for controllers and processors, and enforcement by the ANPD. This guide covers legal bases, data subject rights, and practical compliance.
Learn moreNDPA
NDPA: The Complete Guide to Nigeria's Data Protection Act
Nigeria's NDPA is Africa's largest economy's comprehensive data protection law, establishing the NDPC as the regulatory body, requiring annual audits for major data processors, and granting extensive data subject rights.
Learn morePDPA (Singapore)
PDPA Singapore: The Complete Guide to Compliance
Singapore's PDPA governs the collection, use, and disclosure of personal data by private organizations, with mandatory breach notification, DPO appointment requirements, and the Do Not Call Registry.
Learn morePDPA (Thailand)
PDPA Thailand: The Complete Guide to Compliance
Thailand's PDPA is a comprehensive data protection law modeled on the GDPR, establishing consent requirements, data subject rights, breach notification obligations, and cross-border transfer restrictions for organizations processing personal data in Thailand.
Learn morePDPL
PDPL Saudi Arabia: The Complete Guide to Compliance
Saudi Arabia's PDPL is the Kingdom's first comprehensive data protection law, establishing consent requirements, data subject rights, cross-border transfer restrictions, and the SDAIA as the supervisory authority for personal data protection.
Learn morePIPA
PIPA: The Complete Guide to South Korea's Data Protection Law
South Korea's PIPA is one of Asia's strictest data protection laws, featuring detailed consent requirements, strong individual rights, a robust pseudonymization framework, and the PIPC as an independent supervisory authority with significant enforcement powers.
Learn morePIPEDA
PIPEDA: The Complete Guide to Canada's Privacy Law
PIPEDA is Canada's federal private-sector privacy law built on ten fair information principles. It governs how commercial organizations collect, use, and disclose personal information in the course of business activities.
Learn morePIPL
PIPL: The Complete Guide to China's Personal Information Protection Law
China's PIPL is one of the world's strictest data protection laws, combining GDPR-like individual rights with stringent cross-border transfer controls, data localization requirements, and significant penalties for non-compliance.
Learn morePOPIA
POPIA: The Complete Guide to South Africa's Data Protection Law
POPIA is South Africa's comprehensive data protection law modeled on European data protection principles. It establishes eight conditions for lawful processing, data subject rights, and the Information Regulator as the supervisory authority.
Learn moreVCDPA
VCDPA: The Complete Guide to Compliance
The VCDPA is Virginia's comprehensive consumer data protection law, granting residents rights over their personal data and imposing obligations on businesses regarding data processing, consent, and protection assessments.
Learn more