Rättskällor med officiella primärkällor

Utskrivet ·

Hoppa till innehåll
Hoppa till svaret

Global privacy laws compared

Eight privacy regimes side by side: the GDPR, the UK GDPR, California's CCPA as amended by the CPRA, China's PIPL, India's DPDP Act, Brazil's LGPD, Japan's APPI and South Africa's POPIA. Same six dimensions for each, and every row cited to the official text.

The comparison

Regimes
8
Dimensions
Scope, rights, transfers, sanction, authority
Read date
2026-08-26
RegimeScopeTransfersMax sanctionAuthority
GDPRAny controller or processor, anywhere, that targets or monitors people in the Union.Chapter V: adequacy decisions, standard contractual clauses, binding corporate rules.Up to 20 million euro or 4 percent of global turnover.National supervisory authorities, coordinated by the EDPB.
UK GDPRControllers and processors targeting or monitoring people in the United Kingdom.UK adequacy regulations and the UK addendum to the EU standard contractual clauses.Up to 17.5 million pounds or 4 percent of global turnover.Information Commissioner's Office (ICO).
CCPA / CPRAFor-profit businesses above revenue, volume or data-sale thresholds that serve California residents.No general transfer restriction; contracts with service providers and contractors do the work.Up to 7,500 dollars per intentional violation, plus a private right of action for breaches.California Privacy Protection Agency (CPPA) and the Attorney General.
PIPLProcessing in China, and processing abroad that targets people in China with products, services or analysis.CAC security assessment, standard contract or certification; separate consent required per transfer.Up to 50 million yuan or 5 percent of the previous year's turnover.Cyberspace Administration of China (CAC) with sector regulators.
DPDP ActDigital personal data processed in India, and processing abroad connected to offering goods or services in India.Open by default: transfers allowed to any country the central government has not blacklisted.Up to 250 crore rupees per significant breach category.Data Protection Board of India.
LGPDProcessing in Brazil, or processing aimed at offering goods or services to people in Brazil.Adequacy, standard contractual clauses and specific corporate rules, modelled on the EU.Up to 2 percent of revenue in Brazil, capped at 50 million reais per infraction.Autoridade Nacional de Proteção de Dados (ANPD).
APPIBusiness operators handling personal information, including foreign operators targeting people in Japan.Consent, or recipient-side systems equivalent to Japanese standards; Japan holds EU adequacy.Orders and fines up to 100 million yen for corporations breaching orders.Personal Information Protection Commission (PPC).
POPIAProcessing in South Africa by public and private bodies, with limited exclusions.Recipient must be bound by law, binding corporate rules or agreement at a substantially similar level.Fines up to 10 million rand or imprisonment for serious offences.Information Regulator of South Africa.

GDPR — European Union and EEA

The GDPR is the reference regime: extraterritorial scope, six legal bases, a full catalogue of data subject rights and the strictest transfer rules in the comparison. Almost every later regime borrows its vocabulary, and most compliance programmes start here and map outward.

Individual rights: Access, rectification, erasure, restriction, portability, objection, and protection against solely automated decisions.

Regulation (EU) 2016/679, EUR-Lex · Read the GDPR article by article in our register

UK GDPR — United Kingdom

The UK GDPR is the EU regulation as retained and amended in domestic law after Brexit. The substance still tracks the EU original closely, but adequacy, transfers and enforcement now run on UK instruments, so a programme built for the Union needs a parallel UK mapping.

Individual rights: Mirrors the GDPR catalogue, with UK-specific exemptions.

Data Protection Act 2018, legislation.gov.uk

CCPA / CPRA — California, United States

The CCPA, as amended by the CPRA, is an opt-out regime rather than a consent regime: the consumer's core power is to stop sale and sharing, not to approve collection in advance. It reaches fewer businesses than the GDPR but gives California the first dedicated privacy regulator in the United States.

Individual rights: Know, delete, correct, opt out of sale and sharing, limit sensitive personal information, non-discrimination.

California Civil Code, title 1.81.5 · US privacy in our register

PIPL — People's Republic of China

The PIPL combines GDPR-style rights with state security logic: localisation duties for critical infrastructure and large processors, a regulator-gated transfer regime and separate consent at each step. For exporters toward China it is the transfer chapter, not the rights catalogue, that decides the architecture.

Individual rights: Know, decide, restrict, access, copy, correct, delete, and explanation of automated decisions.

PIPL, National People's Congress · PIPL mirrored against the GDPR in the China corridor

DPDP Act — India

The DPDP Act is deliberately leaner than the GDPR: consent or a closed list of legitimate uses, a digital-only scope and a negative-list approach to transfers that keeps Chapter V-style mechanics out of the default path. The detailed duties arrive through rules, so the Act must be read together with its rulemaking.

Individual rights: Access, correction, erasure, grievance redress and nomination; consent or legitimate uses as the basis.

DPDP Act 2023, Gazette of India · DPDP section 16 mirrored against GDPR Chapter V

LGPD — Brazil

The LGPD is the GDPR's closest relative in the comparison: ten legal bases, a broad rights catalogue and an EU-style transfer toolbox, enforced by a dedicated national authority. A GDPR programme translates to Brazil with less friction than to any other regime here.

Individual rights: Access, correction, anonymisation, portability, deletion, information on sharing, and review of automated decisions.

Lei nº 13.709/2018, Planalto

APPI — Japan

The APPI is a duty-based regime: fewer individual rights than the GDPR, but strict handling duties, mandatory breach reporting and a mutual adequacy arrangement with the EU that makes Japan the smoothest transfer corridor in Asia for European data.

Individual rights: Disclosure, correction, suspension of use and deletion, with a duty to respond without delay.

APPI, Japanese Law Translation

POPIA — South Africa

POPIA follows the EU conditions model with eight processing conditions and a substantially-similar test for outbound transfers. It is the regime most African privacy laws are now measured against, and the one most often paired with the GDPR in regional programmes.

Individual rights: Access, correction, deletion, objection and civil remedies, plus direct-marketing opt-outs.

POPIA, gov.za

Method

Each regime is read from its official publication, listed above, on 2026-08-26. Where we cover the regime in depth the section links into our own register; where we do not, the official text is the only source we cite. The global export corridors apply these regimes to companies selling into the Union from China and India.

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift