Global legal questions
The questions asked most often, without a jurisdiction, answered per jurisdiction. The EU, the United States, Sweden, Norway and Germany stand side by side, each with its primary source, identifier and date read.
About the global question nodes
The same question is answered in several jurisdictions and then set side by side. The comparison shows where requirements coincide and where they genuinely differ, each row anchored in its own source of law.
No jurisdiction is described in another's terms. Differences remain differences.
- Read the question, then the answer per jurisdiction.
- The comparison points back at the provision in each jurisdiction.
- Read dates are stated per legal order, not for the page as a whole.
The questions
- What are my rights over my personal data, and how do I exercise them?
In the EU the rights are set out in the GDPR: access, rectification, erasure, restriction, portability and objection, exercised by a request to the controller, who answers within one month. In the United States there is no federal equivalent, so the rights follow state law, and California grants access, deletion, correction and opt-out of sale or sharing.
Regulation (EU) 2016/679 · Cal. Civ. Code § 1798.100 · SFS 2018:218 · LOV-2018-06-15-38 · BDSG 2018 · read 2026-08-24
- Does the GDPR apply to a company established outside the EU?
Yes, where the company offers goods or services to people in the EU or monitors their behaviour there. Establishment is not the test: Article 3 attaches to the location of the individual, and a company caught this way must appoint a representative inside the Union.
Regulation (EU) 2016/679 · Cal. Civ. Code § 1798.100 · SFS 2018:218 · LOV-2018-06-15-38 · BDSG 2018 · read 2026-08-24
- How can personal data be transferred from the EU to the United States lawfully?
Chapter V of the GDPR allows a transfer on an adequacy decision, on appropriate safeguards or on a narrow derogation. For the United States the first route is the Data Privacy Framework, open only to certified recipients, and everyone else relies on standard contractual clauses with a transfer impact assessment.
Regulation (EU) 2016/679 · Commission Implementing Decision (EU) 2021/914 · Commission Implementing Decision (EU) 2023/1795 · SFS 2018:218 · LOV-2018-06-15-38 · BDSG 2018 · read 2026-08-24
- What is the EU AI Act, and which systems does it cover?
Regulation (EU) 2024/1689 regulates artificial intelligence by risk: a short list of prohibited practices, a defined set of high risk systems with duties before and after placing on the market, transparency duties for systems that interact with people or generate content, and no new duties for everything else.
Regulation (EU) 2024/1689 · Colorado SB24-205 · Regulation (EU) 2016/679 · read 2026-08-24
- When must a personal data breach be reported, and to whom?
Under the GDPR the controller notifies the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk, and notifies the affected people without undue delay where the risk is high. In the United States the duty is set by state law and runs to the affected residents and often to the attorney general.
Regulation (EU) 2016/679 · Cal. Civ. Code § 1798.82 · Directive (EU) 2022/2555 · IMY, anmälan av personuppgiftsincident · Datatilsynet, avviksmelding · BfDI, Meldung nach Art. 33 DSGVO · read 2026-08-24
The page reports what the sources say, with identifier and address to the publisher. It is not legal advice and does not assess an individual matter.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.