Data Protection Laws by Country: 2026 Global Privacy Law Guide
Comprehensive guide to data protection and privacy laws by country. Key provisions, access rights, breach notification, and penalties for major global jurisdictions.
Last updated: 2026-08-30
The Global Privacy Landscape in 2026
Over 160 countries now have some form of data protection or privacy legislation. For any business that operates online, handles international customers, or uses global service providers, understanding which laws apply — and what they require — is no longer optional.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. Consult a qualified attorney for guidance specific to your business. This guide reflects the state of the laws discussed as of the date of publication.
This guide provides a practical overview of data protection laws by country and region, focusing on the provisions that matter most for DSAR compliance: individual access rights, response deadlines, breach notification requirements, and penalties.
Europe
European Union — GDPR
The General Data Protection Regulation is the benchmark against which most modern privacy laws are measured. It applies to any organization processing personal data of individuals in the EEA, regardless of where the organization is based.
Key provisions: Right of access (Article 15), right to erasure (Article 17), right to data portability (Article 20), right to rectification (Article 16). Access request deadline is 30 calendar days, extendable by 60 days for complex requests. Breach notification to the supervisory authority within 72 hours. Penalties up to 20 million euros or 4% of global annual turnover, whichever is higher.
See our GDPR jurisdiction guide for a full breakdown.
United Kingdom — UK GDPR
Post-Brexit, the UK operates under its own version of the GDPR, retained as the UK GDPR alongside the Data Protection Act 2018. The requirements closely mirror EU GDPR. The ICO (Information Commissioner's Office) is the supervisory authority.
Key provisions: Substantially identical to EU GDPR. 30-day access request deadline. 72-hour breach notification. Penalties up to 17.5 million pounds or 4% of global turnover. The UK has EU adequacy status, facilitating data transfers between the two jurisdictions.
See our UK GDPR jurisdiction guide.
Switzerland — nFADP
Switzerland's revised Federal Act on Data Protection (nFADP) took effect on September 1, 2023. It modernized Swiss privacy law to align more closely with the GDPR. Access request deadline is 30 days. Breach notification to the FDPIC is required "as soon as possible." Criminal penalties can apply to individuals, with fines up to CHF 250,000.
North America
Canada — PIPEDA
The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It applies to organizations conducting commercial activity across provincial borders, with provincial laws (Alberta PIPA, British Columbia PIPA, Quebec Law 25) covering intra-provincial activity.
Key provisions: Right of access under Principle 9. 30-day response deadline. Breach notification to the OPC and affected individuals when there is a "real risk of significant harm." Penalties up to CAD 100,000 per violation for certain offenses.
See our PIPEDA jurisdiction guide.
Canada — Quebec Law 25
Quebec's Act respecting the protection of personal information in the private sector, as modernized by Law 25, applies to all private-sector organizations in Quebec with no size threshold. It includes rights of access, rectification, and erasure. Privacy impact assessments are mandatory for certain processing. Penalties up to CAD 25 million or 4% of worldwide turnover.
United States — State Laws
The US has no comprehensive federal privacy law. Privacy is governed by a patchwork of state laws and sector-specific federal regulations.
California (CCPA/CPRA): Applies to businesses meeting revenue or processing thresholds. Access, deletion, correction, and opt-out rights. 45-day response deadline. Penalties up to $7,500 per intentional violation.
Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), and others: Multiple states have enacted comprehensive privacy laws with varying applicability thresholds and provisions. Common elements include access, deletion, and opt-out rights, with 45-day response deadlines.
As of mid-2026, over 20 US states have enacted comprehensive consumer privacy laws.
Asia-Pacific
Australia — Privacy Act 1988
Australia's Privacy Act applies to organizations with annual turnover exceeding AUD 3 million, plus health service providers, government agencies, and certain other entities regardless of turnover. The Australian Privacy Principles (APPs) govern data handling. APP 12 provides the right to access personal information. Response deadline is 30 days. Breach notification to the OAIC is required for "eligible data breaches" involving serious harm. Penalties were significantly increased in 2022, with maximum fines for serious or repeated breaches reaching AUD 50 million, three times the benefit obtained, or 30% of adjusted turnover (whichever is greatest).
See our Australian Privacy Act jurisdiction guide.
India — DPDP Act 2023
India's Digital Personal Data Protection Act was enacted in August 2023. It establishes rights for data principals (individuals) including the right to access, correction, and erasure. The Data Protection Board of India handles enforcement. Penalties can reach INR 250 crore (approximately USD 30 million) for serious violations. Implementation is being phased through subordinate rules, with the full framework expected to be operational by 2026.
Japan — APPI
Japan's Act on the Protection of Personal Information applies to all business operators handling personal information. It provides rights of access, correction, and deletion. Japan has EU adequacy status, facilitating data transfers with the EU. The Personal Information Protection Commission oversees enforcement.
South Korea — PIPA
The Personal Information Protection Act is South Korea's comprehensive privacy law, enforced by the Personal Information Protection Commission. It applies broadly to all personal information handlers. South Korea also holds EU adequacy status. Access requests must be responded to within 10 days. Penalties include criminal sanctions and administrative fines up to 5% of related revenue.
New Zealand — Privacy Act 2020
New Zealand's Privacy Act applies to all agencies (including private-sector organizations) with no size threshold. It provides access and correction rights under Information Privacy Principles 6 and 7. Response deadline is 20 working days. New Zealand has EU adequacy status. Breach notification to the Privacy Commissioner is mandatory for privacy breaches that cause or are likely to cause serious harm.
Singapore — PDPA
Singapore's Personal Data Protection Act applies to all private-sector organizations. It provides access and correction rights with a 30-day response deadline. The Personal Data Protection Commission handles enforcement. Penalties can reach SGD 1 million or 10% of annual turnover for organizations with turnover exceeding SGD 10 million.
Africa
South Africa — POPIA
South Africa's Protection of Personal Information Act applies to all responsible parties processing personal information, with no size exemption. It provides access, correction, and deletion rights. The Information Regulator oversees enforcement. Penalties include fines up to ZAR 10 million and imprisonment.
Nigeria — NDPA
Nigeria's Data Protection Act 2023 established a comprehensive privacy framework, replacing the earlier NDPR regulation. It applies to data controllers and processors operating in Nigeria or processing the data of Nigerian residents. The Nigeria Data Protection Commission handles enforcement.
Kenya — Data Protection Act 2019
Kenya's Data Protection Act provides access, correction, and deletion rights. The Office of the Data Protection Commissioner handles enforcement. Penalties up to KES 5 million or 1% of annual turnover.
South America
Brazil — LGPD
Brazil's Lei Geral de Protecao de Dados applies to any processing of personal data collected in Brazil or used to offer goods/services to individuals in Brazil. It provides access, correction, deletion, and portability rights. The ANPD (Autoridade Nacional de Protecao de Dados) handles enforcement. Administrative penalties can reach 2% of revenue in Brazil, capped at BRL 50 million per violation.
Argentina — PDPL
Argentina's Personal Data Protection Law has been in force since 2000 and is being updated. Argentina has EU adequacy status. The law provides access, rectification, and deletion rights with a 10-day response deadline for access requests.
Middle East
Saudi Arabia — PDPL
Saudi Arabia's Personal Data Protection Law applies to all processing of personal data within Saudi Arabia. It provides access, correction, and deletion rights. The Saudi Data and Artificial Intelligence Authority (SDAIA) oversees implementation.
UAE — Federal Data Protection Law
The UAE enacted its Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. It applies to processing of personal data within the UAE and of UAE residents. It provides access, correction, and deletion rights.
Bahrain — PDPL
Bahrain's Personal Data Protection Law provides comprehensive privacy protections including access and correction rights, enforced by the Personal Data Protection Authority.
EU Adequacy Decisions
The European Commission can grant adequacy decisions to countries whose data protection laws are deemed to provide an essentially equivalent level of protection to the GDPR. This facilitates data transfers from the EU to those countries without additional safeguards.
Countries and territories with EU adequacy decisions include: Andorra, Argentina, Canada (for PIPEDA-covered organizations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom, and Uruguay. The EU-US Data Privacy Framework provides a mechanism for transfers to certified US organizations.
Key Takeaways
Most modern privacy laws share common elements: right of access, right to correction, right to deletion (with exceptions), breach notification requirements, and administrative penalties. The details differ, but the core structure is converging.
Extraterritorial application is the norm. GDPR, UK GDPR, LGPD, and many other laws apply based on where the data subjects are located, not where the organization is incorporated. A business with a global customer base may be subject to multiple jurisdictions simultaneously.
Response deadlines vary. From 10 days (South Korea, Argentina) to 45 days (US state laws), the time you have to respond to access requests depends on which law applies. See our DSAR response deadlines guide for a detailed comparison.
For guidance on handling requests that span multiple jurisdictions, see our cross-border DSARs guide.
Related Guides
- Cross-Border DSARs — handling requests across jurisdictions
- Privacy Laws With No Revenue Threshold — laws that apply to every business
- GDPR Jurisdiction Guide — full GDPR breakdown
References
- GDPR: Full text
- UK GDPR: ICO guidance
- LGPD: ANPD
- POPIA: Information Regulator South Africa
- India DPDP: Digital Personal Data Protection Act 2023
- EU Adequacy Decisions: European Commission adequacy decisions
Last reviewed: August 2026. Privacy laws change frequently, and new legislation is enacted regularly. Verify all information against the current text of the relevant law and consult qualified legal counsel before making compliance decisions.