Data Privacy Laws Worldwide: An Orientation Guide
Last reviewed: 18 August 2026. This page is an orientation guide to the data privacy laws most likely to apply to a European or international organisation. It is not legal advice, and the detail changes constantly. Where a figure or date matters to a decision, verify it against the regulator or the official text before relying on it. Several entries below carry explicit warnings where sources genuinely disagree.
Start here: which laws apply to you
Most privacy laws now reach beyond their own borders. The practical test is rarely where your company is registered. It is usually some combination of: where the people whose data you hold are located, whether you offer them goods or services, and whether you monitor their behaviour. A German company with no US presence can fall under a US state law. A US company with no European office falls under the GDPR the moment it markets to people in the EU.
The second thing worth knowing is that the obligations converge far more than the statutes do. Almost all of these laws require you to know what personal data you hold, delete it on request, keep it no longer than necessary, secure it, and report breaches within a deadline. If you build the capability to do those five things, you are most of the way to compliance with any of them.
Quick reference
| Jurisdiction | Law | Applies from | Extraterritorial | Headline maximum penalty |
|---|---|---|---|---|
| European Union | GDPR (DSGVO) | 25 May 2018 | Yes | EUR 20m or 4% of global turnover |
| United Kingdom | UK GDPR + DPA 2018, as amended by the Data (Use and Access) Act 2025 | 2018; DUAA fully in force 19 Jun 2026 | Yes | GBP 17.5m or 4% |
| Switzerland | Revised FADP / nDSG | 1 Sep 2023 | Yes | CHF 250,000, levied on the individual |
| California | CCPA as amended by CPRA | 2020; CPRA from 2023 | Applies by activity | USD 7,988 per intentional violation |
| Brazil | LGPD | 18 Sep 2020 | Yes | 2% of Brazilian revenue, capped at BRL 50m |
| China | PIPL | 1 Nov 2021 | Yes | RMB 50m or 5% of turnover |
| India | DPDP Act 2023 | Rules notified Nov 2025, 18-month runway | Yes | INR 250 crore |
| Saudi Arabia | PDPL | Enforceable 14 Sep 2024 | Yes | SAR 5m, doubled for repeat |
| South Africa | POPIA | 1 Jul 2021 | Yes | ZAR 10m and/or 10 years |
| Nigeria | NDPA 2023 | 14 Jun 2023 | Yes | NGN 10m or 2% of gross revenue |
| Australia | Privacy Act 1988, first reform tranche 2024 | 1989; tort from Jun 2025 | Yes | AUD 50m, 3x benefit, or 30% of turnover |
Europe
GDPR, European Union
Regulation (EU) 2016/679, in German the Datenschutz-Grundverordnung or DSGVO. Applicable since 25 May 2018. Article 3(2) catches controllers and processors outside the EU that offer goods or services to, or monitor the behaviour of, people in the EU.
Fines run in two tiers: up to EUR 10 million or 2% of total worldwide annual turnover for most procedural failures, and up to EUR 20 million or 4% for breaches of the core principles and data subject rights. In both cases the higher of the two figures applies.
United Kingdom
The UK GDPR and the Data Protection Act 2018 both remain in force. The Data (Use and Access) Act 2025 amends rather than replaces them; it received Royal Assent in June 2025 and its data protection provisions were fully in force by 19 June 2026. It introduces a “recognised legitimate interests” lawful basis, relaxes some automated decision-making rules, adds cookie consent exemptions, and codifies “stop the clock” and reasonable-and-proportionate search rules for subject access requests. Maximum fines are unchanged at GBP 17.5 million or 4%.
Note for anyone tracking older commentary: this Act is the successor to the Data Protection and Digital Information Bill, which fell at the 2024 general election.
Switzerland
The fully revised Federal Act on Data Protection, in German the DSG, has applied since 1 September 2023. Switzerland is a genuine outlier in how it enforces. The maximum fine is CHF 250,000, which is modest by European standards, but it is a criminal penalty imposed on the responsible natural person rather than an administrative fine on the company. That can be any employee who intentionally breached, not only a director. An employer may not lawfully pay the individual’s fine, and directors’ and officers’ policies typically do not cover it. Only where the fine would not exceed CHF 50,000 and identifying the individual would take disproportionate effort may the authority fine the undertaking instead.
NIS2, and why it is not a privacy law
Directive (EU) 2022/2555 is a cybersecurity directive, not a data protection one, and it is frequently miscategorised. It imposes risk-management and incident-reporting duties on essential and important entities across 18 critical sectors, and it applies alongside the GDPR rather than instead of it.
The transposition deadline was 17 October 2024 and many Member States missed it. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice in July 2026. Because obligations bite through national law, both timing and detail still vary by country. Ceilings are EUR 10 million or 2% of turnover for essential entities and EUR 7 million or 1.4% for important ones, and Member States may set higher figures.
EU AI Act
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases. The timeline was formally amended in July 2026 by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026.
Already in force and enforceable: the prohibited practices in Article 5 since 2 February 2025, and the general-purpose AI model obligations since 2 August 2025. The Article 50 transparency obligations apply from 2 August 2026.
Deferred by the amendment: stand-alone high-risk systems under Annex III moved from 2 August 2026 to 2 December 2027, and high-risk AI embedded in regulated products under Annex I moved from 2 August 2027 to 2 August 2028. A new prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material applies from December 2026, and the window for deploying content-marking solutions was in fact shortened.
The accurate summary is deferred, not cancelled, and only for the high-risk tiers. Saying the AI Act has been delayed, without qualification, is wrong. Penalties were not changed: up to EUR 35 million or 7% of turnover for breaching the prohibitions.
EU Data Act
Regulation (EU) 2023/2854 has applied since 12 September 2025. It governs access to data generated by connected products, unfair terms in business-to-business data sharing, and cloud switching and egress fees. Penalties are set nationally rather than at EU level, and where a breach also involves personal data the GDPR ceilings can apply.
United States
There is still no federal comprehensive privacy law
The United States regulates privacy sectorally at federal level, through laws such as HIPAA for health data and COPPA for children, and comprehensively at state level. That means compliance is a patchwork rather than a single obligation.
How many states have comprehensive laws
As of August 2026: 20 state laws are in force, and 24 have been enacted. The four enacted but not yet effective are Louisiana and Oklahoma from 1 January 2027, Alabama from 1 May 2027, and Vermont from 1 January 2028.
Treat any bare headline number with suspicion, including ours. Trackers disagree because they differ on whether Florida’s Digital Bill of Rights counts as comprehensive, given its roughly USD 1 billion revenue threshold means it covers very few businesses, and on when in a legislative session each new law is logged. Published counts in 2026 have ranged from 19 to 24 depending on definition and date. The split of “in force” and “enacted” is the defensible way to state it.
The 20 currently in force: California, Virginia, Colorado, Connecticut, Utah, Texas, Florida, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island.
California, CCPA as amended by CPRA
Applies to for-profit entities doing business in California that meet any one of three thresholds: annual gross revenue above USD 26,625,000 in the preceding calendar year; buying, selling or sharing the personal information of 100,000 or more California consumers or households; or deriving 50% or more of annual revenue from selling or sharing personal information.
Penalties are USD 2,663 per violation and USD 7,988 per intentional violation or one involving a consumer under 16, plus a private right of action for certain breaches. These figures are adjusted for inflation in odd-numbered years only. The current values took effect on 1 January 2025 and remain correct throughout 2026; the next adjustment is due 1 January 2027.
HIPAA
HIPAA is sectoral. It applies to covered entities, meaning health plans, healthcare clearinghouses and healthcare providers transmitting health information electronically, and to their business associates. It does not apply to most software vendors unless they act as a business associate.
Per-violation minimums effective 28 January 2026 run from USD 145 for no knowledge, through USD 1,461 for reasonable cause and USD 14,602 for willful neglect corrected within 30 days, to USD 73,011 for uncorrected willful neglect. Criminal penalties reach USD 250,000 and 10 years’ imprisonment.
One honest caveat: the annual caps are genuinely ambiguous. HHS applies enforcement-discretion figures from 2019 in practice but has never formally amended the regulation, so the indexed statutory caps and the applied caps differ. Anyone relying on a specific annual cap should take advice rather than a published figure.
Rest of world
Brazil, LGPD
In force since 18 September 2020, with sanctions enforceable by the ANPD since 1 August 2021. Applies extraterritorially where the purpose is offering goods or services to people in Brazil or where the data was collected there. Fines reach 2% of the group’s Brazilian revenue for the last financial year, capped at BRL 50 million per infringement, alongside daily fines, publicity of the violation and suspension of processing.
India, DPDP Act 2023
Commonly misreported as being in force since 2023. It is not. The Act received assent in August 2023 but awaited rules. The Digital Personal Data Protection Rules were notified on 14 November 2025 with an eighteen-month phased compliance period, which places the principal substantive obligations around mid-2027. The framework is notified and the transition is running, but the core duties on data fiduciaries are not yet fully enforceable. Penalties reach INR 250 crore for failing to take reasonable security safeguards.
China, PIPL
In force since 1 November 2021, with extraterritorial reach under Article 3 over processing outside China aimed at people in China. Entities caught by it must appoint a local representative. Ordinary violations reach RMB 1 million; grave violations reach RMB 50 million or 5% of prior-year turnover, plus suspension of business. Directly responsible individuals face personal fines and possible bans from senior roles.
Canada
PIPEDA has governed the federal private sector since 2001 and still does. Bill C-27, which would have introduced the CPPA, died when Parliament was prorogued in January 2025 and was not revived. On 15 June 2026 the government tabled Bill C-36, the Protecting Privacy and Consumer Data Act, which would recognise privacy as a fundamental right and create a new commission with order-making and penalty powers. It is a bill, not law. Under PIPEDA as it stands there are no administrative fines and the Privacy Commissioner has no order-making power.
Saudi Arabia, PDPL
Effective 14 September 2023 and fully enforceable by SDAIA since 14 September 2024. Reaches entities outside the Kingdom processing data of residents. Administrative fines reach SAR 5 million, doubled for repeat offences, with criminal liability for unauthorised disclosure of sensitive data.
Asia-Pacific and Africa in brief
Japan. The APPI has applied since 2005 and was substantially amended in 2020. A further amendment bill was approved by Cabinet in April 2026 and submitted to the Diet, but has not passed.
South Korea. PIPA has applied since 2011. A significant overhaul was promulgated in March 2026 and takes effect on 11 September 2026, adding a punitive tier of up to 10% of total turnover for repeated intentional violations and for breaches affecting ten million or more people, plus personal accountability for chief executives. If you are reading this after mid-September 2026, that regime is live.
Australia. The Privacy Act 1988 was amended by a first reform tranche in December 2024, which created a statutory tort for serious invasions of privacy, commenced in June 2025. Serious or repeated interferences carry the greater of AUD 50 million, three times the benefit obtained, or 30% of adjusted turnover. A second tranche remains proposed.
South Africa. POPIA has been fully enforceable since 1 July 2021, with fines to ZAR 10 million and up to 10 years’ imprisonment. The Information Regulator has issued its first ZAR 5 million fine.
Nigeria. The NDPA 2023 applies extraterritorially. For controllers and processors of major importance, sanctions are the greater of NGN 10 million or 2% of the preceding year’s gross revenue.
What is changing right now
The GDPR itself is under negotiation. The European Commission adopted a Digital Omnibus package in November 2025 which would amend the GDPR: narrowing the definition of personal data so that pseudonymised data is treated as non-personal in the hands of an entity unable to re-identify it, adding an express legitimate-interest basis for training AI systems, moving cookie consent rules out of the ePrivacy Directive, and raising breach-notification thresholds.
It has not been adopted and is currently stalled. The EDPB and EDPS objected in February 2026 that the personal-data redefinition goes far beyond a targeted amendment. The Council failed to reach a qualified majority in June 2026 and the file passed to the Irish Presidency without a general approach. Nothing in the GDPR has changed. Treat every current obligation as fully applicable while watching the file.
The five obligations that recur almost everywhere
Whatever the statute, the same technical capabilities keep being required:
- Know what personal data you hold and where. You cannot delete, export or secure what you cannot find.
- Delete it on request. The right to erasure or its equivalent appears in the GDPR, LGPD, PIPL, the DPDP Act and most US state laws.
- Provide it on request. Access and portability rights are near universal.
- Keep it no longer than necessary. Storage limitation is a principle in most of these regimes, not an optional extra.
- Report breaches within a deadline. Usually 72 hours in Europe, with variations elsewhere.
For organisations running Jira and Confluence, the first of those is usually the hard one, because personal data accumulates in ticket descriptions, comments, attachments and page history rather than in tidy database fields. If that is your situation, our guides on finding personal data in Confluence and handling erasure requests in Jira Cloud cover the practical side.
Frequently asked questions
Does the GDPR apply to companies outside the EU?
Yes, where they offer goods or services to people in the EU or monitor their behaviour. Physical presence in the EU is not required and is not the test.
How many US states have privacy laws?
Twenty are in force as of August 2026 and twenty-four have been enacted. Published counts vary because trackers define “comprehensive” differently, so always check the date and definition behind any figure.
Is NIS2 a data protection law?
No. It is a cybersecurity directive covering network and information system security in critical sectors. It applies alongside the GDPR, not instead of it.
Has the EU AI Act been delayed?
Partly. High-risk obligations were deferred to December 2027 and August 2028 by an amending regulation in July 2026, but the prohibitions and the general-purpose AI rules are already in force and enforceable, and transparency obligations apply from August 2026.
Is India’s DPDP Act in force?
Not fully. Rules were notified in November 2025 with an eighteen-month phased runway, placing the main obligations around mid-2027.
Which law has the largest fines?
By headline percentage, the EU AI Act at 7% of global turnover, ahead of the GDPR at 4%. South Korea’s amended PIPA reaches 10% of total turnover for repeated serious violations once it commences in September 2026. Headline maximums are rarely imposed, so they are a poor guide to actual risk.
Using this page
Privacy law moves quickly, and several entries above are dated within weeks of publication. This page was last reviewed on 18 August 2026. Where a date, threshold or penalty matters to a decision, confirm it against the regulator or the official text, and take advice on how it applies to your organisation. Actonic builds data protection software; we are not a law firm, and nothing here is legal advice.