# GLOBAL CYBER LAW COMPENDIUM
## Volume I · Regulations & Frameworks

*Global Cyber Law Compendium*
First Edition · June 2026
**ISBN:** 978-7-XXX-XXXX-X (申请中 / Pending Registration)
47 Chapters · English Edition

---

# TABLE OF CONTENTS

**Chapter 1: Foundations of Cyber Law**
**Chapter 2: The Global Legislative Landscape (2026 Data)**
**Chapter 3: General Data Protection Regulation (GDPR)**
**Chapter 4: ePrivacy Directive**
**Chapter 5: Digital Markets Act (DMA)**
**Chapter 6: Digital Services Act (DSA)**
**Chapter 7: EU AI Act**
**Chapter 8: Digital Operational Resilience Act (DORA)**
**Chapter 9: NIS2 Directive**
**Chapter 10: EEA Extensions — Iceland, Liechtenstein, Norway**
**Chapter 11: Switzerland — Revised Federal Act on Data Protection (FADP)**
**Chapter 12: UK Data Protection Framework**
**Chapter 13: UK Cyber Security and Resilience Bill**
**Chapter 14: UK Online Safety Act (2023)**
**Chapter 15: UK Computer Misuse Act 1990**
**Chapter 16: Federal Cyber and Privacy Laws (United States)**
**Chapter 17: Section 230 — 47 U.S.C. § 230**
**Chapter 18: State Comprehensive Privacy Laws**
**Chapter 19: Sectoral State Laws**
**Chapter 20: Proposed Federal Privacy Legislation**
**Chapter 21: Cybersecurity Law of the PRC (2016)**
**Chapter 22: Data Security Law of the PRC (2021)**
**Chapter 23: Personal Information Protection Law (PIPL, 2021)**
**Chapter 24: Network Data Security Management Regulations**
**Chapter 25: Supporting Regulations and Measures**
**Chapter 26: Court Interpretations and Internet Courts**
**Chapter 27: Japan — Act on the Protection of Personal Information (APPI)**
**Chapter 28: South Korea — Personal Information Protection Act (PIPA)**
**Chapter 29: Singapore — Personal Data Protection Act (PDPA)**
**Chapter 30: India — Digital Personal Data Protection Act (DPDPA, 2023)**
**Chapter 31: Australia — Privacy Act 1988 & Privacy Legislation Amendment Act 2022**
**Chapter 32: Additional Asia-Pacific Jurisdictions**
**Chapter 33: Brazil — Lei Geral de Proteção de Dados Pessoais (LGPD, Law 13,709/2018, effective 2020)**
**Chapter 34: Argentina — Ley de Protección de Datos Personales (2000)**
**Chapter 35: Additional Latin American Jurisdictions**
**Chapter 36: South Africa — Protection of Personal Information Act (POPIA, Act 4 of 2013, effective 2020/2021)**
**Chapter 37: Additional African Jurisdictions**
**Chapter 38: Middle Eastern Jurisdictions**
**Chapter 39: Russia — Federal Law on Personal Data (152-FZ, 2006/Amended)**
**Chapter 40: Russia — Sovereign Internet Law & Additional CIS Jurisdictions**
**Chapter 41: Council of Europe — Budapest Convention on Cybercrime (2001)**
**Chapter 42: Council of Europe — Convention 108+ (Modernised Convention for the Protection of Individuals)**
**Chapter 43: OECD Privacy Guidelines (2013) & AI Principles (2019)**
**Chapter 44: United Nations**
**Chapter 45: APEC Cross-Border Privacy Rules (CBPR)**
**Chapter 46: African Union — Malabo Convention on Cyber Security and Personal Data Protection**
**Chapter 47: Regional Coordination Frameworks and Global Trends**
**Appendix I: Master Table of Data Protection Authorities Worldwide**
**Appendix II: Cross-Jurisdictional Comparison Charts**
**Appendix III: Glossary of Cyber Law Terminology**
**Appendix IV: Language Key — Source Text Languages & Translation Status**
**Appendix V: Index of Laws by Jurisdiction**
**Appendix VI: Other Commonwealth of Independent States (CIS) Jurisdictions — Data Protection Law (Summary)**
  EDITORIAL NOTES

---


# Chapter 1: Foundations of Cyber Law

Cyber law—or "Internet law," "digital law," or "information technology law"—denotes the body of legal rules, principles, and institutions that govern the use of digital technologies, electronic communications, and data-driven activities. It is not a single,
self-contained branch of law in the way that criminal law or contract law is traditionally understood. Rather, it is an interdisciplinary field that draws from constitutional law, criminal law, private international law, intellectual property, consumer protection,
administrative law, and human rights law, applying and adapting their doctrines to the unique characteristics of networked digital environments.
The absence of a universally accepted definition reflects the field's breadth. Professor Lawrence Lessig famously observed that "code is law"
in cyberspace, arguing that the architecture of digital platforms—their protocols, algorithms, and design choices—regulates behaviour as powerfully as any legal norm.[1] The United Nations Office on Drugs and
Crime (UNODC), in its Comprehensive Study on Cybercrime (2013), took a more conventional approach, defining cybercrime legislation as encompassing offences against the confidentiality, integrity, and availability of computer data and systems (e.g., unauthorized access,
data interference), computer-related offences (e.g., computer-enabled fraud, identity theft), and content-related offences (e.g., child exploitation material, hate speech).[2] The Council of Europe's Budapest
Convention on Cybercrime (2001) adopted a similarly tripartite structure, establishing the first international framework for harmonizing cybercrime definitions.[3]
For the purposes of this Volume, "cyber law" is defined capaciously to encompass at least six substantive domains:
Data Protection and Privacy Law — the regulation of the collection,
processing, storage, and transfer of personal data by public and private actors (e.g., the EU General Data Protection Regulation[4], China's
Personal Information Protection Law[5]).
Cybersecurity Law — the legal obligations imposed on entities to protect networked systems, critical infrastructure, and data from unauthorized access, disruption, or destruction (e.g., the EU NIS2
Directive[6], China's Cybersecurity Law[7], the US Cybersecurity
Information Sharing Act).
Electronic Commerce and Digital Consumer Protection — the regulation of online commercial transactions, digital contracts, electronic signatures, and consumer rights in digital markets (e.g., the EU
E-Commerce Directive, the UNCITRAL Model Law on Electronic
Commerce[8]).
Content Regulation and Platform Governance — the rules governing the moderation, removal, and liability of user-generated content on digital platforms, including intermediary liability regimes and online safety obligations (e.g., Section 230 of the US Communications Decency Act[9],
the EU Digital Services Act[10]).
Intellectual Property in the Digital Environment — the adaptation of copyright, trademark, and patent law to digital reproduction,
distribution, algorithmic creation, and platform-based infringement
(e.g., the EU Digital Single Market Directive Art. 17[11], the US
Digital Millennium Copyright Act[12]).
Cybercrime — the criminalization of computer- and internet-facilitated offences, including hacking, ransomware, phishing,
online fraud, child exploitation, and state-sponsored cyber-espionage
(e.g., the US Computer Fraud and Abuse Act[13], the Budapest
Convention).
These domains overlap and interact. A single data breach, for instance, may trigger obligations under cybersecurity law, data protection law, consumer protection law, and sector-specific regulation
(e.g., financial services, healthcare) simultaneously, across multiple jurisdictions. This regulatory density and cross-domain complexity is one of the defining features of cyber law and a central preoccupation of this Volume.
The evolution of cyber law can be periodized into four overlapping phases.
Phase I: Emergence (1990s–2001). The commercialization of the
Internet in the early 1990s created an urgent need for legal frameworks.
The United States led with the Electronic Communications Privacy Act
(1986)[14], the Computer Fraud and Abuse Act (1986, as amended)[15], and the Communications Decency Act (1996), whose Section 230 established the platform immunity regime that would define American internet governance for decades.[16] The European Union enacted the Data Protection
Directive (95/46/EC)[17] and the E-Commerce Directive (2000/31/EC)[18].
At the international level, the Council of Europe opened the Budapest
Convention on Cybercrime for signature in 2001—the first and, to date,
the only binding international treaty on cybercrime.[19] During this period, legal scholarship was dominated by the question of whether cyberspace required fundamentally new legal principles or whether existing doctrines could be extended by analogy.[20]
Phase II: Expansion and Divergence (2001–2013). The September 11
attacks and the rise of transnational cybercrime prompted a wave of new legislation emphasizing security and surveillance. The USA PATRIOT Act
(2001)[21] dramatically expanded government access to electronic communications. The EU adopted the Data Retention Directive
(2006/24/EC)[22], later invalidated by the CJEU in Digital Rights
Ireland (2014) for violating the proportionality principle.[23]
Meanwhile, the EU began its ambitious regulatory program with the adoption of the ePrivacy Directive (2002/58/EC)[24] and the development of the GDPR proposal. China enacted its first Criminal Law Amendment
(VII) in 2009, criminalizing certain cyber offences, and began developing the regulatory architecture that would culminate in the
Cybersecurity Law (2017).[25] This phase also saw the rise of multi-stakeholder governance models, with the Internet Governance Forum
(IGF) established by the UN in 2006.
Phase III: The Regulatory Revolution (2014–2022). This phase was dominated by three concurrent developments. First, the EU enacted a succession of landmark regulations: the GDPR (2016)[26], the Law
Enforcement Directive (2016)[27], and began drafting the Digital Markets
Act, Digital Services Act, AI Act, and Data Act. Second, China enacted a comprehensive "digital legal framework" comprising the Cybersecurity Law
(2017)[28], the Data Security Law (2021)[29], and the Personal
Information Protection Law (2021)[30], along with supporting regulations on algorithmic recommendations and deep synthesis. Third, the United
States, in the absence of federal privacy legislation, saw a proliferation of state comprehensive privacy laws beginning with the
California Consumer Privacy Act (2018)[31], creating a patchwork that
Chapter 18 of this Volume examines in detail.
Phase IV: Global Convergence and Contestation (2022–present). The current phase is characterized by the maturation of earlier frameworks and the emergence of new regulatory frontiers. The EU AI Act (2024)[32]
established the world's first comprehensive AI regulation. The proposed
UN Cybercrime Convention (2024–2025)[33] has generated intense debate over human rights safeguards. The Schrems II decision (2020)[34] and its aftermath—culminating in the EU-US Data Privacy Framework (2023)[35] and its validation by the EU General Court in Latombe (2025)[36]—have defined the ongoing transatlantic data transfer saga. China's Network
Data Security Management Regulations (effective January 2025)[37]
further tightened data governance. Concurrently, cyber operations by state actors, including the Salt Typhoon and Volt Typhoon campaigns against US telecommunications infrastructure, have sharpened the intersection of cyber law, national security, and international law.
Several characteristics of digital technologies justify treating cyber law as a distinct field of inquiry, even if it lacks the autonomy of a traditional legal branch.
First, territorial indeterminacy. Internet communications routinely cross multiple jurisdictions within milliseconds. A social media post created in one country, stored on servers in a second, and viewed by users in dozens of others implicates the laws of all involved states.
This fundamentally challenges the territorial premises of most legal systems.
Second, scale and velocity. The volume of data processed daily—estimated at over 2.5 quintillion bytes globally—vastly exceeds anything contemplated by pre-digital legal frameworks. The speed of data processing, algorithmic decision-making, and automated content moderation operates on timescales that traditional legal processes
(judicial review, legislative deliberation) cannot match.
Third, technical opacity. The complexity of modern digital systems—cloud computing architectures, machine learning models,
distributed ledger technologies—creates persistent information asymmetries between regulated entities and regulators, between platforms and users, and between governments and technology firms.
Fourth, rights concentration. A small number of technology companies exercise governance functions that rival those of sovereign states,
including rule-making (community guidelines, algorithmic ranking),
adjudication (content moderation decisions), and enforcement (account suspension, demonetization).[38] This concentration of power raises fundamental questions about democratic accountability, due process, and the appropriate allocation of regulatory authority.
Jurisdiction—the authority of a state to exercise its legal power—is the bedrock of any legal system. In public international law,
jurisdiction is typically classified into prescriptive jurisdiction (the authority to make laws), enforcement jurisdiction (the authority to enforce laws), and adjudicative jurisdiction (the authority to adjudicate disputes).[39] The traditional bases for prescriptive jurisdiction—the territoriality principle, the nationality principle,
the protective principle, the passive personality principle, and the universality principle—were developed in an era when human activities were firmly anchored in physical space. Cyberspace poses a structural challenge to each.
The territoriality principle—the most widely accepted basis for jurisdiction—holds that a state may regulate conduct occurring within its territory.[40] But what does "within its territory" mean when a server is in one country, the user in another, and the data traverses a dozen intermediary networks? The CJEU grappled with this question in
Google Spain v. AELPI (C-131/12, 2014),[41] holding that the operator of a search engine is subject to EU data protection law when it has a branch or subsidiary in an EU Member State that promotes and sells advertising space to EU residents—effectively establishing an
"establishment" test rather than a strictly territorial one. Similarly,
the US Supreme Court in Reno v. ACLU (1997)[42] recognized the inherently transnational nature of internet communications and struck down provisions of the Communications Decency Act that would have subjected all internet speakers to the most restrictive community standards in the United States.
The effects doctrine—a variant of territoriality—permits a state to regulate conduct outside its territory that produces harmful effects within it.[43] This principle has been central to US antitrust and securities law and has been extensively applied in cyber law.
The seminal case is United States v. Ivanov (2001), in which a
Russian national operating from Russia was prosecuted under the US
Computer Fraud and Abuse Act for hacking into US-based computer systems.
The court held that the CFAA's extraterritorial reach extended to foreign conduct that caused damage to computers "used in or affecting interstate or foreign commerce or communication," effectively adopting a broad effects-based test.[44]
The LICRA v. Yahoo! litigation (2000–2006) remains the most instructive case on jurisdictional conflict in cyberspace.[45] French anti-racism organizations sued Yahoo! in French courts for permitting the auction of Nazi memorabilia on its US-hosted platform, arguing that
French users could access the content in violation of French anti-hate speech laws (Law No. 90-615 of 13 July 1990). The Tribunal de Grande
Instance de Paris ordered Yahoo! to filter access to Nazi materials for
French users. Yahoo! then sued in the US District Court for the Northern
District of California, arguing that the French order violated the First
Amendment. The court initially held that the French order was unenforceable in the United States, but the Ninth Circuit reversed,
finding that the French court had properly exercised jurisdiction and that Yahoo! had not demonstrated a "real and immediate" threat of enforcement in the United States.[46] The case crystallized the fundamental jurisdictional tension in cyber law: the same conduct,
occurring on a single platform, can be lawful in one jurisdiction and unlawful in another, with no mechanism for resolving the conflict beyond comity and diplomatic negotiation.
China's data localization regime under the Cybersecurity Law (Article
37) and the Data Security Law (Article 31)[47] represents an aggressive assertion of territorial jurisdiction over data flows. These provisions require that "critical information infrastructure operators" and entities processing "important data" store such data within Chinese territory and undergo security assessments before transferring data abroad. Similarly, Russia's Federal Law No. 242-FZ (2015) amended the
Personal Data Law (152-FZ)[48] to require the localization of Russian citizens' personal data on servers physically located in Russia. These laws represent the most expansive claims of data sovereignty in the contemporary era and have been the subject of significant trade and diplomatic friction.
"Long-arm jurisdiction" refers to the ability of a court to exercise personal jurisdiction over a non-resident defendant who has sufficient
"minimum contacts" with the forum state.[49] In US law, the framework established in International Shoe Co. v. Washington (1945)[50] has been applied to internet-related disputes through the analytical framework developed in Zippo Mfg. Co. v. Zippo Dot Com, Inc. (1997).[51] The Zippo court created a "sliding scale" for internet jurisdiction: at one end,
defendants who actively conduct business over the internet (e.g.,
entering into contracts with forum residents) are subject to specific jurisdiction; at the other, defendants who merely post information accessible in the forum state are not.[52] Although the Zippo framework has been criticized and supplemented by subsequent cases emphasizing
"purposeful availment" and "stream of commerce" analysis,[53] it remains a foundational reference point in US cyber jurisdiction doctrine.
The universality principle permits any state to exercise jurisdiction over certain universally condemned offences, such as piracy, torture,
and genocide, regardless of where the offence occurs or the nationality of the perpetrator.[54] While cybercrime has not generally been recognized as a universal jurisdiction offence, the increasing severity of transnational cyber threats—ransomware attacks on hospitals, critical infrastructure sabotage, and state-sponsored cyber espionage targeting democratic institutions—has prompted calls for its inclusion.[55]
International cooperation mechanisms include mutual legal assistance treaties (MLATs), Interpol's cybercrime initiatives, and the Budapest
Convention's framework for cross-border investigative cooperation.[56]
The proposed UN Cybercrime Convention, however, has been criticized by civil society organizations and some states for potentially enabling expanded government surveillance powers without adequate human rights safeguards.[57] The 2025 DOJ prosecution of the Nefilim ransomware operator, involving extradition and a coordinated multi-country investigation, illustrates the practical functioning of these cooperation mechanisms.[58]
Despite the proliferation of national cyber laws, three broad regulatory paradigms can be identified, each reflecting a distinct philosophical orientation toward the relationship between the state, the market, and digital technologies. These are the Comprehensive Model
(exemplified by the European Union), the Sectoral/Patchwork Model
(exemplified by the United States), and the Systemic Model (exemplified by China). These paradigms are ideal types; actual regulatory systems contain elements of more than one. Nonetheless, the typology illuminates the structural choices that shape national and regional approaches to cyber governance.
The EU model is characterized by horizontal, rights-based, and precautionary regulation. It proceeds from the premise that fundamental rights—including privacy, data protection, freedom of expression, and non-discrimination—must be actively protected by legislation, not merely left to market forces or self-regulation.
Key features include:
Rights foundationalism. The GDPR (Regulation (EU) 2016/679)[59] is rooted in Article 8 of the Charter of Fundamental Rights of the European
Union, which provides that "everyone has the right to the protection of personal data concerning him or her." Data protection is thus not merely a regulatory objective but a fundamental right, which constrains the design of the regulatory framework and the discretion of both public authorities and private actors.
Comprehensiveness. The GDPR applies to all processing of personal data by controllers and processors established in the EU, regardless of whether the processing takes place within the EU, and to processing outside the EU where the activities relate to offering goods or services to EU data subjects or monitoring their behaviour (Article 3).[60] This broad extraterritorial reach has made the GDPR the de facto global standard for data protection, a phenomenon scholars have termed the
"Brussels Effect."[61]
Precautionary and innovation-sensitive regulation. The EU AI Act
(Regulation (EU) 2024/1689)[62] adopts a risk-based classification of AI
systems, prohibiting certain practices (e.g., social scoring, real-time biometric identification in public spaces for law enforcement, with narrow exceptions), imposing rigorous obligations on "high-risk" AI, and requiring transparency for AI systems that interact with humans. This approach reflects a precautionary orientation: regulate potential harms before they materialize at scale.
Institutional enforcement. The GDPR provides for independent supervisory authorities in each Member State (Article 51) with extensive investigative and corrective powers (Article 58) and the ability to impose administrative fines of up to €20 million or 4% of worldwide annual turnover (Article 83).[63] The consistency mechanism (Chapter
VII) seeks to ensure uniform application across the Union.
Regulatory breadth. The EU's digital strategy encompasses not only data protection and AI but also platform competition (DMA), content governance (DSA), cybersecurity (NIS2, DORA), electronic privacy
(ePrivacy Directive), digital identity (eIDAS Regulation), and data sharing (Data Act).
Advantages of this model include legal certainty, strong rights protection, and the capacity to shape global regulatory standards through the "Brussels Effect." Disadvantages include compliance costs,
potential barriers to innovation, regulatory complexity, and the challenge of achieving uniform enforcement across 27 Member States with distinct legal traditions.
The US model is characterized by sector-specific, market-oriented,
and decentralized regulation. It reflects a preference for limited federal intervention, reliance on market mechanisms and self-regulation,
and a strong First Amendment tradition that constrains content regulation.
Sectoral federal regulation. Rather than a comprehensive federal privacy law, the US regulates data privacy through a patchwork of sector-specific statutes: HIPAA for health data[64], GLBA for financial data[65], COPPA for children's data[66], FERPA for educational records[67], and VPPA for video rental records[68]. The FTC Act §5 (15
U.S.C. §45)[69] provides a backstop against "unfair or deceptive acts or practices," which the Federal Trade Commission has used extensively to enforce privacy commitments.
First Amendment primacy. The US constitutional tradition assigns the highest level of protection to speech, including digital speech. Reno v.
ACLU (1997)[70] struck down the indecency provisions of the
Communications Decency Act, and Section 230 of the CDA[71] has been interpreted to provide broad immunity to platforms for third-party content—though the scope of that immunity is under increasing judicial and legislative scrutiny.[72]
State-level innovation. In the absence of federal comprehensive privacy legislation, states have become laboratories for privacy regulation. California led with the CCPA (2018) and CPRA (2020)[73], and as of 2025, more than twenty states have enacted comprehensive privacy laws (Chapter 18 of this Volume). This creates a complex patchwork that burdens multistate and multinational businesses but also drives innovation and regulatory competition.
Light-touch platform regulation. Section 230 and the DMCA safe harbors have created a legal environment in which platforms face minimal legal obligations regarding user-generated content, provided they comply with notice-and-takedown procedures.[74] This approach has been credited with fostering the growth of the American technology sector but criticized for enabling the spread of misinformation, hate speech, and other harmful content.
Enforcement through litigation. The US relies heavily on private litigation, class actions, and state attorneys general enforcement.
Illinois' Biometric Information Privacy Act (BIPA)[75], for instance,
provides for a private right of action that has generated billions of dollars in settlements, including the $1.375 billion Texas settlement with Google in 2025 and the $51.75 million Clearview AI BIPA
settlement.[76]
Advantages of the US model include flexibility,
innovation-friendliness, and the discipline of competitive federalism.
Disadvantages include regulatory fragmentation, inadequate protection for certain categories of personal data (particularly in the absence of a comprehensive federal law), and the potential for regulatory arbitrage. The American Privacy Rights Act (APRA)[77], if enacted, would represent a significant shift toward a more comprehensive approach, but its prospects remain uncertain as of 2026.
China's model is characterized by state-centric,
sovereignty-oriented, and technology-integrated regulation. It reflects a governance philosophy in which the Communist Party of China exercises comprehensive leadership over the digital domain, viewing cyberspace as an extension of state sovereignty and a critical dimension of national security.
Sovereignty and security as organizing principles. China's
Cybersecurity Law (2017)[78] establishes "cyber sovereignty" (cyber sovereignty)
as a foundational concept, affirming the right of the state to regulate internet governance, data flows, and online content within its territory. The Data Security Law (2021)[79] introduces a data classification system in which data is categorized by importance to national security, economic development, and public interest, with
"important data" subject to enhanced protection and transfer restrictions.
Comprehensive data protection. The Personal Information Protection
Law (PIPL, 2021)[80] establishes consent-based processing rules, data subject rights, and cross-border transfer mechanisms that draw on the
GDPR in structure but differ in substance—notably, the PIPL provides for extraterritorial application (Article 3) but subjects cross-border transfers to security assessments, standard contracts, or certification by the Cyberspace Administration of China (CAC), reflecting a more restrictive approach to data flows.[81]
Content regulation. China maintains one of the world's most comprehensive content regulation systems, with the CAC exercising authority over online information content through the Measures for the
Administration of Internet Information Services, the Measures for the
Management of Algorithmic Recommendations (2022), and the Interim
Measures for the Management of Generative AI Services (2023).[82]
Content that "endangers national security," "subverts state power," or
"undermines national unity" is prohibited, and platforms bear primary responsibility for content moderation.
Technology regulation. China has enacted specific regulations governing algorithmic recommendation systems, deep synthesis (deepfake)
technology, and generative AI services—areas where the EU is only now developing regulatory frameworks.[83] These measures require algorithmic transparency, content labelling, and adherence to "core socialist values."
Strong enforcement. The CAC and other regulatory authorities have imposed substantial penalties for data protection violations, including the landmark €530 million fine on TikTok in May 2025 for unlawful transfers of EEA user data to China[84] and the record $1.2 billion fine on Didi Global in 2022 for cybersecurity and data security violations.[85]
Advantages of the Chinese model include regulatory coherence, rapid response to emerging technologies, and strong national security protections. Disadvantages include the suppression of free expression,
the absence of independent regulatory oversight, and the creation of a fragmented global data governance system through data localization and sovereignty assertions.
The application of public international law to cyberspace has been one of the most contested questions in international legal discourse over the past two decades. The core issue is whether cyberspace constitutes a "global commons" governed by a distinct set of norms, or whether existing international law—including the UN Charter,
international human rights law, and international humanitarian law—applies to state conduct in cyberspace by analogy.
The prevailing view, endorsed by the majority of states through successive UN processes, is that international law applies to cyberspace in its entirety.[86] The UN Group of Governmental Experts (GGE) on
Developments in the Field of Information and Telecommunications in the
Context of International Security, in its 2013 and 2015 consensus reports, affirmed that "international law, and in particular the Charter of the United Nations, is applicable and is essential to maintaining peace and stability and promoting an open, secure, peaceful and accessible ICT environment."[87] The 2015 report further identified a set of voluntary, non-binding norms of responsible state behaviour,
including:
Refraining from damaging or impairing critical infrastructure (Norm
11(b));
Not knowingly allowing territory to be used for internationally wrongful acts using ICTs (Norm 13(a));
Cooperating in good faith to reduce and mitigate malicious ICT
activity (Norm 13(d)).[88]
These norms, while non-binding, have significantly influenced state practice and national cybersecurity strategies.
The Council of Europe's Budapest Convention on Cybercrime (2001)[89]
remains the most important binding international instrument on cybercrime. As of 2026, it has been ratified by over 70 states,
including non-Council-of-Europe members such as the United States,
Japan, and Australia. The Convention establishes a common framework for:
(a) the criminalization of cyber offences (Articles 2–13); (b)
procedural powers for investigation and prosecution (Articles 14–22);
and (c) international cooperation (Articles 23–35).[90]
The Second Additional Protocol (2022)[91] updated the Convention to address new challenges, including electronic evidence, cross-border access to data, and enhanced cooperation mechanisms. However, the
Budapest Convention has been criticized by China and Russia as reflecting Western legal values and imposing an inadequate balance between law enforcement cooperation and human rights protection.[92]
This criticism has been a central driver of the proposed UN Cybercrime
Convention, which has been negotiated since 2021 under the auspices of the UN Ad Hoc Committee.[93]
The principle of state sovereignty—the foundational norm of international law—has a contested application in cyberspace. The traditional understanding of sovereignty encompasses territorial integrity, political independence, and the exclusive authority of a state over matters within its territory.[94] In cyberspace, sovereignty raises three distinct questions:
First, territorial sovereignty over data: does a state have the right to regulate data flows into and out of its territory? China, Russia, and several other states have answered affirmatively through data localization laws, as discussed in Section 1.2. The EU, while supporting free data flows within the Single Market, restricts transfers to non-adequate countries under the GDPR (Articles 44–49),[95] reflecting a conditional sovereignty approach.
Second, sovereignty as a prohibition: does state sovereignty prohibit cyber operations that penetrate another state's cyber infrastructure?
The 2015 UN GGE report was deliberately ambiguous on this point, but the
Tallinn Manual 2.0 (2017), a scholarly restatement by international law experts, concluded that a cyber operation that causes physical damage or loss of life would violate the prohibition on the use of force (Article
2(4) of the UN Charter), and that a cyber operation that interferes with the functions of another state's government would violate the principle of sovereignty.[96]
Third, due diligence: does a state have an obligation to prevent its territory from being used for harmful cyber operations against other states? The 2015 GGE Norm 13(a) (not knowingly allowing territory to be used for internationally wrongful acts) suggests a qualified due diligence obligation, though its precise scope and content remain contested.[97]
The Salt Typhoon and Volt Typhoon campaigns against US
telecommunications infrastructure in 2024–2025, and the DOJ indictments of twelve PRC nationals in March 2025, illustrate the practical implications of these contested norms.[98] When state-sponsored actors penetrate another state's critical cyber infrastructure—potentially for espionage, positioning for future attacks, or both—the existing international legal framework provides no clear, enforceable mechanism for response, deterrence, or resolution.
Beyond the Budapest Convention and the UN GGE/OEWG processes, several additional international frameworks are shaping the global cyber law landscape:
Convention 108+ (the Council of Europe's modernised Convention for the Protection of Individuals with regard to Automatic Processing of
Personal Data, 2023)[99] provides a global framework for data protection, open to accession by any state.
OECD Privacy Guidelines (2013) and OECD AI Principles (2019)[100]
establish non-binding but influential standards for data protection and
AI governance.
APEC Cross-Border Privacy Rules (CBPR)[101] provide a voluntary certification framework for data flows among Asia-Pacific economies.
African Union Malabo Convention (2014)[102] addresses both cybercrime and data protection on the African continent.
ASEAN Framework on Digital Data Governance (2022)[103] promotes voluntary interoperability of data governance frameworks among Southeast
Asian states.
These instruments, varying in legal force and geographic scope,
collectively constitute the "soft law" infrastructure of global cyber governance—a dense, overlapping, and sometimes contradictory web of norms, standards, and frameworks that this Volume seeks to map and analyze.
This Volume adopts a functional comparative method as its principal analytical framework. Drawing on the tradition of comparative law scholarship pioneered by René David, Konrad Zweigert, and Hein
Kötz,[104] the Volume identifies regulatory problems common to multiple jurisdictions and examines how different legal systems have responded.
The focus is on function rather than form: we ask what problem the law is designed to solve, what institutional mechanisms it deploys, and how effective it has been in practice, rather than whether two provisions are worded identically.
This approach is particularly suited to cyber law for several reasons. First, the problems addressed—data protection, cybersecurity,
content moderation, cybercrime—are global in nature; no jurisdiction has a monopoly on solutions. Second, the rapid pace of technological change means that regulatory innovation in one jurisdiction frequently serves as a model (or a cautionary tale) for others. The GDPR's influence on subsequent legislation in Brazil (LGPD), Japan (APPI amendments), India
(DPDPA), and other jurisdictions is a prominent example.[105] Third, the increasing interconnectedness of digital economies means that regulatory choices in one jurisdiction have extraterritorial effects that demand comparative understanding.
The Volume is organized by jurisdictional scope rather than by substantive topic, reflecting the editorial judgment that legal analysis is most meaningful when grounded in the institutional, constitutional,
and political context of a specific legal system. Thus, Parts Two through Nine examine the cyber law frameworks of specific jurisdictions or regions (EU/EEA, UK, US, China, Asia-Pacific, Latin America,
Africa/Middle East, Russia/Central Asia), while Part Ten addresses international treaties and soft law instruments. The Appendices provide cross-jurisdictional comparison tables, glossaries, and indices designed to facilitate comparative analysis across the entire Volume.
Within each jurisdictional chapter, the following structural elements are generally present:
Legislative history and institutional framework — the political,
economic, and legal context in which the legislation was adopted.
Scope and key definitions — the material and personal scope of the legislation and its defining concepts.
Core obligations and rights — the substantive rules imposed on regulated entities and the rights conferred on individuals.
Cross-border dimensions — the mechanisms governing data transfers,
cross-border enforcement, and international cooperation.
Enforcement and penalties — the institutional architecture of enforcement and the sanctions available for non-compliance.
Selected provisions — full text — key legislative provisions reproduced in full, in the original language where an official English text is not available.
The Volume follows a four-tier source verification protocol:
Tier 1: Official government legislative databases — EUR-Lex, the US
Government Publishing Office (govinfo.gov), the NPC Standing Committee database (npc.gov.cn), and equivalent official sources. These are the primary authorities for legislative text and status.
Tier 2: International organization databases — UN Treaty Collection,
UNCTAD, OECD, Council of Europe, and APEC. These provide authoritative data on treaty status, signatories, and implementation reports.
Tier 3: Court databases — EUR-Lex for CJEU decisions, BAILII for UK
cases, CourtListener for US cases,  for Chinese court decisions, and equivalent national databases. These are the primary authorities for case law.
Tier 4: Law firm publications and academic analysis — used for commentary, contextual analysis, and identification of enforcement trends, but not as authoritative sources for the text of laws or court decisions.
All citations in this Volume follow The Bluebook: A Uniform System of
Citation (21st edition) for US and international sources, with jurisdiction-specific citation formats for national sources (e.g.,
OSCOLA for UK sources, the CJEU's official citation format for EU
cases).
Several methodological limitations should be noted. First, the pace of legislative change in cyber law is such that some provisions may have been amended, repealed, or supplemented between the time of writing and publication. The Volume adopts a cut-off date of early 2026 and will be updated through annual supplements. Second, the analysis focuses on formal legal rules (legislation, case law, and binding international instruments) rather than on regulatory practice, which may diverge significantly from formal rules. Third, the Volume's jurisdictional coverage, while extensive, is not exhaustive; certain jurisdictions with developing cyber law frameworks are treated at a summary level in regional chapters. Finally, translation of legal texts from non-English languages inevitably introduces interpretive questions; where possible,
original-language text is provided alongside English translation, and the Volume acknowledges that professional legal translation may introduce nuances of meaning.

  # Chapter 2: The Global Legislative Landscape

The global data protection landscape has undergone a transformation of historic proportions over the past decade. According to the United
Nations Conference on Trade and Development (UNCTAD) Cyberlaw Tracker,
as of late 2025, approximately 79% of countries worldwide have enacted some form of data protection and privacy legislation. This figure represents a dramatic acceleration from previous tracking cycles: in
2015, only 66% of countries had such laws on the books; by 2020, that figure had risen to approximately 71%; and by mid-2023, UNCTAD recorded
137 out of 194 UN member states—roughly 71%—with dedicated privacy statutes. The jump to 79% by 2025 signals that the pace of legislative adoption has not merely continued but intensified, driven by mounting public concern over surveillance capitalism, large-scale data breaches,
and the regulatory pull of the European Union's General Data Protection
Regulation (GDPR).
The significance of this statistic cannot be overstated. Data protection law has transitioned from a niche regulatory concern of a handful of developed jurisdictions into a near-universal legislative norm. In practical terms, of the 194 UN member states tracked by UNCTAD,
an estimated 153 to 155 now maintain standalone data protection statutes, framework laws, or constitutional privacy provisions supplemented by sector-specific regulation. The remaining approximately
40 countries—disproportionately concentrated among least developed countries (LDCs), small island developing states (SIDS), and a handful of conflict-affected states—continue to operate without comprehensive data protection frameworks, though many have bills in various stages of legislative drafting.
Several structural factors explain this acceleration. First, the
GDPR's extraterritorial reach, which took effect on 25 May 2018, created a powerful "Brussels effect": jurisdictions seeking to maintain data flows with the European Union faced strong incentives to adopt laws deemed "essentially equivalent" to EU standards. Second, regional harmonization initiatives—notably the African Union's Malabo Convention
(2014), the Economic Community of West African States (ECOWAS)
Supplementary Act A/SA.1/01/10, and the ASEAN Framework on Digital Data
Governance (2022)—provided legislative templates that lowered the drafting burden for smaller economies. Third, international financial institutions and development agencies, including the World Bank and
UNCTAD itself, have integrated data protection capacity-building into technical assistance programs. Fourth, a series of high-profile data breaches—Cambridge Analytica (2018), Equifax (2017), and the MOVEit vulnerability cascade (2023)—generated sustained political pressure for legislative action across both developed and developing economies.
It is important to note that the UNCTAD headline figure, while useful as a global benchmark, obscures considerable variation in the scope,
sophistication, and enforcement capacity of these laws. Having a data protection statute on the books does not guarantee effective implementation. Many countries in sub-Saharan Africa, South Asia, and
Central America have enacted framework legislation that lacks dedicated supervisory authorities, sufficient budgets, or independent enforcement powers. The gap between legislative adoption and operational enforcement remains one of the defining challenges of global data protection governance in 2026.
Virtually all developed economies—defined by UNCTAD as members of the
OECD high-income group—now maintain comprehensive data protection regimes. The sole exceptions are marginal cases where legislation is pending but not yet enacted. The European Union and European Economic
Area provide the paradigmatic model through the GDPR (Regulation (EU)
2016/679), supplemented by the ePrivacy Directive (2002/58/EC), the
Digital Markets Act, the Digital Services Act, the EU AI Act, NIS2, and
DORA. The United Kingdom, post-Brexit, has retained the UK GDPR and the
Data Protection Act 2018 while beginning to diverge through the Data
(Use and Access) Act 2025. Switzerland revised its Federal Act on Data
Protection (FADP) in September 2023, bringing it substantially closer to
GDPR standards.
The United States presents a distinctive picture within the developed-economy category. Lacking a single federal comprehensive privacy statute, the US relies on a dense patchwork of sectoral laws
(HIPAA, COPPA, GLBA, FERPA, VPPA, TCPA) and, increasingly, a rapidly proliferating set of state comprehensive privacy laws. As of early 2026,
nineteen US states have enacted such laws: California (CCPA/CPRA),
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA),
Texas (TDPSA), Florida (FDBR), Maryland (MODPA), Oregon, Montana,
Indiana, Delaware, New Jersey, Minnesota, New Hampshire, Tennessee,
Iowa, Kentucky, and Nebraska. Several additional states, including
Massachusetts, Pennsylvania, and Illinois (via potential comprehensive reforms), have active legislative proposals. The proposed American
Privacy Rights Act (APRA), if enacted, would establish a federal floor pre-empting many state provisions, though its prospects remain uncertain as of early 2026. The Federal Trade Commission continues to exercise broad privacy enforcement authority under Section 5 of the FTC Act, and the DOJ's 2025 Data Security Program has introduced new restrictions on bulk transfers of sensitive personal data to countries of concern.
Japan (Act on the Protection of Personal Information, APPI, as amended in 2022), South Korea (Personal Information Protection Act,
PIPA, as amended in 2023), Australia (Privacy Act 1988, amended by the
Privacy Legislation Amendment Act 2022), New Zealand (Privacy Act 2020),
and Canada (the proposed Consumer Privacy Protection Act, still under parliamentary consideration as of 2026) round out the developed-economy landscape. Canada remains a notable gap: its PIPEDA framework, enacted in 2000, has been widely criticized as outdated, and legislative reform has stalled repeatedly. Israel's Protection of Privacy Law (1981),
supplemented by the Privacy Protection Regulations (Data Security), also operates in this tier, though a comprehensive proposed amendment remains under discussion.
Latin America has emerged as one of the world's most dynamic regions for data protection legislation. The region's 88% adoption rate reflects a sustained wave of legislative activity over the past decade, catalyzed in part by the EU's adequacy decisions for Argentina (2003, renewed in
2023) and, more recently, the comprehensive framework established by
Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD, Law No.
13,709/2018, effective September 2020).
Brazil's LGPD deserves particular attention as the largest data protection regime in the Global South. Modeled substantially on the
GDPR, the LGPD establishes ten core processing principles, creates the
Autoridade Nacional de Proteção de Dados (ANPD) as the supervisory authority, and provides for administrative penalties of up to 2% of the entity's revenue in Brazil, capped at R$50 million per violation. The
ANPD has steadily expanded its enforcement profile since assuming full regulatory authority in 2022, issuing guidance on international data transfers, data breach notification, and the processing of children's data.
Argentina's Ley de Protección de Datos Personales (Law No. 25,326,
2000) was the region's pioneering statute and remains one of the few non-European laws to receive EU adequacy recognition. Mexico's Ley
Federal de Protección de Datos Personales en Posesión de los
Particulares (2010) established the Instituto Nacional de Transparencia,
Acceso a la Información y Protección de Datos Personales (INAI) as the supervisory authority. Chile amended its constitutional privacy protections and enacted the Ley de Protección de la Vida Privada in
2023, modernizing its framework. Colombia (Ley 1581 de 2012), Peru (Ley de Protección de Datos Personales, Ley 29733), and Uruguay (Ley de
Protección de Datos Personales, Ley 18.331) have all established comprehensive regimes, with Uruguay also holding EU adequacy status.
The Caribbean presents a more mixed picture. While several states have enacted or are developing data protection legislation—Jamaica (Data
Protection Act 2020), Trinidad and Tobago, and Barbados—the smaller island nations face resource constraints that limit enforcement capacity. Regional bodies, including the Caribbean Community (CARICOM),
have begun to explore harmonized approaches, but progress has been slower than in other regional blocs.
Africa's data protection landscape has undergone a remarkable transformation. From fewer than a dozen countries with privacy laws in
2015, the continent now counts approximately 36 to 38 jurisdictions with enacted data protection legislation, representing roughly 76% of African states. This growth has been driven by regional instruments—notably the
African Union's Convention on Cyber Security and Personal Data
Protection (the Malabo Convention, adopted in 2014, which entered into force in June 2023 after receiving the required ratifications) and the
ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection
(2010)—as well as by bilateral trade relationships that create incentives for regulatory alignment.
South Africa's Protection of Personal Information Act (POPIA), signed in 2013 and fully effective from July 2021, stands as the continent's most comprehensive and rigorously enforced data protection law.
Administered by the Information Regulator, POPIA establishes eight conditions for lawful processing, provides for fines of up to R10
million and imprisonment of up to 10 years for serious violations, and includes a data breach notification requirement. Nigeria enacted its
Data Protection Act in June 2023, establishing the Nigeria Data
Protection Commission (NDPC) and introducing penalties of up to 2% of annual gross revenue. Kenya's Data Protection Act (2019), administered by the Office of the Data Protection Commissioner, and Egypt's Data
Protection Law (Law No. 151 of 2020) represent significant framework legislation. Morocco (Law 09-08, enacted 2009) and Rwanda (Law
N°058/2021) have also adopted modern data protection statutes.
Despite this progress, enforcement remains uneven across the continent. Many data protection authorities operate with minimal budgets and staffing. The gap between legislative text and institutional capacity is particularly acute in Francophone West and Central Africa,
where the OHADA business law framework overlaps with data protection concerns. The African Union and development partners have invested in capacity-building programs, but achieving effective enforcement across
54 diverse jurisdictions remains a long-term challenge.
The Asia-Pacific region presents the most heterogeneous data protection landscape of any major geographic zone. At 65% adoption, it lags behind both developed economies and Latin America, reflecting the vast diversity of political systems, economic development levels, and regulatory philosophies across the region. The contrast between, on one hand, Japan, South Korea, and Singapore—jurisdictions with mature,
well-resourced data protection regimes—and, on the other, countries like
Myanmar, Laos, and Brunei, which lack comprehensive framework laws,
illustrates this diversity starkly.
China's data protection framework deserves special attention given its scale and systemic distinctiveness. Rather than a single omnibus statute, China has constructed a "three-pillar" architecture: the
Cybersecurity Law (2017), the Data Security Law (2021), and the Personal
Information Protection Law (PIPL, 2021), supplemented by the Network
Data Security Management Regulations (effective January 2025) and extensive sector-specific measures. The PIPL shares conceptual DNA with the GDPR—consent-based processing, data subject rights, cross-border transfer restrictions—but operates within China's distinctive governance model, including data localization requirements, state-security carve-outs, and the powerful role of the Cyberspace Administration of
China (CAC) as both regulator and enforcer.
India's Digital Personal Data Protection Act (DPDPA, 2023) represents another significant development, potentially covering 1.4 billion data subjects. The DPDPA adopts a consent-based framework but departs from the GDPR model in several respects: it does not establish an independent data protection commission but rather a government-appointed Data
Protection Board, and it provides the central government with broad exemptions on grounds of national security and public interest. Draft implementing rules were under public consultation through 2025, and the full operationalization of the DPDPA remains a work in progress.
Southeast Asia has seen significant legislative activity. Indonesia enacted its Personal Data Protection Law (UU PDP) in 2022. Thailand's
Personal Data Protection Act (PDPA) took full effect in June 2022.
Vietnam's Decree 13/2023 on Personal Data Protection introduced, among other measures, requirements for data protection impact assessments and cross-border transfer assessments. The Philippines' Data Privacy Act
(2012), administered by the National Privacy Commission, was one of the region's early adopters. Malaysia's Personal Data Protection Act (2010)
is currently undergoing revision to strengthen individual rights and modernize its provisions. Singapore's Personal Data Protection Act
(PDPA), administered by the Personal Data Protection Commission, has been progressively amended to introduce mandatory data breach notification and strengthen consent requirements.
Taiwan's Personal Data Protection Act (2015 amendment) and Hong
Kong's Personal Data (Privacy) Ordinance (amended 2021 to introduce mandatory breach notification) complete the major Asia-Pacific frameworks. The region's remaining gaps—Myanmar, Cambodia, Laos,
Bangladesh, Pakistan (which has a pending Personal Data Protection
Bill), Bhutan, and several Pacific Island states—represent both a challenge and an opportunity for regional harmonization efforts.
Least developed countries, as classified by the United Nations,
present the lowest rate of data protection legislation adoption at approximately 57%. This figure, while the lowest among the regional categories tracked by UNCTAD, nonetheless represents a substantial improvement from approximately 30% a decade ago. Countries such as
Bangladesh, Nepal, Rwanda, Senegal, and Uganda have enacted or are in the process of enacting data protection legislation, often with technical assistance from UNCTAD, the World Bank, or bilateral development partners.
The challenges facing LDCs in implementing data protection are structural. Limited legislative drafting capacity, competing policy priorities, underfunded regulatory institutions, and the absence of a robust domestic data-processing industry all constrain both adoption and enforcement. Moreover, many LDCs serve primarily as data subjects rather than data controllers: their citizens' data is harvested by multinational technology platforms headquartered abroad, raising acute questions about extraterritorial enforcement and the practical utility of domestic legislation without international cooperation mechanisms.
Nevertheless, the trajectory is upward. The African Union's Malabo
Convention, the ASEAN Framework on Digital Data Governance, and bilateral trade agreements increasingly include data protection provisions that create incentives for LDCs to adopt minimum standards.
The principle that data protection is not merely a developed-world luxury but a fundamental component of digital development and consumer trust in the digital economy has gained broad acceptance in international policy circles.
Despite the diversity of legal traditions, political systems, and economic structures across jurisdictions, the global data protection landscape exhibits remarkable convergence around a core set of principles and institutional mechanisms. This convergence is attributable in significant part to the "Brussels effect" of the GDPR,
which has served as a de facto template for legislation worldwide, but it also reflects deeper underlying consensus about the nature of privacy as a fundamental right.
Consent as a foundational mechanism. The vast majority of data protection statutes enacted since 2018 treat informed, freely given,
specific, and unambiguous consent as the primary (though not exclusive)
lawful basis for data processing. Article 6(1)(a) of the GDPR, Article 7
of China's PIPL, Section 6 of Brazil's LGPD, and Section 4 of India's
DPDPA all center consent as the default mechanism. While the practical operation of consent varies—EU law requires affirmative opt-in for non-essential processing, while many US state laws permit opt-out models for certain categories—the conceptual centrality of consent is near-universal.
Data breach notification. Mandatory data breach notification has become a standard feature of data protection legislation worldwide. The
GDPR's 72-hour notification requirement (Article 33) has been replicated or adapted in the UK GDPR, Brazil's LGPD (Article 48), South Korea's
PIPA, Australia's Notifiable Data Breaches scheme, Singapore's PDPA
(2019 amendment), China's PIPL (Article 57), and virtually every state comprehensive privacy law in the United States. Notification thresholds and timeframes vary—from 24 hours in some US state laws to 72 hours in the GDPR to "without undue delay" in several jurisdictions—but the principle that organizations must disclose breaches to affected individuals and supervisory authorities is now established global norm.
Supervisory authorities and data protection officers. The institutional architecture of data protection has also converged. Most comprehensive statutes establish or designate a supervisory authority with investigative, corrective, and advisory powers. The GDPR's requirement for a Data Protection Officer (DPO) in certain circumstances
(Article 37) has been widely replicated, including in China's PIPL
(Article 52, which requires a "person in charge of personal information protection"), Brazil's LGPD (Encarregado), and India's DPDPA. The independence of these authorities varies considerably—EU data protection authorities operate with a high degree of institutional independence mandated by the GDPR itself, while authorities in China, India, and several African states operate within executive branch structures—but the institutional form is now standardized.
Cross-border data transfer restrictions. Virtually every comprehensive data protection regime imposes some form of restriction on the transfer of personal data to foreign jurisdictions. The mechanisms employed—adequacy decisions (EU), standard contractual clauses, binding corporate rules, consent-based transfers, and data localization requirements—vary, but the underlying principle that data transferred abroad must receive an "essentially equivalent" level of protection has become a global norm. China's PIPL (Articles 38–43), India's DPDPA
(Chapter V), Russia's Federal Law No. 152-FZ (with its data localization requirement), and Turkey's Law on the Protection of Personal Data (KVKK)
all reflect this convergence, even as they implement it through distinct mechanisms.
Notwithstanding these convergences, significant divergences persist across jurisdictions, creating compliance complexity for multinational organizations and friction in the cross-border data transfer regime.
Consent models: opt-in versus opt-out. The most fundamental divergence concerns the default consent model. The EU, following the
GDPR, operates on a strict opt-in basis: consent must be an affirmative,
unambiguous indication of the data subject's wishes (Article 4(11),
GDPR). By contrast, the United States, across its state privacy laws,
generally permits an opt-out model for many processing activities:
businesses may process personal data by default unless the consumer affirmatively opts out. California's CPRA, for example, permits businesses to process data for "business purposes" unless the consumer submits a "do not sell or share my personal information" request. This divergence reflects fundamentally different philosophical orientations toward privacy—the EU's rights-based, deontological approach versus the
US's harm-based, pragmatic approach—and has profound implications for the design of privacy notices, consent management platforms, and data processing architectures.
Enforcement architecture and independence. The independence and powers of supervisory authorities vary dramatically. EU data protection authorities, established under Chapter VI of the GDPR, operate with a degree of institutional independence that is constitutionally mandated and judicially enforceable. Ireland's Data Protection Commission,
France's CNIL, and Germany's state-level authorities have all demonstrated the capacity to impose substantial fines and issue binding corrective decisions. By contrast, India's Data Protection Board is a government-appointed body with limited independence. China's CAC
operates within the party-state apparatus and exercises its authority in coordination with broader political objectives. In many African jurisdictions, data protection authorities lack the budgets, staffing,
and political autonomy to function as effective regulators. The result is a global enforcement landscape characterized by extreme asymmetry: a handful of European authorities account for the vast majority of substantial fines, while most supervisory authorities worldwide remain largely dormant.
Maximum penalties. Penalty structures exhibit both convergence in principle (most regimes provide for administrative fines proportionate to the severity of the violation) and significant divergence in scale.
The GDPR's maximum of €20 million or 4% of global annual turnover
(whichever is higher) sets the benchmark. Brazil's LGPD caps fines at 2%
of revenue in Brazil (capped at R$50 million per infraction). China's
PIPL provides for fines of up to ¥50 million or 5% of the previous year's revenue for serious violations (Article 66). US state laws typically provide for per-violation civil penalties of $2,000–$7,500,
with some states adding enhanced penalties for violations involving children's data. The practical impact of these penalty regimes varies enormously: the GDPR's global turnover basis creates the largest potential liability, while per-violation penalties in the United States can accumulate rapidly in class-action litigation.
Scope and definitions. The scope of personal data, the treatment of pseudonymized versus anonymized data, and the definition of "sensitive"
data categories vary across jurisdictions. The GDPR defines personal data broadly as "any information relating to an identified or identifiable natural person" (Article 4(1)). The US state laws generally adopt similar definitions but vary in their treatment of de-identified data and the scope of exemptions for certain data types (employee data,
HIPAA-covered data, GLBA-covered data). China's PIPL distinguishes between "general personal information" and "sensitive personal information," with heightened protections for the latter, and introduces the concept of "important data" in the Data Security Law, a category with no direct equivalent in Western frameworks. These definitional divergences create practical compliance challenges, particularly for organizations that must simultaneously satisfy multiple jurisdictions'
data classification requirements.
The global legislative landscape is not merely a collection of standalone data protection statutes; it is an increasingly dense and interconnected web of regulations spanning four overlapping domains:
data protection, cybersecurity, e-commerce, and content regulation.
Understanding the intersections among these domains is essential for any comprehensive account of cyber law in 2026.
Data protection and cybersecurity have become inseparable regulatory domains. At the most basic level, cybersecurity measures—encryption,
access controls, network segmentation, intrusion detection—are the technical mechanisms through which data protection obligations
(confidentiality, integrity, availability of personal data) are operationalized. The GDPR itself recognizes this relationship, requiring data controllers and processors to implement "appropriate technical and organizational measures to ensure a level of security appropriate to the risk" (Article 32). The EU's NIS2 Directive (Directive (EU) 2022/2555),
which expanded the scope of critical infrastructure sectors subject to cybersecurity obligations and as of early 2025 had been transposed into national law by 15 of 27 member states, operates in parallel with the
GDPR but addresses distinct (though overlapping) concerns: the resilience of network and information systems, as opposed to the protection of personal data per se.
China's Cybersecurity Law (2017) explicitly links network security obligations with personal information protection, requiring network operators to establish data classification systems, conduct security assessments, and report security incidents. The Data Security Law (2021)
introduces a comprehensive data classification hierarchy—core data,
important data, and general data—each carrying different security obligations, with the CAC empowered to designate data categories and establish protection standards. The UK's Cyber Security and Resilience
Bill (2025) further expands this convergence by introducing data center regulation and critical supplier obligations alongside traditional cybersecurity measures.
In the United States, the intersection is more fragmented. The New
York SHIELD Act requires "reasonable safeguards" for private information of New York residents. HIPAA's Security Rule establishes detailed technical and administrative safeguards for electronic protected health information. State comprehensive privacy laws increasingly incorporate cybersecurity requirements: California's CPRA mandates cybersecurity audits for certain businesses (effective 2028), and Virginia's VCDPA
requires data protection impact assessments. The SEC's cybersecurity disclosure rules (2023) have added a securities-law dimension, requiring public companies to disclose material cybersecurity incidents within four business days.
Electronic commerce regulation intersects with data protection at multiple points: the collection and processing of consumer data for marketing and personalization, the use of cookies and tracking technologies, the enforcement of consumer rights (including data portability and deletion), and the regulation of online marketplaces.
The EU's ePrivacy Directive (2002/58/EC), which regulates the use of cookies, direct marketing, and traffic and location data, sits alongside the GDPR as a complementary framework specifically targeting electronic communications. The proposed ePrivacy Regulation, which would have modernized the directive, was withdrawn in February 2025 after years of legislative stalemate, leaving the 2002 directive in force.
The United States regulates e-commerce through a combination of federal and state law. The CAN-SPAM Act (2003) governs commercial email.
The FTC Act §5 prohibits unfair or deceptive practices in e-commerce,
including misleading privacy representations. State consumer protection laws supplement federal authority. China's E-Commerce Law (2019)
regulates online platform operators, consumer protection, and data handling in e-commerce contexts, with the CAC issuing supplementary measures on algorithmic recommendation services. India's forthcoming e-commerce rules, drafted under the Consumer Protection (E-Commerce)
Rules 2020, address data protection alongside competition and consumer rights concerns.
The regulation of online content—harmful content, disinformation,
terrorist propaganda, child sexual abuse material (CSAM), and illegal speech—has become one of the most contentious areas of cyber law, and it intersects with data protection in complex ways. Content moderation systems rely on automated processing of user data, including behavioral analysis, linguistic profiling, and, increasingly, AI-based classification. The use of such systems implicates data protection obligations regarding the processing of personal data for content moderation purposes.
The EU's Digital Services Act (DSA, Regulation (EU) 2022/2065)
establishes tiered obligations for online platforms based on their size and systemic risk. Very large online platforms (VLOPs) and very large online search engines (VLOSEs) must conduct annual risk assessments,
implement risk mitigation measures, and submit to independent audits—all of which involve the processing and analysis of significant quantities of personal data. The DSA's transparency requirements regarding advertising and content moderation create additional data collection and disclosure obligations that must be reconciled with GDPR principles of data minimization and purpose limitation.
The UK's Online Safety Act (2023) imposes a duty of care on platform providers regarding illegal content and content harmful to children,
creating enforcement powers for Ofcom that operate alongside the
Information Commissioner's Office (ICO) under the UK GDPR. The tension between content regulation objectives (which may require extensive data collection and analysis) and data protection principles (which limit such collection) is a recurring theme in both jurisdictions.
In the United States, content regulation operates primarily through
Section 230 of the Communications Decency Act (47 U.S.C. § 230), which provides platforms with immunity from liability for third-party content.
The future of Section 230 is subject to intense political and judicial scrutiny, as illustrated by the Supreme Court's treatment in NetChoice,
LLC v. Paxton, 595 U.S. 42 (2024). Several states have enacted content moderation laws (Texas HB 20, Florida SB 7072) that regulate how platforms may moderate content, creating a direct collision between content regulation and platforms' First Amendment rights. India's
Information Technology (Intermediary Guidelines and Digital Media Ethics
Code) Rules 2021 impose content moderation obligations on intermediaries, including traceability requirements for messaging platforms, with significant data protection implications.
The cumulative effect of these regulatory developments is what may be termed the "quadruple overlay": organizations operating in the digital economy must simultaneously comply with data protection laws,
cybersecurity obligations, e-commerce regulations, and content moderation requirements—each governed by distinct (and sometimes conflicting) legal frameworks, enforced by different regulators, and subject to different penalty regimes. The EU has made the most systematic effort to integrate these domains through its comprehensive digital regulation package (GDPR + ePrivacy + DMA + DSA + AI Act + NIS2
+ DORA), but even within the EU, the challenge of regulatory coherence across multiple directives and regulations remains significant.
For multinational organizations, the compliance challenge is formidable. A technology company operating across the EU, the United
States, China, and India must navigate at least four fundamentally different regulatory philosophies, each with its own consent requirements, cross-border transfer mechanisms, enforcement institutions, and penalty structures. The concept of "regulatory interoperability"—the development of mechanisms by which different jurisdictions' requirements can be simultaneously satisfied without fragmentation of the global digital economy—has emerged as a central concern in international policy discussions, including the OECD's work on privacy guidelines and AI principles, the APEC Cross-Border Privacy
Rules (CBPR) system, and the United Nations Open-Ended Working Group on developments in the field of information and telecommunications in the context of international security (OEWG).
As the regulatory landscape continues to evolve, the quadruple overlay is likely to deepen. The full enforcement of the EU AI Act
(August 2026), the potential enactment of a US federal privacy law, the operationalization of India's DPDPA, and the ongoing maturation of
China's three-pillar data governance framework will all add layers of complexity. The challenge for policymakers, regulators, and the regulated community alike is to manage this complexity in ways that protect individual rights, promote cybersecurity, enable digital commerce, and safeguard public discourse—without creating an incoherent patchwork that stifles innovation and undermines the global nature of the digital economy.
This chapter provides the statistical and analytical foundation for the jurisdiction-specific analyses that follow in Parts Two through Nine of this Volume.

# Chapter 2: The Global Legislative Landscape (2026 Data)

The global data protection landscape has undergone a transformation of historic proportions over the past decade. According to the United
Nations Conference on Trade and Development (UNCTAD) Cyberlaw Tracker,
as of late 2025, approximately 79% of countries worldwide have enacted some form of data protection and privacy legislation. This figure represents a dramatic acceleration from previous tracking cycles: in
2015, only 66% of countries had such laws on the books; by 2020, that figure had risen to approximately 71%; and by mid-2023, UNCTAD recorded
137 out of 194 UN member states—roughly 71%—with dedicated privacy statutes. The jump to 79% by 2025 signals that the pace of legislative adoption has not merely continued but intensified, driven by mounting public concern over surveillance capitalism, large-scale data breaches,
and the regulatory pull of the European Union's General Data Protection
Regulation (GDPR).
The significance of this statistic cannot be overstated. Data protection law has transitioned from a niche regulatory concern of a handful of developed jurisdictions into a near-universal legislative norm. In practical terms, of the 194 UN member states tracked by UNCTAD,
an estimated 153 to 155 now maintain standalone data protection statutes, framework laws, or constitutional privacy provisions supplemented by sector-specific regulation. The remaining approximately
40 countries—disproportionately concentrated among least developed countries (LDCs), small island developing states (SIDS), and a handful of conflict-affected states—continue to operate without comprehensive data protection frameworks, though many have bills in various stages of legislative drafting.
Several structural factors explain this acceleration. First, the
GDPR's extraterritorial reach, which took effect on 25 May 2018, created a powerful "Brussels effect": jurisdictions seeking to maintain data flows with the European Union faced strong incentives to adopt laws deemed "essentially equivalent" to EU standards. Second, regional harmonization initiatives—notably the African Union's Malabo Convention
(2014), the Economic Community of West African States (ECOWAS)
Supplementary Act A/SA.1/01/10, and the ASEAN Framework on Digital Data
Governance (2022)—provided legislative templates that lowered the drafting burden for smaller economies. Third, international financial institutions and development agencies, including the World Bank and
UNCTAD itself, have integrated data protection capacity-building into technical assistance programs. Fourth, a series of high-profile data breaches—Cambridge Analytica (2018), Equifax (2017), and the MOVEit vulnerability cascade (2023)—generated sustained political pressure for legislative action across both developed and developing economies.
It is important to note that the UNCTAD headline figure, while useful as a global benchmark, obscures considerable variation in the scope,
sophistication, and enforcement capacity of these laws. Having a data protection statute on the books does not guarantee effective implementation. Many countries in sub-Saharan Africa, South Asia, and
Central America have enacted framework legislation that lacks dedicated supervisory authorities, sufficient budgets, or independent enforcement powers. The gap between legislative adoption and operational enforcement remains one of the defining challenges of global data protection governance in 2026.
Virtually all developed economies—defined by UNCTAD as members of the
OECD high-income group—now maintain comprehensive data protection regimes. The sole exceptions are marginal cases where legislation is pending but not yet enacted. The European Union and European Economic
Area provide the paradigmatic model through the GDPR (Regulation (EU)
2016/679), supplemented by the ePrivacy Directive (2002/58/EC), the
Digital Markets Act, the Digital Services Act, the EU AI Act, NIS2, and
DORA. The United Kingdom, post-Brexit, has retained the UK GDPR and the
Data Protection Act 2018 while beginning to diverge through the Data
(Use and Access) Act 2025. Switzerland revised its Federal Act on Data
Protection (FADP) in September 2023, bringing it substantially closer to
GDPR standards.
The United States presents a distinctive picture within the developed-economy category. Lacking a single federal comprehensive privacy statute, the US relies on a dense patchwork of sectoral laws
(HIPAA, COPPA, GLBA, FERPA, VPPA, TCPA) and, increasingly, a rapidly proliferating set of state comprehensive privacy laws. As of early 2026,
nineteen US states have enacted such laws: California (CCPA/CPRA),
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA),
Texas (TDPSA), Florida (FDBR), Maryland (MODPA), Oregon, Montana,
Indiana, Delaware, New Jersey, Minnesota, New Hampshire, Tennessee,
Iowa, Kentucky, and Nebraska. Several additional states, including
Massachusetts, Pennsylvania, and Illinois (via potential comprehensive reforms), have active legislative proposals. The proposed American
Privacy Rights Act (APRA), if enacted, would establish a federal floor pre-empting many state provisions, though its prospects remain uncertain as of early 2026. The Federal Trade Commission continues to exercise broad privacy enforcement authority under Section 5 of the FTC Act, and the DOJ's 2025 Data Security Program has introduced new restrictions on bulk transfers of sensitive personal data to countries of concern.
Japan (Act on the Protection of Personal Information, APPI, as amended in 2022), South Korea (Personal Information Protection Act,
PIPA, as amended in 2023), Australia (Privacy Act 1988, amended by the
Privacy Legislation Amendment Act 2022), New Zealand (Privacy Act 2020),
and Canada (the proposed Consumer Privacy Protection Act, still under parliamentary consideration as of 2026) round out the developed-economy landscape. Canada remains a notable gap: its PIPEDA framework, enacted in 2000, has been widely criticized as outdated, and legislative reform has stalled repeatedly. Israel's Protection of Privacy Law (1981),
supplemented by the Privacy Protection Regulations (Data Security), also operates in this tier, though a comprehensive proposed amendment remains under discussion.
Latin America has emerged as one of the world's most dynamic regions for data protection legislation. The region's 88% adoption rate reflects a sustained wave of legislative activity over the past decade, catalyzed in part by the EU's adequacy decisions for Argentina (2003, renewed in
2023) and, more recently, the comprehensive framework established by
Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD, Law No.
13,709/2018, effective September 2020).
Brazil's LGPD deserves particular attention as the largest data protection regime in the Global South. Modeled substantially on the
GDPR, the LGPD establishes ten core processing principles, creates the
Autoridade Nacional de Proteção de Dados (ANPD) as the supervisory authority, and provides for administrative penalties of up to 2% of the entity's revenue in Brazil, capped at R$50 million per violation. The
ANPD has steadily expanded its enforcement profile since assuming full regulatory authority in 2022, issuing guidance on international data transfers, data breach notification, and the processing of children's data.
Argentina's Ley de Protección de Datos Personales (Law No. 25,326,
2000) was the region's pioneering statute and remains one of the few non-European laws to receive EU adequacy recognition. Mexico's Ley
Federal de Protección de Datos Personales en Posesión de los
Particulares (2010) established the Instituto Nacional de Transparencia,
Acceso a la Información y Protección de Datos Personales (INAI) as the supervisory authority. Chile amended its constitutional privacy protections and enacted the Ley de Protección de la Vida Privada in
2023, modernizing its framework. Colombia (Ley 1581 de 2012), Peru (Ley de Protección de Datos Personales, Ley 29733), and Uruguay (Ley de
Protección de Datos Personales, Ley 18.331) have all established comprehensive regimes, with Uruguay also holding EU adequacy status.
The Caribbean presents a more mixed picture. While several states have enacted or are developing data protection legislation—Jamaica (Data
Protection Act 2020), Trinidad and Tobago, and Barbados—the smaller island nations face resource constraints that limit enforcement capacity. Regional bodies, including the Caribbean Community (CARICOM),
have begun to explore harmonized approaches, but progress has been slower than in other regional blocs.
Africa's data protection landscape has undergone a remarkable transformation. From fewer than a dozen countries with privacy laws in
2015, the continent now counts approximately 36 to 38 jurisdictions with enacted data protection legislation, representing roughly 76% of African states. This growth has been driven by regional instruments—notably the
African Union's Convention on Cyber Security and Personal Data
Protection (the Malabo Convention, adopted in 2014, which entered into force in June 2023 after receiving the required ratifications) and the
ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection
(2010)—as well as by bilateral trade relationships that create incentives for regulatory alignment.
South Africa's Protection of Personal Information Act (POPIA), signed in 2013 and fully effective from July 2021, stands as the continent's most comprehensive and rigorously enforced data protection law.
Administered by the Information Regulator, POPIA establishes eight conditions for lawful processing, provides for fines of up to R10
million and imprisonment of up to 10 years for serious violations, and includes a data breach notification requirement. Nigeria enacted its
Data Protection Act in June 2023, establishing the Nigeria Data
Protection Commission (NDPC) and introducing penalties of up to 2% of annual gross revenue. Kenya's Data Protection Act (2019), administered by the Office of the Data Protection Commissioner, and Egypt's Data
Protection Law (Law No. 151 of 2020) represent significant framework legislation. Morocco (Law 09-08, enacted 2009) and Rwanda (Law
N°058/2021) have also adopted modern data protection statutes.
Despite this progress, enforcement remains uneven across the continent. Many data protection authorities operate with minimal budgets and staffing. The gap between legislative text and institutional capacity is particularly acute in Francophone West and Central Africa,
where the OHADA business law framework overlaps with data protection concerns. The African Union and development partners have invested in capacity-building programs, but achieving effective enforcement across
54 diverse jurisdictions remains a long-term challenge.
The Asia-Pacific region presents the most heterogeneous data protection landscape of any major geographic zone. At 65% adoption, it lags behind both developed economies and Latin America, reflecting the vast diversity of political systems, economic development levels, and regulatory philosophies across the region. The contrast between, on one hand, Japan, South Korea, and Singapore—jurisdictions with mature,
well-resourced data protection regimes—and, on the other, countries like
Myanmar, Laos, and Brunei, which lack comprehensive framework laws,
illustrates this diversity starkly.
China's data protection framework deserves special attention given its scale and systemic distinctiveness. Rather than a single omnibus statute, China has constructed a "three-pillar" architecture: the
Cybersecurity Law (2017), the Data Security Law (2021), and the Personal
Information Protection Law (PIPL, 2021), supplemented by the Network
Data Security Management Regulations (effective January 2025) and extensive sector-specific measures. The PIPL shares conceptual DNA with the GDPR—consent-based processing, data subject rights, cross-border transfer restrictions—but operates within China's distinctive governance model, including data localization requirements, state-security carve-outs, and the powerful role of the Cyberspace Administration of
China (CAC) as both regulator and enforcer.
India's Digital Personal Data Protection Act (DPDPA, 2023) represents another significant development, potentially covering 1.4 billion data subjects. The DPDPA adopts a consent-based framework but departs from the GDPR model in several respects: it does not establish an independent data protection commission but rather a government-appointed Data
Protection Board, and it provides the central government with broad exemptions on grounds of national security and public interest. Draft implementing rules were under public consultation through 2025, and the full operationalization of the DPDPA remains a work in progress.
Southeast Asia has seen significant legislative activity. Indonesia enacted its Personal Data Protection Law (UU PDP) in 2022. Thailand's
Personal Data Protection Act (PDPA) took full effect in June 2022.
Vietnam's Decree 13/2023 on Personal Data Protection introduced, among other measures, requirements for data protection impact assessments and cross-border transfer assessments. The Philippines' Data Privacy Act
(2012), administered by the National Privacy Commission, was one of the region's early adopters. Malaysia's Personal Data Protection Act (2010)
is currently undergoing revision to strengthen individual rights and modernize its provisions. Singapore's Personal Data Protection Act
(PDPA), administered by the Personal Data Protection Commission, has been progressively amended to introduce mandatory data breach notification and strengthen consent requirements.
Taiwan's Personal Data Protection Act (2015 amendment) and Hong
Kong's Personal Data (Privacy) Ordinance (amended 2021 to introduce mandatory breach notification) complete the major Asia-Pacific frameworks. The region's remaining gaps—Myanmar, Cambodia, Laos,
Bangladesh, Pakistan (which has a pending Personal Data Protection
Bill), Bhutan, and several Pacific Island states—represent both a challenge and an opportunity for regional harmonization efforts.
Least developed countries, as classified by the United Nations,
present the lowest rate of data protection legislation adoption at approximately 57%. This figure, while the lowest among the regional categories tracked by UNCTAD, nonetheless represents a substantial improvement from approximately 30% a decade ago. Countries such as
Bangladesh, Nepal, Rwanda, Senegal, and Uganda have enacted or are in the process of enacting data protection legislation, often with technical assistance from UNCTAD, the World Bank, or bilateral development partners.
The challenges facing LDCs in implementing data protection are structural. Limited legislative drafting capacity, competing policy priorities, underfunded regulatory institutions, and the absence of a robust domestic data-processing industry all constrain both adoption and enforcement. Moreover, many LDCs serve primarily as data subjects rather than data controllers: their citizens' data is harvested by multinational technology platforms headquartered abroad, raising acute questions about extraterritorial enforcement and the practical utility of domestic legislation without international cooperation mechanisms.
Nevertheless, the trajectory is upward. The African Union's Malabo
Convention, the ASEAN Framework on Digital Data Governance, and bilateral trade agreements increasingly include data protection provisions that create incentives for LDCs to adopt minimum standards.
The principle that data protection is not merely a developed-world luxury but a fundamental component of digital development and consumer trust in the digital economy has gained broad acceptance in international policy circles.
Despite the diversity of legal traditions, political systems, and economic structures across jurisdictions, the global data protection landscape exhibits remarkable convergence around a core set of principles and institutional mechanisms. This convergence is attributable in significant part to the "Brussels effect" of the GDPR,
which has served as a de facto template for legislation worldwide, but it also reflects deeper underlying consensus about the nature of privacy as a fundamental right.
Consent as a foundational mechanism. The vast majority of data protection statutes enacted since 2018 treat informed, freely given,
specific, and unambiguous consent as the primary (though not exclusive)
lawful basis for data processing. Article 6(1)(a) of the GDPR, Article 7
of China's PIPL, Section 6 of Brazil's LGPD, and Section 4 of India's
DPDPA all center consent as the default mechanism. While the practical operation of consent varies—EU law requires affirmative opt-in for non-essential processing, while many US state laws permit opt-out models for certain categories—the conceptual centrality of consent is near-universal.
Data breach notification. Mandatory data breach notification has become a standard feature of data protection legislation worldwide. The
GDPR's 72-hour notification requirement (Article 33) has been replicated or adapted in the UK GDPR, Brazil's LGPD (Article 48), South Korea's
PIPA, Australia's Notifiable Data Breaches scheme, Singapore's PDPA
(2019 amendment), China's PIPL (Article 57), and virtually every state comprehensive privacy law in the United States. Notification thresholds and timeframes vary—from 24 hours in some US state laws to 72 hours in the GDPR to "without undue delay" in several jurisdictions—but the principle that organizations must disclose breaches to affected individuals and supervisory authorities is now established global norm.
Supervisory authorities and data protection officers. The institutional architecture of data protection has also converged. Most comprehensive statutes establish or designate a supervisory authority with investigative, corrective, and advisory powers. The GDPR's requirement for a Data Protection Officer (DPO) in certain circumstances
(Article 37) has been widely replicated, including in China's PIPL
(Article 52, which requires a "person in charge of personal information protection"), Brazil's LGPD (Encarregado), and India's DPDPA. The independence of these authorities varies considerably—EU data protection authorities operate with a high degree of institutional independence mandated by the GDPR itself, while authorities in China, India, and several African states operate within executive branch structures—but the institutional form is now standardized.
Cross-border data transfer restrictions. Virtually every comprehensive data protection regime imposes some form of restriction on the transfer of personal data to foreign jurisdictions. The mechanisms employed—adequacy decisions (EU), standard contractual clauses, binding corporate rules, consent-based transfers, and data localization requirements—vary, but the underlying principle that data transferred abroad must receive an "essentially equivalent" level of protection has become a global norm. China's PIPL (Articles 38–43), India's DPDPA
(Chapter V), Russia's Federal Law No. 152-FZ (with its data localization requirement), and Turkey's Law on the Protection of Personal Data (KVKK)
all reflect this convergence, even as they implement it through distinct mechanisms.
Notwithstanding these convergences, significant divergences persist across jurisdictions, creating compliance complexity for multinational organizations and friction in the cross-border data transfer regime.
Consent models: opt-in versus opt-out. The most fundamental divergence concerns the default consent model. The EU, following the
GDPR, operates on a strict opt-in basis: consent must be an affirmative,
unambiguous indication of the data subject's wishes (Article 4(11),
GDPR). By contrast, the United States, across its state privacy laws,
generally permits an opt-out model for many processing activities:
businesses may process personal data by default unless the consumer affirmatively opts out. California's CPRA, for example, permits businesses to process data for "business purposes" unless the consumer submits a "do not sell or share my personal information" request. This divergence reflects fundamentally different philosophical orientations toward privacy—the EU's rights-based, deontological approach versus the
US's harm-based, pragmatic approach—and has profound implications for the design of privacy notices, consent management platforms, and data processing architectures.
Enforcement architecture and independence. The independence and powers of supervisory authorities vary dramatically. EU data protection authorities, established under Chapter VI of the GDPR, operate with a degree of institutional independence that is constitutionally mandated and judicially enforceable. Ireland's Data Protection Commission,
France's CNIL, and Germany's state-level authorities have all demonstrated the capacity to impose substantial fines and issue binding corrective decisions. By contrast, India's Data Protection Board is a government-appointed body with limited independence. China's CAC
operates within the party-state apparatus and exercises its authority in coordination with broader political objectives. In many African jurisdictions, data protection authorities lack the budgets, staffing,
and political autonomy to function as effective regulators. The result is a global enforcement landscape characterized by extreme asymmetry: a handful of European authorities account for the vast majority of substantial fines, while most supervisory authorities worldwide remain largely dormant.
Maximum penalties. Penalty structures exhibit both convergence in principle (most regimes provide for administrative fines proportionate to the severity of the violation) and significant divergence in scale.
The GDPR's maximum of €20 million or 4% of global annual turnover
(whichever is higher) sets the benchmark. Brazil's LGPD caps fines at 2%
of revenue in Brazil (capped at R$50 million per infraction). China's
PIPL provides for fines of up to ¥50 million or 5% of the previous year's revenue for serious violations (Article 66). US state laws typically provide for per-violation civil penalties of $2,000–$7,500,
with some states adding enhanced penalties for violations involving children's data. The practical impact of these penalty regimes varies enormously: the GDPR's global turnover basis creates the largest potential liability, while per-violation penalties in the United States can accumulate rapidly in class-action litigation.
Scope and definitions. The scope of personal data, the treatment of pseudonymized versus anonymized data, and the definition of "sensitive"
data categories vary across jurisdictions. The GDPR defines personal data broadly as "any information relating to an identified or identifiable natural person" (Article 4(1)). The US state laws generally adopt similar definitions but vary in their treatment of de-identified data and the scope of exemptions for certain data types (employee data,
HIPAA-covered data, GLBA-covered data). China's PIPL distinguishes between "general personal information" and "sensitive personal information," with heightened protections for the latter, and introduces the concept of "important data" in the Data Security Law, a category with no direct equivalent in Western frameworks. These definitional divergences create practical compliance challenges, particularly for organizations that must simultaneously satisfy multiple jurisdictions'
data classification requirements.
The global legislative landscape is not merely a collection of standalone data protection statutes; it is an increasingly dense and interconnected web of regulations spanning four overlapping domains:
data protection, cybersecurity, e-commerce, and content regulation.
Understanding the intersections among these domains is essential for any comprehensive account of cyber law in 2026.
Data protection and cybersecurity have become inseparable regulatory domains. At the most basic level, cybersecurity measures—encryption,
access controls, network segmentation, intrusion detection—are the technical mechanisms through which data protection obligations
(confidentiality, integrity, availability of personal data) are operationalized. The GDPR itself recognizes this relationship, requiring data controllers and processors to implement "appropriate technical and organizational measures to ensure a level of security appropriate to the risk" (Article 32). The EU's NIS2 Directive (Directive (EU) 2022/2555),
which expanded the scope of critical infrastructure sectors subject to cybersecurity obligations and as of early 2025 had been transposed into national law by 15 of 27 member states, operates in parallel with the
GDPR but addresses distinct (though overlapping) concerns: the resilience of network and information systems, as opposed to the protection of personal data per se.
China's Cybersecurity Law (2017) explicitly links network security obligations with personal information protection, requiring network operators to establish data classification systems, conduct security assessments, and report security incidents. The Data Security Law (2021)
introduces a comprehensive data classification hierarchy—core data,
important data, and general data—each carrying different security obligations, with the CAC empowered to designate data categories and establish protection standards. The UK's Cyber Security and Resilience
Bill (2025) further expands this convergence by introducing data center regulation and critical supplier obligations alongside traditional cybersecurity measures.
In the United States, the intersection is more fragmented. The New
York SHIELD Act requires "reasonable safeguards" for private information of New York residents. HIPAA's Security Rule establishes detailed technical and administrative safeguards for electronic protected health information. State comprehensive privacy laws increasingly incorporate cybersecurity requirements: California's CPRA mandates cybersecurity audits for certain businesses (effective 2028), and Virginia's VCDPA
requires data protection impact assessments. The SEC's cybersecurity disclosure rules (2023) have added a securities-law dimension, requiring public companies to disclose material cybersecurity incidents within four business days.
Electronic commerce regulation intersects with data protection at multiple points: the collection and processing of consumer data for marketing and personalization, the use of cookies and tracking technologies, the enforcement of consumer rights (including data portability and deletion), and the regulation of online marketplaces.
The EU's ePrivacy Directive (2002/58/EC), which regulates the use of cookies, direct marketing, and traffic and location data, sits alongside the GDPR as a complementary framework specifically targeting electronic communications. The proposed ePrivacy Regulation, which would have modernized the directive, was withdrawn in February 2025 after years of legislative stalemate, leaving the 2002 directive in force.
The United States regulates e-commerce through a combination of federal and state law. The CAN-SPAM Act (2003) governs commercial email.
The FTC Act §5 prohibits unfair or deceptive practices in e-commerce,
including misleading privacy representations. State consumer protection laws supplement federal authority. China's E-Commerce Law (2019)
regulates online platform operators, consumer protection, and data handling in e-commerce contexts, with the CAC issuing supplementary measures on algorithmic recommendation services. India's forthcoming e-commerce rules, drafted under the Consumer Protection (E-Commerce)
Rules 2020, address data protection alongside competition and consumer rights concerns.
The regulation of online content—harmful content, disinformation,
terrorist propaganda, child sexual abuse material (CSAM), and illegal speech—has become one of the most contentious areas of cyber law, and it intersects with data protection in complex ways. Content moderation systems rely on automated processing of user data, including behavioral analysis, linguistic profiling, and, increasingly, AI-based classification. The use of such systems implicates data protection obligations regarding the processing of personal data for content moderation purposes.
The EU's Digital Services Act (DSA, Regulation (EU) 2022/2065)
establishes tiered obligations for online platforms based on their size and systemic risk. Very large online platforms (VLOPs) and very large online search engines (VLOSEs) must conduct annual risk assessments,
implement risk mitigation measures, and submit to independent audits—all of which involve the processing and analysis of significant quantities of personal data. The DSA's transparency requirements regarding advertising and content moderation create additional data collection and disclosure obligations that must be reconciled with GDPR principles of data minimization and purpose limitation.
The UK's Online Safety Act (2023) imposes a duty of care on platform providers regarding illegal content and content harmful to children,
creating enforcement powers for Ofcom that operate alongside the
Information Commissioner's Office (ICO) under the UK GDPR. The tension between content regulation objectives (which may require extensive data collection and analysis) and data protection principles (which limit such collection) is a recurring theme in both jurisdictions.
In the United States, content regulation operates primarily through
Section 230 of the Communications Decency Act (47 U.S.C. § 230), which provides platforms with immunity from liability for third-party content.
The future of Section 230 is subject to intense political and judicial scrutiny, as illustrated by the Supreme Court's treatment in NetChoice,
LLC v. Paxton, 595 U.S. 42 (2024). Several states have enacted content moderation laws (Texas HB 20, Florida SB 7072) that regulate how platforms may moderate content, creating a direct collision between content regulation and platforms' First Amendment rights. India's
Information Technology (Intermediary Guidelines and Digital Media Ethics
Code) Rules 2021 impose content moderation obligations on intermediaries, including traceability requirements for messaging platforms, with significant data protection implications.
The cumulative effect of these regulatory developments is what may be termed the "quadruple overlay": organizations operating in the digital economy must simultaneously comply with data protection laws,
cybersecurity obligations, e-commerce regulations, and content moderation requirements—each governed by distinct (and sometimes conflicting) legal frameworks, enforced by different regulators, and subject to different penalty regimes. The EU has made the most systematic effort to integrate these domains through its comprehensive digital regulation package (GDPR + ePrivacy + DMA + DSA + AI Act + NIS2
+ DORA), but even within the EU, the challenge of regulatory coherence across multiple directives and regulations remains significant.
For multinational organizations, the compliance challenge is formidable. A technology company operating across the EU, the United
States, China, and India must navigate at least four fundamentally different regulatory philosophies, each with its own consent requirements, cross-border transfer mechanisms, enforcement institutions, and penalty structures. The concept of "regulatory interoperability"—the development of mechanisms by which different jurisdictions' requirements can be simultaneously satisfied without fragmentation of the global digital economy—has emerged as a central concern in international policy discussions, including the OECD's work on privacy guidelines and AI principles, the APEC Cross-Border Privacy
Rules (CBPR) system, and the United Nations Open-Ended Working Group on developments in the field of information and telecommunications in the context of international security (OEWG).
As the regulatory landscape continues to evolve, the quadruple overlay is likely to deepen. The full enforcement of the EU AI Act
(August 2026), the potential enactment of a US federal privacy law, the operationalization of India's DPDPA, and the ongoing maturation of
China's three-pillar data governance framework will all add layers of complexity. The challenge for policymakers, regulators, and the regulated community alike is to manage this complexity in ways that protect individual rights, promote cybersecurity, enable digital commerce, and safeguard public discourse—without creating an incoherent patchwork that stifles innovation and undermines the global nature of the digital economy.
This chapter provides the statistical and analytical foundation for the jurisdiction-specific analyses that follow in Parts Two through Nine of this Volume.

# Chapter 3: General Data Protection Regulation (GDPR)

The General Data Protection Regulation represents the culmination of more than two decades of European data protection policy development.
Its predecessor, Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data, was adopted on October 24, 1995, and required member states to implement national legislation conforming to its minimum standards by October 1998. The Directive established core principles of data protection—lawfulness, fairness, purpose limitation, data quality,
and individual rights—that would later be carried forward and strengthened in the GDPR. However, the Directive's reliance on national transposition created a fragmented regulatory landscape: member states implemented the minimum standards in different ways, resulting in 28
different national data protection regimes with varying levels of protection and enforcement. This fragmentation was widely perceived as inconsistent with the EU's objective of a single digital market.
The political impetus for GDPR reform emerged from several converging factors. The rapid development of internet-based services, social media platforms, and cloud computing in the 2000s rendered the Directive's framework increasingly inadequate for the scale and nature of personal data processing. The increasing frequency and severity of data breaches—including high-profile incidents such as the loss of 25 million child benefit records by HM Revenue & Customs in the United Kingdom
(2007) and the PlayStation Network breach affecting 77 million accounts
(2011)—demonstrated the insufficiency of existing enforcement mechanisms. The 2009 Lisbon Treaty, by elevating data protection to the status of a fundamental right in Article 8 of the Charter of Fundamental
Rights of the European Union and introducing a dedicated legal basis for
EU data protection legislation in Article 16 of the Treaty on the
Functioning of the European Union (TFEU), provided the constitutional foundation for more ambitious regulation.
The European Commission published its first draft proposal for a
General Data Protection Regulation on January 25, 2012. The decision to adopt a regulation rather than a directive was itself significant: a regulation would be directly applicable in all member states without the need for national transposition, thereby ensuring a uniform level of protection. The Commission's proposal introduced several innovations,
including the "right to be forgotten," data portability, the one-stop-shop mechanism, and the requirement for data protection by design and by default.
The legislative process involved extensive negotiation among the
European Parliament, the Council of the European Union, and the European
Commission. The European Parliament's Civil Liberties, Justice and Home
Affairs (LIBE) Committee, led by rapporteur Jan Philipp Albrecht,
adopted a significantly strengthened version of the proposal in October
2013, including a higher maximum penalty (5% of global annual turnover,
later reduced to 4%), a broader definition of personal data, and stronger data subject rights. The Council of the European Union,
representing member state governments, adopted its general approach in
June 2015, reflecting a more business-friendly orientation. The trilogue negotiations between the three institutions concluded in December 2015,
and the final text was formally adopted by the European Parliament on
April 14, 2016, and by the Council on May 4, 2016.
The GDPR entered into force on May 25, 2016, with a two-year transition period before its operative date of May 25, 2018. This transition period was intended to allow organizations to bring their data processing practices into compliance with the new framework. The period was marked by intensive compliance activity, with an estimated
80% of large enterprises investing significant resources in GDPR
readiness programs.
The GDPR's institutional architecture centers on three interconnected components: the European Data Protection Board (EDPB), national data protection authorities (DPAs), and the one-stop-shop mechanism.
The EDPB, established under Article 68, replaced the Article 29
Working Party that had served as the EU's data protection advisory body under the 1995 Directive. The EDPB is composed of the heads of each national DPA (or their representatives) and the European Data Protection
Supervisor (EDPS). Its principal functions include ensuring the consistent application of the GDPR across all member states, issuing guidelines and recommendations on the interpretation of the GDPR,
advising the European Commission on matters related to data protection,
and promoting cooperation and the exchange of best practices among national DPAs. The EDPB's consistency mechanism, described in Articles
63-67, provides a structured process for resolving disagreements between national DPAs on cross-border processing matters. When a lead supervisory authority (LSA) prepares a draft decision on a cross-border matter, concerned supervisory authorities may raise objections. If the
EDPB cannot resolve these objections within one month, the matter may be escalated to the dispute resolution procedure, which can result in a binding decision by the EDPB within specified timeframes.
National DPAs, established under Article 51, are independent public authorities responsible for monitoring the application of the GDPR
within their respective jurisdictions. Each member state is required to establish at least one DPA, though some (such as Germany, which has one federal and 16 state-level DPAs) maintain multiple authorities. DPAs possess investigative powers (including the power to access premises and data), corrective powers (including the power to issue warnings,
reprimands, and orders), and authorization and advisory powers
(including the power to provide guidance on processing operations). The
GDPR requires DPAs to be completely independent in the exercise of their functions and not to receive instructions from any other authority.
The one-stop-shop mechanism, described in Articles 56-60, establishes that when a controller or processor has establishments in multiple member states, the DPA of the member state in which the controller's main establishment is located serves as the lead supervisory authority.
The main establishment is defined as the place of central administration in the EU, or, where decisions on the purposes and means of processing are taken, the place where those decisions are actually implemented. The
LSA is responsible for handling cross-border complaints and investigations, though concerned DPAs participate through the cooperation mechanism.
The GDPR's definitions establish the conceptual foundation for its regulatory framework. The most important definitions include:
"Personal data" (Article 4(1)) is defined as "any information relating to an identified or identifiable natural person ('data subject')." A natural person is considered identifiable if they can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier, or to one or more factors specific to the physical,
physiological, genetic, mental, economic, cultural, or social identity of that natural person. The inclusion of "online identifiers" (such as
IP addresses and cookie identifiers) was a significant expansion from the 1995 Directive, recognizing the reality of online identification.
"Processing" (Article 4(2)) means "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means." The definition is deliberately broad,
encompassing collection, recording, organization, structuring, storage,
adaptation, retrieval, consultation, use, disclosure by transmission,
dissemination, alignment, combination, restriction, erasure, or destruction.
"Controller" (Article 4(7)) means "the natural or legal person,
public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data." The determination of who is a controller is a factual question,
depending on who has the power to decide the purposes (the "why") and means (the "how") of processing.
"Processor" (Article 4(8)) means "a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller." Processors act as agents of the controller and must process data only on documented instructions from the controller.
"Consent" (Article 4(11)) is defined as "any freely given, specific,
informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action,
signifies agreement to the processing of personal data relating to him or her." The requirement for a "clear affirmative action" means that pre-ticked boxes, silence, or inactivity do not constitute valid consent.
"Special categories of personal data" (Article 9(1)) include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation.
The GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller or processor in the
Union, regardless of whether the processing takes place in the Union or not (Article 2(1)). This "establishment" criterion is broadly interpreted: the CJEU has held that Google Ireland was an establishment subject to the GDPR even for processing of personal data that took place at Google Inc. in the United States, because the Irish entity was responsible for the advertising sales that generated revenue from the processing (Case C-131/12, Google Spain).
Article 3(2) extends the GDPR's application extraterritorially to controllers or processors not established in the Union where they process personal data of data subjects who are in the Union by offering goods or services to data subjects in the Union (whether or not payment is required) or by monitoring their behavior as far as their behavior takes place within the Union. This provision, which was one of the most controversial aspects of the GDPR during the legislative process, was designed to prevent a "race to the bottom" in which controllers would relocate processing to third countries to avoid EU data protection requirements. The CJEU's judgment in Case C-585/19 (Planet49), which held that the mere accessibility of a website from the Union could trigger the monitoring provision, has been interpreted by some as requiring a lower threshold for extraterritorial application than the
GDPR's text might suggest.
Article 5 establishes the fundamental principles that govern the processing of personal data. These principles are not merely aspirational; they are legally binding, and compliance with them is a condition of lawful processing.
(a) Lawfulness, fairness, and transparency. Processing must have a valid legal basis (the "lawfulness" requirement), must not be deceptive or harmful to the data subject (the "fairness" requirement), and must be conducted in a manner that is clear and understandable to the data subject (the "transparency" requirement). Transparency requires the provision of clear, plain-language information about the processing,
including the identity of the controller, the purposes of processing,
the categories of personal data processed, the recipients or categories of recipients, and the data subject's rights.
(b) Purpose limitation. Personal data must be collected for specified, explicit, and legitimate purposes and not be further processed in a manner that is incompatible with those purposes. This principle requires controllers to define the purposes of processing at the outset and to assess any further processing for compatibility with the original purposes. The Article 29 Working Party (now the EDPB)
issued Opinion 03/2013 on purpose limitation, which provides guidance on the factors to consider in assessing compatibility, including any link between the purposes, the context of processing, the nature of the data,
the possible consequences for data subjects, and the existence of appropriate safeguards.
(c) Data minimization. Personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. This principle requires controllers to assess, on an ongoing basis, whether the personal data they collect and retain is necessary for the stated purposes. It has been interpreted to require not only the minimization of the volume of data collected but also the minimization of the granularity and retention period of that data.
(d) Accuracy. Personal data must be accurate and, where necessary,
kept up to date. Every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
(e) Storage limitation. Personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. This principle requires controllers to establish and implement data retention schedules and to periodically review the necessity of continued data retention.
(f) Integrity and confidentiality. Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss,
destruction, or damage, using appropriate technical or organizational measures. This principle implements the "security of processing"
obligation more broadly described in Article 32.
(g) Accountability. The controller is responsible for, and must be able to demonstrate compliance with, the principles above. This
"accountability" principle is arguably the GDPR's most significant innovation over the 1995 Directive. It requires controllers not only to comply with the other principles but to maintain documented evidence of compliance. This obligation has given rise to a range of compliance activities, including records of processing activities (Article 30),
data protection impact assessments (Article 35), data protection by design and by default (Article 25), and the appointment of data protection officers (Article 37).
Article 6 provides six lawful bases for processing personal data.
Processing is only lawful if and to the extent that at least one of these bases applies:
(a) Consent. The data subject has given consent to the processing of his or her personal data for one or more specific purposes. The GDPR's consent standard is notably higher than that of the 1995 Directive,
requiring consent to be freely given, specific, informed, and unambiguous, and to be demonstrated by a clear affirmative action.
Controllers must be able to demonstrate that valid consent was obtained,
creating a documentation obligation.
(b) Contract. Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. This basis covers the processing necessary to provide the goods or services that the data subject has requested.
(c) Legal obligation. Processing is necessary for compliance with a legal obligation to which the controller is subject. This basis covers processing required by EU law or member state law.
(d) Vital interests. Processing is necessary in order to protect the vital interests of the data subject or of another natural person. This basis is narrowly construed and applies primarily in life-or-death situations, such as medical emergencies where the data subject is unable to consent.
(e) Public interest. Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This basis is typically invoked by public authorities, and member state law may specify the tasks and authorities covered.
(f) Legitimate interests. Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party,
except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. This basis requires a three-part test: (1) identification of a legitimate interest, (2)
assessment of whether processing is necessary to achieve that interest,
and (3) balancing of the controller's interest against the data subject's interests and rights. The EDPB has published guidance on legitimate interests, emphasizing that this balancing test must be conducted on a case-by-case basis and documented.
Article 7 establishes detailed conditions for the valid processing of consent as a lawful basis. Consent must be demonstrated by the controller, meaning that the controller bears the burden of proving that valid consent was obtained. The GDPR explicitly provides that where the data subject's consent is given in the context of a written declaration that also concerns other matters, the request for consent must be presented in a manner that is clearly distinguishable from those other matters, in an intelligible and easily accessible form, using clear and plain language. Pre-ticked boxes do not constitute valid consent. The data subject has the right to withdraw consent at any time, and withdrawal must be as easy as giving consent. When processing is based on consent, the controller must be able to demonstrate that the data subject has consented to processing of his or her personal data.
Article 9 establishes a general prohibition on the processing of special categories of personal data, subject to ten enumerated exceptions. This "prohibition with exceptions" approach reflects the particularly sensitive nature of the data involved, which, if misused,
could lead to significant discrimination, harm, or violation of fundamental rights.
The exceptions include: explicit consent (Article 9(2)(a));
processing necessary for employment and social security purposes
(Article 9(2)(b)); vital interests (Article 9(2)(c)); processing carried out by foundations, associations, or not-for-profit bodies with political, philosophical, religious, or trade union aims (Article
9(2)(d)); processing relating to personal data manifestly made public by the data subject (Article 9(2)(e)); processing necessary for legal claims (Article 9(2)(f)); processing for substantial public interest reasons (Article 9(2)(g)); processing for health care purposes (Article
9(2)(h)); processing for public health purposes (Article 9(2)(i)); and processing for archiving purposes in the public interest, scientific or historical research, or statistical purposes (Article 9(2)(j)). Each exception has specific conditions and safeguards.
The GDPR establishes a comprehensive set of rights for data subjects,
which represents one of its most significant contributions to data protection law. These rights are not absolute and are subject to the limitations and conditions specified in the GDPR, but they establish a powerful framework for individual control over personal data.
Right of access (Article 15). Data subjects have the right to obtain confirmation as to whether personal data concerning them is being processed, and, where that is the case, access to the personal data and supplementary information including the purposes of processing, the categories of personal data concerned, the recipients, the retention period, the source of the data, and the existence of automated decision-making.
Right to rectification (Article 16). Data subjects have the right to obtain the rectification of inaccurate personal data and the completion of incomplete personal data.
Right to erasure / "right to be forgotten" (Article 17). Data subjects have the right to obtain the erasure of personal data concerning them without undue delay, and the controller has the obligation to erase personal data without undue delay where certain conditions are met, including withdrawal of consent, objection to processing, or unlawfulness of processing. This right is subject to exceptions, including the exercise of the right of freedom of expression and information, compliance with legal obligations, public health purposes, archiving purposes in the public interest, and the establishment, exercise, or defense of legal claims.
Right to restriction of processing (Article 18). Data subjects have the right to obtain the restriction of processing where the accuracy of the data is contested, processing is unlawful but the data subject prefers restriction to erasure, the controller no longer needs the data but the data subject needs it for legal claims, or the data subject has objected to processing pending verification of legitimate grounds.
Right to data portability (Article 20). Data subjects have the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used, and machine-readable format, and have the right to transmit those data to another controller without hindrance. This right applies only where processing is based on consent or contract and is carried out by automated means.
Right to object (Article 21). Data subjects have the right to object,
on grounds relating to their particular situation, at any time to the processing of personal data concerning them which is based on the legitimate interests ground or the public interest ground. The controller must cease processing unless it demonstrates compelling legitimate grounds that override the interests of the data subject. Data subjects also have an absolute right to object to processing for direct marketing purposes.
Rights related to automated decision-making (Article 22). Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. This right is subject to exceptions where the decision is necessary for contract performance, authorized by law, or based on explicit consent.
The GDPR imposes specific obligations on controllers and processors.
Controllers must implement appropriate technical and organizational measures to ensure and be able to demonstrate that processing is performed in accordance with the GDPR (Article 24). Where processing is carried out with the involvement of a processor, the controller must use only processors providing sufficient guarantees to implement appropriate technical and organizational measures. The relationship between controller and processor must be governed by a contract or other legal act that specifies the subject matter, duration, nature, purpose, type of processing, categories of data, and the obligations and rights of the controller. Article 28 sets out mandatory provisions that must be included in controller-processor agreements, including obligations of confidentiality, security measures, sub-processor engagement, assistance with data subject rights, assistance with DPIAs, and data deletion or return at the end of the engagement. Joint controllers must determine their respective responsibilities by means of an arrangement that sets out their respective duties (Article 26).
Article 25 requires controllers to implement data protection by design and by default. This means that, both at the time of determining the means for processing and at the time of the processing itself,
controllers must implement appropriate technical and organizational measures designed to implement data protection principles effectively and to integrate necessary safeguards. By default, controllers must implement measures to ensure that, by default, only personal data necessary for each specific purpose is processed.
Article 35 requires controllers to carry out a data protection impact assessment (DPIA) prior to processing that is "likely to result in a high risk to the rights and freedoms of natural persons." The GDPR
identifies three categories of processing that require a DPIA: (1)
systematic and extensive profiling with significant effects; (2)
large-scale processing of special categories of data or criminal offense data; and (3) systematic monitoring of publicly accessible areas on a large scale. DPIAs must include a systematic description of the processing, an assessment of the necessity and proportionality, an assessment of risks, and the measures envisaged to address those risks.
Chapter V of the GDPR establishes the framework for the transfer of personal data to third countries (countries outside the EEA). The default rule is that transfers to third countries are permitted only if the Commission has decided that the third country ensures an "adequate level of protection" (Article 45), or if appropriate safeguards are provided (Article 46), or in limited derogatory circumstances (Article
49).
Adequacy decisions are the preferred mechanism for lawful transfers.
The Commission has issued adequacy decisions for Andorra, Argentina,
Canada (commercial organizations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, the
United Kingdom, and the United States (under the EU-US Data Privacy
Framework, adopted in July 2023). Each adequacy decision is subject to periodic review and may be withdrawn if the level of protection in the third country deteriorates—a possibility dramatically illustrated by the invalidation of the EU-US Safe Harbor (Schrems I, 2015) and Privacy
Shield (Schrems II, 2020) frameworks.
Where no adequacy decision exists, transfers may be made under appropriate safeguards, including standard contractual clauses (SCCs),
binding corporate rules (BCRs), approved codes of conduct, or approved certification mechanisms. The most widely used safeguard is the SCCs adopted by the Commission in June 2021 (Decision 2021/914), which replaced the previous SCCs from 2001 and 2004. Following Schrems II,
organizations relying on SCCs must conduct a transfer impact assessment to evaluate whether the legal framework in the recipient country provides essentially equivalent protection, and must implement supplementary measures where necessary.
Article 49 provides a limited set of derogations for specific situations where no adequacy decision or appropriate safeguards exist,
including explicit consent, necessity for contract performance,
important reasons of public interest, legal claims, vital interests, and transfers from a public register. These derogations must be interpreted narrowly and may not be used for the regular, systematic, or bulk transfer of personal data.
The GDPR's enforcement regime is among the most robust of any data protection framework globally. Article 83 establishes a tiered penalty structure:
Tier 1 (for the most serious infringements): Up to €20 million or 4%
of the total worldwide annual turnover of the preceding financial year,
whichever is higher. This tier applies to violations of basic principles for processing, data subject rights, cross-border transfer rules, and the obligation to implement appropriate safeguards.
Tier 2 (for other infringements): Up to €10 million or 2% of total worldwide annual turnover, whichever is higher. This tier applies to violations of obligations relating to security, records of processing,
DPIAs, prior consultation, DPO appointment, and codes of conduct.
The GDPR also provides for administrative corrective powers (Article
58), including the power to issue warnings, reprimands, compliance orders, bans on processing, and withdrawal of certifications.
As of 2026, the European Commission has issued adequacy decisions for the following countries and territories:
Andorra (2010, renewed 2023)
Argentina (2003, renewed 2023)
Canada (commercial organizations, 2001, renewed 2023)
Faroe Islands (2014)
Guernsey (2003, renewed 2023)
Israel (2011, renewed 2023)
Isle of Man (2004, renewed 2023)
Japan (2019, renewed 2023)
Jersey (2008, renewed 2023)
New Zealand (2012, renewed 2023)
Republic of Korea (2021)
Switzerland (2000, renewed 2023)
United Kingdom (2021, under the Trade and Cooperation Agreement)
United States (EU-US Data Privacy Framework, July 2023; upheld by EU
General Court in Case T-553/23, September 2025)
The GDPR has generated a significant body of enforcement activity since its operative date. Some of the most notable enforcement actions include:
Meta (Facebook) — €1.2 billion (May 2023): The Irish Data Protection
Commission imposed its largest-ever GDPR penalty on Meta for continuing to transfer personal data of EU users to the United States in reliance on Standard Contractual Clauses, despite the Schrems II judgment. The
DPC found that Meta had not implemented sufficient supplementary measures to address the deficiencies in US surveillance law identified in Schrems II.
Amazon — €746 million (July 2021): The Luxembourg National Commission for Data Protection (CNPD) fined Amazon for processing personal data for advertising purposes in a manner that was not compatible with the purposes for which it was collected. Amazon appealed the decision.
WhatsApp — €225 million (September 2021): The Irish DPC fined
WhatsApp for failing to inform users adequately about how their data was processed and shared between WhatsApp and other Meta companies.
TikTok — €345 million (September 2023, children's data) and €530
million (May 2025, cross-border transfers): The Irish DPC issued two major penalties against TikTok: €345 million for violations related to the processing of children's data, and €530 million for unlawful transfers of EEA user data to China.
Google — multiple fines: The French CNIL fined Google €150 million
(2021) for using advertising cookies without consent, and €60 million
(2019) for lack of transparency and valid consent in personalized advertising. The CNIL imposed a further €325 million fine in September
2025 for displaying advertisements in Gmail's "Promotions" and "Social"
tabs without valid user consent.
Clearview AI — €20 million (2022): The Greek DPA fined Clearview AI
for unlawful processing of biometric data through its facial recognition system.
Infinity Dental — €10,000 (2025): The UK ICO issued a smaller but notable enforcement action against a dental practice for failing to secure personal data, illustrating that GDPR enforcement extends to organizations of all sizes.
The enforcement landscape continues to evolve, with increasing cooperation among national DPAs through the EDPB's consistency mechanism and growing attention to cross-border transfers, children's data, and the use of personal data for artificial intelligence training.

# Chapter 4: ePrivacy Directive

The Directive on Privacy and Electronic Communications, commonly known as the ePrivacy Directive (Directive 2002/58/EC, as amended by
Directive 2009/136/EC), was adopted on July 12, 2002, as a complement to the broader data protection framework established by Directive 95/46/EC.
Its purpose is to ensure the free movement of electronic communications services, networks, and equipment within the EU while guaranteeing an equivalent level of protection of personal data and privacy in the electronic communications sector. The Directive is often described as regulating "the confidentiality of communications" — a domain that sits at the intersection of data protection, telecommunications regulation,
and consumer protection.
The ePrivacy Directive was conceived as a sector-specific instrument to address the particular privacy challenges arising from electronic communications technologies — challenges that the general-purpose data protection framework could not adequately address on its own. These included the interception of communications, the use of location data,
the storage of information on users' devices (cookies), and the sending of unsolicited commercial communications (spam). The Directive's scope extends to all electronic communications services, including traditional telecommunications, internet access services, and over-the-top (OTT)
communication services such as messaging applications and voice-over-IP
platforms.
Article 5(1) prohibits listening to, tapping, storage, or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorized. This provision establishes a fundamental right to the confidentiality of communications that extends beyond the protections afforded by general data protection law. It covers not only the content of communications but also the associated traffic data — information about the source, destination,
time, duration, and routing of communications.
The CJEU has interpreted Article 5 broadly. In Case C-511/10 (SABAM
v. Scarlet Extended), the Court held that requiring an ISP to install a filtering system to prevent the illegal downloading of files would violate Article 5(1), as it would entail a systematic monitoring of all electronic communications. In Case C-293/12 (Digital Rights Ireland),
the Court invalidated the Data Retention Directive, finding that the broad and indiscriminate retention of traffic data required by the
Directive constituted a disproportionate interference with the rights guaranteed by Article 5 and Article 7 of the Charter of Fundamental
Rights.
Article 5(3) is perhaps the ePrivacy Directive's most practically significant provision. It requires that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information about the purposes of the processing, and is given the right to refuse such processing. This is commonly referred to as the "cookie consent" requirement.
The CJEU's interpretation of Article 5(3) has significantly shaped cookie consent practices across Europe. In Case C-585/19 (Planet49), the
Court held that consent for cookie storage must meet the GDPR's consent standard — that is, it must be freely given, specific, informed, and unambiguous, and must be given by a clear affirmative action. This meant that pre-ticked checkboxes could not constitute valid consent for cookie storage. The Court further held that the controller must be able to demonstrate that valid consent was obtained, and that consent must be equally easy to withdraw as to give.
In Case C-154/21 (UFCD and Others, the "Cookiebot" case, decided June
2024), the CJEU provided further guidance, holding that national authorities may take enforcement action against controllers that use cookie banners that do not comply with Article 5(3), even where the cookies are first-party and technically necessary, if the banner fails to provide the required information or to offer a genuine choice. The decision reinforced the principle that cookie consent must be granular,
allowing users to accept or reject different categories of cookies individually.
The practical consequence of these rulings has been the proliferation of cookie consent banners across European websites, a development that has been widely criticized as creating "consent fatigue" and undermining the effectiveness of consent as a mechanism of user empowerment. The ePrivacy Directive's consent requirement applies to a broader range of technologies than just HTTP cookies, including pixel tags, device fingerprinting, local storage, and other forms of tracking technology.
Article 13 addresses unsolicited commercial communications. It requires member states to ensure that the use of electronic mail for the purposes of direct marketing is allowed only in respect of subscribers who have given their prior consent (an "opt-in" requirement). This represents one of the most stringent anti-spam frameworks in the world,
as many jurisdictions outside the EU (including the United States under the CAN-SPAM Act) operate on an opt-out model for commercial email.
Article 13 also requires that unsolicited commercial communications sent by email be clearly identifiable as such, include the identity of the natural or legal person on whose behalf they are sent, and include a valid address to which the recipient may send a request for the cessation of such communications. These requirements apply in addition to the general opt-in consent requirement.
The European Commission proposed a replacement for the ePrivacy
Directive in the form of an ePrivacy Regulation on January 10, 2017. The proposed Regulation was intended to adapt the ePrivacy framework to the digital age by extending its scope to cover machine-to-machine communications, over-the-top services, and metadata generated by messaging applications. The proposal was subject to extensive debate in the European Parliament and Council, with disagreements on issues including the scope of the Regulation's application to workplace communications, the regulation of metadata generated by instant messaging and email services, and the relationship between the ePrivacy
Regulation and the GDPR's consent regime.
After more than eight years of negotiations, the European Commission formally withdrew the proposed ePrivacy Regulation on February 5, 2025.
The withdrawal was attributed to the difficulty of reaching agreement among member states and the increasing overlap between the ePrivacy framework and the GDPR. The practical consequence is that the 2002
ePrivacy Directive, as amended, remains in force. The Commission has indicated that it may propose a new ePrivacy initiative in the future,
but no timeline has been announced.
The implementation of the ePrivacy Directive across EU member states has produced significant variation, despite the Directive's minimum harmonization approach. Member states have transposed the Directive's requirements into national law with differing levels of specificity and stringency. In Germany, the Telecommunications Act
(Telekommunikationsgesetz) and the Unfair Competition Act (Gesetz gegen den unlauteren Wettbewerb) provide the primary legal framework for ePrivacy compliance. In France, the CNIL has issued detailed guidance on cookie consent requirements, including requirements for cookie walls
(which the CNIL considers incompatible with valid consent unless users are offered a genuine alternative). In the United Kingdom, the Privacy and Electronic Communications Regulations (PECR) implement the ePrivacy
Directive, with the ICO providing enforcement guidance. In Italy, the
Garante has been one of the most active enforcement authorities, issuing significant fines for cookie consent violations.

# Chapter 5: Digital Markets Act (DMA)

The Digital Markets Act (Regulation (EU) 2022/1925, entered into force November 1, 2022) represents the European Union's most ambitious effort to regulate the market power of large digital platforms. The DMA
was developed in parallel with the Digital Services Act, and together these two regulations constitute the EU's "Digital Services Package," a comprehensive framework for the governance of digital platforms.
The legislative impetus for the DMA arose from growing concern over the market power of a small number of "gatekeeper" platforms — companies that control the digital ecosystem's key infrastructure and can set the rules of the game for other market participants. The European Commission identified several systemic problems: the self-preferencing of gatekeepers' own services over those of competitors, the imposition of unfair terms on business users, the tying of different services to foreclose competition, and the difficulty faced by users in switching between platforms or interoperating across them. Traditional competition law, with its case-by-case approach and burden of proving consumer harm,
was considered insufficient to address these systemic issues in a timely manner.
The DMA applies specifically to "gatekeepers" — large platforms that serve as important gateways between business users and end users and that enjoy a entrenched and durable position in the digital market.
Article 3 establishes three cumulative criteria for gatekeeper designation:
The undertaking has a significant impact on the internal market, as indicated by its annual EU turnover of at least €7.5 billion in the last three financial years, or its average market capitalization of at least
€75 billion in the last financial year, provided it offers the same core platform service in at least three member states.
The undertaking provides a "core platform service" that serves as an important gateway between business users and end users, including online intermediation services, search engines, social networking services,
video-sharing platform services, number-independent interpersonal communications services, operating systems, cloud computing services,
and advertising services.
The undertaking enjoys an "entrenched and durable position,"
indicated by having at least 45 million monthly active end users and at least 10,000 yearly active business users established in the EU in the last financial year.
As of 2026, the European Commission has designated seven gatekeepers and their core platform services:
Alphabet: Google Search, Google Chrome, Google Maps, Google Play,
Google Shopping, Google Android (including Google Play), Google Ads,
YouTube
Amazon: Amazon Marketplace
Apple: App Store, Safari, iOS
ByteDance: TikTok
Meta: Facebook, Instagram, WhatsApp, Meta Marketplace, Meta Ads
Microsoft: Windows, LinkedIn, Microsoft Edge, Microsoft
Advertising
Booking.com: Booking.com
Article 5 imposes a set of "do's and don'ts" on gatekeepers regarding their core platform services. Key obligations include:
No self-preferencing: Gatekeepers must not treat their own services more favorably than third-party services in ranking, indexing, and presentation. This obligation addresses the long-standing concern that platforms such as Amazon and Google prioritize their own products in search results.
Prohibition on restricting the ability of business users to offer different terms: Gatekeepers must not prevent business users from offering their products or services to end users through third-party channels at conditions that are different from those offered through the gatekeeper's platform. This addresses the "most-favored-nation" (MFN)
clauses that platforms have traditionally imposed on sellers.
No restriction on end user choice: Gatekeepers must not prevent or limit end users from uninstalling any pre-installed software or applications, changing default settings, or accessing services and features offered by the gatekeeper's competitors through the operating system.
Data combination restrictions: Article 5(2) prohibits gatekeepers from combining personal data from their core platform services with personal data from other services offered by the gatekeeper, or from third-party services, without obtaining effective consent. This is one of the DMA's most significant provisions, as it directly addresses the competitive advantage that gatekeepers derive from their ability to create comprehensive user profiles by combining data across multiple services.
Data portability: Gatekeepers must provide effective and interoperable means for business users and end users to port and continuously access data generated through the use of the gatekeeper's core platform services.
Article 6 requires gatekeepers to allow end users to uninstall any software applications and to change default settings on the operating system, virtual assistant, or web browser offered by the gatekeeper.
Article 7 addresses the gatekeeper's obligation not to prevent business users from accessing end users through other channels, and to provide effective mechanisms for business users to advertise and contract with end users outside the gatekeeper's core platform service.
The DMA provides for substantial penalties for non-compliance. The
Commission may impose fines of up to 10% of the gatekeeper's total worldwide annual turnover for initial infringements, and up to 20% for repeated infringements. Additionally, the Commission may impose periodic penalty payments of up to 5% of the gatekeeper's average daily worldwide turnover for each day of non-compliance with a Commission decision.
The Commission also has the power to impose structural remedies,
including the divestiture of businesses, in cases of systematic non-compliance. This provision is particularly significant, as it represents the first time that EU competition legislation has explicitly included the possibility of forced divestiture as a remedy.
As of 2025, the Commission has opened non-compliance proceedings against several gatekeepers, including Apple (regarding App Store rules and alternative payment systems), Google (regarding self-preferencing in
Google Shopping), and Meta (regarding the "subscribe or consent" model for Facebook and Instagram). The outcomes of these proceedings will establish important precedents for the DMA's enforcement.

# Chapter 6: Digital Services Act (DSA)

The Digital Services Act (Regulation (EU) 2022/2065, entered into force November 16, 2022) establishes a comprehensive regulatory framework for digital services across the EU. Its central innovation is a tiered approach that calibrates regulatory obligations to the size and risk profile of the service provider. The DSA creates four categories of regulated entities:
Basic services (Article 4) include all providers of information society services within the meaning of Article 2 of Directive
2000/31/EC. These entities are subject to minimal obligations, primarily the requirement to provide a single point of contact and a legal representative in the EU.
Intermediary services (Articles 6-12) include providers of "mere conduit," "caching," and "hosting" services as defined in the E-Commerce
Directive. These entities are subject to additional obligations including transparency reporting and cooperation with authorities.
Hosting services (Articles 14-16) are subject to obligations regarding the notice-and-action mechanism, the removal of manifestly illegal content, and the protection of users' fundamental rights in content moderation decisions.
Online platforms (Articles 24-33) — intermediaries that store and disseminate information to the public at the request of the user — face the most extensive obligations, including illegal content detection,
risk assessments, transparency reporting, advertising transparency, and user complaint mechanisms.
Very large online platforms (VLOPs) and very large online search engines (VLOSEs) (Articles 34-45), defined as platforms or search engines with an average of at least 45 million monthly active users in the EU, are subject to the most stringent obligations, including systemic risk assessments, independent auditing, and enhanced transparency requirements.
The DSA requires online platforms to implement "notice-and-action mechanisms" that allow users to notify platforms of allegedly illegal content and to receive a reasoned decision regarding that content without undue delay (Article 16). For manifestly illegal content —
content that is obviously illegal, such as child sexual abuse material or terrorist propaganda — platforms must remove or disable access within
24 hours of notification (Article 16(5)). VLOPs are required to conduct annual systemic risk assessments (Article 34), covering the dissemination of illegal content, the negative effects on fundamental rights, the manipulation of the service for disinformation, and the effects on minors. These risk assessments must be independently audited.
The DSA's approach to content moderation is deliberately balanced. It preserves the intermediary liability framework established by the
E-Commerce Directive (the "safe harbor" provisions) while imposing enhanced obligations on larger platforms to proactively address systemic risks. Crucially, the DSA does not impose a general monitoring obligation; platforms are not required to monitor all user-generated content for illegality but must respond effectively to notices and must assess and mitigate systemic risks.
The DSA prohibits "dark patterns" — interfaces designed to manipulate or deceive users into making decisions that they would not otherwise make (Article 25). This includes practices such as making it disproportionately difficult to cancel a subscription, hiding or obscuring important information, or using misleading button design. The prohibition on dark patterns is among the DSA's most widely discussed provisions, as it directly addresses the growing concern over the manipulation of user behavior through interface design.
VLOPs are required to publish annual transparency reports that include detailed information on the number and types of content moderation actions taken, the use of automated tools in content moderation, the outcomes of user appeals, and the handling of advertiser data (Article 42). These reports must be made publicly available and must be presented in machine-readable format to facilitate analysis by researchers and civil society organizations.
The DSA includes specific provisions for the protection of minors.
Platforms must design their services in a manner that is appropriate for minors, taking into account the varying levels of development, needs,
and characteristics of children of different ages (Article 28). VLOPs must assess and mitigate the risks that their systems pose to the health, safety, and rights of minors.
Advertising on online platforms must be clearly distinguishable from other content (Article 26). Users must be informed of the main parameters used to determine the advertising presented to them, and the identity of the advertiser must be disclosed. VLOPs are required to maintain a publicly accessible repository of advertisements served on their platform, including information about the advertiser, the content of the advertisement, the target audience, the duration of display, and the total number of views.
As of 2025, the European Commission has designated the following
VLOPs: Facebook, Instagram, TikTok, YouTube, Snapchat, X (formerly
Twitter), LinkedIn, Pinterest, Wikipedia (the Wikimedia Foundation accepted the designation voluntarily), Amazon Marketplace, Booking.com,
Zalando, and several adult content platforms. Several of these designations have been challenged by the platforms.
Ofcom (in the UK context, under the Online Safety Act, which has a similar framework) and national DPAs cooperate with the Commission in the enforcement of the DSA. The first enforcement actions are expected to focus on systemic risk assessments, dark patterns, and the handling of illegal content.

# Chapter 7: EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) represents the world's first comprehensive legislative framework for artificial intelligence.
Its legislative journey began with the European Commission's proposal published on April 21, 2021, followed by extensive deliberation in the
European Parliament and Council. The Parliament adopted its negotiating position in June 2023, and the trilogue agreement was reached in
December 2023. The final text was formally adopted by the European
Parliament on March 13, 2024, and by the Council on May 21, 2024. The
Regulation entered into force on August 1, 2024, with a phased implementation timeline:
February 2, 2025: Prohibition of banned AI practices (Article 5)
August 2, 2025: Obligations for GPAI models with systemic risk
(Articles 51-56)
August 2, 2026: Most provisions, including high-risk AI obligations and enforcement
August 2, 2027: Obligations for certain AI systems embedded in regulated products (Annex I)
The AI Act adopts a risk-based approach, categorizing AI systems into four risk levels and applying regulatory requirements proportionate to the level of risk:
Unacceptable Risk / Prohibited Practices (Article 5). These AI
practices are banned outright. They include: (a) AI systems that deploy subliminal techniques to manipulate behavior in ways that circumvent a person's free will, causing or likely to cause significant harm; (b) AI
systems that exploit vulnerabilities of specific groups (based on age,
disability, social or economic situation) to materially distort behavior; (c) AI systems used by public authorities for the evaluation or classification of individuals based on social behavior or socio-economic characteristics, leading to detrimental treatment unrelated to the context (social scoring); (d) AI systems for the assessment of individual risk of committing criminal offences based solely on profiling, unless the system is based on objective, verifiable facts directly linked to criminal activity; (e) real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes, subject to limited exceptions for specific law enforcement purposes (e.g., prevention of terrorist attacks, search for victims of specific crimes); and (f) AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
High-Risk AI (Annex I and III). AI systems are classified as high-risk if they are used as safety components in products covered by
EU harmonization legislation (Annex I, including machinery, toys,
medical devices, and vehicles) or if they fall within eight specific categories listed in Annex III: (1) biometric identification and categorization; (2) management and operation of critical infrastructure;
(3) education and vocational training; (4) employment and worker management; (5) access to and enjoyment of essential private services and public services and benefits; (6) law enforcement; (7) migration,
asylum, and border control; (8) administration of justice and democratic processes.
Limited Risk. AI systems that interact directly with humans (such as chatbots), generate or manipulate image, audio, or video content
(deepfakes), or provide emotion recognition or biometric categorization are subject to transparency obligations. Users must be informed that they are interacting with an AI system, or that content has been generated or manipulated by AI.
Minimal Risk. AI systems that do not fall into any of the above categories are not subject to specific regulation under the AI Act,
though they remain subject to general EU law, including data protection,
consumer protection, and product safety legislation.
Providers of high-risk AI systems must comply with the following obligations:
Risk management (Article 9): Providers must establish, implement,
document, and maintain a continuous risk management system that identifies, analyzes, and mitigates risks throughout the system's lifecycle.
Data governance (Article 10): Training, validation, and testing datasets must meet quality criteria in terms of relevance,
representativeness, freedom from errors, and completeness. Datasets must be examined for possible biases.
Technical documentation (Article 11): Providers must draw up and maintain technical documentation sufficient to demonstrate compliance and to enable competent authorities to assess the system. Documentation must include a general description of the system, details of its design and development, and information on its monitoring and functioning.
Record-keeping (Article 12): High-risk AI systems must be designed to enable automatic logging of events relevant to identifying high-risk situations, in a manner that ensures traceability throughout the system's lifecycle.
Transparency (Article 13): Providers must ensure that high-risk AI
systems are designed and developed in such a way that they achieve an appropriate level of transparency, enabling deployers to interpret the system's output and use it appropriately.
Human oversight (Article 14): High-risk AI systems must be designed to allow effective oversight by natural persons during the period in which the system is in use. This includes the ability to understand the system's capabilities and limitations, to monitor its operation, and to intervene or override the system's output.
Accuracy, robustness, and cybersecurity (Article 15): High-risk AI
systems must achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle. They must be resilient against errors, faults, inconsistencies, and unexpected situations, and must be protected against attempts by third parties to alter the system's inputs, outputs, or behavior.
The AI Act introduces a novel regulatory category: general-purpose AI
(GPAI) models. These are AI models that can be used for a wide range of tasks without significant modification, such as large language models
(LLMs). GPAI models with "systemic risk" — those trained using a total computing power of more than 10^25 FLOPS, or assessed as having high-impact capabilities — are subject to enhanced obligations:
Performing and documenting model evaluations
Assessing and mitigating possible systemic risks
Documenting serious incidents
Ensuring an adequate level of cybersecurity protection
Reporting to the AI Office on the adequacy of mitigation measures
The distinction between GPAI models and high-risk AI systems is significant: a GPAI model is not itself classified as high-risk, but a specific AI system built on top of a GPAI model may be classified as high-risk if it falls within the categories in Annex III. This architecture allows the AI Act to regulate the underlying model while maintaining flexibility for downstream applications.
The AI Act establishes the European AI Office within the European
Commission to coordinate the regulation's implementation. The AI Office is responsible for implementing and applying the regulation for GPAI
models, contributing to the development of harmonized standards, and fostering international cooperation.
Penalties for non-compliance are structured in three tiers:
Prohibited practices: Up to €35 million or 7% of the provider's total worldwide annual turnover (whichever is higher)
Non-compliance with high-risk AI obligations: Up to €15 million or 3%
of total worldwide annual turnover
Supplying incorrect information: Up to €7.5 million or 1% of total worldwide annual turnover
Non-compliance by SMEs and start-ups: Reduced penalties
As of February 2025, the prohibition on banned AI practices has taken effect. National competent authorities are beginning to develop enforcement capabilities, and the first enforcement actions are anticipated in the latter half of 2025.

# Chapter 8: Digital Operational Resilience Act (DORA)

The Digital Operational Resilience Act (Regulation (EU) 2022/2554,
"DORA") entered into force on January 16, 2023, and became applicable on
January 17, 2025. It represents the European Union's first comprehensive, cross-sectoral framework for the operational resilience of the financial sector's information and communication technology (ICT)
systems. DORA was developed in response to the growing frequency and severity of cyberattacks targeting financial institutions and the increasing dependence of the financial sector on third-party ICT service providers.
DORA applies to more than 22,000 financial entities and ICT
third-party service providers across the EU. Its scope encompasses a broad range of financial institutions, including: credit institutions and investment firms (as defined in Regulation (EU) No 575/2013 and
Directive 2014/65/EU); payment institutions and electronic money institutions (under Directive 2015/2366); crypto-asset service providers
(under Regulation (EU) 2023/1114); asset managers (under Directive
2009/65/EC and Regulation (EU) No 236/2012); insurance and reinsurance undertakings (under Directive 2009/138/EC); pension fund institutions;
ancillary services providers; credit rating agencies; data reporting services providers; and central securities depositories. The regulation also applies to ICT third-party service providers that provide ICT
services to financial entities, regardless of whether those providers are established within the EU or in a third country.
The legislative background to DORA reflects a decade of growing regulatory concern over the operational resilience of the financial sector. The European Commission's 2017 Communication on "Building a
Capital Markets Union" identified operational resilience as a priority,
and the European Banking Authority (EBA), the European Insurance and
Occupational Pensions Authority (EIOPA), and the European Securities and
Markets Authority (ESMA) — collectively known as the European
Supervisory Authorities (ESAs) — published numerous guidelines and reports on ICT risk management and outsourcing. However, these guidelines were fragmented across sectors and lacked the binding force necessary to ensure consistent implementation. DORA was designed to consolidate and strengthen these existing frameworks into a single,
directly applicable regulation.
Chapter II of DORA establishes a comprehensive ICT risk management framework that applies to all financial entities. The framework requires financial entities to implement a governance framework that is proportionate to the size, risk profile, complexity, and interconnectedness of the entity, and that is subject to regular review and adjustment.
Governance and organization (Articles 5-7). Financial entities are required to define, implement, and maintain a robust ICT risk management framework that includes policies, procedures, and protocols to identify,
assess, manage, and mitigate ICT risk in a proportionate manner. The management body of the financial entity bears ultimate responsibility for the entity's ICT risk management framework and must ensure that it receives sufficient information and training to exercise effective oversight. Financial entities must establish clear roles and responsibilities for ICT risk management, ensuring that functions responsible for risk control are independent from functions responsible for ICT operations.
Identification of ICT-supported business functions and assets
(Article 8). Financial entities must identify, classify, and document all information assets that support their critical or important functions. This includes data assets, ICT systems, software applications, hardware, and third-party services. The identification process must consider the interdependencies between ICT assets and business functions, and the potential impact of ICT disruptions on business operations.
Protection and prevention (Articles 9-11). Financial entities must implement appropriate protection and prevention measures to ensure the resilience of ICT systems. This includes: access control policies (both logical and physical), identity management, data encryption, data loss prevention, network security, system integrity controls, and the use of multi-factor authentication. DORA requires financial entities to perform regular vulnerability assessments and penetration testing, and to develop and maintain an ICT security policy that is reviewed at least annually.
Detection (Article 12). Financial entities must establish mechanisms to detect anomalies and ICT-related incidents through continuous monitoring and automated tools. The detection system must be capable of distinguishing between normal operational events and genuine security incidents, and must generate alerts that are prioritized according to severity.
Response and recovery (Articles 13-14). Financial entities must develop, test, and maintain ICT response and recovery plans that ensure the continued provision of critical functions during and after
ICT-related incidents. These plans must include procedures for incident escalation, crisis communication, backup and restoration of data, and the invocation of business continuity arrangements. Financial entities must establish and regularly test backup procedures, including procedures for the restoration of data and systems from backups. Backup data must be stored in a manner that ensures its confidentiality,
integrity, and availability.
Learning and evolving (Articles 15-16). Financial entities must establish processes for the continuous improvement of their ICT risk management frameworks, drawing on the lessons learned from ICT-related incidents, testing exercises, and changes in the threat landscape.
Chapter III of DORA establishes a standardized incident reporting framework that requires financial entities to report ICT-related incidents to their competent authorities. The framework distinguishes between three categories of incidents based on their severity:
Major ICT-related incidents. A major incident is one that significantly disrupts or degrades the financial entity's ability to maintain its critical functions, or that has a significant impact on the availability, authenticity, integrity, or confidentiality of data.
Financial entities must report major incidents to their competent authority within four hours of classification as major. The initial report must include a preliminary assessment of the incident's nature,
scope, and impact. A follow-up report must be submitted within 72 hours,
and a final report must be submitted within one month of the incident's classification.
Significant ICT-related incidents. A significant incident is one that meets the reporting criteria established by the ESAs in their Regulatory
Technical Standards (RTS) but does not qualify as major. Financial entities must report significant incidents within the timeframe specified in the RTS (generally within 24 to 72 hours).
Ordinary ICT-related incidents. Financial entities must maintain records of all ICT-related incidents and report aggregated information on ordinary incidents to their competent authority as part of their regular reporting obligations.
DORA also requires financial entities to establish and maintain procedures for notifying affected customers and other financial entities in the event of a major incident, where such notification is necessary to mitigate the impact of the incident.
Chapter IV requires financial entities to conduct regular digital operational resilience testing programs to assess the resilience of their ICT systems. The testing framework distinguishes between three levels of testing:
Vulnerability assessments and scanning: Regular identification and assessment of vulnerabilities in ICT systems, including automated scanning tools.
Threat-led penetration testing (TLPT): Advanced testing that simulates sophisticated cyberattacks on critical ICT systems. TLPT must be conducted by qualified independent testers (either internal or external) and must cover the full attack lifecycle, from initial reconnaissance through to impact. TLPT is mandatory for entities identified as significant by their competent authority, based on criteria including the entity's size, interconnectedness, and the systemic importance of the services it provides.
Advanced testing exercises: Scenario-based testing exercises that simulate specific threat scenarios, such as ransomware attacks, supply chain compromises, or distributed denial-of-service (DDoS)
campaigns.
Financial entities must develop a testing program that is tailored to their risk profile, is conducted at least annually, and covers all critical ICT systems and third-party dependencies. The results of testing must be documented, reported to the competent authority, and used to inform improvements to the ICT risk management framework.
Chapter V of DORA is perhaps its most significant and novel contribution to financial sector regulation. It establishes a comprehensive framework for the management of ICT third-party risk,
addressing the growing concern over the concentration of ICT services in a small number of large technology providers — a concern sometimes described as the "too big to fail" problem for technology providers.
ICT third-party service provider risk management framework (Articles
28-30). Financial entities must implement a framework for the management of ICT third-party risk that covers the entire lifecycle of the third-party relationship, from selection and onboarding through ongoing monitoring and exit. The framework must include: a policy for the use of
ICT third-party services; a process for the identification, assessment,
and classification of ICT third-party providers; contractual provisions for third-party agreements; monitoring mechanisms; and exit strategies.
Contractual provisions (Articles 30-31). DORA specifies mandatory contractual provisions that must be included in agreements between financial entities and ICT third-party providers. These provisions cover: the services to be provided and the expected performance levels;
the allocation of responsibilities and liabilities; the right of the financial entity to audit the third-party provider; the third-party provider's obligation to notify the financial entity of material changes, incidents, and threats; data localization and processing requirements; business continuity and exit provisions; and the sub-outsourcing of services (which requires the prior consent of the financial entity).
Monitoring and oversight (Articles 33-35). Financial entities must conduct regular assessments of their ICT third-party providers,
including on-site audits where appropriate. They must maintain registers of all ICT third-party provider relationships and the associated risks.
Critical ICT third-party service providers (Articles 40-44). DORA
introduces a novel designation for "critical" ICT third-party providers
— providers whose services are so widely used by financial entities that a disruption would pose a systemic risk to the financial sector.
Critical providers are subject to enhanced oversight by the Lead
Overseer (one of the three ESAs, designated based on the sector most affected by the provider). The Lead Overseer has the power to: request information; conduct inspections (including on-site inspections);
require the implementation of specific remedial measures; impose periodic penalty payments for non-compliance; and, in extreme cases,
require the provider to cease providing certain services. As of early
2026, the ESAs have begun the process of identifying and designating critical ICT third-party providers, with major cloud providers (AWS,
Microsoft Azure, Google Cloud) and other widely used technology platforms expected to be among the first designations.
DORA's enforcement framework relies on the existing supervisory structures of the financial sector. Competent authorities — which include national central banks, financial supervisory authorities, and the ESAs — are responsible for monitoring compliance and enforcing the regulation. Penalties for non-compliance vary by member state and sector:
In Italy, the Bank of Italy may impose fines of up to €20 million for significant breaches
In Germany, BaFin may impose fines of up to €10 million or 5% of annual turnover
In France, the ACPR and AMF may impose fines of up to €5 million for natural persons and €25 million for legal persons
In Ireland, the Central Bank may impose fines of up to €10 million or
10% of annual turnover
The penalty framework reflects the sector-specific nature of DORA's enforcement, which differs from the uniform penalty structure of the
GDPR. Financial entities that fail to comply with DORA's provisions also face the possibility of supervisory measures, including the imposition of additional capital requirements, restrictions on business activities,
or the withdrawal of authorization.

# Chapter 9: NIS2 Directive

The Directive on measures for a high common level of cybersecurity across the Union (NIS2, Directive (EU) 2022/2555) entered into force on
January 16, 2023, and member states were required to transpose its provisions into national law by October 17, 2024. NIS2 replaces the original Network and Information Security Directive (NIS1, Directive
2016/1148) and represents a substantial expansion of the EU's cybersecurity regulatory framework.
The most significant change introduced by NIS2 is the dramatic expansion of its scope. NIS1 applied to approximately 400 entities across the EU, primarily operators of essential services (OES) in seven sectors and digital service providers (DSPs). NIS2 expands coverage to an estimated 100,000 to 160,000 entities across 18 sectors. This expansion was driven by the recognition that cyberattacks increasingly target sectors beyond traditional critical infrastructure, including public administration, healthcare, education, and space.
NIS2 distinguishes between two categories of regulated entities:
Essential entities (Annex I) include entities operating in critical sectors where a cyberattack could have significant disruptive effects on public safety, economic activity, or national security. Essential entities encompass: energy (electricity, oil, gas, hydrogen, district heating); transport (air, rail, water, road); banking and financial market infrastructure; health (hospitals, laboratories, manufacturers of critical medical devices); drinking water and wastewater; digital infrastructure (DNS service providers, TLD registries, cloud computing service providers, data center service providers, content delivery networks); ICT service management (managed security service providers);
public administration (central and regional government); and space.
Important entities (Annex II) include entities in sectors where the disruption from a cyberattack would be less severe but still significant. Important entities encompass: postal and courier services;
waste management; chemical manufacturing, production and distribution;
food production and distribution; manufacturing of critical products
(computers, electronic and optical products, machinery, electrical equipment, motor vehicles); digital providers (online marketplaces,
search engines, social networking services); and research.
The distinction between essential and important entities has practical consequences: essential entities are subject to more stringent obligations (including supervisory measures prior to non-compliance) and face higher maximum penalties.
Article 21 requires both essential and important entities to take appropriate and proportionate technical, operational, and organizational measures to manage the risks posed to the security of network and information systems. These measures must address, at a minimum: (a)
policies on risk analysis and information system security policies; (b)
incident handling; (c) supply chain security; (d) security in network and information systems acquisition, development, and maintenance; (e)
cryptography and, where relevant, encryption; (f) human resources security; (g) asset management; (h) access control; (i) identity management; (j) the security of network and information systems and the physical environment of such systems; (k) the security of network and information systems as they are being used, developed, and maintained;
and (l) cybersecurity risk-management in an objective manner, which would allow for a cross-sectoral comparison.
NIS2 introduces a particularly important new obligation: the management bodies of essential and important entities are required to approve the cybersecurity risk-management measures taken by those entities, to oversee their implementation, and to undergo cybersecurity training (Article 20). This "management responsibility" provision is designed to ensure cybersecurity accountability at the highest level of organizational governance, reflecting the recognition that cybersecurity cannot be treated as a purely technical matter delegated to IT
departments.
NIS2 establishes a graduated incident reporting framework with strict timelines:
Early warning: Within 24 hours of becoming aware of a significant incident, entities must submit an early warning to the competent authority or the CSIRT. The early warning must include an initial assessment of whether the incident is potentially caused by unlawful or malicious acts and whether it could have cross-border impact.
Incident notification: Within 72 hours of becoming aware of a significant incident, entities must submit an incident notification to the competent authority or the CSIRT. The notification must include an initial assessment of the incident's severity and impact.
Intermediate report: Upon request by the competent authority,
entities must submit an intermediate report providing updates on the incident's evolution and any additional information requested.
Final report: Within one month of the submission of the incident notification, entities must submit a final comprehensive report,
including a detailed description of the incident, the severity and impact, the type of threat or root cause, and the applied and ongoing mitigation measures.
The definition of a "significant incident" under NIS2 is broader than under NIS1. An incident is considered significant if it: (a) has caused or is capable of causing severe operational disruption or financial loss; or (b) has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
NIS2 introduces explicit requirements for the security of supply chains and the relationships between entities and their direct suppliers or service providers. This provision reflects the growing recognition that cyberattacks increasingly exploit supply chain vulnerabilities — a concern dramatically illustrated by the SolarWinds compromise (2020),
the Kaseya ransomware attack (2021), and the MOVEit vulnerability exploitation (2023).
Entities are required to address supply chain security in their risk management measures, including: assessing the cybersecurity risks posed by their direct suppliers and service providers; including appropriate cybersecurity requirements in contracts with suppliers; conducting regular audits of supplier cybersecurity practices; and maintaining awareness of the cybersecurity posture of the overall supply chain.
The transposition deadline of October 17, 2024, was missed by the majority of member states. As of early 2026, approximately 15 of 27
member states have completed transposition, with the remainder at various stages of the legislative process. The European Commission initiated infringement proceedings against non-compliant member states in early 2025.
The delay in transposition reflects the complexity of the directive's requirements and the need for member states to adapt existing national cybersecurity legislation, establish or strengthen national competent authorities, and develop the technical guidance and regulatory infrastructure necessary for effective enforcement. Several member states have reported that the broad scope of NIS2 — covering an estimated 100,000+ entities — has posed significant implementation challenges, particularly for smaller organizations that lack the resources and expertise to comply with the directive's risk management and incident reporting obligations.
NIS2 establishes minimum harmonization of penalties to ensure a consistent level of enforcement across the EU. For essential entities,
member states must ensure that fines for non-compliance can reach up to
€10 million or 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher. For important entities,
the maximum is €7 million or 1.4% of total worldwide annual turnover.
NIS2 also introduces the possibility of criminal penalties for natural persons — such as senior management — who are responsible for non-compliance. This represents a significant departure from NIS1 and reflects the emphasis on management accountability. Member states are required to establish rules on whether and to what extent management bodies can be held personally liable for breaches of cybersecurity obligations.
In addition to financial penalties, competent authorities may take supervisory measures, including: binding instructions to remedy non-compliance; measures restricting or prohibiting the use of specific products, services, or processes; and, in extreme cases, temporary suspension of the entity's operations.

# Chapter 10: EEA Extensions — Iceland, Liechtenstein, Norway

The European Economic Area (EEA) comprises the 27 EU member states plus Iceland, Liechtenstein, and Norway. Under the EEA Agreement, which entered into force on January 1, 1994, the three non-EU states commit to adopting and implementing EU legislation in the areas covered by the
Agreement, which include the internal market, competition policy,
consumer protection, and — critically for this volume — data protection and electronic communications regulation.
EU regulations are incorporated into the EEA through Joint Committee
Decisions (JCDs), which are adopted by the EEA Joint Committee — a body composed of representatives of the EU, Iceland, Liechtenstein, and
Norway. The incorporation process typically involves: (1) the EU
adopting a new regulation; (2) the EEA Joint Committee assessing whether the regulation falls within the scope of the EEA Agreement; (3) the
Committee adopting a JCD incorporating the regulation into the EEA
Agreement; and (4) the three EEA/EFTA states transposing or implementing the regulation through national legislation or administrative action.
For regulations that are directly applicable in the EU (such as the GDPR
and the Digital Markets Act), the JCD extends their application to the
EEA/EFTA states, which are then bound by the regulation in the same manner as EU member states.
The GDPR was incorporated into the EEA by Joint Committee Decision No
239/2017, adopted on July 6, 2017, with effect from the GDPR's operative date of May 25, 2018. The DMA was incorporated by JCD No 401/2022 on
November 4, 2022, and the DSA by JCD No 402/2022 on the same date. This incorporation mechanism ensures that the three EEA/EFTA states operate under essentially the same data protection and platform governance framework as the EU, while maintaining certain national variations.
Iceland implemented the GDPR through Act No. 90/2018 on Data
Protection and the Processing of Personal Data, which entered into force on the same date as the GDPR (May 25, 2018). Iceland's data protection authority, the Data Protection Authority (Persónuvernd), is the supervisory authority responsible for GDPR enforcement in Iceland.
In the area of electronic communications, Iceland has implemented the ePrivacy Directive through the Electronic Communications Act No.
70/2022, which governs the confidentiality of communications, cookie consent, and spam regulation. The Icelandic Post and Telecom
Administration (Póst- og fjarskiptastofnun) shares regulatory responsibility in the electronic communications sector.
Iceland's implementation of the GDPR is largely consistent with the
EU framework, with minor adaptations to accommodate Iceland's existing legal traditions and institutional structures. The Data Protection
Authority participates in the EDPB through the EEA/EFTA Advisory
Committee mechanism, which ensures that the three EEA/EFTA states are represented in the GDPR's governance structure, albeit without voting rights.
Notable enforcement actions in Iceland have included decisions relating to data breaches in the financial sector, the processing of employee data by public authorities, and compliance with the ePrivacy rules in the context of online advertising. Iceland's small population
(approximately 380,000) means that the volume of enforcement cases is relatively limited, but the authority has demonstrated a willingness to engage with complex data protection issues.
Liechtenstein transposed the GDPR into national law through the Act on Data Protection (Datenschutzgesetz, DSG) and the Data Protection
Ordinance (Datenschutzverordnung, DSV). The DSG and DSV are substantially aligned with the GDPR, with the Office for Data Protection
(Amt für Datenschutz) serving as the national supervisory authority.
Liechtenstein's unique position as a microstate with a significant financial services sector has shaped its approach to data protection.
The country has a strong tradition of banking secrecy, which has gradually been adapted to accommodate EU and international data protection standards. The implementation of the GDPR was part of a broader effort to align Liechtenstein's financial regulatory framework with EU standards, motivated in part by the country's interest in maintaining access to the EU's internal market for financial services.
The DSG applies the GDPR's principles, rights, and obligations with only minor modifications. Key differences include the appointment mechanism for the supervisory authority, the specific procedural rules for data subject complaints, and certain exemptions for data processing by public authorities in the context of national security.
Norway implemented the GDPR through the Personal Data Act
(Personopplysningsloven, Act 38/2018), which entered into force on May
25, 2018, alongside the GDPR. Norway's data protection authority, the
Data Protection Authority (Datatilsynet), is an independent administrative body under the Ministry of Digitalisation and is one of the most active and well-respected data protection authorities in
Europe.
Datatilsynet has been notable for its proactive enforcement approach.
Key enforcement actions have included: a fine against the Norwegian Tax
Administration in 2023 for inadequate security measures protecting citizens' tax data; enforcement against municipalities for unlawful video surveillance; actions against transport companies for excessive data collection through electronic ticketing systems; and significant guidance on the use of artificial intelligence and facial recognition technology.
The Norwegian implementation of the GDPR is notable for the emphasis placed on privacy-enhancing technologies (PETs) and data minimization.
Datatilsynet has consistently advocated for privacy-by-design approaches and has been critical of mass surveillance practices, both by public authorities and private companies.
In the area of cybersecurity, Norway has also enacted the Security
Act (Sikkerhetsloven), which entered into force on January 1, 2022. The
Security Act imposes obligations on operators of critical infrastructure to implement security measures and to report security incidents to the
National Security Authority (NSM). The Act complements the NIS2
Directive, which Norway will implement separately through amendments to the existing regulatory framework.
For organizations operating across the EEA, the practical implications of the three EEA/EFTA states' adoption of EU data protection legislation are relatively modest. The core principles,
rights, and obligations of the GDPR apply uniformly across the EU and the three EEA/EFTA states. However, several practical differences merit attention:
First, the one-stop-shop mechanism operates slightly differently.
While the GDPR provides that the lead supervisory authority is the DPA
of the member state in which the controller's main establishment is located, the EEA/EFTA states are not technically "member states" for this purpose. In practice, however, the EEA Joint Committee decisions have extended the one-stop-shop mechanism to the EEA/EFTA states, and the three national DPAs participate in the cross-border cooperation mechanisms.
Second, the EEA/EFTA states are not covered by EU adequacy decisions
— they are not "third countries" requiring adequacy assessments.
Transfers of personal data between EU member states and the three
EEA/EFTA states are unrestricted, as the GDPR (as extended by the JCDs)
applies equally in all 30 EEA states.
Third, the three EEA/EFTA states are not bound by EU legislation that falls outside the scope of the EEA Agreement. For example, the EU AI Act has not yet been extended to the EEA/EFTA states, meaning that Iceland,
Liechtenstein, and Norway are not subject to its requirements (although they may choose to adopt equivalent national legislation).

# Chapter 11: Switzerland — Revised Federal Act on Data Protection (FADP)

Switzerland's Federal Act on Data Protection (FADP, Bundesgesetz über den Datenschutz) was originally enacted on June 19, 1992, and entered into force on July 1, 1993. For nearly three decades, the FADP provided the basic framework for data protection in Switzerland, supplemented by sector-specific legislation and cantonal data protection laws.
Following a popular initiative in 2017, in which Swiss voters approved a constitutional amendment calling for stronger data protection, the Swiss Parliament undertook a comprehensive revision of the FADP. The revised FADP was approved by Parliament on September 25,
2022, and entered into force on September 1, 2023. The revision represented the most significant update to Swiss data protection law in three decades.
Notably, Switzerland is not a member of the EU or the EEA, and the revised FADP was developed independently of the GDPR. However, the influence of the GDPR is evident throughout the revised text,
particularly in the areas of territorial application, data subject rights, and the principles of processing.
The revised FADP introduces several significant changes:
Expanded territorial application (Article 2). The revised FADP
applies to the processing of personal data by Swiss-based private persons or federal bodies, as well as to the processing of personal data of persons in Switzerland by foreign-based private persons if the processing is related to the offering of goods or services in
Switzerland or the monitoring of behavior in Switzerland. This extraterritorial provision mirrors the GDPR's Article 3(2) and represents a significant expansion of the FADP's reach.
Health data and genetic data. The revised FADP introduces special provisions for particularly sensitive personal data, including health data and genetic data, requiring enhanced protections similar to the
GDPR's Article 9.
Data subject rights. The revised FADP strengthens data subject rights, including the right to information, the right to access, the right to rectification, the right to erasure, and the right to data portability. However, the Swiss approach to data subject rights is generally less prescriptive than the GDPR's, leaving greater flexibility for controllers.
Obligation to inform. Controllers must inform data subjects about the processing of their personal data, including the identity of the controller, the purposes of processing, and the data subject's rights.
The obligation is less detailed than the GDPR's Article 14 but covers the essential information requirements.
Data protection by design and by default. While the revised FADP does not explicitly use the GDPR's terminology of "data protection by design and by default," it requires controllers to implement appropriate technical and organizational measures to ensure an adequate level of data protection.
The revised FADP regulates cross-border transfers of personal data.
Transfers to countries that provide an "adequate level of protection"
are permitted without additional safeguards. The Swiss Federal Council has the authority to determine which countries provide adequate protection, using criteria similar to the EU's adequacy assessment.
Where no adequacy determination exists, transfers are permitted if:
(a) the data subject has consented to the transfer; (b) the transfer is necessary for the performance of a contract; (c) the transfer is necessary for the establishment, exercise, or defense of legal claims;
or (d) the transfer is necessary for the protection of the data subject's vital interests. Additionally, transfers may be made on the basis of appropriate contractual safeguards.
Switzerland's data transfer framework is broadly compatible with the
EU's, though the absence of a mutual adequacy decision means that transfers from the EU to Switzerland are governed by the EU's adequacy decision for Switzerland (adopted in 2000 and periodically renewed, most recently in 2023), while transfers from Switzerland to the EU are governed by the FADP's transfer provisions.
The revised FADP introduces criminal penalties for certain violations, including the unlawful processing of sensitive personal data, the unlawful disclosure of personal data, and the failure to comply with data protection obligations despite an order from the
Federal Data Protection and Information Commissioner (FDPIC). Criminal penalties include fines of up to CHF 250,000 for natural persons.
In addition to criminal penalties, the revised FADP provides for administrative enforcement by the FDPIC, including the power to issue binding orders, conduct investigations, and refer matters to the public prosecutor for criminal prosecution.
Notably, the revised FADP does not introduce GDPR-style administrative fines calculated as a percentage of turnover. This has been the subject of criticism, as the absence of large financial penalties may limit the deterrent effect of Swiss data protection enforcement, particularly for large multinational corporations.
Switzerland has held an EU adequacy decision since 2000, most recently renewed in 2023. However, the continued validity of this adequacy decision is not entirely certain. The EU-Switzerland relationship has been complicated by political tensions over various bilateral issues, and the revised FADP's differences from the GDPR —
particularly its lower penalty regime and its somewhat less robust data subject rights — have prompted questions about whether Switzerland continues to provide "essentially equivalent" protection.
Should the EU's adequacy decision for Switzerland be challenged or withdrawn, the consequences for Swiss businesses would be significant,
as they would need to rely on standard contractual clauses or other safeguards for transfers of personal data from the EU. The Swiss government has expressed confidence that the current adequacy arrangement will be maintained, and the revised FADP was designed in part to address EU concerns about the adequacy of Swiss data protection.

# Chapter 12: UK Data Protection Framework

Following Brexit, the United Kingdom retained the GDPR in domestic law as the "UK GDPR," which operates alongside the Data Protection Act
2018 (DPA 2018). The UK GDPR is substantially identical to the EU GDPR,
but several important differences have emerged, particularly with the enactment of the Data (Use and Access) Act 2025.
The most significant original difference concerns the age of consent for processing children's data. The UK GDPR sets the age at which a child can consent to processing at 13, compared with the GDPR's default of 16 (with member states permitted to lower this to 13). This difference reflects the UK's earlier adoption of a lower age threshold through the DPA 2018.
Other structural differences include: the removal of certain provisions relating to multi-DPA cooperation that are unnecessary in a single-authority context (the UK has one supervisory authority, the
Information Commissioner's Office, whereas the EU has 27+ national
DPAs); the introduction of a UK-specific "legitimate interests"
provision that allows the Secretary of State to add additional legitimate interests by regulation; and the modification of certain provisions relating to the processing of personal data for immigration purposes, which is governed by the DPA 2018's immigration exemption.
The Data Protection Act 2018 serves as the UK's comprehensive data protection statute. It performs several functions: it supplements the UK
GDPR with provisions on law enforcement processing (Part 3),
intelligence services processing (Part 4), and the processing of personal data by the Secretary of State for immigration purposes
(Schedule 2); it designates the Information Commissioner's Office (ICO)
as the UK's supervisory authority; it establishes the framework for the
ICO's enforcement powers and penalty regime; and it transposes certain aspects of the EU's Law Enforcement Directive (2016/680) into UK
law.
The DPA 2018's immigration exemption (Section 17 and Schedule 2) has been one of the most controversial provisions, allowing the Secretary of
State to process personal data for immigration purposes without being subject to certain data protection requirements, including the duty to inform data subjects and the right to erasure. This exemption has been the subject of legal challenges, including the landmark case of R
(Bridges) v. Chief Constable of South Wales Police (2020), which addressed the compatibility of facial recognition technology with data protection and human rights law, and the ongoing challenge to the immigration exemption in the context of the Windrush scandal.
The Data (Use and Access) Act 2025 represents the most significant divergence of UK data protection law from the EU GDPR since Brexit. The
Act was enacted in 2025 and introduces a series of modifications to the
UK GDPR that reflect the UK government's desire to create a "more agile,
business-friendly" data protection regime.
Reduced automated decision-making obligations. The Act modifies the
UK GDPR's Article 22, which gives individuals the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. The Act narrows the scope of this right by clarifying that it applies only to decisions that produce
"legal effects" in a narrow sense — decisions that affect an individual's legal rights or obligations — and not to decisions that merely have "significant effects" on the individual. This modification is intended to facilitate the use of AI and automated decision-making by businesses, particularly in areas such as credit scoring, insurance underwriting, and employment.
Simplified data subject access requests (DSARs). The Act introduces a new "tiered" approach to DSARs, allowing controllers to provide a standard response to straightforward requests and a more detailed response to complex requests. It also clarifies that controllers may refuse to comply with requests that are "manifestly unfounded or excessive," and introduces a statutory timeframe for handling DSARs that is intended to reduce the administrative burden on controllers.
Eased cookie consent requirements. The Act modifies the relationship between the UK GDPR and the Privacy and Electronic Communications
Regulations (PECR), providing greater flexibility for controllers in the area of cookie consent. In particular, the Act introduces a "legitimate interests" basis for cookie storage where the cookies are strictly necessary for the provision of a service requested by the user, thereby reducing the need for explicit consent for certain categories of cookies.
Increased ePrivacy penalties. Paradoxically, while easing certain consent requirements, the Act increases the penalties available under the PECR, aligning them with the UK GDPR's penalty framework (up to
£17.5 million or 4% of global turnover).
Legitimate interest modification. The Act introduces a new statutory presumption that the processing of personal data for the purposes of scientific research, historical research, and statistics serves a legitimate interest, reducing the burden on controllers in these areas.
The Data (Use and Access) Act has been welcomed by business groups as a pragmatic rebalancing of data protection in favor of innovation, but it has been criticized by privacy advocates as a weakening of the UK's data protection standards. The Act's impact on the EU's adequacy decision for the UK — which was renewed in June 2025 — remains to be seen, though the European Commission's adequacy assessment has noted the divergences introduced by the Act.
The Privacy and Electronic Communications Regulations (PECR)
implement the ePrivacy Directive in the UK and govern cookie consent,
electronic direct marketing, and the security of electronic communications services. PECR operates alongside the UK GDPR, and the relationship between the two frameworks is governed by the Data (Use and
Access) Act 2025.
The Information Commissioner's Office (ICO) is the UK's supervisory authority for data protection and electronic communications privacy. The
ICO's enforcement powers include: the power to issue information notices, enforcement notices, and penalty notices; the power to conduct audits and assessments; and the power to prosecute criminal offences under the DPA 2018 and PECR. The ICO's penalty framework provides for fines of up to £17.5 million or 4% of global annual turnover for the most serious UK GDPR violations, and lower amounts for PECR
violations.
Notable enforcement actions by the ICO include: a £20 million fine against British Airways (2020) for a data breach affecting approximately
429,000 customers; a £20 million fine against Marriott International
(2020) for a breach affecting approximately 339 million guests; a £12.7
million fine against TikTok (2023) for processing children's data without parental consent; and a £7.5 million fine against Interserve
(2023) for failing to protect the personal data of its employees during a ransomware attack.

# Chapter 13: UK Cyber Security and Resilience Bill

The Cyber Security and Resilience Bill was introduced in Parliament in 2025 as part of the UK government's strategy to update the country's cyber security regulatory framework post-Brexit. The Bill replaces and expands upon the Network and Information Systems Regulations 2018 (NIS
Regulations), which implemented the original EU NIS Directive in the
UK.
The Bill's development reflects several converging pressures: the increasing frequency and sophistication of cyberattacks against UK
organizations (including the NHS WannaCry attack in 2017, the British
Library ransomware attack in 2023, and the MOJ Services Inc. data breach in 2024); the need to align UK cyber security regulation with the EU's
NIS2 Directive (which the UK is not obligated to implement but which sets the international benchmark); and the growing recognition that the
UK's existing cyber security framework needed to be expanded to cover new sectors and threats.
The Bill significantly expands the scope of the UK's cyber security regulatory framework. Key expansions include:
Data centers. For the first time, data centers are brought within the scope of UK cyber security regulation. Data center operators are required to implement appropriate security measures, conduct regular security assessments, and report significant cyber incidents to the relevant authority. This expansion reflects the growing strategic importance of data centers as critical infrastructure and the concentration of UK data processing capacity in a relatively small number of facilities.
Electricity load controllers. The Bill extends coverage to providers of electricity load control services, which manage the distribution of electrical power across the grid. This expansion addresses the risk that cyberattacks on load control systems could cause widespread power disruptions.
AI providers. The Bill introduces provisions requiring AI service providers that supply critical services to implement appropriate security measures and to report AI-related security incidents. This is one of the first instances globally of AI-specific cybersecurity obligations being integrated into a general cyber security regulatory framework.
Managed service providers (MSPs). The Bill extends coverage to managed IT service providers that provide services to regulated entities, addressing the supply chain risk that MSPs can pose.
The Bill introduces unprecedented provisions on "critical suppliers"
— technology providers whose services are essential to the operation of regulated entities. The Secretary of State has the power to designate a supplier as "critical" where the supplier's failure or compromise would pose a significant risk to national security or the provision of essential services.
Once designated, critical suppliers are subject to specific obligations, including: requirements to implement and maintain appropriate security measures; requirements to report significant security incidents; requirements to cooperate with government audits and assessments; and requirements to develop and maintain contingency plans for the continuation of services. The Bill also provides the government with the power to direct critical suppliers to take specific actions,
including the modification of products or services, in the event of a national security threat.
These provisions represent a significant expansion of government authority over private-sector technology providers and have been the subject of considerable debate. Supporters argue that they are necessary to address the concentration of critical technology services in a small number of global providers; critics argue that they could deter technology investment in the UK and create compliance burdens that are disproportionate for smaller providers.
The Bill strengthens the incident reporting framework, requiring regulated entities to report significant cyber incidents to the relevant authority within specified timeframes. The reporting framework is broadly aligned with the NIS2 Directive's graduated approach, with early warning notifications, incident notifications, and final reports.

# Chapter 14: UK Online Safety Act (2023)

The Online Safety Act received Royal Assent on October 26, 2023,
following more than three years of legislative development. The Act originated in the government's 2019 Online Harms White Paper and underwent extensive revision during its passage through Parliament, with significant amendments introduced in the House of Lords, including the addition of provisions on legal but harmful content (which were subsequently removed from the final version).
The Act is one of the most comprehensive regulatory frameworks for online content in the world, establishing a system of "duties of care"
that apply to providers of user-to-user services (social media platforms, messaging services, and other services that allow users to share content with other users) and providers of search services.
The Act establishes a tiered system of duties of care:
Systemic duties apply to all regulated services and require providers to conduct and publish illegal content risk assessments; implement systems and processes to prevent, detect, and remove illegal content;
and provide mechanisms for users to report illegal content and to appeal content moderation decisions.
Content duties require providers to take specified action in relation to particular categories of content, including: terrorism content; child sexual abuse material (CSAM); fraud content; suicide and self-harm content; and content relating to eating disorders. These duties impose specific obligations, including the use of proactive detection technology (particularly for CSAM and terrorism content), removal timeframes, and reporting requirements.
Children's safety duties require providers to conduct and publish children's risk assessments and to implement measures to protect children from harmful content and activity. These duties apply to all services likely to be accessed by children and include: age-verification or age-estimation requirements; content moderation standards that are appropriate for children; the prohibition of features that encourage children to view harmful content; and the requirement to provide parents with tools to manage their children's online experience.
The distinction between "illegal content" (content that is unlawful under UK law) and "content harmful to adults" (content that is lawful but may cause harm) is a central feature of the Act. The Act imposes the most stringent obligations in relation to illegal content, with more limited obligations in relation to content harmful to adults.
Ofcom, the UK's communications regulator, is designated as the Online
Safety Act's enforcement authority. Ofcom's powers include: the power to issue codes of practice providing guidance on compliance; the power to require information from regulated services; the power to conduct technology assessments to evaluate the effectiveness of content moderation systems; the power to issue enforcement notices requiring specific actions; and the power to impose financial penalties of up to
£18 million or 10% of "qualifying worldwide revenue" (defined as global revenue attributable to UK users), whichever is greater.
Ofcom published its first set of Illegal Content Codes of Practice in
2024, providing detailed guidance on the systems and processes that providers must implement to comply with the Act. The codes address: risk assessment; content moderation; user reporting; transparency reporting;
and the protection of children.
The Online Safety Act's implementation is phased, with different provisions taking effect at different times. Ofcom has published its implementation timetable, with the first enforcement actions expected in
2025-2026. The practical challenges of implementation are considerable:
the Act requires providers to conduct detailed risk assessments of their services, implement sophisticated content moderation systems (including for categories such as CSAM and terrorism content), and comply with extensive transparency reporting requirements. Smaller providers have expressed concerns about the compliance burden, though the Act includes provisions that exempt very small services from certain obligations.

# Chapter 15: UK Computer Misuse Act 1990

The Computer Misuse Act 1990 (CMA) was enacted in response to growing concern over the unauthorized use of computer systems, following high-profile cases such as the hacking of the British Telecom Prestel system by Robert Schifreen and Stephen Gold in 1985 (R v. Gold and
Schifreen, 1988). The CMA has been the UK's primary criminal legislation addressing computer misuse for over three decades, though it has been increasingly criticized as outdated in the face of modern cyber threats.
The CMA establishes four principal offences:
Section 1: Unauthorized access to computer material. This offence criminalizes the act of causing a computer to perform any function with the intent to secure access to any program or data held in any computer,
where the access is unauthorized. The offence is triable either way,
with a maximum penalty of two years' imprisonment on indictment. Section
1 is the CMA's most commonly charged offence and covers a wide range of activities, from low-level hacking to unauthorized access to corporate systems.
Section 2: Unauthorized access with intent to commit further offences. This offence extends Section 1 by criminalizing unauthorized access to a computer where the offender intends to commit or facilitate the commission of a further offence (such as fraud, theft, or extortion). The maximum penalty is five years' imprisonment.
Section 3: Unauthorized acts intended to impair computer operation.
This offence criminalizes unauthorized acts that cause impairment of the operation of any computer, prevent or hinder access to any program or data, or impair the reliability of any such program or data. The maximum penalty was increased from five to ten years' imprisonment by the Police and Justice Act 2006. Section 3 covers a broad range of activities,
including the distribution of malware, denial-of-service attacks, and ransomware attacks.
Section 3A: Making, supplying, or obtaining articles for use in computer misuse offences. This offence, introduced by the Serious Crime
Act 2015, criminalizes the creation, distribution, and procurement of tools (such as malware, exploits, or hacking tools) that are intended to be used to commit CMA offences. The maximum penalty is ten years'
imprisonment. Section 3A was designed to address the challenge of prosecuting individuals who develop or distribute hacking tools without themselves conducting the underlying attacks.
The CMA has been interpreted by the courts in several significant cases:
In R v. Lindley (1996), the Court of Appeal held that a person who exceeded his authorized access to a computer (by accessing areas he was not permitted to access, even though he had legitimate access to the system) could be liable under Section 1. This interpretation was consistent with the broad approach taken by US courts in interpreting the CFAA before the Van Buren decision narrowed its scope.
In R v. McGill (2017), the Court of Appeal held that the
"authorization" test under Section 1 requires an assessment of whether the access was within the scope of the authority granted to the user,
considering the terms and conditions of use, the nature of the relationship between the user and the computer owner, and any specific restrictions imposed on the user's access.
In R v. Mudd (2021), the defendant was convicted under Section 3 for creating and distributing a remote access trojan (RAT) that was used to compromise victims' computers. The case illustrated the application of
Section 3A to the development and distribution of malware.
The CMA has been widely criticized as inadequate to address the modern cyber threat landscape. Key criticisms include: the difficulty of prosecuting foreign-based attackers who operate from jurisdictions without extradition treaties; the lack of a specific offence for cyber-espionage or state-sponsored attacks; the overlap between the CMA
and other criminal offences (such as fraud and theft); and the relatively low penalties compared with the scale of economic harm caused by cyberattacks.
The Cyber Security and Resilience Bill (Chapter 13) is expected to address some of these criticisms by introducing new offences and strengthening existing penalties. Proposals under consideration include:
a specific offence of "cyber-sabotage" targeting critical infrastructure; enhanced penalties for attacks that cause widespread disruption; and provisions addressing the use of AI in cyberattacks.

# Chapter 16: Federal Cyber and Privacy Laws (United States)

The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. §
1030, stands as the principal federal statute addressing computer-related offenses in the United States. Enacted in 1986 as part of the Comprehensive Crime Control Act, the CFAA was a direct congressional response to growing concerns about unauthorized access to government and financial computer systems. The Act's original scope was relatively narrow, targeting hacking into federal government computers,
computers used in interstate commerce, and financial institution systems.
Congress has amended the CFAA on multiple occasions to expand its reach and adapt to evolving technological threats. The National
Information Infrastructure Protection Act of 1996 broadened the statute's coverage significantly, adding protections for computers used in "interstate or foreign communication," which effectively brought the vast majority of internet-connected computers within the statute's ambit. The USA PATRIOT Act of 2001 further expanded the CFAA by lowering the threshold for certain offenses and adding computer fraud as a predicate act for RICO prosecutions. The Identity Theft Enforcement and
Restitution Act of 2008 clarified and expanded the definition of
"damage" and "loss" for purposes of civil remedies. Most recently, the
Cybersecurity Information Sharing Act of 2015 introduced additional provisions concerning the authorization of defensive measures in cyberspace.
The foundational concept of the CFAA is the "protected computer,"
defined at 18 U.S.C. § 1030(e)(2). The definition encompasses:
(A) a computer exclusively for the use of a financial institution or the United States Government, or, in the case of a computer not exclusively for such use, used by or for a financial institution or the
United States Government and the conduct constituting the offense affects that use by or for the financial institution or the Government;
or
(B) a computer which is used in or affecting interstate or foreign commerce or communication, including a computer located outside the
United States that is used in a manner that affects United States commerce or communication.
The inclusion of computers "used in or affecting interstate or foreign commerce" has been interpreted so broadly that virtually every internet-connected computer qualifies as a "protected computer" under the statute. This expansive jurisdictional hook has drawn criticism from scholars and practitioners who argue that it grants federal prosecutors nearly unlimited reach over state-level computer disputes and transforms the CFAA from a tool for prosecuting genuine cybercrime into a mechanism for enforcing private use restrictions.
The CFAA enumerates seven principal offenses at 18 U.S.C. §
1030(a)(1) through (a)(7):
§ 1030(a)(1) — Computer Espionage. This provision criminalizes the knowing access of a protected computer without authorization or exceeding authorized access, with the intent to obtain classified information with reason to believe such information could harm the
United States or benefit a foreign nation. Violations carry penalties of up to ten years' imprisonment for a first offense and twenty years for subsequent offenses.
§ 1030(a)(2) — Unauthorized Access to Obtain Information. Perhaps the most frequently invoked subsection, (a)(2) prohibits intentionally accessing a protected computer without authorization or exceeding authorized access, thereby obtaining information from any protected computer. Congress subdivided this provision at (a)(2)(B)–(F) to address access to financial records, information from any department or agency of the United States, and information from any protected computer. The
(a)(2)(C) clause, which criminalizes obtaining information "from any protected computer," has served as the basis for numerous prosecutions involving employee misconduct, competitive intelligence gathering, and violations of employer computer use policies.
§ 1030(a)(3) — Government Computers. This subsection criminalizes unauthorized access to a non-public computer of a department or agency of the United States. Unlike (a)(2), no obtaining of information is required; the mere act of unauthorized access suffices for conviction.
§ 1030(a)(4) — Computer Fraud. This provision targets individuals who, with intent to defraud, access a protected computer without authorization or exceed authorized access, and by means of such conduct further the intended fraud and obtain anything of value (other than the use of the computer, unless the use is valued at more than $5,000 in any one-year period). This subsection bridges computer intrusions with traditional fraud, encompassing schemes ranging from online auction fraud to sophisticated business email compromise operations.
§ 1030(a)(5) — Causing Damage. This subsection prohibits knowingly causing the transmission of a program, information, code, or command,
and as a result of such conduct, intentionally causing damage without authorization to a protected computer. It also covers reckless damage and negligent damage causing loss aggregating at least $5,000. The term
"damage" is defined at § 1030(e)(8) as any impairment to the integrity or availability of data, a program, a system, or information. This provision has been the primary statutory basis for prosecuting malware distribution, denial-of-service attacks, and ransomware incidents.
§ 1030(a)(6) — Trafficking in Passwords. This provision criminalizes knowingly and with intent to defraud trafficking in passwords or similar information that permits unauthorized access to a computer affecting interstate commerce, where such computer is used by or for the government.
§ 1030(a)(7) — Threats to Damage Protected Computers. This subsection prohibits threats to cause damage to a protected computer, extortion involving computers, and threats to access a protected computer without authorization, obtain information, or cause damage. It has been applied to ransomware demands and threats directed at critical infrastructure operators.
Penalties under the CFAA are structured in tiers at 18 U.S.C. §
1030(c). The base misdemeanor offense, applicable to violations of subsections (a)(2), (a)(4), and (a)(5)(C) where the loss does not exceed
$5,000, carries a maximum sentence of one year of imprisonment. felony penalties range from five years for first offenses involving subsections
(a)(3), (a)(5)(B), and (a)(7), to ten years for subsections (a)(1) and aggravated (a)(5) offenses, to twenty years for second or subsequent offenses and for violations committed for purposes of commercial advantage or private financial gain, in furtherance of a criminal or tortious act, or where the offense causes or attempts to cause serious bodily injury. Fines may be imposed under Title 18 generally, and the statute also provides for mandatory restitution in cases resulting in damage to victims.
Section 1030(g) provides a private right of action for any person who suffers damage or loss by reason of a violation of the CFAA. To maintain a civil action, the plaintiff must demonstrate either: (1) loss aggregating at least $5,000 in value during any one-year period; (2)
modification or impairment of medical examination, diagnosis, treatment,
or care; (3) physical injury; (4) a threat to public health or safety;
or (5) damage affecting ten or more protected computers during any one-year period. The civil action may seek compensatory damages and injunctive relief. This private right of action has been invoked extensively in employment disputes, trade secret litigation, and disputes over web scraping and terms-of-service violations, making the
CFAA one of the most litigated federal statutes in the technology sector.
The Supreme Court's decision in Van Buren v. United States, 593 U.S.
374 (2021), represents the most significant judicial interpretation of the CFAA in its history. The case arose when Nathan Van Buren, a police sergeant in Georgia, used his legitimate access to a law enforcement database to retrieve license plate records for an acquaintance in exchange for money. Although Van Buren had permission to access the database for law enforcement purposes, he used it for an unauthorized personal purpose. He was convicted under § 1030(a)(2) for "exceed[ing]
authorized access."
Justice Barrett, writing for a 6-3 majority, held that the phrase
"exceeds authorized access" in § 1030(a)(2) does not extend to violations of use restrictions. Rather, the Court interpreted the phrase to refer only to situations where a person accesses areas of a computer—such as files, folders, or databases—that are off-limits to that particular user. The Court grounded its analysis in the statutory text, noting that § 1030(e)(6) defines "exceeds authorized access" as accessing a computer "with authorization" but using such access "to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter." Under this reading, if a person is entitled to obtain particular information, the person does not "exceed authorized access" by using it for an improper purpose.
The Van Buren decision dramatically narrowed the scope of the CFAA's
(a)(2) provision, which had previously been used to prosecute employees who violated employer computer use policies, journalists who circumvented website paywalls, and researchers who collected publicly available data in violation of website terms of service. While the decision was welcomed by civil liberties organizations, technology companies, and legal scholars who had long argued that the CFAA was overbroad, it left open the question of how to address genuine insider threats and misuse of authorized access in contexts that do not involve accessing off-limits areas of a computer system.
The CFAA has been the subject of sustained criticism across the political spectrum. Critics on the left argue that its broad definitions of "unauthorized access" and "damage" have been weaponized against security researchers, journalists, and whistleblowers, creating a chilling effect on legitimate security research and the free flow of information. The prosecution of Aaron Swartz under the CFAA for downloading academic articles from JSTOR became a rallying point for reform advocates. Critics on the right focus on the statute's overcriminalization of routine internet activity and its potential to criminalize terms-of-service violations.
Multiple reform proposals have been introduced in Congress. The
Aaron's Law Act, first proposed in 2013, sought to narrow the CFAA's definitions of "unauthorized access" and "exceeds authorized access" to exclude violations of terms of service and similar contractual agreements. The International Cybercrime Prevention Act and various other proposals have sought to modernize the statute's approach to botnets, data breaches, and transnational cybercrime. While Van Buren addressed the most pressing interpretive issue, the statute's definitions of "damage" and "loss" remain expansive, and the civil private right of action continues to generate significant litigation that some commentators argue exceeds the statute's intended scope.
The Electronic Communications Privacy Act, enacted in 1986,
represents Congress's initial effort to extend privacy protections to emerging digital communications technologies. The ECPA was structured as an amendment to the existing Wiretap Act of 1968 and is organized into three titles, each addressing a distinct aspect of electronic communications privacy.
Title I of the ECPA, commonly referred to as the Wiretap Act, governs the real-time interception of electronic communications. Section
2511(1)(a) establishes the general prohibition: it is unlawful for any person to intentionally intercept, endeavor to intercept, or procure any other person to intercept or endeavor to intercept any wire, oral, or electronic communication. The statute defines "intercept" at § 2510(4)
as the aural or other acquisition of the contents of any wire, oral, or electronic communication through the use of an electronic, mechanical,
or other device.
The Wiretap Act provides several statutory exceptions that have been interpreted expansively by courts. Section 2511(2)(d) permits interception by a provider of electronic communication service in the ordinary course of business, which has been used to justify email scanning and content filtering. Section 2511(2)(i) provides a defense when interception is with the consent of one party to the communication,
forming the basis for the federal one-party consent framework that governs telephone recording in most states. Section 2511(3) allows interception pursuant to a judicial order issued under the stringent probable cause standard of § 2518.
The Wiretap Act also provides for civil remedies at § 2520, including actual damages, statutory damages of $10,000, punitive damages, and attorney's fees. Criminal penalties for willful violations include fines and imprisonment of up to five years.
Title II, known as the Stored Communications Act, regulates government and third-party access to stored electronic communications and records. The SCA distinguishes among different categories of stored data and imposes varying levels of procedural protection depending on the nature of the data and the age of the communication.
For contents of communications in electronic storage for 180 days or less, the government must obtain a warrant based on probable cause under
§ 2703(a). For contents stored for more than 180 days, the government may use a subpoena or court order under the lesser standard of "specific and articulable facts showing reasonable grounds to believe" the records are relevant and material to an ongoing criminal investigation, per §
2703(d). This 180-day distinction drew heavily from the third-party doctrine established in Smith v. Maryland, 442 U.S. 735 (1979), which held that individuals have no reasonable expectation of privacy in information voluntarily conveyed to third parties.
Non-content records, including subscriber information, IP logs, and transactional records, may be obtained with a subpoena, court order, or voluntary disclosure under § 2703(c). Section 2702 addresses voluntary disclosures by service providers, permitting disclosure to any person if consent is given by the originator or recipient, if the disclosure concerns the commission of a crime, or under emergency circumstances involving imminent death or serious physical injury.
The SCA has been the subject of significant litigation regarding the definition of "electronic storage." In The United States v. Warshak, 631
F.3d 266 (6th Cir. 2010), the Sixth Circuit held that individuals have a reasonable expectation of privacy in their emails, and government access to stored emails requires a warrant regardless of their age. While the
Warshak decision established this principle within the Sixth Circuit,
Congress ultimately addressed the issue through the Email Privacy Act
(also known as the bipartisan reform bill H.R. 387), which was enacted as part of the Consolidated Appropriations Act of 2018, eliminating the
180-day distinction and requiring warrants for all stored email contents.
Title III of the ECPA, codified separately as the Pen Register and
Trap and Trace Statute, governs the collection of dialing, routing,
addressing, and signaling information in real time. Section 3121
prohibits the installation or use of a pen register or trap and trace device without a court order. The relevant standard is significantly lower than that required for content interception: the government must certify that the information likely to be obtained is relevant to an ongoing criminal investigation. No showing of probable cause is required.
A pen register records the numbers dialed from a telephone or the addressing information associated with communications from a computer,
while a trap and trace device captures the numbers of incoming calls or the originating addressing information. In the internet context, these devices can capture IP addresses, email headers, URLs visited, and other metadata that, while technically non-content, can reveal highly sensitive information about a user's activities and associations. The expansion of metadata collection capabilities in the digital era has intensified debates about whether the statute's lower evidentiary threshold remains appropriate.
The ECPA has been widely criticized as technologically outdated. The
180-day rule in the SCA, which distinguished between recent and older stored communications based on an assumption that old messages would be routinely deleted, was rendered anachronistic by the advent of unlimited cloud storage. The Act's terminology—including references to "electronic communication," "electronic storage," and "remote computing service"—does not map cleanly onto modern cloud computing architectures,
social media platforms, and internet-of-things devices. Although the
Email Privacy Act of 2018 addressed the most glaring deficiency,
comprehensive reform of the ECPA remains an ongoing legislative priority, with proposals including updating definitions, clarifying the legal framework for geolocation data, and establishing a unified warrant standard for all digital content regardless of storage duration.
The Children's Online Privacy Protection Act, enacted in 1998 and implemented by the Federal Trade Commission's COPPA Rule at 16 C.F.R.
Part 312, regulates the online collection of personal information from children under the age of 13. The statute applies to operators of websites and online services that are either directed to children or that have actual knowledge that they collect personal information from children. "Personal information" under the statute encompasses a broad range of data, including name, address, online contact information,
telephone number, Social Security number, geolocation information sufficient to identify a street address, photographs, video and audio recordings, persistent identifiers used for behavioral advertising, and,
as of the 2025 amendments, biometric identifiers.
COPPA requires operators to obtain verifiable parental consent before collecting, using, or disclosing personal information from children. The
COPPA Rule specifies several acceptable methods for obtaining verifiable parental consent, including signed consent forms returned by mail or fax, credit card or debit card transactions, calling a toll-free telephone number staffed by trained personnel, digital signatures using public key technology, email accompanied by a PIN or password obtained through a multi-step consent process, and, under certain conditions, the
"sliding scale" method that permits less rigorous consent mechanisms where only internal use of the information is contemplated.
Operators must also provide parents with direct notice of their information practices, including the types of personal information collected, how the information will be used, and the operator's disclosure practices. Parents must be given the opportunity to review the information collected from their children, to request its deletion,
and to refuse to permit further collection or use. The FTC has emphasized that operators bear the burden of ensuring that any third-party services integrated into their platforms—such as advertising networks, analytics providers, and social media plug-ins—comply with
COPPA's requirements.
In January 2025, the FTC finalized significant amendments to the
COPPA Rule, reflecting the dramatic evolution of children's digital environments since the prior major revision in 2013. The 2025 amendments introduce several notable changes:
Expanded Biometric Identifiers. The amended Rule explicitly includes biometric identifiers within the definition of personal information,
encompassing fingerprints, retina and iris patterns, voiceprints, DNA
sequence, facial geometry templates, and gait patterns. Operators targeting children must now treat all such data as subject to COPPA's parental consent and data protection requirements.
Separate Consent for Non-Integral Disclosures. The amendments require operators to obtain separate, affirmative parental consent before disclosing personal information collected from children to third parties for purposes that are not integral to the service provided. This requirement closes a significant gap in the prior Rule, which permitted operators to rely on a single consent for both collection and disclosure. The new approach recognizes the heightened privacy risks associated with secondary data sharing and empowers parents to make granular decisions about their children's data.
Mandatory Written Information Security Program. The 2025 amendments require operators to establish, implement, and maintain a comprehensive written information security program. The program must include administrative, technical, and physical safeguards appropriate to the nature and sensitivity of the personal information collected, the size and complexity of the operator's business, and the nature of the operator's activities. This requirement aligns COPPA with emerging data security obligations under other federal and state privacy laws and reflects the FTC's recognition that privacy cannot be meaningfully protected without robust security measures.
Data Retention Policy Requirements. Operators must now implement and maintain a written data retention policy that specifies the criteria for determining the period for which personal information collected from children will be retained. The policy must require the deletion of personal information when it is no longer necessary for the purpose for which it was collected, and operators must establish and enforce procedures for responding to parental deletion requests within a specified timeframe.
These amendments represent the most comprehensive update to COPPA
since its enactment and signal the FTC's intention to strengthen protections for children in an era of ubiquitous data collection,
artificial intelligence, and immersive digital environments.
The Health Insurance Portability and Accountability Act of 1996,
implemented through regulations at 45 CFR Parts 160 and 164, establishes the federal framework for protecting the privacy, security, and integrity of individually identifiable health information. Administered by the Department of Health and Human Services (HHS) Office for Civil
Rights, HIPAA's regulatory framework consists of three principal rules:
the Privacy Rule, the Security Rule, and the Breach Notification
Rule.
The Privacy Rule, codified at 45 CFR Part 164, Subparts A and E,
establishes national standards for the protection of individually identifiable health information, known as protected health information
(PHI). PHI is defined broadly to include any individually identifiable health information held or transmitted by a covered entity or its business associates, in any form or medium—whether electronic, paper, or oral. Covered entities include health plans, healthcare clearinghouses,
and healthcare providers that transmit health information electronically in connection with covered transactions.
The Privacy Rule requires covered entities to provide patients with a
Notice of Privacy Practices describing how PHI may be used and disclosed. Uses and disclosures of PHI are generally prohibited unless the patient provides authorization or a specific regulatory exception applies. Key exceptions include uses and disclosures for treatment,
payment, and healthcare operations; disclosures required by law;
disclosures for public health activities; and disclosures to the individual who is the subject of the information.
The Security Rule, codified at 45 CFR Part 164, Subpart C,
establishes standards for the protection of electronic protected health information (ePHI). The Rule requires covered entities and their business associates to implement administrative safeguards (policies and procedures), physical safeguards (facility access controls and workstation security), and technical safeguards (access controls, audit controls, encryption, and integrity controls). The Security Rule adopts a flexible, scalable approach, requiring entities to assess their own risk environments and implement protections that are reasonable and appropriate in light of the size, complexity, and capabilities of the entity.
The Breach Notification Rule, codified at 45 CFR Parts 164.400-414,
requires covered entities to notify affected individuals, HHS, and, in some cases, the media following the discovery of a breach of unsecured
PHI. A breach is defined as the unauthorized acquisition, access, use,
or disclosure of PHI that compromises the security or privacy of the information. Notification to affected individuals must occur without unreasonable delay and no later than 60 calendar days after discovery.
Breaches affecting 500 or more individuals must be reported to HHS and prominent media outlets; smaller breaches are reported to HHS
annually.
In 2025, HHS issued proposed amendments to the HIPAA Security Rule that would represent the most significant update to the regulation since its initial adoption in 2003. Key proposals include:
Mandatory Encryption. The proposed rule would eliminate the current
"addressable" status of encryption, making it a required safeguard for all ePHI both at rest and in transit. The current framework permits covered entities to implement encryption or document an alternative measure that achieves the equivalent level of protection; the proposed amendment would remove this discretion and mandate encryption as a minimum standard.
Annual Security Audits. The proposed amendments would require covered entities and business associates to conduct annual security audits performed by qualified independent assessors. These audits would evaluate the entity's compliance with all Security Rule standards and implementation specifications and would be required to be documented and retained for a specified period.
Enhanced Risk Assessment Requirements. The proposal significantly strengthens the risk analysis requirement, mandating a more structured and comprehensive approach that includes identification of all systems and data flows containing ePHI, evaluation of threats and vulnerabilities specific to each system, documentation of the likelihood and impact of potential risks, and implementation of a risk management plan that prioritizes remediation based on severity.
Additional proposals include mandatory multifactor authentication,
expanded requirements for vendor and business associate agreements, and the establishment of a formal patch management program with defined timelines for applying critical security updates.
The Gramm-Leach-Bliley Act, also known as the Financial Services
Modernization Act of 1999, establishes the federal framework for privacy and data security in the financial services sector. Title V of the GLBA,
codified at 15 U.S.C. §§ 6801-6809, imposes obligations on financial institutions regarding the collection, use, and protection of consumers'
personal financial information.
The GLBA's Privacy Rule, implemented at 12 C.F.R. Part 216 (for banking agencies) and 16 C.F.R. Part 313 (for the FTC), requires financial institutions to provide customers with clear and conspicuous initial and annual privacy notices describing their information-sharing practices. The notices must inform consumers of the categories of nonpublic personal information collected, the categories of parties to whom the information is disclosed, and the policies regarding the sharing of such information with both affiliated and nonaffiliated third parties.
The GLBA establishes an opt-out right for consumers, permitting them to direct financial institutions not to share their nonpublic personal information with nonaffiliated third parties for purposes other than those necessary to effect, administer, or enforce a transaction authorized by the consumer. Financial institutions must provide a reasonable opportunity for consumers to exercise this opt-out right,
typically through a mailed response form, toll-free telephone number, or electronic mechanism.
The Safeguards Rule, codified at 16 C.F.R. Part 314, requires financial institutions to develop, implement, and maintain a comprehensive information security program. The program must include designated personnel responsible for information security, a risk assessment identifying foreseeable internal and external threats,
safeguards to control identified risks, regular testing and monitoring of safeguards, service provider oversight, and procedures for evaluating and adjusting the program in response to changes in technology, the sensitivity of customer information, and internal or external threats to information security. The FTC significantly updated the Safeguards Rule in 2021, adding specific requirements including encryption, multifactor authentication, access controls, and incident response planning.
The GLBA also includes provisions at § 6802(b) permitting sharing of information among financial institutions' affiliated entities, provided that consumers are given notice and an opportunity to opt out. This affiliate sharing provision has been the subject of ongoing policy debate, with consumer advocates arguing that it undermines the Act's privacy protections by permitting data sharing within corporate conglomerates without meaningful consumer control.
The Family Educational Rights and Privacy Act, enacted in 1974,
protects the privacy of student education records. FERPA applies to all educational agencies and institutions that receive federal funding under any program administered by the Department of Education. The statute grants parents of students under 18 and eligible students (those over 18
or attending postsecondary institutions) the right to inspect and review education records maintained by the school, to request amendment of inaccurate records, and to consent to the disclosure of personally identifiable information from education records, with specified exceptions.
Key exceptions to the consent requirement include disclosures to school officials with legitimate educational interests, disclosures to other schools where the student seeks to enroll, disclosures to authorized representatives for audit or evaluation purposes, and disclosures in connection with financial aid for which the student has applied. FERPA also permits the disclosure of directory information—such as name, address, telephone number, date and place of birth, honors and awards, and dates of attendance—provided that the institution gives public notice of the categories of information it designates as directory information and allows students a reasonable period to restrict such disclosure. In the digital era, the proliferation of educational technology platforms, learning management systems, and third-party analytics tools has raised significant FERPA compliance questions regarding the classification of digital records as education records and the scope of the "school official" exception when third-party technology vendors are involved.
The Video Privacy Protection Act, enacted in 1988 in response to the disclosure of Supreme Court nominee Robert Bork's video rental records,
protects personally identifiable information relating to consumers'
video rental or sale records. The VPPA prohibits "video tape service providers" from disclosing personally identifiable rental information to any person without the informed, written consent of the consumer. The statute provides a private right of action, allowing consumers to recover actual damages, statutory damages of $2,500, and punitive damages.
The scope of the VPPA has been the subject of significant litigation,
particularly in the context of digital streaming services. In United
States v. West, the Northern District of California held that streaming video is not a "video tape" and streaming services are not "video tape service providers," a position subsequently adopted by other courts.
However, Congress amended the VPPA in 2012 to specifically extend its protections to personally identifiable information of consumers of
"video streaming services," while also clarifying that the consent requirement does not apply to disclosures to third parties for the purpose of performing services on behalf of the provider. Courts have continued to grapple with the application of the VPPA to social media platforms that host video content, data sharing between streaming services and advertisers, and the definition of "personally identifiable information" in the context of anonymized viewing data.
Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45(a),
authorizes the FTC to prevent "unfair methods of competition" and
"unfair or deceptive acts or practices in or affecting commerce." While not a sector-specific privacy or cybersecurity statute, Section 5 has emerged as the most broadly applicable federal consumer protection tool in the digital economy. The FTC has used its Section 5 authority to bring enforcement actions against companies for inadequate data security practices, misleading privacy representations, failure to honor do-not-track signals, deceptive marketing of mobile applications, and violations of self-regulatory privacy frameworks.
The FTC's approach to privacy and data security enforcement is grounded in its 2012 "Protecting Consumer Privacy in an Era of Rapid
Change" report and its 2023 Policy Statement on privacy. The
Commission's privacy framework rests on three core principles: (1)
companies should provide consumers with clear, prominent, and accessible privacy disclosures; (2) companies should offer consumers meaningful choices about the collection, use, and sharing of their personal information; and (3) companies should implement reasonable data security measures appropriate to the sensitivity of the information collected and the nature of the business.
In 2023, the FTC announced a comprehensive update to its approach,
signaling its intention to pursue aggressive enforcement against companies that engage in surveillance practices that are disproportionate to the benefits provided to consumers, that engage in indiscriminate data harvesting, or that combine data in ways that are not reasonably anticipated by consumers. The FTC's Health Breach
Notification Rule, implemented under Section 5 authority, extends breach notification requirements to health applications and connected devices that are not covered by HIPAA, creating an important complementary enforcement mechanism in the digital health space.
The Controlling the Assault of Non-Solicited Pornography and
Marketing (CAN-SPAM) Act of 2003 establishes national standards for the sending of commercial email messages. The Act does not prohibit commercial email outright but imposes a set of requirements that senders must satisfy. These include prohibitions on false or misleading header information and deceptive subject lines, requirements that commercial emails include a functioning return email address, a physical postal address of the sender, and a clear and conspicuous mechanism for recipients to opt out of future messages.
The CAN-SPAM Act preempts state laws that impose additional requirements on the sending of commercial email, but it preserves state laws that address fraud or computer crime. The Act authorizes enforcement by the FTC, other designated federal agencies, state attorneys general, and internet service providers through a private right of action. Criminal penalties, including imprisonment, may be imposed for aggravated violations involving fraudulent header information, registration of multiple email accounts using false information, or relaying email through multiple computers to disguise its origin.
Critics of the CAN-SPAM Act have argued that its opt-out (rather than opt-in) framework is insufficiently protective, that its preemption of state consumer protection laws weakens overall protections, and that its enforcement has been inadequate relative to the volume of unsolicited commercial email. Despite these criticisms, the Act remains the primary federal statute governing commercial email practices.
The Telephone Consumer Protection Act of 1991, codified at 47 U.S.C.
§ 227, restricts the use of automatic telephone dialing systems
(autodialers), artificial or prerecorded voice messages, and fax machines. The TCPA's central consent requirement, at § 227(b)(1)(A),
prohibits the use of autodialers or prerecorded voice messages to call any cellular telephone number or any service for which the called party is charged, without the prior express consent of the called party. The
TCPA provides a private right of action with statutory damages of $500
per violation (trebled to $1,500 for willful or knowing violations),
making it one of the most potent consumer protection statutes in terms of potential liability exposure.
The TCPA distinguishes between two levels of consent. "Prior express consent" is required for non-telemarketing calls and texts made using an autodialer or prerecorded voice. "Prior express written consent" is required for telemarketing calls and texts to cellular numbers, with the consent agreement clearly and conspicuously disclosing that the consumer authorizes the caller to deliver telemarketing calls using an autodialer or prerecorded voice. The Federal Communications Commission (FCC) has defined "prior express consent" as consent that is given before the call or text is initiated, and has interpreted the requirement to apply to calls and texts to any number that has been reassigned to a new subscriber.
Two significant regulatory developments in 2025 have reshaped the
TCPA compliance landscape:
Eleventh Circuit Strikes the One-to-One Consent Rule. In January
2025, the U.S. Court of Appeals for the Eleventh Circuit, in Insurance
Marketing Alliance v. FCC, invalidated the FCC's One-to-One Consent
Rule, which had required that prior express written consent be obtained separately for each individual seller identified in a telemarketing call. The court held that the FCC exceeded its statutory authority under the TCPA by imposing consent requirements more stringent than those established by Congress. The decision created a circuit split with the
Ninth Circuit, which had upheld the rule, and generated significant uncertainty regarding the appropriate consent standard for lead-generation activities, where a single consumer inquiry may trigger calls from multiple sellers.
FCC Opt-Out Rule Effective April 2025. In April 2025, the FCC's revised Opt-Out Rule took effect, establishing new requirements for the
"do not call" framework applicable to telemarketing calls. The rule requires that callers provide a clear and conspicuous mechanism for consumers to opt out of future calls during each telemarketing call, and mandates that the opt-out request be honored immediately—within the same calling campaign and across all sellers on whose behalf the call was made. The rule also expanded the definition of "telemarketing" to encompass certain types of text messages and imposes enhanced recordkeeping requirements on callers.
These 2025 developments have created significant compliance challenges for businesses that rely on outbound calling and texting,
particularly in the lead generation, financial services, and healthcare industries, where the scope of permissible consent and the requirements for honoring opt-out requests remain subject to ongoing litigation and regulatory uncertainty.
In 2025, the Department of Justice (DOJ) promulgated the Data
Security Program regulations at 28 C.F.R. Part 202, implementing
Executive Order 14117 on "Preventing Access to Americans' Bulk Sensitive
Personal Data and United States Government-Related Data by Countries of
Concern." This first-of-its-kind regulatory framework establishes national security-based restrictions on the transfer and access of
Americans' sensitive personal data by entities subject to the jurisdiction or control of specified foreign adversaries. The program represents a fundamental departure from the United States' historically sector-specific and voluntary approach to data protection, establishing a national security data governance regime comparable in ambition,
though not in structure, to the European Union's General Data Protection
Regulation.
The regulations designate six countries as "countries of concern":
the People's Republic of China (including Hong Kong and Macau), the
Russian Federation, the Islamic Republic of Iran, the Democratic
People's Republic of Korea, the Republic of Cuba, and the Bolivarian
Republic of Venezuela. Entities organized under the laws of these countries, entities with a principal place of business in these countries, and persons domiciled in these countries are subject to the regulations' restrictions. The regulations also extend to entities that are 50 percent or more owned, whether directly or indirectly, by a country of concern or by one of its covered persons.
The regulations define a broad set of "restricted data categories"
that are subject to transfer limitations. These include:
Identified Persons Data: Precise geolocation data, biometric identifiers, genetic data, health data, personal financial data, and data concerning individuals' employment or familial relationships, when linked to identifiers that can be used to identify specific U.S.
persons.
United States Government-Related Data: Data concerning U.S. military or intelligence personnel, data relating to government facilities and critical infrastructure, data concerning government procurements and contracts, and data relating to government employee travel and movements.
Bulk Sensitive Personal Data: Any dataset of sensitive personal information concerning 100 or more U.S. persons, or data concerning
1,000 or more U.S. persons derived from publicly available sources, when aggregated in a manner that creates national security risks.
The regulations prohibit or restrict several categories of data transactions between covered persons and countries of concern.
Prohibited transactions include bulk transfers of human genomic data,
data brokerage transactions involving restricted data categories, and agreements that provide countries of concern with access to restricted data through vendor agreements, employment agreements, or investment agreements. Restricted transactions, which are subject to a licensing requirement rather than outright prohibition, include certain employment arrangements, certain investment activities, and certain agreements that involve access to restricted data but do not constitute outright transfers.
The enforcement mechanism for violations of the Data Security Program is robust and multi-faceted. Civil penalties may reach up to twice the value of the restricted transaction, providing a deterrent mechanism proportionate to the scale of the violation. Criminal penalties include fines of up to $1,000,000 and imprisonment of up to 20 years for willful violations that endanger national security. The DOJ's authority to impose civil money penalties is supplemented by the Attorney General's authority to seek injunctive relief in federal court to enjoin ongoing or imminent violations.
The Data Security Program has generated significant compliance challenges for the U.S. business community. The breadth of the restricted data categories and the ambiguity of key terms—including
"covered person," "access," and "bulk"—have created uncertainty regarding the scope of covered transactions. The regulations'
extraterritorial reach, which applies to any entity that facilitates or enables a prohibited transaction regardless of where the entity is located, raises questions about their compatibility with the data protection laws of U.S. allies and trading partners.
At the time of promulgation, substantial guidance gaps remain. The
DOJ has indicated that it will issue implementing regulations,
interpretive guidance, and a licensing framework in phases, but the absence of comprehensive compliance guidance at the time the regulations became effective has placed significant burden on affected companies to develop compliance programs in an environment of legal uncertainty.
Industry groups have called for safe harbors, de minimis thresholds, and a formal consultation process to resolve compliance questions before enforcement actions are initiated. The program's ultimate effectiveness will depend significantly on the quality and timeliness of the implementing guidance, the consistency of enforcement, and the resolution of inevitable jurisdictional conflicts with other nations'
data protection regimes.

# Chapter 17: Section 230 — 47 U.S.C. § 230

Section 230 of the Communications Act of 1934, as added by Section
509 of the Telecommunications Act of 1996 and codified at 47 U.S.C. §
230, is widely regarded as the most consequential legal provision shaping the modern internet. The provision emerged from two cases in the early 1990s that exposed the liability exposure faced by online platforms: Cubby, Inc. v. CompuServe Inc., 776 F. Supp. 135 (S.D.N.Y.
1991), which held that CompuServe was not liable for defamatory content posted by third parties because it exercised no editorial control, and
Stratton Oakmont, Inc. v. Prodigy Services Co., 1995 WL 323710 (N.Y.
Sup. Ct. 1995), which reached the opposite conclusion on the grounds that Prodigy's content moderation efforts made it a "publisher."
Congress recognized that the Stratton Oakmont decision created a perverse incentive: platforms that attempted to moderate content to remove offensive material would be treated as publishers and held liable for content they failed to remove, while platforms that took a completely hands-off approach would enjoy immunity. This "moderator's dilemma" threatened to stifle the development of the internet by discouraging platforms from investing in content moderation tools and policies.
Congress addressed this problem through Section 230, which was introduced by Representatives Chris Cox (R-CA) and Ron Wyden (D-OR) as part of the broader Communications Decency Act of 1996. The findings and policy statement at § 230(a)(1)-(3) declared:
(1) The rapidly developing array of Internet and other interactive computer services, the availability of educational resources to homes and schools, and the growing ease with which people can access the
Internet for commercial and other purposes have brought tremendous benefits to American commerce, education, and society as a whole;
(2) These services offer consumers a great degree of control over the information they receive, as well as the potential for even greater control in the future as technology develops;
(3) The Internet and other interactive computer services offer a forum for a true diversity of political discourse, unique opportunities for cultural development, and a myriad of avenues for intellectual activity.
Congress further found at § 230(b)(4) that "the Internet has flourished, to the benefit of all Americans, with a minimum of government regulation," and that federal policy should therefore
"preserve the vibrant and competitive free market that presently exists for the Internet and other interactive computer services, unfettered by
Federal or State regulation."
Section 230(c)(1) provides the core immunity: "No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider." The terms of this provision have been the subject of extensive judicial interpretation:
Interactive Computer Service. Defined at § 230(f)(2) as "any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server." This definition has been interpreted broadly to encompass social media platforms, search engines, email providers, review websites, discussion forums, and virtually any online service that facilitates user-generated content.
Information Content Provider. Defined at § 230(f)(3) as "any person or entity that is responsible, in whole or in part, for the creation or development of information provided through the Internet or any other interactive computer service." This definition excludes platforms from liability for content created by their users, while preserving liability for content that the platform itself creates.
Publisher or Speaker. The immunity shields platforms from liability that would attach to a "publisher or speaker," which includes defamation, invasion of privacy, and other torts based on the communicative content. Courts have consistently held that the immunity is broad, precluding state-law tort claims, intellectual property claims
(except as expressly provided in § 230(e)(2)), and certain federal statutory claims. Notably, § 230(e)(2) preserves intellectual property claims, providing that the immunity "shall not be construed to limit or expand any law pertaining to intellectual property," which has been interpreted to bar Section 230 immunity from copyright infringement claims.
Section 230(c)(2) complements the immunity provision by providing a
"Good Samaritan" safe harbor for content moderation activities:
No provider or user of an interactive computer service shall be held liable on account of— (2) any action taken to enable or make available to information content providers or others the technical means to restrict access to material described in paragraph (1).
The categories of objectionable content referenced in (c)(2)(A)
include material that the provider or user "considers to be obscene,
lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable." The use of the word "considers" has been interpreted to mean that the Good Samaritan provision protects content moderation decisions regardless of whether the moderated content actually falls within any of these categories. This subjective standard grants platforms wide discretion in establishing and enforcing their community standards and content moderation policies, protecting them from liability for both over-inclusive and under-inclusive moderation.
The Good Samaritan provision addresses the moderator's dilemma identified in Stratton Oakmont by ensuring that platforms can engage in content moderation without incurring publisher liability. This provision has been critical to the development of sophisticated content moderation systems that employ a combination of automated detection tools and human review.
In Reno v. American Civil Liberties Union, 521 U.S. 844 (1997), the
Supreme Court struck down the anti-indecency provisions of the
Communications Decency Act as violating the First Amendment. While this decision addressed provisions other than Section 230, it established the constitutional framework within which internet speech is analyzed. The
Court recognized that the internet is entitled to the highest level of
First Amendment protection and that content-based restrictions on speech must survive strict scrutiny. Reno implicitly validated Congress's judgment that the internet should remain largely unregulated,
reinforcing the policy rationale underlying Section 230.
In Gonzalez v. Google LLC, 598 U.S. 417 (2023), the Supreme Court addressed the scope of Section 230 immunity in the context of algorithmic content recommendation. The case arose from the estate of
Nohemi Gonzalez, a victim of the 2015 Paris terrorist attacks, who alleged that Google's YouTube platform's recommendation algorithm promoted ISIS-related videos to users, thereby facilitating radicalization and recruitment.
The Court declined to address the substantive question of whether algorithmic recommendations constitute "publisher" conduct covered by
Section 230(c)(1). Writing for a unanimous Court, Justice Thomas determined that the plaintiff's complaint did not plausibly allege that
YouTube's algorithmic recommendations constituted "aiding and abetting"
terrorism under the Antiterrorism Act, and therefore the Court had no occasion to reach the Section 230 question. The Court noted, however,
that "Section 230(c)(1) shields an interactive computer service from liability for its own expression, but not for the expression of others,"
and that the parties' arguments raised "novel and difficult" questions about the boundaries of the immunity.
The Gonzalez decision was notable for what it did not decide: it left unresolved the critical question of whether platforms that use algorithms to curate, rank, and recommend user-generated content are engaged in "publishing" conduct that falls within Section 230's immunity. This unresolved question has continued to generate intense debate among scholars, practitioners, and policymakers.
In 2024, the Supreme Court decided NetChoice, LLC v. Paxton, 603 U.S.
942 (2024), and Moody v. NetChoice, LLC, 603 U.S. 943 (2024), which together addressed the constitutionality of state laws in Texas and
Florida that restricted platforms' content moderation decisions. While these cases were decided primarily on First Amendment grounds rather than Section 230, they have significant implications for the platform immunity framework.
The Texas law, HB 20, prohibited large social media platforms from removing content based on the "viewpoint" of the user, while the Florida law, SB 7072, imposed similar restrictions and additional transparency requirements. The Supreme Court vacated the Fifth Circuit's upholding of
HB 20 and remanded both cases for further proceedings, holding that the lower courts had not properly applied the correct First Amendment analysis. The Court suggested that content moderation decisions by platforms constitute First Amendment-protected editorial judgment, but left for remand the question of whether the specific provisions of these laws were unconstitutional in their entirety or only as applied.
These decisions reinforced the principle that platforms have First
Amendment rights of their own, which coexist with—and complicate—any effort to narrow Section 230 immunity through legislation. A state law that effectively compels platforms to carry content they would otherwise remove could face First Amendment challenge, even if Section 230's immunity were simultaneously narrowed.
Texas House Bill 20, enacted in 2021, prohibits social media platforms with more than 50 million monthly active users from censoring users' expression based on viewpoint. The law creates a private right of action for users whose content is removed, and authorizes the Texas
Attorney General to bring enforcement actions. The law was upheld by the
Fifth Circuit in NetChoice v. Paxton, 49 F.4th 439 (5th Cir. 2022),
which held that the platforms' content moderation decisions did not constitute protected First Amendment speech and that the law was a permissible regulation of common carriers. The Supreme Court's subsequent decision vacating this ruling on First Amendment grounds leaves the law's viability uncertain, pending further proceedings.
Florida Senate Bill 7072, enacted in 2021, imposes a range of obligations on large social media platforms, including a prohibition on deplatforming political candidates, a requirement to provide individualized explanations for content moderation decisions, and a
"must-carry" obligation for content from journalistic enterprises. The
Eleventh Circuit invalidated most of the law's provisions in NetChoice v. Moody, 34 F.4th 1196 (11th Cir. 2022), holding that the law violated the platforms' First Amendment rights by compelling them to publish speech they would otherwise choose to exclude. The Supreme Court's remand in Moody v. NetChoice requires further consideration of the law's specific provisions under the correct constitutional standard.
These state-level efforts represent a broader strategy to regulate platform behavior by circumventing Section 230 through common carrier designations, antitrust frameworks, and consumer protection statutes.
Other states, including California, New York, and Ohio, have considered or enacted legislation targeting platform transparency, algorithmic accountability, and user data portability, each raising distinct questions about the preemption of state regulation by Section 230 and the First Amendment.
The current debate over Section 230 reflects a fundamental tension between the values that the provision was designed to promote and the consequences of its application in the contemporary internet ecosystem.
Proponents of the current framework argue that Section 230 has been indispensable to the development of the internet as a platform for free expression, innovation, and economic growth. The provision's supporters contend that:
Section 230 enables platforms to host massive volumes of user-generated content without facing crippling litigation costs.
Without immunity, platforms would be forced to pre-screen all content before publication, imposing costs and delays that would fundamentally alter the nature of online communication.
The immunity incentivizes investment in content moderation. By removing the threat of publisher liability, Section 230 encourages platforms to experiment with new moderation tools and policies. The Good
Samaritan provision specifically protects platforms that take proactive steps to address harmful content.
Narrowing immunity would disproportionately harm smaller platforms.
Large technology companies have the resources to absorb litigation costs and negotiate liability insurance; startups and smaller platforms do not. Reform that imposes liability for user content would entrench existing incumbents and reduce competition.
Section 230 supports democratic discourse. By providing a safe harbor for the hosting of diverse viewpoints, including controversial and unpopular ones, the provision has facilitated the internet's role as the most significant forum for public discourse in history.
Existing legal frameworks provide adequate remedies for harmful content. Victims of illegal content can pursue claims against the actual authors of harmful content, and law enforcement agencies have tools to address criminal activity. Section 230 does not prevent prosecution of the underlying illegal conduct.
Critics of the current framework argue that Section 230's broad immunity has created perverse incentives that undermine public safety,
democratic discourse, and individual rights. Reform advocates contend that:
Platforms have become gatekeepers of public discourse and should bear corresponding responsibility. The major social media platforms exercise editorial judgment through their algorithms and content moderation policies, and their decisions have profound effects on public discourse,
public health, and democratic processes. Treating them as neutral conduits that merely host others' content ignores the reality of their operations.
Immunity has incentivized platforms to prioritize engagement over safety. Because platforms face no liability for the consequences of harmful content on their services, they have financial incentives to promote content that drives user engagement, regardless of its accuracy or potential for harm. This incentive structure has been implicated in the spread of misinformation, online radicalization, and public health threats.
The immunity is broader than necessary to achieve its stated purpose.
Congress intended Section 230 to address the moderator's dilemma, but courts have interpreted it to provide near-absolute immunity from virtually all state-law claims arising from user-generated content, far exceeding the scope necessary to protect platforms' content moderation decisions.
Current enforcement mechanisms are inadequate. Existing avenues for addressing harmful online content—including claims against individual content creators and criminal prosecution—have proven insufficient to address the scale and speed of online harm. The private right of action against individual speakers is often practically unenforceable when speakers are anonymous, located abroad, or judgment-proof.
Section 230 creates a market failure in safety investment. The absence of liability means that platforms have no legal incentive to invest in safety measures beyond what is necessary to protect their brand reputation. Empirical evidence suggests that platforms underinvest in trust and safety relative to the social costs of harmful content.
As of early 2025, Section 230 reform remains one of the most actively debated topics in technology policy, with numerous legislative proposals at various stages of consideration. Several key trends and proposals merit attention:
Targeted Reform Approaches. Recent legislative proposals have moved away from wholesale repeal of Section 230 toward targeted reforms that would narrow immunity for specific categories of harmful content or conduct. Proposals under consideration include conditioning immunity on platforms' compliance with specified content moderation practices,
requiring platforms to provide transparency reports regarding their moderation decisions, narrowing immunity for content involving illegal activity, and creating carve-outs for categories of content such as child sexual abuse material (CSAM), terrorism-related content, and content that contributes to public health harms.
Algorithmic Accountability and Transparency. Building on the questions left unresolved in Gonzalez, several proposals would condition
Section 230 immunity on platforms' disclosure of how their algorithms rank, promote, and demote content. These proposals reflect a growing consensus that the distinction between "publishing" and "hosting"
content has become artificial in the context of algorithmically curated platforms, where the platform's editorial judgment is embedded in the technology that determines what users see.
Executive Action. The executive branch has pursued Section 230 reform through regulatory and procurement channels. Executive Order 13925,
signed in 2020, directed the Secretary of Commerce to file a petition with the FCC requesting rulemaking to clarify the scope of Section 230.
While the FCC's subsequent rulemaking proceedings generated substantial public comment, the legal authority of the FCC to reinterpret Section
230—a provision of the Communications Act that the Commission has historically treated as a policy statement rather than a regulatory mandate—remains contested.
Judicial Evolution. Lower courts continue to refine the boundaries of
Section 230 immunity. Several recent decisions have carved out exceptions in cases involving platforms that are alleged to have materially contributed to the development of allegedly unlawful content,
or where the platform's conduct is characterized as the creation of new content rather than the republication of existing third-party content.
The Supreme Court's decisions in Gonzalez and NetChoice have created an environment of legal uncertainty that may itself spur legislative action to clarify the statute's scope.
International Harmonization Pressures. As the European Union's
Digital Services Act (DSA), the United Kingdom's Online Safety Act, and similar regulatory frameworks in other jurisdictions impose increasingly detailed obligations on platforms regarding content moderation,
transparency, and user safety, pressure is mounting for the United
States to adopt a more comprehensive regulatory approach. The contrast between the EU's prescriptive regulatory model and the United States'
immunity-based approach creates compliance challenges for global platforms and raises questions about the adequacy of Section 230 as a standalone framework for governing online content in the modern era.
The trajectory of Section 230 reform will likely be shaped by several factors: the outcome of ongoing litigation challenging the scope of the immunity, the political dynamics of divided government, the evolution of platform business models in response to competitive pressures, and the growing body of empirical evidence regarding the societal impacts of platform-mediated discourse. While wholesale repeal remains unlikely,
incremental reforms that narrow the immunity for specific categories of content, condition immunity on transparency and accountability obligations, or establish new enforcement mechanisms for platform harms appear increasingly probable. The fundamental question facing policymakers is not whether Section 230 should be reformed, but how to calibrate reforms that address legitimate concerns about platform power and online harm without undermining the values of free expression,
innovation, and an open internet that Section 230 was designed to protect.

# Chapter 18: State Comprehensive Privacy Laws

The California Consumer Privacy Act (CCPA) was signed into law on
June 28, 2018, and took effect on January 1, 2020, making it the most comprehensive state privacy law in the United States. The California
Privacy Rights Act (CPRA), a ballot initiative passed by California voters on November 3, 2020, substantially amended and expanded the CCPA,
with most provisions taking effect on January 1, 2023.
Together, the CCPA/CPRA establishes a comprehensive framework for the protection of consumer personal information in California, applying to for-profit businesses that collect personal information from California residents and meet at least one of the following thresholds:
Annual gross revenue exceeding $25 million.
Buying, selling, or sharing the personal information of 100,000 or more consumers or households annually.
Deriving 50% or more of annual revenue from selling or sharing consumers' personal information.
The CCPA/CPRA grants California consumers the following rights:
Right to know: The right to request that a business disclose the personal information it has collected, used, disclosed, and sold about the consumer in the preceding 12 months.
Right to delete: The right to request deletion of personal information collected from the consumer.
Right to correct: The right to request correction of inaccurate personal information (introduced by CPRA).
Right to opt-out of sale/sharing: The right to opt out of the sale or sharing of personal information. Businesses must provide a "Do Not Sell or Share My Personal Information" link on their homepage.
Right to limit use of sensitive personal information: The right to limit the use and disclosure of sensitive personal information to uses necessary to perform services (introduced by CPRA).
Right to non-discrimination: The right not to be discriminated against for exercising privacy rights.
Right to data portability: The right to receive personal information in a portable, readily usable format that allows the consumer to transmit the data to another entity without hindrance.
The CPRA introduced the category of "sensitive personal information,"
which includes:
Social Security number, driver's license, or government ID
numbers.
Financial account information (including login credentials).
Precise geolocation.
Racial or ethnic origin.
Religious or philosophical beliefs.
Union membership.
Contents of mail, email, and text messages (unless the business is the intended recipient).
Genetic data.
Biometric data.
Health information.
Information concerning sex life or sexual orientation.
Consumers have the right to direct businesses to limit the use and disclosure of their sensitive personal information.
The CPRA requires businesses that meet the CPRA's applicability thresholds and conduct high-risk processing activities to:
Submit an annual cybersecurity audit to the California Privacy
Protection Agency (CPPA), starting in 2028.
Conduct regular cybersecurity risk assessments and maintain documentation sufficient to demonstrate compliance.
Businesses must conduct risk assessments for processing activities that present significant risk to consumers' privacy or security,
including:
Processing personal information for behavioral advertising.
Selling or sharing personal information.
Processing sensitive personal information.
The risk assessment must identify, evaluate, and mitigate the risks associated with the processing activity.
The CPPA has proposed regulations restricting the use of Automated
Decision-Making Technology (ADMT), including:
Access and opt-out rights for consumers subject to ADMT in decisions that produce legal or similarly significant effects (employment,
housing, credit, education, healthcare, insurance).
Pre-use notice requirements.
Prohibition on profiling in certain contexts involving minors.
California Privacy Protection Agency (CPPA): Established by the CPRA
as an independent agency responsible for enforcing the CCPA/CPRA and issuing implementing regulations.
California Attorney General: Retains concurrent enforcement authority and may seek civil penalties of up to $7,500 per intentional violation and $2,500 per unintentional violation.
Private right of action: Available for data breaches involving the failure to implement and maintain reasonable security procedures
(statutory damages of $100-$750 per consumer per incident).
2024-2025 saw significant enforcement activity:
CPPA enforcement actions: The CPPA initiated investigations into major technology companies for violations of the opt-out requirements,
data minimization obligations, and the use of sensitive personal information for automated decision-making.
Settlements: Notable settlements included Tractor Supply Company
($1.35M), Sling TV ($530K), and various investigations into data broker practices.
Regulatory rulemaking: The CPPA has been actively engaged in rulemaking on ADMT, risk assessments, cybersecurity audits, and automated decision-making, with final regulations expected to be adopted in 2026-2027.
The Virginia Consumer Data Protection Act (VCDPA) took effect on
January 1, 2023. Key features:
Scope: Applies to persons that conduct business in Virginia or produce products/services targeted to Virginia residents and control or process personal data of at least 100,000 consumers or control or process personal data of at least 25,000 consumers and derive over 50%
of gross revenue from the sale of personal data.
Consumer rights: Access, correction, deletion, data portability,
opt-out of targeted advertising/sale/profiling, and appeal of controller decisions.
Sensitive data: Processing of sensitive data requires consent.
Exemptions: Broad exemptions for HIPAA-covered entities, GLBA-covered entities, nonprofit organizations, and government entities.
Enforcement: Virginia Attorney General (no private right of action).
Civil penalties of up to $7,500 per violation.
The Colorado Privacy Act (CPA) took effect on July 1, 2023. Key features:
Scope: Applies to controllers that conduct business in Colorado or target Colorado residents and process personal data of 100,000+
consumers or derive revenue from the sale of personal data and process personal data of 25,000+ consumers.
Consumer rights: Access, correction, deletion, data portability,
opt-out, and appeal.
Universal opt-out: Controllers must recognize and honor universal opt-out signals.
DPIA requirements: Controllers must conduct data protection assessments for high-risk processing.
Enforcement: Colorado Attorney General. Civil penalties of up to
$20,000 per violation.
2024 amendment: Enhanced provisions on the use of personal data for training AI models, requiring notice and opt-out rights for data subjects.
The Connecticut Data Privacy Act (CTDPA) took effect on July 1, 2023.
Key features:
Scope: Similar to VCDPA thresholds.
Consumer rights: Access, correction, deletion, data portability,
opt-out.
Sensitive data: Consent required.
Universal opt-out: Required.
Enforcement: Connecticut Attorney General. Civil penalties up to
$20,000 per violation.
The Utah Consumer Privacy Act (UCPA) took effect on December 31,
2023. Key features:
Scope: Higher threshold — applies to entities processing personal data of 100,000+ consumers (excluding data processed solely for payment transactions).
Consumer rights: Access, deletion, data portability, opt-out (sale and targeted advertising only, not profiling).
Limited scope: The UCPA is the narrowest of the comprehensive state privacy laws, excluding profiling from the opt-out right and not recognizing a right to correct personal information.
Utah AI Policy Act (effective May 2024): Requires disclosure and opt-out rights for consumers subject to generative AI in regulated occupations (healthcare, legal, financial), and imposes liability on deployers for AI-generated content in certain regulated contexts.
The Texas Data Privacy and Security Act (TDPSA) took effect on July
1, 2024. Key features:
Scope: Applies to entities conducting business in Texas that process personal data of 100,000+ consumers or derive revenue from the sale of personal data and process personal data of 25,000+ consumers.
Enforcement: Texas Attorney General. Civil penalties of up to $7,500
per violation.
Significance: Texas, as the second-largest state economy,
significantly expands the reach of US state privacy law.
The Florida Digital Bill of Rights (FDBR) took effect on July 1,
2024. Key features:
Narrower scope: Applies only to entities operating in specific sectors (profit-making entities that collect data concerning individuals, government entities, and large online platforms) and meet higher thresholds.
First enforcement action: Florida v. Roku (October 2025) — the first-ever FDBR enforcement action, involving the collection and sale of children's data.
Enforcement: Florida Attorney General. No private right of action.
The Maryland Online Data Privacy Act (MODPA) was signed into law on
May 9, 2024, with most provisions taking effect on October 1, 2025. Key features:
Scope: Similar to other state laws (100,000 consumers or 25,000
consumers + revenue from data sales).
Enforcement: Maryland Attorney General. Civil penalties up to $10,000
per violation.
Unique features: The MODPA includes specific provisions on data minimization and purpose limitation, reflecting a trend toward GDPR-like principles in US state law.
The following states enacted comprehensive privacy laws in 2024-2025,
with most taking effect in 2025-2027:
Oregon: Oregon Consumer Privacy Act (effective July 2024) — includes specific provisions on health data and data broker regulation.
Montana: Montana Consumer Data Privacy Act (effective October 2024) —
follows the Virginia model with enhanced data minimization requirements.
Indiana: Indiana Data Privacy Act (effective January 2026) — includes a private right of action for data breaches.
Delaware: Delaware Personal Data Privacy Act (effective January 2025)
— includes specific provisions on the processing of children's data.
New Jersey: New Jersey Data Privacy Act (effective January 2025) —
includes enhanced provisions on biometric data and geolocation data.
Minnesota: Minnesota Consumer Data Privacy Act (effective January
2026) — includes specific provisions on algorithmic decision-making and
AI.
New Hampshire: New Hampshire Privacy Act (effective January
2025).
Tennessee: Tennessee Information Protection Act (effective July
2025).
Nebraska: Nebraska Data Privacy Act (effective January 2026) —
includes unique provisions on agricultural data.
As of early 2026, over 20 US states have enacted comprehensive privacy legislation, with additional states considering bills. This patchwork of state laws has increased the complexity of compliance for businesses operating across state lines and has intensified the debate over the need for a federal privacy law.

# Chapter 19: Sectoral State Laws

The Illinois Biometric Information Privacy Act (BIPA), effective
January 1, 2009, is widely regarded as the most consequential state biometric privacy law in the United States. BIPA regulates the collection, use, storage, retention, and disclosure of biometric identifiers and biometric information by private entities in
Illinois.
Biometric identifiers: Include retina or iris scans, fingerprints,
voiceprints, DNA, hand scans, face geometry, and any other identifying characteristic that can be captured and used for identification.
Written release: Private entities must inform individuals in writing of the specific purpose and length of term for which biometric data will be collected, stored, used, and disclosed, and must obtain a written release from the individual.
Prohibition on sale: Private entities may not sell, lease, trade, or otherwise profit from biometric data.
Prohibition on disclosure: Private entities may not disclose biometric data unless the individual consents or the disclosure is required by law.
Retention and destruction: Biometric data must be destroyed when the initial purpose for collection has been satisfied or within three years of the individual's last interaction with the entity, whichever occurs first.
Data security: Private entities must store, transmit, and protect biometric data using a reasonable standard of care, including at least one security protocol (encryption, redaction, or other comparable method).
BIPA provides a private right of action, allowing individuals to sue for violations. This has generated an enormous volume of litigation:
Damages: Individuals may recover liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation,
plus attorney's fees and costs.
Per-scan liability: Some courts have held that each scan constitutes a separate violation, potentially multiplying damages significantly.
Class actions: BIPA has generated hundreds of class action lawsuits,
with total settlement values exceeding $1 billion.
The Illinois legislature has considered but not yet enacted significant amendments to BIPA, including provisions that would:
Limit liability to actual damages in cases where no actual harm was suffered.
Clarify the statute of limitations for BIPA claims.
Establish a safe harbor for entities that obtain written consent and implement reasonable security measures.
As of early 2026, BIPA remains largely unchanged from its original
2008 text, and litigation continues at a high volume.
The My Health My Data Act (MHMDA) was signed into law on March 9,
2023, and took effect on June 30, 2024. Key features:
Scope: Applies to entities that conduct business in Washington or target Washington residents and collect, process, or share consumer health data that is not covered by HIPAA. The MHMDA fills the gap between HIPAA (which covers healthcare providers and insurers) and the general consumer data protection framework.
Health data definition: Broadly defined to include information that identifies a consumer and relates to the consumer's past, present, or future physical or mental health status, including reproductive health data, mental health data, fitness data, biometric data, and genetic data.
Consent requirement: Prior affirmative consent is required before the collection, processing, or sharing of consumer health data. Consent must be specific and may be withdrawn at any time.
Private right of action: A unique feature of the MHMDA, providing individuals with a private right of action for violations. Statutory damages of $100-$750 per consumer per incident, plus attorney's fees.
First lawsuit (February 2025): An Ad SDK class action tested the scope of the MHMDA's private right of action in the context of mobile advertising technology collecting health-adjacent location data.
Significance: The MHMDA is particularly significant in the post-Roe v. Wade landscape, as it provides protection for reproductive health data in a state that has protected reproductive rights. It has been cited as a model for other states considering health data protection legislation.
The Stop Hacks and Improve Electronic Data Security (SHIELD) Act was signed into law on March 21, 2019, and took effect on March 21, 2020.
Key features:
Data security requirement: Requires any person or business that owns or licenses computerized data including private information of New York residents to implement and maintain "reasonable safeguards" to protect the security, confidentiality, and integrity of such information.
Reasonable safeguards: The Act specifies that reasonable safeguards include administrative, technical, and physical safeguards appropriate to the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the personal information.
Expanded breach notification: Broadened the definition of "private information" to include biometric data, username/password combinations,
and driver's license numbers. Expanded the breach notification requirement to include any person or business that acquires private information of New York residents, regardless of whether they do business in New York.
Enforcement: New York Attorney General. Civil penalties of up to
$5,000 per violation.
Several states have enacted or proposed age-appropriate design codes that impose specific requirements on the design of digital products and services accessible to children:
California Age-Appropriate Design Code Act (CAADCA): Enacted in 2022,
the CAADCA requires businesses that provide online services, products,
or features likely to be accessed by children to: (1) complete a Data
Protection Impact Assessment before offering new services; (2) configure privacy settings to default to the highest level of privacy; (3) avoid using personal information in ways that are detrimental to children's well-being; and (4) provide children with an accessible mechanism to report concerns. The CAADCA was challenged in court and subsequently revised, with final regulations pending as of early 2026.
Nebraska: The Nebraska Children's Online Privacy Act (2024) imposes age verification, parental consent, and design requirements for online services accessible to children under 18.
Vermont: The Vermont Data Privacy Act (pending) includes specific provisions on the protection of children's data and age-appropriate design.
Trend: Age-appropriate design codes represent a growing trend in US
state privacy legislation, reflecting the influence of the UK
Age-Appropriate Design Code (the "Children's Code") and increasing concern about the impact of social media and digital services on children's mental health.

# Chapter 20: Proposed Federal Privacy Legislation

The American Privacy Rights Act (APRA) is the most significant federal privacy legislation to advance in the US Congress in recent years. A bipartisan bill, APRA was introduced in the 118th Congress
(2023-2024) by Representative Cathy McMorris Rodgers (R-WA) and Senator
Maria Cantwell (D-WA), then reintroduced in modified form in the 119th
Congress.
National standard: APRA would establish a single, comprehensive federal standard for data privacy, preempting most state privacy laws
(with exceptions for certain sectoral laws including HIPAA, GLBA, COPPA,
and FCRA, as well as Illinois BIPA and state laws addressing specific non-privacy issues).
Universal opt-out: APRA would require covered entities to provide consumers with a clear, accessible, and universal opt-out mechanism from targeted advertising, the sale of personal data, and the use of personal data for training AI systems.
Data minimization: APRA would impose data minimization requirements on covered entities, requiring them to limit the collection, processing,
and retention of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service.
Consumer rights: Access, correction, deletion, data portability, and opt-out of covered data uses.
Sensitive data: Processing of sensitive personal information would require consent. Sensitive data would include Social Security numbers,
financial account data, precise geolocation, health data, biometric data, and data concerning minors.
Children's data: Enhanced protections for data concerning individuals under 17, including a requirement for parental consent for the collection of personal data from children under 13.
Enforcement: APRA would grant enforcement authority to the Federal
Trade Commission (FTC) and state attorneys general. The FTC would have the authority to issue regulations implementing the Act.
Private right of action: Initially included but controversial. The current version of APRA includes a limited private right of action after a period of exclusive FTC/state AG enforcement, allowing individuals to seek statutory damages for data breaches and willful violations.
AI provisions: APRA includes provisions requiring covered entities to provide consumers with the right to opt out of the use of their personal data for training AI systems, and to receive notice when their personal data is used for such purposes.
APRA's legislative prospects have fluctuated significantly:
Supporters argue that a federal privacy law is urgently needed to address the growing patchwork of state laws, reduce compliance costs for businesses, and provide consistent privacy protections for all Americans regardless of their state of residence.
Opponents raise concerns about preemption of stronger state laws
(particularly California's CCPA/CPRA), the adequacy of enforcement mechanisms, and the potential for a federal standard to become a ceiling rather than a floor for privacy protection.
Industry position: Major technology companies have generally supported federal privacy legislation, arguing that a single national standard would reduce compliance complexity. Consumer advocacy groups have been more divided, with some supporting APRA as a pragmatic step forward and others opposing it for preempting stronger state laws.
As of early 2026: APRA has not been enacted. The political dynamics of the 119th Congress make comprehensive federal privacy legislation challenging, though the growing number of state laws (now exceeding 20)
continues to increase pressure for federal action.
The prospects for a comprehensive federal privacy law in the United
States remain uncertain but the trajectory is clearly toward eventual enactment. Key factors include:
Growing state patchwork: With over 20 states having enacted comprehensive privacy laws, the compliance burden on businesses operating across state lines has become substantial, increasing the business community's support for federal preemption.
Partisan dynamics: Privacy has been a rare bipartisan issue, though disagreements persist on preemption, enforcement mechanisms, and the role of the FTC versus a new dedicated agency.
International pressure: The lack of a comprehensive federal privacy law has been cited as a weakness in US negotiations on cross-border data transfer arrangements (particularly with the EU) and has complicated efforts to obtain adequacy determinations from foreign regulators.
AI governance: The growing focus on AI regulation has created additional momentum for comprehensive data governance legislation, as AI
governance inherently involves data governance.
Timeline: While no specific timeline is certain, most observers expect that a comprehensive federal privacy law will eventually be enacted, likely within the next 5-10 years, though the exact shape and scope of such legislation remain uncertain.

## Part Five: China


# Chapter 21: Cybersecurity Law of the PRC (2016)

The Cybersecurity Law of the People's Republic of China (People's
Republic of China Cybersecurity Law) was adopted by the Standing
Committee of the National People's Congress on November 7, 2016, and entered into force on June 1, 2017. It represents the foundational legislation of China's three-pillar data governance framework and was the first comprehensive cybersecurity statute enacted by the People's
Republic.
The legislative process was remarkable for its speed. The first draft was published for public comment in July 2015, and the final text was adopted just 16 months later — an unusually rapid timeline for major
Chinese legislation. This urgency reflected the Chinese government's growing concern over cybersecurity threats, the increasing volume of cyberattacks targeting Chinese government and commercial systems, and the need to establish a legal framework for the governance of cyberspace consistent with the government's vision of "cyber sovereignty"
(cyber sovereignty).
The Cybersecurity Law must be understood within the broader context of China's approach to internet governance. Since the early 2000s, the
Chinese government has pursued a strategy of regulating cyberspace as a sovereign domain, subject to the same principles of territorial jurisdiction and state control that apply to physical territory. This approach, often described as the "Great Firewall" model, combines technical measures (content filtering, traffic management, DNS
manipulation) with legal and administrative measures (real-name registration, content licensing, criminal sanctions) to create a controlled digital environment. The Cybersecurity Law provides the statutory foundation for many of these measures.
The Cybersecurity Law imposes a comprehensive set of obligations on
"network operators" (网络运营者), broadly defined to include all persons and organizations that own, manage, or operate networks and information systems. The key obligations include:
Classified Protection System (classified protection system) (Article 21). Network operators must implement the "Multi-Level Protection Scheme" (MLPS,
classified protection system) — a hierarchical system of cybersecurity requirements calibrated to the classification level of the information system. The
MLPS, originally established by the State Council in 1994 and significantly revised in 2019 (MLPS 2.0), classifies information systems into five levels (Level 1 to Level 5) based on the potential impact of a security breach on national security, social order, and the public interest. Each level imposes progressively more stringent security requirements. Level 3 and above require annual security assessments conducted by certified assessment organizations and approved by the public security organ.
Real-name registration (Articles 24, 61). Network operators providing services that require users to provide personal information (such as internet access services, mobile telecommunications, and social media platforms) must verify the real identity of users. This requirement applies to both individual users (who must provide government-issued identification) and organizational users (who must provide business registration information). The real-name registration requirement is one of the most distinctive features of China's internet governance framework and serves multiple purposes: combating anonymous online speech, facilitating law enforcement investigations, and enabling the government to monitor online activity.
Emergency response plans (Article 25). Network operators must develop and maintain emergency response plans for cybersecurity incidents,
including procedures for incident detection, reporting, containment,
recovery, and post-incident review. Emergency response plans must be regularly tested and updated.
Data breach notification (Article 25). Network operators must promptly notify affected users and relevant authorities when they discover that personal information has been leaked, corrupted, or lost.
The 2019 MLPS 2.0 and subsequent implementing regulations have specified the notification timelines and content requirements, generally requiring notification within 24 hours of discovering a significant breach.
Personal information protection (Articles 40-45). The Cybersecurity
Law contains foundational provisions on the protection of personal information, including requirements to: collect personal information in accordance with the principle of lawfulness, legitimacy, and necessity;
inform data subjects of the purpose, method, and scope of collection;
obtain consent from data subjects; and protect the confidentiality,
integrity, and availability of personal information. These provisions were substantially supplemented and expanded by the Personal Information
Protection Law (PIPL, 2021), which superseded the Cybersecurity Law's personal information provisions in areas of overlap.
Critical Information Infrastructure (CII) Protection (Articles
31-39). The Cybersecurity Law establishes a special regime for "critical information infrastructure" — systems and facilities that, if destroyed,
lost of function, or subjected to data leakage, would seriously endanger national security, national economy, or the public interest. The Law requires CII operators to: (a) conduct annual security assessments of the CII; (b) develop and maintain dedicated cybersecurity management systems and specialized security management personnel; (c) implement enhanced security measures, including intrusion detection, vulnerability scanning, and encryption; and (d) store personal information and important data collected in China within China (data localization requirement).
The identification of CII is carried out by the Cyberspace
Administration of China (CAC), in coordination with relevant industry regulators (such as the People's Bank of China for financial infrastructure and the National Health Commission for healthcare systems). As of 2026, the CAC has not published a comprehensive list of designated CII, though it is widely understood to include: core telecommunications networks; major financial payment and settlement systems; energy infrastructure control systems; transportation management systems; government information systems handling state secrets; and large-scale databases of personal information.
The Cybersecurity Law provides for both administrative and criminal penalties:
Administrative penalties for organizations: Network operators that violate the Law's security obligations may be subject to warnings,
orders for rectification, fines of up to RMB 1 million (approximately
$140,000), orders to suspend related business, closure of websites,
revocation of business licenses, and orders to deregister domain names.
For particularly serious violations, fines may exceed RMB 1 million.
Administrative penalties for individuals: Individuals directly responsible for violations may be fined RMB 10,000 to RMB 100,000
(approximately $1,400 to $14,000), and may be prohibited from engaging in cybersecurity management or network operator positions for a specified period.
Criminal liability: Where violations constitute crimes, criminal liability is pursued in accordance with the Criminal Law of the PRC.
Relevant criminal provisions include: Article 285 (illegal access to computer information systems), Article 286 (destruction of computer information systems), Article 287 (illegal use of information networks),
and Article 287bis (assisting information network criminal activities).
Criminal penalties can range up to life imprisonment in the most serious cases involving state secrets or espionage.
People's Republic of ChinaCybersecurity Law
（2016117the 12th NPC Standing Committee24th Sessionadopted）
[Full Chinese text to be reproduced from official source.
Professional legal translation into English required.]

# Chapter 22: Data Security Law of the PRC (2021)

The Data Security Law (People's Republic of ChinaData Security Law,
DSL) was adopted on June 10, 2021, and entered into force on September
1, 2021. It represents the second pillar of China's three-pillar data governance framework and complements the Cybersecurity Law by focusing on the security of "data" as a distinct regulatory object, separate from the "network" and "information systems" addressed by the Cybersecurity
Law.
The DSL's most significant structural innovation is the establishment of a data classification and grading system ()
(Article 21). Under this system, all data is classified into three categories:
Core data (core data): Data that relates to national security,
national economy, and the vital interests of the people, and whose leakage, tampering, destruction, or illegal use would cause the most serious harm. Core data is subject to the most stringent controls,
including mandatory data localization, strict access restrictions, and security assessments for any cross-border transfer. The criteria for identifying core data and the specific categories of data classified as
"core" are determined by the State Council and relevant authorities.
Important data (important data): Data that, once leaked, tampered with,
destroyed, or illegally used, may endanger national security, public interest, or the lawful rights and interests of citizens and organizations. Important data is subject to enhanced security requirements, including data security assessments, restrictions on cross-border processing, and mandatory data localization for certain categories. The criteria for identifying important data are established by relevant authorities in accordance with industry-specific guidelines.
General data (一般数据)
of core data or important data. General data is subject to the general requirements of the DSL, the Cybersecurity Law, and the PIPL.
The DSL requires all data processing organizations to establish a data classification system, to identify and classify the data they handle, and to implement security measures appropriate to the classification level of the data.
Data security risk assessment (Article 30). Organizations that process data must conduct regular data security risk assessments to identify and mitigate risks to data security. For important data, risk assessments must be conducted annually and reported to relevant authorities.
Important data export security review (Article 31). The cross-border transfer of important data is subject to a mandatory security review by the relevant authorities. This review assesses whether the transfer poses risks to national security, public interest, or the rights and interests of citizens and organizations.
Data security emergency response (Article 29). Organizations must develop emergency response plans for data security incidents, including procedures for incident detection, reporting, containment, and recovery.
Obligations of data processors entrusted with data processing
(Articles 27-28). Organizations that process data on behalf of data controllers are subject to obligations including: the implementation of appropriate security measures; compliance with the data controller's instructions regarding data classification, security, and handling; and notification to the data controller in the event of a data security incident.
The DSL includes specific provisions on the security of government data, reflecting the Chinese government's emphasis on the protection of state information. These provisions require government agencies to:
implement data security management systems; classify government data according to its sensitivity; restrict cross-border transfers of government data; and ensure the security of data shared between government agencies and third parties.
The DSL provides for the following penalties:
Organizational penalties: Organizations that violate the DSL may be subject to warnings, orders for rectification, fines of up to RMB 2
million (approximately $280,000), orders to suspend data processing activities, revocation of business licenses, and closure of websites.
For violations involving core data, penalties may be significantly enhanced.
Individual penalties: Individuals directly responsible for violations may be fined RMB 10,000 to RMB 200,000 (approximately $1,400 to
$28,000), and may be prohibited from holding positions involving data security management for a specified period.
Criminal liability: Where violations constitute crimes, criminal liability is pursued under the Criminal Law of the PRC.
People's Republic of ChinaData Security Law
（2021610the 13th NPC Standing Committee29th Sessionadopted）

# Chapter 23: Personal Information Protection Law (PIPL, 2021)

The Personal Information Protection Law (People's Republic of
ChinaPersonal Information Protection Law, PIPL) was adopted on August
20, 2021, and entered into force on November 1, 2021. It represents the third and most comprehensive pillar of China's data governance framework and the country's first dedicated personal information protection statute. The PIPL is widely regarded as China's counterpart to the GDPR,
though it differs in several important respects that reflect China's distinctive regulatory philosophy.
The PIPL's legislative history was long and contentious. The first draft was published for public comment in October 2020, and the law underwent three readings in the Standing Committee of the National
People's Congress before its adoption. The legislative process generated significant public interest, with the draft receiving over 5,400 public comments — one of the highest volumes of public engagement for any
Chinese legislation in recent years. The final text reflects a balance between the protection of individual rights and the government's interest in maintaining national security and social stability.
The PIPL's relationship with the Cybersecurity Law and the Data
Security Law is hierarchical: where provisions overlap, the PIPL takes precedence over the Cybersecurity Law in matters relating to personal information protection, while the Data Security Law's classification system applies to data that qualifies as "important data" or "core data." The three laws together form an integrated framework for the governance of data in China, often described as the "three laws on data"
(the three data laws).
The PIPL applies to three categories of processing activities within
China: (a) the processing of personal information by organizations within China; (b) the processing of personal information of individuals within China by organizations outside China, where the purpose of the processing is to provide products or services to individuals within
China or to analyze or assess the behavior of individuals within China;
and (c) other processing activities specified by laws and administrative regulations.
Article 3(2)'s extraterritorial provision mirrors the GDPR's Article
3(2) in its attempt to regulate the processing of Chinese residents'
personal data by foreign organizations. However, the PIPL's extraterritorial provision is broader in one respect: it applies to the
"analysis or assessment of behavior" of individuals within China, a formulation that captures a wider range of data processing activities
(including surveillance, market research, and behavioral profiling) than the GDPR's "monitoring" standard.
The PIPL defines "personal information" (personal information) as all kinds of information, recorded electronically or otherwise, relating to identified or identifiable natural persons, excluding information that has been anonymized. This definition is broadly similar to the GDPR's definition of "personal data," though the PIPL places greater emphasis on the distinction between personal information and anonymized data.
"Sensitive personal information" (sensitive personal information) is defined as personal information that, once leaked or illegally used, easily leads to infringement of the personal dignity or、 of natural persons, including biometric data, religious beliefs, specific identities, medical and health data, financial account data, location tracking data, and the personal information of minors under 14. The
PIPL's definition of sensitive information is broader than the GDPR's in certain respects (notably, the inclusion of location tracking data) and narrower in others (it does not include racial or ethnic origin,
political opinions, or trade union membership).
"Automated decision-making" (automated decision-making) is defined as the use of personal information through automated means for activities including screening, evaluation, and management. The PIPL's approach to automated decision-making is distinct from the GDPR's: rather than establishing a general right not to be subject to automated decisions, the PIPL
requires that automated decision-making be transparent, fair, and non-discriminatory, and provides individuals with the right to refuse and the right to request human intervention.
The PIPL establishes seven core principles for the processing of personal information:
Lawfulness, legitimacy, and necessity (lawful, legitimate, and necessary): Processing must have a lawful basis, must be conducted for a legitimate purpose,
and must be limited to the minimum extent necessary.
Informed consent as default: Consent is the default lawful basis for processing, though the PIPL provides alternative bases (contract performance, legal obligation, public health emergency, public interest,
and the legitimate interests of the processor).
Minimum necessity (minimum necessity): The collection and use of personal information must be limited to the minimum scope necessary to achieve the processing purpose. This principle has been interpreted by the CAC
to require that processors collect only the personal information categories that are directly necessary for the stated purpose and that they must not collect "excessive" information.
Purpose limitation: Personal information must not be collected for purposes unrelated to the stated purpose, and must not be used beyond the scope of the consent given by the data subject.
Openness and transparency: Processors must disclose the processing activities to data subjects in a clear and understandable manner.
Quality assurance: Personal information must be accurate, complete,
and up to date.
Accountability: Processors are responsible for the security of the personal information they process and must take necessary measures to ensure its security.
The PIPL provides seven lawful bases for processing personal information:
Consent (consent): The data subject gives informed, voluntary, and explicit consent to the processing. The PIPL requires consent to be given separately for sensitive personal information, cross-border transfers, and data sharing with third parties — a "separate consent"
(separate consent) requirement that goes beyond the GDPR's general consent standard.
Contract performance (contract): Processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of human resource management in accordance with labor laws and collective contracts.
Legal obligation (法律义务). Processing is necessary for the performance of a statutory duty or legal obligation.
Public health emergency (公共卫生紧急情况). Processing is necessary for the prevention and control of public health emergencies or the protection of the life, health, and property safety of natural persons in emergencies.
Public interest (公共利益). Processing is necessary for public-interest activities such as news reporting, public opinion supervision, and other public-interest activities conducted in accordance with the law.
Legitimate interests of the processor (处理者的合法利益). Processing is necessary for the legitimate interests of the processor in the course of providing products or services, within the scope of the consent given by the data subject.
Other circumstances specified by law (法律规定的其他情况). Processing is permitted under other circumstances specified by laws and administrative regulations.
The PIPL imposes rigorous consent requirements. Consent must be:
informed (the data subject must be provided with clear and comprehensive information about the processing), voluntary (consent must not be obtained through deception, coercion, or exploitation of the data subject's vulnerable position), and explicit (the data subject must take affirmative action to indicate consent; silence or inactivity does not constitute consent).
Separate consent (separate consent) is required for: (a) the processing of sensitive personal information; (b) the cross-border transfer of personal information; (c) the disclosure of personal information to third parties; (d) the processing of personal information for automated decision-making; and (e) the collection of personal information from public spaces through installed devices. The separate consent requirement means that consent for these activities cannot be bundled with consent for other processing activities — the data subject must give a specific, distinct consent for each qualifying activity.
The PIPL also requires that consent be obtained by clear and conspicuous means, that the data subject be informed of the right to withdraw consent at any time, and that the withdrawal of consent be as easy as giving consent.
The PIPL establishes the following rights for data subjects:
Right to be informed and decide (right to be informed and right to decide) (Article 44): Data subjects have the right to know about and decide on the processing of their personal information, subject to exceptions for the processing of information by news media in accordance with the law.
Right to access and copy (查阅权和复制权) (Article 45): Data subjects have the right to access and obtain a copy of their personal information, subject to exceptions where disclosure would endanger national security, public security, or the rights of others.
Right to correct and supplement (更正和补充权) (Article 46): Data subjects have the right to request the correction or supplementation of inaccurate or incomplete personal information.
Right to delete (删除权) (Article 47): Data subjects have the right to request the deletion of their personal information in specified circumstances, including where the processing purpose has been achieved,
the retention period has expired, consent has been withdrawn, the processing is illegal, or the processor ceases to provide products or services.
Right to portability (right to portability) (Article 45): Data subjects have the right to request the transfer of their personal information to another processor, where technically feasible.
Right to restrict and refuse automated decision-making (right to restrict and refuse)
(Article 24): Data subjects have the right to refuse automated decision-making and profiling that produces legal or similarly significant effects, and to request human intervention in such decisions.
Right to withdraw consent (right to withdraw consent) (Article 15): Data subjects have the right to withdraw consent at any time, and the processor must provide convenient means for withdrawal.
The PIPL also provides that, where a data subject has difficulty exercising their rights due to age, cognitive impairment, or disability,
the data subject's guardian may exercise the rights on their behalf.
Chapter III of the PIPL establishes the framework for the cross-border transfer of personal information. This is one of the most stringent cross-border transfer regimes in the world and reflects the
Chinese government's emphasis on data sovereignty.
Security assessment by the CAC (): A security assessment by the CAC is mandatory in the following circumstances: (a) when the processor is a critical information infrastructure operator; (b) when the processor processes personal information of 100,000 or more individuals; (c) when the processor processes sensitive personal information of 10,000 or more individuals; or (d) when the CAC
determines that a security assessment is necessary. The security assessment evaluates the legality, necessity, and proportionality of the transfer, the protection level of the recipient country, and the security measures to be implemented. Processing subject to mandatory security assessment may not be transferred until the CAC has approved the assessment.
Personal information protection certification (personal information):
Processors may transfer personal information to third countries through a certification mechanism administered by a designated institution. The
CAC has issued implementing rules for the certification mechanism, which is still in its early stages of development.
Standard contract (standard contract): Processors may transfer personal information to third countries on the basis of a standard contract prescribed by the CAC. The standard contract must be filed with the competent department of the people's government at or above the provincial level. The CAC published the Standard Contract Measures in
2023, providing a template contract that must be used for qualifying transfers.
Thresholds triggering mandatory security assessment: The PIPL
establishes clear numerical thresholds that trigger the mandatory security assessment requirement: processing of personal information of
100,000 or more individuals, or processing of sensitive personal information of 10,000 or more individuals. These thresholds are cumulative (based on the total number of individuals whose data has been processed since the PIPL's entry into force), meaning that once an organization crosses the threshold, all of its cross-border transfers of personal information are subject to the security assessment requirement.
The PIPL requires that automated decision-making be conducted in a transparent, fair, and non-discriminatory manner, and that individuals have the right to refuse automated decisions that produce legal or similarly significant effects and to request human intervention.
Processors using automated decision-making must provide: a clear explanation of the basic principles, parameters, and purposes of the automated decision-making; an explanation of the specific factors and weights used in the decision; and information about the data subject's right to refuse and to request human intervention.
The PIPL establishes enhanced protections for minors under 14,
requiring that the processing of their personal information be subject to the informed consent of their parent or other guardian. The PIPL also requires processors to formulate special rules for the processing of minors' personal information and to designate dedicated personnel to oversee such processing. Minors under 14 are classified as a category of sensitive personal information, meaning that the additional requirements for sensitive data processing apply.
The PIPL provides for the most severe penalties of any Chinese data protection law:
Organizational penalties: Organizations that violate the PIPL may be subject to: orders for rectification; warnings; fines of up to RMB 5
million (approximately $700,000); orders to suspend relevant business or close websites; revocation of business licenses. For serious violations,
the fine may be increased to up to RMB 50 million (approximately $7
million) or 5% of the prior year's annual revenue, whichever is higher.
The PIPL also authorizes the suspension of business operations for a specified period and the prohibition on the use of applications.
Individual penalties: Individuals directly responsible for violations may be fined RMB 100,000 to RMB 1 million (approximately $14,000 to
$140,000), and may be prohibited from holding positions involving personal information protection for a specified period (up to 5 years for serious violations) or for life.
Private right of action (Articles 69-70): The PIPL provides a private right of action for data subjects whose rights have been infringed. Data subjects may bring proceedings in a people's court to seek cessation of the infringement, removal of obstacles, and compensation for actual losses. Where the processor is at fault, the court may award damages of up to five times the actual losses (punitive damages). The burden of proof is reversed for certain violations: where the processor fails to demonstrate that it has complied with the PIPL, it is presumed to be at fault.
People's Republic of ChinaPersonal Information Protection Law
（2021820the 13th NPC Standing Committee30th Sessionadopted）

# Chapter 24: Network Data Security Management Regulations

The Network Data Security Management Regulations (Regulations on
Network Data Security Management, NDSMR) were promulgated by the State
Council on September 24, 2024, and entered into force on January 1,
2025. They represent the most detailed implementing regulation under
China's three-pillar data governance framework, providing operational guidance for the Cybersecurity Law, the Data Security Law, and the
PIPL.
The NDSMR were developed through an extensive drafting process. An initial draft was published for public comment in November 2021,
generating over 5,600 public comments. A second draft was published in
July 2023, reflecting significant revisions in response to stakeholder feedback. The final text, adopted in September 2024, represents a carefully balanced instrument that provides greater specificity while maintaining consistency with the three parent statutes.
One of the NDSMR's most practically significant provisions is the requirement for network platform service providers to display a "dual list" () in their privacy policies:
Collection list (collection list): A detailed list specifying each category of personal information collected, the purpose of collection, the method of collection, and the retention period for each category. This list must be displayed in a conspicuous location on the platform and must be presented in clear, plain language.
Third-party sharing list (): A detailed list specifying each third party with whom personal information is shared, the categories of personal information shared, the purpose of sharing, and the method of sharing. This list must be updated in real time and must allow data subjects to easily understand which third parties have access to their data.
The dual-list requirement is one of the most demanding transparency obligations in global data protection law. It goes beyond the GDPR's privacy notice requirements by requiring platform operators to disclose not only the categories of data collected but also the specific identity of each third-party recipient. The requirement has significant practical implications for major Chinese platforms (such as WeChat, Douyin,
Taobao, and Meituan), which share data with hundreds or thousands of third-party service providers.
The NDSMR elaborates on the PIPL's "separate consent" requirement,
specifying the circumstances in which separate consent must be obtained:
Processing of sensitive personal information
Cross-border transfers of personal information
Sharing of personal information with third parties
Automated decision-making
Collection of personal information through devices installed in public spaces
Processing of personal information for the purpose of targeted advertising
Transferring personal information between applications or mini-programs within the same platform ecosystem
The NDSMR also specifies that separate consent must be obtained through a mechanism that is independent from the general privacy agreement — that is, the user must take a specific, affirmative action to consent to each qualifying processing activity, rather than providing a single blanket consent.
The NDSMR requires network data processors to conduct:
Annual risk assessments: A comprehensive assessment of the security of personal information processing activities, conducted at least once per year. The assessment must cover: the necessity and legitimacy of processing; the impact on data subjects' rights and interests; the adequacy of security measures; and the risk of data breaches. The results of annual risk assessments must be reported to the competent authority.
Scenario-based risk assessments: A targeted assessment conducted before processing activities that pose a "significant risk" to the rights and interests of data subjects. The NDSMR identifies several categories of processing that require scenario-based assessments,
including: the processing of sensitive personal information on a large scale; the use of personal information for automated decision-making;
the deployment of new technologies or business models that involve personal information processing; and any processing activity that has been the subject of data subject complaints or regulatory enforcement.
The risk assessment requirements are among the NDSMR's most operationally demanding provisions. They require organizations to develop internal methodologies for identifying, assessing, and mitigating data protection risks, and to maintain documentation sufficient to demonstrate compliance.
The NDSMR establishes specific obligations for "network platform service providers" — organizations that provide platforms that enable information exchange, content distribution, or transaction facilitation.
These obligations include:
Defining the security obligations of third parties (such as app developers and merchants) operating on the platform
Establishing mechanisms for monitoring third-party compliance with the platform's data security rules
Providing users with channels for reporting data security concerns
Maintaining records of third-party data processing activities on the platform
Platform providers that fail to fulfill these obligations may be held jointly liable with third parties for data security violations that occur on their platforms.
The NDSMR provides for the following penalties:
For general violations: fines of up to RMB 1 million (approximately
$140,000) for organizations and RMB 100,000 for individuals
For serious violations: fines of up to RMB 5 million (approximately
$700,000) for organizations and RMB 500,000 for individuals
For very serious violations involving state security or public interest: fines of up to RMB 50 million (approximately $7 million) for organizations

# Chapter 25: Supporting Regulations and Measures

These Measures, jointly promulgated by the CAC, the National
Development and Reform Commission, the Ministry of Industry and
Information Technology, and the Ministry of Public Security on July 7,
2022, implement the PIPL's cross-border transfer security assessment mechanism. Key provisions include:
Scope: The security assessment applies to: (a) CII operators transferring data overseas; (b) processors meeting the PIPL's threshold
(100,000+ individuals' personal information or 10,000+ individuals'
sensitive personal information); and (c) transfers that have been ordered to undergo a security assessment by the CAC.
Assessment criteria: The assessment evaluates: the legality,
legitimacy, and necessity of the transfer; the volume, scope, and categories of data involved; the degree to which the transfer impacts national security, public interest, and the lawful rights and interests of individuals and organizations; the security measures implemented by the data exporter and importer; and the political, legal, and data protection environment in the recipient country.
Process: The assessment process consists of three steps: (1)
self-assessment by the data exporter; (2) submission of the assessment report and supporting materials to the CAC; and (3) CAC review and determination. The CAC has 60 working days to complete its review, with the possibility of a 60-day extension.
The Provisions on Facilitating and Regulating Cross-Border Data Flows
(), effective March 22, 2024, represent a significant relaxation of China's cross-border data transfer requirements. The Provisions exempt certain categories of data processing from the mandatory security assessment requirement,
including:
International trade activities, academic cooperation, and cross-border manufacturing where no important data is involved
Processing activities by subsidiaries of multinational corporations where the parent company needs access to data for global management purposes
Processing activities within free trade pilot zones
The Provisions also simplify the standard contract filing process and clarify the relationship between the three transfer mechanisms (security assessment, standard contract, and certification). They reflect the
Chinese government's recognition that overly restrictive data transfer rules could impede economic development and international trade.
The Provisions on the Management of Algorithmic Recommendations in
Internet Information Services (Measures for the Administration of Algorithmic Recommendation of Internet Information Services),
effective March 1, 2022, regulate the use of algorithmic recommendation systems by internet information service providers. Key provisions include:
Algorithm transparency: Providers must disclose the basic principles,
purposes, and parameters of their recommendation algorithms to users and regulators.
User right to opt out: Users must be provided with a convenient option to opt out of personalized recommendations and to receive non-personalized content instead.
Prohibition of price discrimination: Providers are prohibited from using algorithms to set different prices for the same goods or services based on user characteristics, a practice commonly known as "algorithmic discrimination" or "big data price discrimination" ().
Protection of minors and vulnerable groups: Providers must implement enhanced protections for minors, including the restriction of content recommendations that may affect minors' physical or mental health.
The Interim Measures for the Management of Generative AI Services
(Interim Measures for the Administration of Generative Artificial Intelligence Services), effective August 15, 2023, are the world's first dedicated regulation of generative AI. Key provisions include:
Training data compliance: Training data must be obtained from lawful sources and must not infringe intellectual property rights or personal information rights. Providers must conduct a personal information protection impact assessment before using personal information for AI
training.
Content safety: Generated content must not: incite subversion of state power; undermine national unity; promote terrorism or extremism;
spread false information; or infringe the lawful rights and interests of others.
User consent for input processing: Providers must obtain the user's informed consent for the processing of personal information contained in user inputs to the generative AI system.
Labeling requirement: Generated content (including text, images,
audio, and video) must be clearly labeled as AI-generated.
Real-name registration: Service providers must register users' real identities in accordance with the law.
The Provisions on the Management of Deep Synthesis Internet
Information Services (Measures for the Administration of Deep Synthesis of Internet Information Services), effective January
10, 2023, regulate the creation and distribution of deepfake content.
Key provisions include:
Mandatory labeling: Deepfake content (including AI-generated faces,
voices, and images) must be clearly labeled as synthesized content.
Provider identification: Deep synthesis service providers must be identifiable and must maintain records of deep synthesis activities.
Prohibition of harmful use: The use of deepfake technology to produce content that harms national security, undermines social stability,
infringes personal rights, or violates intellectual property rights is prohibited.
Other significant supporting measures include: the Measures for
Security Assessment of Data Processing Activities (Data Security Management Regulations,
2024), which elaborate on the data security risk assessment requirements of the DSL and PIPL; the Provisions on the Management of Internet
Information Service Ecologies (Internet Information Service Algorithm Filing System), which require algorithm registration with the CAC; and various industry-specific data protection guidelines issued by sector regulators
(including the People's Bank of China for financial data, the National
Health Commission for health data, and the Ministry of Education for education data).

# Chapter 26: Court Interpretations and Internet Courts

The Supreme People's Court (SPC) has issued several judicial interpretations that elaborate on the application of criminal law to cybercrime:
Interpretation on Defamation via Information Networks (2013). This interpretation addresses the use of information networks to commit defamation (Article 246 of the Criminal Law). It provides that defamatory information that has been viewed by 5,000 or more users,
reposted 500 or more times, or has caused serious consequences such as mental disorders, self-harm, or suicide may be prosecuted as a criminal case. The interpretation established thresholds for the criminal prosecution of online defamation that significantly expanded the scope of criminal liability for online speech.
Interpretation on Personal Information Crime (2015). This interpretation addresses the crime of infringing citizens' personal information (Article 253bis of the Criminal Law). It clarifies the definition of "personal information," the elements of the offense, and the thresholds for prosecution (generally, the personal information of
5,000 or more individuals, or illegal income of RMB 50,000 or more). The interpretation also addresses the liability of platform operators who fail to fulfill their duty of care in protecting users' personal information.
Interpretation on Illegal Use of Information Networks (2015). This interpretation addresses Articles 287 and 287bis of the Criminal Law,
which criminalize the illegal use of information networks and the provision of technical support for cybercrime. It provides detailed guidance on the elements of these offenses and the circumstances under which criminal liability arises.
Interpretation on Computer System Crime (2024). The most recent interpretation addresses the crime of destroying computer information systems (Article 286 of the Criminal Law), providing guidance on the application of the offense to modern cyber threats, including ransomware attacks, DDoS attacks, and the unauthorized modification of data.
The SPC has issued several guiding cases on personal information protection, which serve as binding precedents for lower courts. Notable guiding cases include:
Guiding Case No. 192 (2022): Addressing the liability of a platform operator for the unauthorized collection and use of user location data without consent.
Guiding Case No. 193 (2022): Addressing the liability of an employer for monitoring employees' electronic communications without adequate legal basis.
Guiding Case No. 194 (2022): Addressing the obligation of a data processor to implement security measures and to notify affected individuals of data breaches.
China has established three dedicated Internet Courts to adjudicate disputes arising from online activities:
Beijing Internet Court (est. September 9, 2018): Jurisdiction over internet-related disputes in Beijing, Tianjin, Hebei, Shanxi, Inner
Mongolia, and other northern provinces. The Beijing Internet Court has heard landmark cases on AI-generated content copyright, online platform liability, and data protection.
Hangzhou Internet Court (est. August 18, 2017): China's first internet court, with jurisdiction over Zhejiang, Jiangsu, and other eastern provinces. The Hangzhou Internet Court has been the most prolific of the three internet courts, issuing notable rulings on the
"right to be forgotten" (in the context of inaccurate information displayed in search results), online copyright infringement, and data portability.
Guangzhou Internet Court (est. September 28, 2018): Jurisdiction over
Guangdong, Guangxi, Hainan, and other southern provinces. The Guangzhou
Internet Court has focused on e-commerce disputes, online intellectual property, and data protection cases arising from the Pearl River Delta's technology sector.
The Internet Courts operate under specialized procedural rules that enable online filing, online hearings, electronic evidence submission,
and blockchain-based evidence preservation. They represent an innovative approach to the adjudication of technology-related disputes, providing a model that has attracted international attention.
Notable rulings by the Internet Courts include: the Hangzhou court's
2019 ruling recognizing a limited "right to be forgotten" in the context of inaccurate employment information displayed in Baidu search results;
the Beijing court's 2023 ruling on the copyrightability of AI-generated images (finding that AI-generated works may qualify for copyright protection where sufficient human creative contribution is involved);
and various rulings on the obligations of platform operators under the
PIPL and the Cybersecurity Law.
All judicial interpretations and internet court rulings cited in this chapter are available in Chinese from the China Judgments Online database (China) and the official websites of the respective courts. Professional legal translation into English is required for inclusion in this volume.

# Chapter 27: Japan — Act on the Protection of Personal Information (APPI)

The Act on the Protection of Personal Information
(のにする, APPI) was first enacted in 2003 and took effect in 2005. It represented Japan's first comprehensive framework for the protection of personal information, establishing basic principles for the handling of personal information by business operators.
The APPI underwent a major revision in 2015 (effective 2017), which significantly expanded its scope and introduced new regulatory mechanisms. The most substantial amendments followed in April 2022,
bringing the APPI into closer alignment with the GDPR and strengthening enforcement capabilities. The 2022 amendments were driven in part by
Japan's desire to maintain the EU-Japan mutual adequacy arrangement,
which requires Japan's data protection framework to be deemed
"essentially equivalent" to EU standards.
The APPI is administered by the Personal Information Protection
Commission (PPC, ), an independent regulatory body established in 2016. The PPC has the authority to issue guidance,
conduct investigations, and impose administrative penalties for violations.
Personal information (): The APPI defines personal information as information about a living individual that can identify the individual by name, date of birth, or other description contained in the information (including information that can be easily cross-referenced with other information to identify the individual).
This definition is broader than the GDPR's concept of personal data in some respects, as it includes information that enables identification through combination with other available information.
Personally referable information (): The 2022 amendments introduced this concept, which covers identification codes such as my number (individual number), passport numbers, driver's license numbers,
and other codes that can be used to identify a specific individual. This category receives enhanced protection similar to the GDPR's treatment of unique identifiers.
Care-required personal information (): This category,
introduced in the 2015 revision, covers information that requires special care due to the risk of discrimination or prejudice, including race, ethnicity, creed, social status, medical history, criminal record,
and disability status. Processing of care-required personal information requires the prior consent of the data subject, except in limited circumstances.
Retention period purpose test (データ): The 2022 amendments clarified the distinction between "retained personal data" (subject to the data subject's access and correction rights) and other categories of personal information, narrowing the scope of data over which data subjects can exercise their rights.
The April 2022 amendments represent the most significant overhaul of the APPI since its enactment. Key changes include:
Right to request cessation of use (): Data subjects may now request the cessation of use, deletion, or cessation of provision to third parties of their personal information when the information is used beyond its originally stated purpose, when it was obtained by fraudulent or wrongful means, or when it is no longer necessary for the purpose of use. Previously, this right was limited to cases where the handling of the information was likely to harm the rights and interests of the individual.
Right to request disclosure of personal information used for automated decision-making: Data subjects have the right to request information about the logic and results of automated decision-making that affects them significantly.
Shorter response timelines: Business operators must respond to access requests within 60 days (previously no statutory deadline existed in practice).
The 2022 amendments introduced a structured framework for cross-border transfers of personal information to foreign countries:
Adequacy-based transfers: Transfers to countries recognized by the
PPC as having equivalent data protection standards may proceed without additional safeguards.
Transfer with consent: Transfers may be made to any country with the prior consent of the data subject, provided the data subject is informed of the data protection standards in the recipient country (or that the country has not been recognized by the PPC).
Transfer under prescribed standards: Transfers may proceed where the recipient implements data protection standards prescribed by the PPC,
such as contractual safeguards or binding corporate rules.
Country-specific requirements: Before making a transfer, the business operator must provide the data subject with information about the recipient country's data protection regime, unless an adequacy decision applies.
The 2022 amendments significantly strengthened penalties:
For violations of PPC orders: imprisonment of up to one year and/or a fine of up to ¥1 million (approximately $6,700) for individuals; fines of up to ¥100 million (approximately $670,000) for corporations.
For providing false reports to the PPC or obstructing investigations:
imprisonment of up to six months and/or a fine of up to ¥300,000 for individuals.
The PPC may now issue compliance orders requiring business operators to correct violations and report on remedial measures, with criminal penalties for non-compliance.
The APPI distinguishes between:
Pseudonymized information (): Personal information that has been processed so that it cannot be attributed to a specific individual without additional information. Pseudonymized information is subject to reduced regulatory requirements but cannot be freely transferred abroad.
Anonymized information (): Information that has been processed so that it cannot be attributed to a specific individual and cannot be restored to identify the individual. Anonymized information is no longer considered personal information and can be freely processed and transferred, subject to certain safeguards.
The EU-Japan mutual adequacy arrangement, which entered into force on
January 23, 2019, is one of the world's most significant cross-border data transfer frameworks. Under this arrangement:
The European Commission has recognized Japan as providing an
"adequate level of protection" for personal data transferred from the
EEA to Japan.
Japan has recognized EU member states as providing an equivalent level of protection for personal data transferred from Japan to the
EEA.
The adequacy arrangement was supplemented by supplementary rules adopted by Japan to address specific concerns raised by the European
Commission, including enhanced protections for data subjects in the EU
who wish to exercise their rights against Japanese business operators,
limitations on the access of Japanese government authorities to data transferred from the EU, and an independent supervisory mechanism to handle complaints from EU data subjects.
The mutual adequacy was reaffirmed following the APPI's 2022
amendments, which brought Japan's framework into closer alignment with
GDPR standards. The arrangement facilitates data flows between two of the world's largest economies, covering approximately 600 million people.
The Act on Protection of Personal Information Held by Specified
Business Operators (Act on Protection of Personal Information Held by Specified Business Operators), administered by the Financial
Services Agency (FSA), imposes additional requirements on financial institutions, including mandatory privacy impact assessments for the handling of specific types of personal information (such as credit card data and loan records).
The Telecommunications Business Act imposes consent requirements for the collection and use of subscriber information by telecommunications carriers. The Ministry of Internal Affairs and Communications (MIC) has issued guidelines on the handling of location data and communication records.
The Ministry of Health, Labour and Welfare has issued guidelines on the handling of medical information, which impose stricter requirements than the general APPI framework. Medical institutions must implement enhanced security measures and obtain explicit consent for the secondary use of medical data.
The PPC has been increasingly active in issuing guidance and enforcement notices. Notable trends include:
Enhanced scrutiny of cross-border data transfers, particularly transfers to countries without adequacy recognition.
Increased attention to data breach notification requirements
(business operators must notify the PPC and affected individuals without undue delay when a breach is likely to cause harm to the rights and interests of data subjects).
Growing focus on the use of personal information for profiling and behavioral targeting in digital advertising.
Issuance of guidance on the handling of personal information in the context of AI development, including guidance on the use of personal information for machine learning training data.
The full text of the APPI (as amended through April 2022) is available in Japanese from the PPC's official website
(https://www.ppc.go.jp) and in English translation from the Japanese government's e-Gov portal (https://elaws.e-gov.go.jp). PPC guidelines are available in both Japanese and English.

# Chapter 28: South Korea — Personal Information Protection Act (PIPA)

The Personal Information Protection Act (개인정보 보호법, PIPA) was enacted on September 30, 2011, and entered into force on September 30,
2011, replacing the Act on the Promotion of Information and
Communications Network Utilization and Data Protection (which remains in force for the telecommunications and online sector). South Korea thus operates a dual regulatory framework: PIPA as the general data protection law and the Network Act (정보통신망 이용촉진 및 정보보호 등에
관한 법률) for online and telecommunications services.
The PIPA has been amended multiple times since its enactment, with significant revisions in 2020 and 2023. The 2023 amendments, effective
September 15, 2023, represent the most substantial overhaul, introducing provisions on automated decision-making, data portability, and strengthened consent requirements.
The Personal Information Protection Commission (PIPC,
개인정보보호위원회), established as an independent body in August 2020
by merging the previous PIPC (under the Ministry of the Interior and
Safety) with the telecommunications data protection functions of the
Korea Communications Commission (KCC). The PIPC has broad regulatory,
investigatory, and enforcement powers, including the authority to conduct on-site inspections, issue corrective orders, and impose administrative fines.
Personal information (개인정보): Information pertaining to a living person, including name, identification number, image, and other information that can identify the person (including information that can be easily combined with other information to identify the person). This definition is broadly construed.
Sensitive personal information (민감정보): Information that may cause significant disadvantage or discrimination if leaked, including ideology, belief, trade union membership, political opinion, health,
sexual orientation, genetic information, and biometric data. Processing of sensitive personal information generally requires explicit consent.
High-risk personal information (고위험 개인정보): The 2023 amendments introduced this category, covering personal information that requires enhanced protection due to the nature of the processing activity or the volume of data involved. Processing of high-risk personal information requires a privacy impact assessment.
Eight core principles: The PIPA establishes eight principles for the processing of personal information: (1) purpose limitation, (2) minimum collection, (3) accuracy, (4) safety and security, (5) openness, (6)
individual participation, (7) accountability, and (8) restriction on collection of sensitive information.
The 2023 amendments modernize the PIPA to address evolving data protection challenges:
Clearer consent standards: Consent must be freely given, specific,
and informed. Pre-checked boxes or bundled consent are not valid.
Withdrawal of consent: Data subjects must be able to withdraw consent as easily as they gave it. The 2023 amendments require business operators to provide a simple mechanism for consent withdrawal.
Separate consent for sensitive processing: Processing of sensitive personal information requires explicit separate consent, distinct from general privacy agreement consent.
The 2023 amendments introduced provisions on automated decision-making, including profiling:
Data subjects have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant impacts, without their explicit consent.
Business operators must inform data subjects about the logic involved, the significance, and the envisaged consequences of automated decision-making.
Data subjects may request human intervention in automated decisions that significantly affect them.
The 2023 amendments establish a right to data portability, enabling data subjects to request the transfer of their personal information from one service provider to another in a machine-readable format. This right applies to information that the data subject has provided directly to the controller.
Business operators processing high-risk personal information must conduct a privacy impact assessment (PIA) before commencing the processing activity and must submit the results to the PIPC. The 2023
amendments expanded the scope of processing activities that require a
PIA.
Under the PIPA, personal information may be transferred to a foreign entity:
With the consent of the data subject, after being informed of the recipient country's data protection status.
To a country or international organization recognized by the PIPC as maintaining an adequate level of data protection.
Under a contract that includes data protection standards prescribed by the PIPC.
The PIPC has recognized a limited number of countries as having adequate protection, including Japan, Australia, and selected European countries. Transfers to the United States, China, and most other countries require consent or contractual safeguards.
The Credit Information Act (신용정보의 이용 및 보호에 관한 법률)
governs the collection and use of credit information, including financial transaction data, in South Korea. Key provisions include:
Financial institutions and credit information companies must obtain consent for the collection and use of credit information.
Credit information may be shared with authorized credit information companies and financial institutions for specific purposes.
The Financial Services Commission (FSC) and the Financial Supervisory
Service (FSS) have overlapping jurisdiction with the PIPC over financial data protection matters, which has created regulatory coordination challenges.
MyData services, introduced through the 2020 amendment to the Credit
Information Act, allow consumers to authorize the transfer of their financial data from their existing financial institutions to new service providers. This framework has been widely adopted in South Korea's fintech sector.
The PIPA provides for significant penalties:
Criminal penalties: Up to five years' imprisonment and/or up to KRW
50 million (approximately $37,000) for violations including the unauthorized collection or provision of personal information, the destruction of personal information to obstruct investigation, or the provision of false information to the PIPC.
Administrative fines: The PIPC may impose administrative fines of up to 3% of the relevant revenue (similar to the GDPR's maximum) for serious violations. The 2020 amendments introduced this penalty regime,
marking a significant increase in enforcement power.
Corrective orders: The PIPC may order business operators to cease violations, adopt remedial measures, and report on compliance.
Name-and-shame: The PIPC may publicly announce the identity of business operators that have committed serious violations, subject to procedural safeguards.
Notable enforcement actions include the PIPC's 2022 fine against Meta
Platforms (KRW 30.8 million, approximately $23,000) for sharing personal information with third parties without consent, and ongoing investigations into the data practices of major Korean and international technology companies.
The full text of the PIPA (as amended through September 2023) is available in Korean from the PIPC's official website
(https://www.pipc.go.kr) and in English translation from the Korea
Legislation Research Institute (http://elaw.klri.re.kr). PIPC guidelines are available in Korean, with selected translations in English.

# Chapter 29: Singapore — Personal Data Protection Act (PDPA)

The Personal Data Protection Act (PDPA) was enacted in 2012 and came into full operation on July 2, 2014. It established Singapore's comprehensive data protection framework, consolidating various sectoral data protection provisions (including those previously contained in the
Banking Act, the Insurance Act, and the Telecommunications Act) into a unified statute.
The PDPA is administered by the Personal Data Protection Commission
(PDPC), which operates under the Infocomm Media Development Authority
(IMDA). The PDPC is responsible for issuing guidance, managing the registration of data intermediaries, and enforcing the PDPA.
The PDPA has been amended several times, with the most significant reforms introduced through the 2020 and 2021 amendments, which strengthened consent requirements, introduced mandatory data breach notification, enhanced financial penalties, and clarified obligations in the context of novel technologies including artificial intelligence.
Personal data: Data about an individual who can be identified from that data, or from that data and other information to which the organization has or is likely to have access. The definition covers both digital and analog records.
Key obligations: The PDPA establishes nine main obligations for data protection in Singapore:
Consent obligation: Personal data may only be collected, used, or disclosed with the individual's consent (or where an exception applies).
Purpose limitation obligation: Personal data may only be collected,
used, or disclosed for purposes that a reasonable person would consider appropriate in the circumstances.
Notification obligation: Organizations must notify individuals of the purposes for which personal data is collected, used, or disclosed.
Access and correction obligation: Individuals have the right to access their personal data and to request correction of inaccurate data.
Protection obligation: Organizations must implement reasonable security arrangements to protect personal data.
Retention limitation obligation: Personal data should be deleted or anonymized when no longer necessary for the purpose for which it was collected.
Transfer limitation obligation: Personal data may only be transferred outside Singapore under prescribed conditions ensuring a comparable standard of protection.
Data intermediary obligations: Data intermediaries (organizations that process personal data on behalf of other organizations) are subject to modified obligations focusing primarily on protection and retention limitation.
Do Not Call (DNC) obligation: Organizations must check the DNC
registry before sending marketing messages to Singapore telephone numbers.
The 2020 amendments introduced mandatory data breach notification requirements, effective February 1, 2021. Organizations must notify the
PDPC and affected individuals of notifiable data breaches:
Notification to PDPC: Required where the breach involves 500 or more individuals, or where the breach involves personal data of a sensitive nature (such as NRIC numbers, passport numbers, or financial data).
Notification to affected individuals: Required where the breach is likely to result in significant harm to the affected individuals,
including identity theft, fraud, humiliation, or damage to reputation.
Timeline: Notifications must be made as soon as practicable, and in any event within three calendar days of the organization's assessment that the breach is notifiable.
The PDPA's transfer limitation obligation requires organizations to ensure that personal data transferred to another country receives a comparable standard of protection. The PDPC has prescribed several mechanisms for compliant cross-border transfers:
Contractual arrangements: Transfers under a contract that requires the recipient to provide a standard of protection comparable to the
PDPA.
Binding corporate rules: Intra-group transfers under approved binding corporate rules.
APEC Cross-Border Privacy Rules: Transfers to organizations certified under the APEC CBPR system.
Exemptions for specific countries: The PDPC may prescribe countries as providing an adequate standard of protection.
Consent-based transfers: Transfers with the informed consent of the data subject.
The 2021 amendments introduced the concept of "prescribed countries,"
allowing the Minister to designate countries whose data protection frameworks are deemed comparable to Singapore's. As of 2025, no countries have been formally prescribed under this mechanism, though discussions with key trading partners are ongoing.
The 2020 amendments significantly increased financial penalties for
PDPA violations:
For organizations with annual turnover exceeding SGD 10 million:
penalties of up to 10% of annual turnover for Singapore operations,
capped at SGD 1 million (approximately $750,000) for the most serious violations.
For all other organizations: penalties of up to SGD 1 million.
The PDPC may also issue compliance directions requiring organizations to stop processing personal data, destroy data, or implement specific remedial measures.
Notable enforcement actions include the PDPC's 2019 fine against
SingHealth (SGD 250,000, approximately $185,000) for the 2018 data breach that affected 1.5 million patients' records, including the personal data of Singapore's Prime Minister; and the 2022 fine against
MobileAir (SGD 14,000) for failing to implement adequate security measures.
While not legally binding, Singapore's Model AI Governance Framework
(first published in 2019, updated in 2020 as the Second Edition) has been influential in shaping the approach to AI regulation in the
Asia-Pacific region. Key principles include:
Human-centeredness: AI should be designed to benefit human beings and enhance human well-being.
Explainability, transparency, and fairness: Organizations using AI
should be able to explain how AI models arrive at decisions,
particularly where those decisions affect individuals.
Repeatability and reliability: AI systems should function as intended and produce consistent results.
Safety and resilience: AI systems should be secure and resilient against attacks.
Accountability: Organizations deploying AI should be accountable for the decisions made by their AI systems.
The PDPC has also issued the AI Verify framework (2022), a governance testing framework and toolkit that enables organizations to demonstrate the responsible use of AI through standardized testing. AI Verify is designed as an open-source toolkit that assesses AI systems against key governance principles including fairness, explainability, and robustness.
Singapore's approach to AI governance is notably pragmatic and industry-friendly, emphasizing voluntary adoption, flexibility, and innovation. The government has positioned Singapore as a testbed for AI
governance, and the AI Verify framework has been adopted by organizations across the region as a benchmark for responsible AI
deployment.
The full text of the PDPA (as amended through 2021) is available from the Singapore Statutes Online database (https://sso.agc.gov.sg). PDPC
advisory guidelines and guidance notes are available from the PDPC
website (https://www.pdpc.gov.sg).

# Chapter 30: India — Digital Personal Data Protection Act (DPDPA, 2023)

The Digital Personal Data Protection Act (DPDPA) received
Presidential assent on August 11, 2023, and represents India's first comprehensive federal data protection legislation. The Act emerged from a decade-long legislative process that began with the Justice A.P. Shah
Committee Report in 2012, followed by the Srikrishna Committee's draft
Personal Data Protection Bill in 2018, a revised bill in 2019, a Joint
Parliamentary Committee review (2021-2022), and a substantially redrafted version withdrawn in 2022 before the current DPDPA was introduced in November 2022 and passed in August 2023.
The DPDPA is notable for its relatively concise structure — 30
sections in total — which distinguishes it from the far more detailed
GDPR and other comprehensive data protection statutes. The brevity reflects a deliberate legislative choice to establish broad principles while delegating detailed implementation to subordinate rules and regulations.
The Act is administered by the Data Protection Board of India, a quasi-judicial body to be established by the central government. Unlike the GDPR's independent supervisory authorities or South Korea's PIPC,
the Data Protection Board is not structured as a fully independent regulator — its members are appointed by and serve at the pleasure of the central government, a design choice that has drawn criticism from privacy advocates and comparisons with the RBI and SEBI governance models.
Personal data: The DPDPA defines personal data as any data about an individual who is identifiable by or in relation to such data. This definition is broad and covers both digital and non-digital data that has been digitized.
Data principal: The natural person to whom personal data relates. The concept is equivalent to the GDPR's "data subject."
Data fiduciary: The entity that determines the purpose and means of processing personal data. This is equivalent to the GDPR's "data controller."
Data processor: An entity that processes personal data on behalf of a data fiduciary.
Significant data fiduciary: The central government may designate certain data fiduciaries as "significant" based on factors including the volume and sensitivity of personal data processed, the risk of harm to data principals, and the entity's impact on India's sovereignty and integrity. Significant data fiduciaries face additional obligations including the appointment of a Data Protection Officer based in India,
the conduct of independent data audits, and the conduct of Data
Protection Impact Assessments.
The DPDPA establishes a consent-based framework as the primary lawful basis for processing personal data, but with notable deviations from the
GDPR model:
Consent under the DPDPA must be:
Free, specific, informed, unconditional, and unambiguous.
Given through a clear affirmative action — pre-ticked boxes or default opt-ins are not valid.
Withdrawing must be as easy as giving consent.
The data fiduciary must provide a notice to the data principal before or at the time of requesting consent, specifying the personal data sought, the purpose of processing, and other prescribed particulars.
The DPDPA provides for "deemed consent" in several circumstances,
where consent is presumed without an explicit affirmative action by the data principal:
Where the data principal has voluntarily provided personal data for a specific purpose.
In employment contexts, where personal data is provided by the data principal to the employer.
Where processing is necessary for compliance with any law, for the provision of government benefits or services, or for medical emergencies.
Where processing is necessary for public interest, as determined by the government.
The broad scope of deemed consent has been criticized as potentially undermining the consent-based framework, as it permits significant processing without the data principal's explicit agreement.
The DPDPA also permits processing without consent for certain
"legitimate uses," including:
The performance of any function under Indian law by the State.
Compliance with a judgment or order of any court or tribunal.
The prevention, detection, investigation, or prosecution of any offence.
Medical or epidemiological purposes in the event of an outbreak or epidemic.
Monitoring of public order or during a disaster.
These exceptions are broadly worded and provide the government with significant discretion to authorize processing without consent.
The DPDPA grants data principals the following rights:
Right to information: The right to obtain information about the processing of their personal data, including the categories of data processed, the purposes of processing, and the identity of data fiduciaries and recipients.
Right to correction and completion: The right to request correction of inaccurate or misleading personal data, and completion of incomplete personal data.
Right to erasure: The right to request the erasure of personal data
(referred to as "right to grievance redressal" in some contexts) once the purpose for which it was collected has been fulfilled or consent has been withdrawn.
Right to nomination: A unique feature of the DPDPA, allowing data principals to nominate another individual to exercise their rights in the event of their death or incapacity.
Right to grievance redressal: The right to lodge a complaint with the data fiduciary and to appeal to the Data Protection Board.
Notably absent from the DPDPA is an explicit right to data portability or a right to object to profiling, both of which are present in the GDPR and several other comprehensive data protection statutes.
The DPDPA's approach to cross-border data transfers is markedly different from both the GDPR and China's PIPL. The Act permits the transfer of personal data to all countries except those specifically blacklisted by the central government:
The central government may restrict transfers to certain countries by notification, based on an assessment of the destination country's data protection standards and any perceived threat to India's security or strategic interests.
Where no restriction is in place, personal data may be transferred freely to any country.
Data fiduciaries remain responsible for ensuring that processing by overseas entities complies with the DPDPA's requirements.
This "whitelist by default" approach (or more accurately, "blacklist exception") has been praised for its business-friendly design but criticized for potentially inadequate protection of Indian citizens'
data transferred to countries with weak data protection regimes. The government has stated that the framework is designed to promote India's position as a global data hub and to avoid imposing unnecessary compliance burdens on Indian businesses.
The DPDPA defines a "child" as a person who has not completed 18
years of age — significantly higher than the GDPR's age threshold of 16
(with member state discretion to lower to 13). Key provisions include:
Data fiduciaries must obtain verifiable parental consent before processing children's personal data.
Data fiduciaries must not undertake behavioral monitoring or targeted advertising directed at children.
Data fiduciaries must not engage in processing that is likely to cause any detrimental effect on children.
The government may prescribe additional safeguards for children's data processing.
The 18-year age threshold has been the subject of significant debate,
with critics arguing that it is impractically high and may effectively exclude older teenagers from accessing digital services, while supporters argue that it reflects India's social context and the need for enhanced protection of minors.
The Data Protection Board of India is established as a quasi-judicial body with the following functions:
Determining non-compliance with the DPDPA's provisions.
Imposing monetary penalties (up to ₹250 crore, approximately $30
million, for each instance of non-compliance by significant data fiduciaries; up to ₹50 crore for other data fiduciaries).
Hearing appeals against decisions of data fiduciaries.
Issuing directions to data fiduciaries for compliance.
Key structural features:
The Board consists of a Chairperson and up to six members, appointed by the central government.
Board members are not required to have judicial qualifications,
though the government has indicated a preference for technical and legal expertise.
The Board's decisions may be appealed to the High Court or the
Supreme Court.
The Board's governance structure has been criticized as insufficiently independent, given that its members are appointed by and removable at the pleasure of the executive branch. Comparative analysis suggests that this model provides less institutional independence than the GDPR's independent supervisory authorities or South Korea's
PIPC.
The DPDPA introduces a tiered penalty structure:
General violations (failure to comply with consent requirements,
notice requirements, or data principal rights): up to ₹50 crore
(approximately $6 million) per instance.
Violations by significant data fiduciaries (failure to conduct DPAs,
appoint a DPO, or conduct independent audits): up to ₹250 crore
(approximately $30 million) per instance.
Failure to notify data breaches: up to ₹200 crore (approximately $24
million) per instance.
False or misleading information provided to the Board: up to ₹200
crore.
Penalties are calculated per instance of non-compliance, and the
Board has discretion to consider the nature, gravity, and duration of the violation, as well as the data fiduciary's cooperation and remedial actions. Criminal penalties are not provided for in the DPDPA —
enforcement is exclusively through monetary penalties and compliance directions.
As of early 2025, the Indian government released draft rules for public consultation to operationalize the DPDPA. Key provisions in the draft rules include:
Consent Manager framework: A new category of intermediary (Consent
Manager) will be registered with the Data Protection Board and will facilitate the management of consents between data principals and data fiduciaries. Consent Managers will act as consent intermediaries,
providing a unified interface for individuals to manage their consent preferences across multiple platforms.
Exemptions for startups: Data fiduciaries classified as startups under the government's startup promotion schemes may be granted time-limited exemptions from certain compliance requirements.
Data localization requirements for significant data fiduciaries:
Significant data fiduciaries may be required to store a copy of personal data within India.
Transitional provisions: Existing data fiduciaries are given a period to come into compliance with the DPDPA's requirements.
The draft rules have generated significant public comment,
particularly regarding the Consent Manager framework, the scope of exemptions, and the adequacy of the Board's enforcement powers.
The DPDPA represents a distinctly Indian approach to data protection,
combining elements of the GDPR's comprehensive framework with a more pragmatic, business-friendly orientation. Key comparative observations include:
Conciseness: At 30 sections, the DPDPA is one of the shortest comprehensive data protection statutes in the world, relying heavily on delegated rulemaking.
Government access: The broad "legitimate uses" exception provides extensive processing authority to the government, raising concerns about state surveillance and individual privacy.
Cross-border transfers: The blacklist approach is the most permissive among major jurisdictions, facilitating international data flows but potentially at the cost of data subject protection.
Children's threshold: The 18-year age threshold is the highest among major data protection regimes.
The full text of the DPDPA (Act No. 41 of 2023) is available from the
Legislative Department of the Ministry of Law and Justice, Government of
India (https://www legislative.gov.in). Draft rules are available from the Ministry of Electronics and Information Technology (MeitY)
website.

# Chapter 31: Australia — Privacy Act 1988 & Privacy Legislation Amendment Act 2022

Australia's principal data protection law is the Privacy Act 1988
(Cth), which has been in force since 1991 and has been amended numerous times. The Privacy Act established the Office of the Australian
Information Commissioner (OAIC) as the primary data protection regulator and introduced the Information Privacy Principles (IPPs) applicable to
Australian government agencies and the Australian Privacy Principles
(APPs) applicable to private sector organizations with annual turnover exceeding AUD 3 million (with some exceptions).
Australia's federal privacy framework has historically been characterized as relatively light-touch compared to the GDPR and other comprehensive regimes. The Privacy Act does not apply to all private sector organizations (small businesses with turnover below AUD 3 million are generally exempt), does not provide a general right to sue for privacy breaches (though limited statutory damages are available under the Privacy Act), and has historically imposed relatively modest penalties for non-compliance.
The Privacy Legislation Amendment Act 2022 (effective December 2022)
represents the most significant reform of Australia's privacy framework since the Act's inception. The amendments were driven by the Optus data breach (September 2022), which exposed the personal information of approximately 10 million customers, and the Medibank data breach
(October 2022), which compromised the health data of approximately 9.7
million customers.
The APPs, which took effect on March 12, 2014, establish 13
principles for the collection, use, disclosure, and management of personal information:
Open and transparent management of personal information:
Organizations must have a clearly expressed and up-to-date APP privacy policy.
Anonymisation and de-identification: Organizations must take reasonable steps to implement practices, procedures, and systems to protect personal information, including considering de-identification.
Collection of solicited personal information: Collection must be necessary, by lawful and fair means, and with notice.
Dealing with unsolicited personal information: Organizations must destroy or de-identify unsolicited personal information if it is unreasonable to use or disclose it.
Notification of the collection of personal information: Organizations must take reasonable steps to notify individuals of certain matters at or before the time of collection.
Use or disclosure of personal information: Use and disclosure must be for the primary purpose of collection (or a related secondary purpose)
unless an exception applies (e.g., consent, lawful obligation, public interest).
Direct marketing: Organizations may only use or disclose personal information for direct marketing with the individual's consent (or where the individual would reasonably expect it and it is not sensitive information).
Cross-border disclosure: Personal information may only be disclosed overseas where the recipient is subject to a law that is substantially similar to the APPs, or where the entity takes reasonable steps to ensure compliance.
Adoption, use or disclosure of government-related identifiers:
Generally prohibited, with exceptions for law enforcement and public health purposes.
Quality of personal information: Organizations must take reasonable steps to ensure personal information is accurate, up to date, and complete.
Security of personal information: Organizations must take reasonable steps to protect personal information from misuse, interference, loss,
unauthorized access, modification, or disclosure.
Access to personal information: Individuals have a right to access their personal information, subject to limited exceptions.
Correction of personal information: Organizations must take reasonable steps to correct personal information that is inaccurate,
incomplete, or out of date.
The Notifiable Data Breaches (NDB) scheme, which came into effect on
February 22, 2018, requires organizations covered by the Privacy Act
(and with annual turnover exceeding AUD 3 million) to notify the OAIC
and affected individuals of "eligible data breaches." An eligible data breach occurs when:
Personal information is lost or subjected to unauthorized access or disclosure.
This conduct is likely to result in serious harm to the individuals whose information is involved.
The entity has been unable to remediate the breach through remedial action.
Notifications must be made as soon as practicable after the entity becomes aware of the breach. The statement must include: the identity and contact details of the organization; a description of the data breach; the kinds of information involved; and recommendations about steps individuals should take in response.
The Privacy Legislation Amendment Act 2022 introduced several significant reforms:
Maximum civil penalties increased from AUD 2.22 million (for corporations) to the greater of AUD 50 million, three times the value of any benefit obtained through the contravention, or 30% of the entity's adjusted turnover during the relevant period (whichever is greater).
This brings Australian penalties into line with the GDPR's approach of linking maximum fines to revenue.
For individuals: Maximum penalties increased to AUD 2.5 million.
The amendments expanded the concept of "serious interference with privacy" to provide a clearer basis for the OAIC to pursue enforcement action and for individuals to seek compensation through the Federal
Court or Federal Circuit Court.
The OAIC received additional powers, including the ability to:
Accept enforceable undertakings from organizations.
Issue infringement notices for less serious breaches (with penalties of AUD 50,000 for individuals and AUD 505,000 for corporations).
Resolve privacy complaints through external dispute resolution,
including arbitration.
The 2022 amendments clarified that organizations must handle personal information in a way that is consistent with "community expectations," a standard that is assessed by reference to the conduct of a reasonable person.
Following the Optus and Medibank breaches, the Australian Government commissioned a comprehensive review of the Privacy Act, which reported in February 2023. The review made 116 recommendations, including:
Removing the small business exemption to extend privacy protections to all Australian organizations.
Introducing a positive and express right of action for individuals whose privacy has been interfered with.
Introducing a tort of serious invasion of privacy at the federal level.
Mandating "fair and reasonable" processing as a new general principle.
Restricting the collection and use of personal information by government agencies for secondary purposes.
Strengthening protections for children's data, including raising the age of digital consent to 18 or introducing specific protections for minors.
Reforming the cross-border disclosure framework to require greater accountability for overseas processing.
As of early 2026, several of these recommendations are under active legislative consideration, with the government signaling support for increased penalties, enhanced individual rights, and broader application of the Privacy Act.
In addition to the federal Privacy Act, several Australian states and territories have enacted their own privacy legislation:
New South Wales: Privacy and Personal Information Protection Act 1998
(NSW) and Health Records and Information Privacy Act 2002 (NSW). The NSW
Privacy Commissioner has independent enforcement powers.
Victoria: Privacy and Data Protection Act 2014 (Vic), which establishes the Office of the Victorian Information Commissioner (OVIC)
with oversight of the Victorian public sector.
Australian Capital Territory: Information Privacy Act 2014 (ACT).
South Australia: Personal Information Protection Act 2023 (SA) —
provides private sector protections in addition to the federal regime,
filling gaps in the small business exemption.
Queensland, Western Australia, Tasmania, and the Northern Territory do not have standalone privacy legislation but are covered by federal law and sector-specific regulations.
The My Health Records Act 2012 (Cth) governs the national electronic health record system, imposing additional consent and access requirements. State and territory health privacy laws (such as NSW's
HRIP Act) impose additional obligations on health service providers.
The Australian Securities and Investments Commission Act 2001 (Cth)
and the Banking Act 1959 (Cth) impose data protection requirements on financial institutions. The Consumer Data Right (CDR), operational since
2019, enables consumers to authorize the sharing of their banking,
energy, and telecommunications data with accredited recipients. The CDR
represents one of the most ambitious open banking frameworks in the world and includes robust consent management and data security requirements.
The Telecommunications Act 1997 (Cth) and the Telecommunications
(Interception and Access) Act 1979 (Cth) regulate the collection and use of telecommunications data, including metadata. These acts include provisions for government access to telecommunications data under warrant and for national security purposes.
The full text of the Privacy Act 1988 (as amended through 2022) is available from the Federal Register of Legislation
(https://www.legislation.gov.au). OAIC guidance materials are available from the OAIC website (https://www.oaic.gov.au). APP guidelines are registered as legislative instruments under the Legislation Act
2003.

# Chapter 32: Additional Asia-Pacific Jurisdictions

New Zealand's Privacy Act 2020 replaced the Privacy Act 1993 and entered into force on December 1, 2020. Key features include:
13 Information Privacy Principles (IPPs) modeled on the Australian framework but with notable differences, including stronger protections for cross-border data transfers.
Mandatory data breach notification: Organizations must notify the
Privacy Commissioner and affected individuals of "notifiable privacy breaches" where the breach has caused or is likely to cause serious harm. This was a new requirement not present in the 1993 Act.
Increased financial penalties: The Privacy Commissioner may seek civil penalties of up to NZD 10,000 for individuals and NZD 50,000 for organizations (though these have been criticized as insufficient relative to other jurisdictions).
Cross-border disclosure restrictions: Personal information may only be disclosed overseas where the recipient is subject to comparable privacy safeguards, the data subject consents, or an exception applies.
Exemptions for small businesses: The Act applies to all organizations, but small businesses have longer compliance periods.
Privacy Commissioner: The Office of the Privacy Commissioner (OPC) is the independent regulator, with powers to investigate complaints, issue compliance notices, and refer matters to the Human Rights Review
Tribunal.
The Privacy Act 2020 also introduced a privacy tort through amendments to the Harassment Act 1997 and the tort of "public disclosure of private facts" developed through common law, providing individuals with a cause of action for serious privacy invasions.
Taiwan's Personal Data Protection Act (Personal Data Protection Act, PDPA) was enacted in 2010 (replacing the 1995 Computer-Processed Personal Data
Protection Act) and entered into full force on October 1, 2015. Key features include:
Broad scope of application: Covers both public and private sector organizations.
Sensitive data: Enhanced protections for personal data on medical records, health, sexual life, financial affairs, and genetic data.
Processing requires express written consent.
Purpose limitation: Personal data may only be used for the specific purpose for which it was collected, or for purposes closely related to the original purpose, without the data subject's consent.
Cross-border transfers: Permitted where the recipient country or region has adequate data protection laws, where adequate contractual safeguards are in place, or where the data subject consents.
Criminal penalties: Up to five years' imprisonment and/or a fine of up to NT$100 million (approximately $3.2 million) for violations involving the unlawful collection, sale, or disclosure of personal data.
Regulator: The Ministry of Justice is the primary regulator for the private sector, while the National Development Council oversees public sector compliance. Taiwan does not have a dedicated independent data protection authority.
Taiwan has been recognized by Japan as an adequate jurisdiction for cross-border data transfers and has sought to position itself as a data protection leader in the Asia-Pacific region. The PDPA has been the subject of several proposed amendments, including provisions on automated decision-making, data breach notification, and the establishment of an independent data protection authority.
Hong Kong's Personal Data (Privacy) Ordinance (Personal Data (Privacy) Ordinance,
PDPO), enacted in 1995 and amended most recently in 2021 and 2023, is one of the older data protection statutes in the Asia-Pacific region.
Key features include:
Six Data Protection Principles (DPPs): Purpose and manner of collection; accuracy and duration of retention; use of personal data;
security of personal data; information to be generally available
(openness); and access to personal data.
Direct marketing regulation: The 2013 amendments introduced a consent-based framework for direct marketing, requiring organizations to obtain opt-in consent before using personal data for direct marketing purposes.
Data breach notification: The 2021 amendments introduced a mandatory data breach notification scheme, requiring data users to notify the
Privacy Commissioner and affected data subjects of notifiable data breaches without undue delay.
Exemptions: The PDPO includes broad exemptions for domestic purposes,
health purposes, and data processed for statutory functions, which have been criticized as creating significant gaps in protection.
Privacy Commissioner for Personal Data: The Office of the Privacy
Commissioner for Personal Data (PCPD) is the independent regulator, with powers to investigate complaints, issue enforcement notices, and prosecute criminal offenses under the Ordinance.
Criminal sanctions: Up to HKD 1 million fine and imprisonment for up to 5 years for offenses including the disclosure of personal data without consent, the use of personal data for a new purpose without prescribed consent, and the provision of false information to the
Commissioner.
The 2023 amendments, which took effect in 2024, introduced additional provisions including enhanced requirements for the handling of data access requests and strengthened protections for the personal data of children.
Malaysia's Personal Data Protection Act 2010 (Akta Perlindungan Data
Peribadi 2010) entered into force on November 15, 2013. Key features include:
Seven Personal Data Protection Principles: General, Notice and
Choice, Disclosure, Security, Retention, Data Integrity, and Access principles.
Consent-based framework: Processing generally requires consent,
though the PDPA includes several exceptions for public interest,
business transactions, and journalistic purposes.
Sensitive personal data: Enhanced protections for data concerning physical or mental health, political opinions, religious beliefs, and criminal offenses. Processing requires explicit consent.
Cross-border transfers: Permitted to jurisdictions specified by the
Minister, or where the data subject has been informed of the transfer and has not objected.
Registration requirement: Data users must register with the Personal
Data Protection Department (JPDP) and pay an annual fee.
Penalties: Fines of up to RM 500,000 (approximately $107,000) and/or imprisonment of up to 3 years for violations.
Regulator: The Personal Data Protection Commissioner, established under the PDPA, administers the Act. The Commissioner has been criticized for limited enforcement capacity and a small budget relative to the scope of the Commissioner's mandate.
Thailand's Personal Data Protection Act (พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ.
2562) was enacted in May 2019, with most provisions entering into force on June 1, 2022. Key features include:
GDPR-inspired framework: The Thai PDPA closely follows the GDPR's structure, including consent requirements, data subject rights (access,
rectification, erasure, data portability, objection, and restriction of processing), and data protection officer requirements.
Sensitive personal data: Processing requires explicit consent (except for health data processing by health professionals for treatment purposes, and other specified exceptions).
Cross-border transfers: Permitted where the destination country has adequate data protection standards, where appropriate safeguards are in place (standard contractual clauses, binding corporate rules, or codes of conduct), or where the data subject consents after being informed of the destination country's protection level.
Exemptions: Certain categories of data processing are excluded from the PDPA's scope, including processing by government agencies for national security purposes, processing by natural persons for personal or household activities, and processing for journalistic, artistic, or literary purposes.
Penalties: Administrative fines of up to THB 5 million (approximately
$140,000) for administrative violations, and criminal penalties of up to
1 year's imprisonment and/or a fine of up to THB 5 million for criminal offenses. For serious offenses involving the sale of personal data,
penalties increase to up to 3 years' imprisonment and/or a fine of up to
THB 20 million (approximately $560,000).
Regulator: The Ministry of Digital Economy and Society is responsible for administering the PDPA. The establishment of an independent data protection authority, the Expert Committee on Personal Data Protection,
has been delayed, raising concerns about regulatory independence and enforcement capacity.
The Philippines' Data Privacy Act (Republic Act No. 10173) was signed into law on August 15, 2012, and its Implementing Rules and Regulations took effect on September 8, 2016. Key features include:
Comprehensive framework: The Act covers the processing of all types of personal information and applies to natural and juridical persons in the Philippines, as well as those outside the Philippines if they process personal information of Philippine residents.
Sensitive personal information: Includes information about race,
ethnicity, health, sexual life, religious beliefs, and biometric data.
Processing requires explicit consent, except in limited circumstances.
Data subject rights: The Act provides for rights of access,
correction, deletion, and data portability. Data subjects may also lodge complaints with the National Privacy Commission.
Cross-border transfers: Permitted where the recipient country ensures an adequate level of protection, where appropriate safeguards are in place, or where the data subject consents.
National Privacy Commission (NPC): The NPC is the independent data protection authority, established in 2016. The NPC has the authority to investigate complaints, issue cease and desist orders, and impose administrative fines.
Penalties: Criminal penalties of 1–3 years' imprisonment and/or fines of PHP 500,000 to PHP 2,000,000 (approximately $8,500 to $34,000) for negligent violations; 3–6 years' imprisonment and/or fines of PHP
500,000 to PHP 4,000,000 for malicious violations. Administrative fines of up to PHP 5,000,000 (approximately $85,000) per violation.
Indonesia's Personal Data Protection Law (Undang-Undang Pelindungan
Data Pribadi, PDP Law) was enacted on October 17, 2022, and entered into force in stages, with most provisions effective October 17, 2024. Key features include:
Comprehensive framework: Indonesia's first standalone data protection law, covering the processing of personal data by both public and private sector organizations.
Personal data categories: The PDP Law distinguishes between general personal data and specific personal data (data concerning health,
biometrics, financial data, personal beliefs, and criminal records),
with enhanced protections for specific data requiring explicit consent.
Data subject rights: Access, correction, completion, deletion, data portability, objection, and restriction of processing.
Cross-border transfers: Permitted where the destination country has data protection standards at least equivalent to Indonesia's, or where appropriate safeguards are in place.
Data localization: Controllers and processors of specific categories of personal data (particularly data classified as strategic or by public entities) must store data within Indonesia or ensure that copies are maintained within Indonesian territory.
Penalties: Administrative fines of up to 2% of annual revenue;
criminal penalties of up to 5 years' imprisonment and a fine of up to
IDR 5 billion (approximately $310,000) for intentional violations; up to
7 years' imprisonment and a fine of up to IDR 70 billion (approximately
$4.3 million) for falsification of personal data.
Regulator: The establishment of an independent Data Protection
Supervisory Agency is required under the PDP Law but had not been fully operationalized as of early 2026, creating implementation challenges. In the interim, enforcement responsibilities are shared between the
Ministry of Communication and Information Technology (Kominfo) and sectoral regulators.
Vietnam's primary data protection instrument is Decree 13/2023/ND-CP
on Personal Data Protection (Nghị định 13/2023/NĐ-CP), which took effect on July 1, 2023. Vietnam does not yet have a standalone data protection law enacted by the National Assembly; the Decree was issued by the government under the authority of existing cybersecurity and telecommunications legislation. Key features include:
Personal data classification: The Decree classifies personal data into two categories: basic personal data and sensitive personal data
(data concerning political opinions, religious beliefs, health,
financial records, biometric data, genetic data, sexual orientation, and criminal records). Processing of sensitive data requires explicit consent.
Consent requirements: Processing requires the data subject's consent,
which must be given in writing or by electronic means. Consent may be withdrawn at any time.
Data protection impact assessment (DPIA): Organizations processing sensitive personal data of more than 10,000 data subjects, or processing personal data through automated decision-making, must conduct a DPIA
before commencing processing.
Cross-border transfers: Personal data may be transferred abroad where: the data subject consents after being informed of the transfer;
the destination country has data protection equivalent to Vietnam's; the transfer is necessary for the performance of a contract with the data subject; or the transfer is necessary for national defense, security, or public order.
Data localization: The Decree requires the storage of certain categories of personal data within Vietnam. Organizations processing personal data of Vietnamese data subjects must establish a data storage system in Vietnam or use data storage services provided by organizations that have established such systems in the country.
Data Protection Authority: The Department of Cybersecurity and
Hi-tech Crime Prevention under the Ministry of Public Security serves as the de facto data protection authority. The Decree provides for the establishment of a Personal Data Protection Commission, but as of early
2026, this body has not been formally established.
Penalties: Fines of up to VND 5 billion (approximately $200,000) for violations, with additional penalties under the Cybersecurity Law for more serious offenses, including suspension of operations for up to 12
months.

# Chapter 33: Brazil — Lei Geral de Proteção de Dados Pessoais (LGPD, Law 13,709/2018, effective 2020)

Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD, Law No.
13,709/2018) was signed into law on August 14, 2018, and its primary provisions entered into force on September 18, 2020, with the administrative sanction provisions becoming effective on August 1, 2021.
The LGPD represents the most comprehensive data protection law in Latin
America and one of the most GDPR-inspired statutes outside the European
Union.
The LGPD emerged from a complex legislative process. An initial bill
(PLS 330/2013) was introduced in the Senate in 2013, followed by extensive debate, public consultation, and multiple revisions. The final text passed the Senate in July 2018, at a moment of heightened public awareness following the Cambridge Analytica scandal. President Michel
Temer signed the law with several provisional measures (Medidas
Provisórias) that modified certain provisions, creating legislative ambiguity that was subsequently resolved by additional legislation.
The LGPD was initially to be enforced by the Autoridade Nacional de
Proteção de Dados (ANPD, National Data Protection Authority), but the
ANPD was not fully operationalized until 2020-2021. During the interim period, enforcement was technically handled by the Ministério da Justiça and the Conselho Administrativo de Defesa Econômica (CADE, Brazil's antitrust authority), though no significant enforcement actions were taken before the ANPD became operational.
Brazil's Constitution also protects privacy rights. Article 5, items
X and XII, establish the inviolability of privacy, personal honor, and image, and the secrecy of correspondence and communications. The Marco
Civil da Internet (Law No. 12,965/2014, Brazil's internet bill of rights) provides additional data protection provisions for the online environment.
Personal data (dados pessoais): Any information relating to an identified or identifiable natural person. The definition closely mirrors the GDPR's concept of personal data.
Sensitive personal data (dados pessoais sensíveis): Data concerning racial or ethnic origin, religious belief, political opinion, trade union or religious, philosophical, or political organization membership,
health or sex life data, and genetic or biometric data. The LGPD also classifies data concerning children and adolescents as sensitive.
Processing of sensitive data is subject to heightened restrictions.
Anonymized data (dados anonimizados): Data relating to a natural person who is not identifiable, considering the use of reasonable and available technical means at the time of processing. Anonymized data is excluded from the LGPD's scope.
Personal data of children and adolescents: Requiring specific protections, including the obligation to obtain consent from at least one parent or legal guardian (or, in the best interest of the child, by the authorities or guardians designated by law).
Controller (controlador): The natural or legal person, public or private, that takes decisions regarding the processing of personal data.
Equivalent to the GDPR's "data controller."
Operator (operador): The natural or legal person, public or private,
that processes personal data on behalf of the controller. Equivalent to the GDPR's "data processor."
Data protection officer (encarregado): The individual appointed by the controller to be the point of contact between the controller, the data subjects, and the ANPD. Commonly referred to in Brazil as the DPO
(Data Protection Officer), though the LGPD uses the Portuguese term
"encarregado."
Article 6 of the LGPD establishes ten principles that must govern the processing of personal data:
Purpose (finalidade): Processing must be carried out for legitimate,
specific, and explicit purposes informed to the data subject, without the possibility of subsequent processing incompatible with these purposes.
Adequacy (adequação): Processing must be compatible with the purposes informed to the data subject, in accordance with the context of the processing.
Necessity (necessidade): Processing must be limited to the minimum necessary for the fulfillment of its purposes, covering the relevant data, within the scope of the temporal duration of the processing, and the processing operations.
Free access (livre acesso): Data subjects must be guaranteed convenient and free access to information about the processing of their data and the entities that process it.
Transparency (transparência): Information regarding processing must be provided in a clear, accessible, and appropriate format.
Data security (segurança): Technical and administrative measures must be adopted to protect personal data from unauthorized access,
destruction, loss, alteration, communication, or any form of inappropriate or illegal processing.
Prevention (prevenção): Measures must be adopted to prevent the occurrence of damages from the processing of personal data.
Non-discrimination (não discriminação): Processing may not be used for discriminatory, unlawful, abusive, or excludatory purposes.
Accountability (responsabilização e prestação de contas): Controllers must demonstrate the adoption of effective measures capable of protecting personal data and confirm their compliance with the LGPD.
Compliance (conformidade): Data processing must be carried out in compliance with the law and in good faith.
Article 7 of the LGPD provides ten lawful bases for processing personal data — more than the GDPR's six:
Consent of the data subject, given in writing or by another means demonstrating the data subject's will.
Compliance with a legal or regulatory obligation by the controller.
Execution of public policies by the public administration.
Carrying out studies by research entities, ensuring anonymization of personal data whenever possible.
Execution of a contract or preliminary procedures related to a contract to which the data subject is a party.
Regular exercise of rights in judicial, administrative, or arbitration proceedings.
Protection of the data subject's life or physical safety.
Protection of health, exclusively by health professionals, health services, or sanitary authorities.
Legitimate interests of the controller or a third party, provided that the data subject's fundamental rights and liberties that require personal data protection prevail.
Credit protection (proteção do crédito), a uniquely Brazilian lawful basis that permits processing for credit scoring and financial risk assessment purposes.
The inclusion of "credit protection" as a standalone lawful basis reflects the importance of Brazil's credit information industry
(including agencies such as Serasa, SPC Brasil, and Boa Vista) and was a subject of significant legislative debate. Critics argue that it provides a broad exception that could undermine consent requirements for financial data processing.
Articles 17-22 of the LGPD grant data subjects the following rights:
Confirmation of the existence of processing: Right to confirm whether the controller processes their personal data.
Access: Right to access their personal data.
Correction: Right to request the correction of incomplete,
inaccurate, or outdated personal data.
Anonymization, blocking, or deletion: Right to request the anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data.
Portability: Right to request the portability of data to another service or product provider, through an express request and subject to commercial and industrial secrecy provisions.
Deletion of processed data with consent: Right to request the deletion of personal data processed based on consent.
Information about sharing: Right to obtain information about the entities with which the controller has shared personal data.
Information about the possibility of not providing consent: Right to be informed about the possibility of not providing consent and the consequences of refusing consent.
Revocation of consent: Right to revoke consent at any time.
Articles 33-36 of the LGPD establish the framework for international data transfers. Personal data may be transferred to other countries or international organizations under the following conditions:
To countries or international organizations that provide an adequate level of data protection, as determined by the ANPD.
Where the controller provides and ensures contractual clauses
(cláusulas contratuais específicas) providing adequate safeguards,
subject to ANPD approval.
To international organizations with which Brazil has entered into international agreements.
Where the transfer is necessary for the execution of a public policy or legal obligation by the controller.
Where the transfer is carried out by the controller based on the legitimate interest lawful basis, subject to safeguards approved by the
ANPD.
Where the transfer has received the specific consent of the data subject, with prior and express information about the non-adequacy of the destination country.
The ANPD has been slow to issue adequacy determinations, which has created practical uncertainty for international data transfers. As of early 2026, the ANPD has not formally recognized any country as providing an adequate level of protection, though this determination is expected to be issued for EU member states and other countries with comprehensive data protection regimes.
The ANPD was established by Law No. 13,853/2019 as a federal agency linked to the Presidency of the Republic. Key structural features:
Governance: The ANPD is led by a Board of Directors (Conselho
Diretor) consisting of five members, including a Chairperson, appointed by the President of the Republic. Board members serve four-year terms that may be renewed once.
Independence concerns: The ANPD's relationship with the executive branch has been the subject of debate. While the LGPD describes the ANPD
as an "autonomous" body, its budgetary and personnel dependence on the
Presidency has been cited as a potential limitation on its independence.
Powers: The ANPD has the authority to issue regulations and guidelines, conduct audits and inspections, process complaints and reports, impose administrative sanctions, promote awareness and training programs, and cooperate with international data protection authorities.
Sanctioning powers: The ANPD may issue warnings, fines, publication of infractions, blocking or deletion of personal data, partial or total suspension of database operations, and partial or total suspension of data processing activities.
The ANPD's enforcement activity has been accelerating. Notable actions include:
2022-2023: The ANPD issued its first administrative sanction decisions, focusing on smaller organizations as test cases for its enforcement framework.
2024: The ANPD initiated investigations into major technology companies operating in Brazil, including proceedings related to consent mechanisms, data breach notifications, and cross-border transfer compliance.
2025: The ANPD imposed its first significant fines on large corporations, signaling a shift toward full enforcement maturity. Total sanctions issued in 2025 exceeded BRL 30 million (approximately $5.3
million).
The LGPD provides for a graduated system of administrative sanctions
(Article 52):
Warning: Issued with a deadline for the adoption of corrective measures.
Simple fine: Up to 2% of the revenue of the enterprise, group, or conglomerate in Brazil in the preceding fiscal year, excluding subsidiaries, limited to BRL 50 million (approximately $8.8 million) per infraction.
Daily fine: Up to BRL 50 million per day of non-compliance with a warning or simple fine.
Publication of the infraction: Public disclosure of the infraction after due investigation.
Blocking or deletion of data: Of personal data that is irrelevant,
excessive, or processed in non-compliance with the LGPD.
Partial suspension of database functioning: For up to 6 months,
renewable for an equal period.
Partial or total suspension of data processing: For up to 6 months,
renewable for an equal period.
Partial or total prohibition of data processing activities.
In determining sanctions, the ANPD considers: the gravity and nature of the infraction; the health rights of the data subjects; the economic and financial condition of the infringer; the degree of cooperation; the operating methods; the adoption of good practices and governance programs; the adoption of codes of conduct, seals, and certificates; and prior compliance history.
While not directly part of the LGPD, the Brazilian Supreme Federal
Court's (STF) landmark ruling in June 2025 on Themes 533 and 987,
reinterpreting Article 19 of the Marco Civil da Internet, has profoundly affected the broader data protection landscape. The ruling held that:
Platform operators can be held liable for third-party content without requiring a prior court order.
The previous "notice-and-takedown" regime is replaced by a proactive duty of care requiring platforms to take preventive measures against unlawful content.
This shift creates significant overlap with the LGPD's accountability principle and increases compliance obligations for digital platforms operating in Brazil.
The ruling is expected to have major implications for platform liability, content moderation practices, and the intersection between data protection and intermediary liability in Brazil.
The full text of the LGPD (Law No. 13,709/2018, as amended) is available in Portuguese from the Planalto Palace website
(http://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13709.htm).
The ANPD's official website (https://www.gov.br/anpd) provides regulations, guidance, and enforcement decisions in Portuguese, with selected materials translated into English and Spanish.

# Chapter 34: Argentina — Ley de Protección de Datos Personales (2000)

Argentina's Ley de Protección de Datos Personales (Law No. 25,326)
was enacted on October 30, 2000, making it one of the earliest comprehensive data protection laws in Latin America and among the first in the world outside Europe. The law was largely inspired by EU
Directive 95/46/EC and was designed to facilitate data flows between
Argentina and the European Union.
Argentina's early adoption of comprehensive data protection legislation was motivated by both domestic concerns about privacy rights and the strategic goal of obtaining EU adequacy recognition, which would enable the free flow of personal data from the EU to Argentina. This adequacy was granted by the European Commission in 2003, making
Argentina the first country in Latin America — and one of the first outside the EEA — to receive such recognition.
The law is regulated by Decree 1558/2001 and supplemented by
Disposition 11/2006 of the Dirección Nacional de Protección de Datos
Personales (DNPDP, National Directorate for Personal Data Protection),
which provides detailed implementing rules.
Article 43 of the Argentine Constitution (as amended in 1994)
establishes the right to habeas data, providing that:
Any person may request information about personal data concerning them that is contained in public registries or databases, or in private ones intended to provide reports.
Information must be truthful and may not affect the honor or reputation of the person concerned.
The source of the data must be disclosed.
The owner of the database must correct or suppress the data if it is false or inaccurate.
This constitutional provision provides a strong legal foundation for data protection rights in Argentina and gives individuals a direct constitutional cause of action for data protection violations.
Law No. 25,326 establishes the following key principles:
Lawfulness: Data processing must be lawful, adequate, relevant, and not excessive in relation to the scope and purpose for which it was collected.
Consent: Processing generally requires the prior, express, and informed consent of the data subject. Consent is not required where the data is obtained from publicly accessible sources, is collected for the exercise of public authority functions, or is collected for health,
safety, or public interest purposes.
Purpose limitation: Personal data may not be collected for purposes other than those declared and lawful, nor may it be communicated to third parties without the data subject's consent.
Data quality: Data must be accurate, complete, and updated as necessary.
Information obligation: Data subjects must be informed of the existence of a database, its purpose, the identity of the data controller, and the data subject's rights.
Security: Data controllers must adopt technical and organizational measures to ensure the security and confidentiality of personal data.
Retention limitation: Personal data must be canceled when it has fulfilled the purpose for which it was collected.
The law provides enhanced protections for sensitive personal data,
defined as data revealing racial or ethnic origin, political opinions,
religious or philosophical beliefs, trade union membership, health, or sex life. Processing of sensitive data is generally prohibited, with exceptions for:
Statistical or scientific purposes, with dissociation of data.
Health or epidemiological purposes, by health professionals or health authorities.
Court orders.
National defense or public security purposes.
Data subjects have the following rights under Argentine law:
Right of access and habeas data: The right to access personal data contained in any database, whether public or private.
Right of rectification and suppression: The right to request correction or deletion of inaccurate, incomplete, or excessive personal data.
Right to object: The right to object to the processing of personal data in certain circumstances.
Right to confidentiality: The right to have personal data treated confidentially.
The constitutional right of habeas data provides an accelerated judicial procedure through which data subjects can seek the protection of their rights before a court, providing a practical and effective remedy.
Argentina's cross-border transfer framework was designed to align with EU standards. Personal data may be transferred to other countries or international organizations where:
Adequate levels of protection exist.
The data subject has given express and informed consent.
The transfer is necessary for the performance of a contract or legal obligation.
The transfer is necessary for the exercise or defense of a legal claim.
An international treaty provides adequate protection.
The 2003 EU adequacy decision (2003/490/EC) found that Argentina provides an "adequate level of protection" for personal data transferred from the EEA. This determination was reaffirmed following subsequent reviews, and Argentina remains one of only a handful of non-European countries with EU adequacy recognition.
The DNPDP, within the Ministry of Justice and Human Rights, is responsible for administering the law. Key functions include:
Maintaining the National Registry of Databases.
Processing complaints and conducting investigations.
Issuing guidance and recommendations.
Imposing sanctions for violations.
Administrative fines: Ranging from ARS 1,000 to ARS 100,000
(approximately $0.60 to $60 at current official exchange rates, though penalties are periodically updated). The law provides for the possibility of significantly higher fines through regulatory updates.
Database suspension or cancellation: For serious or repeated violations.
Publication of infractions.
Criminal penalties: The Criminal Code (as amended by Law No. 26,388
in 2008) provides for penalties of six months to three years'
imprisonment for the unauthorized insertion of personal data into a database, and for the provision of false or incomplete information in response to a habeas data request.
Criticism: The DNPDP has been criticized for its limited enforcement capacity, modest budget, and position within the executive branch rather than as an independent authority. Argentina's chronic economic instability and high inflation have also eroded the real value of administrative fines, reducing their deterrent effect.
Multiple bills to modernize Argentina's data protection framework have been introduced in Congress in recent years. Proposed reforms include:
Strengthening the DNPDP's independence and enforcement powers.
Updating the legal bases for processing to reflect modern data practices.
Introducing explicit provisions on automated decision-making, data portability, and the right to be forgotten.
Updating penalties to reflect current economic conditions.
Establishing mandatory data breach notification requirements.
As of early 2026, none of these modernization bills has been enacted,
though legislative momentum has increased following the Argentine government's interest in maintaining EU adequacy recognition and aligning with evolving international data protection standards.
The full text of Law No. 25,326 is available in Spanish from the
Argentine Ministry of Justice and Human Rights website
(http://www.jus.gob.ar) and from the Infoleg database
(http://infoleg.gob.ar). Dispositions and guidance from the DNPDP are available from the DNPDP website.

# Chapter 35: Additional Latin American Jurisdictions

Mexico's Federal Law on the Protection of Personal Data Held by
Private Parties (Ley Federal de Protección de Datos Personales en
Posesión de los Particulares) was enacted on April 27, 2010, and entered into force on July 5, 2010 (with implementing regulations effective
December 22, 2011). Mexico also enacted a separate law for the public sector: the Ley General de Protección de Datos Personales en Posesión de
Sujetos Obligados (2017).
Key features:
ARCO rights: Data subjects have the right of Access (Acceso),
Rectification (Rectificación), Cancellation (Cancelación), and
Opposition (Oposición) — collectively known as ARCO rights.
Consent-based framework: Processing generally requires consent, with exceptions for certain categories of processing (including processing for compliance with legal obligations, emergency situations, and processing of data in the public domain).
Data protection principles: Legality, consent, information, quality,
purpose, loyalty, proportionality, and accountability.
Sensitive personal data: Enhanced protections for data concerning health, sexual orientation, ethnic or racial origin, religious beliefs,
political opinions, union membership, and biometric data.
Cross-border transfers: Permitted where the destination country provides an adequate level of protection, where the data subject consents, or where an international treaty applies.
Regulatory authority: The Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI, National
Institute for Transparency, Access to Information, and Personal Data
Protection). INAI is an autonomous constitutional body with enforcement powers including the ability to impose fines.
Penalties: Administrative fines of up to MXN 20,000,000
(approximately $1,000,000 at 2025 exchange rates) for data protection violations, with the possibility of criminal sanctions in certain cases.
INAI's challenges: INAI has faced budget cuts and political pressure in recent years, raising concerns about its capacity to enforce data protection law effectively.
Mexico has sought EU adequacy recognition but has not yet obtained it, though the quality of Mexico's legal framework is generally regarded as comparable to other countries that have received adequacy determinations.
Chile's data protection framework is primarily based on
Constitutional Article 19, No. 4 (which protects private life and personal data) and Law No. 19,628 on the Protection of Private Life
(1999). Chile was the first country in South America to enact a data protection law, but the 1999 law was widely regarded as outdated and insufficiently comprehensive.
A major reform — the Ley de Protección de Datos Personales (Bill modifying Law No. 19,628) — was enacted in 2023 after a lengthy legislative process that began in 2017. Key features of the amended framework include:
Creation of an independent data protection authority: The Agencia de
Protección de Datos Personales (Data Protection Agency), an autonomous body responsible for regulating, supervising, and sanctioning violations of data protection law.
Expanded data subject rights: Including the right to data portability, the right to be forgotten (in certain circumstances), and the right to object to automated decision-making.
Consent requirements: Strengthened consent standards, including the requirement for explicit consent for the processing of sensitive data.
Data breach notification: Mandatory notification to the Agency and affected individuals within 72 hours of a qualifying data breach.
Data Protection Officer: Requirement for designated data protection officers for organizations processing personal data at scale.
Penalties: Fines of up to 5,000 UTM (approximately USD 400,000) for the most serious violations, and up to 20,000 UTM (approximately USD 1.6
million) for repeated or aggravated violations.
Cross-border transfers: Permitted where the destination country provides an adequate level of protection or where appropriate safeguards are in place.
The 2023 reform significantly modernized Chile's data protection framework, bringing it into closer alignment with the GDPR and positioning Chile as a regional leader in data protection alongside
Brazil and Argentina.
Colombia's Ley 1581 de 2012 (Law on the Protection of Personal Data)
established a comprehensive framework for the protection of personal data in Colombia, supplemented by Decree 1377 of 2013 (implementing regulations) and Decree 886 of 2014 (sectoral provisions for the financial sector). Key features include:
Habeas data right: Constitutional right to access, update, and rectify personal information (Article 15 of the Colombian
Constitution).
Principles: Legality, purpose, freedom, truthfulness/quality,
transparency, access, restricted circulation, and security.
Processing bases: Consent is the primary basis, though the law provides exceptions for legal obligations, contractual necessity, public interest, and statistical or scientific purposes.
Sensitive data: Enhanced protections for data concerning racial or ethnic origin, political orientation, religious or philosophical beliefs, membership in trade unions, health data, and sex life.
Processing requires express authorization.
Children's data: Processing of children's data requires the authorization of the legal representative, ensuring the best interests of the child.
Cross-border transfers: Permitted where the destination country provides an adequate level of protection, where the data subject consents, or where a contract providing adequate safeguards is in place.
Regulatory authority: The Superintendencia de Industria y Comercio
(SIC, Superintendency of Industry and Commerce), which serves as both
Colombia's competition authority and data protection authority. The SIC
has enforcement powers including the ability to impose fines and issue compliance orders.
Penalties: Fines of up to COP 2 billion (approximately USD 500,000)
for violations.
Peru's Personal Data Protection Law (Ley de Protección de Datos
Personales, Law No. 29733) was enacted on July 3, 2011, and entered into force in 2013. Key features include:
Constitutional basis: Article 2, paragraph 5 of the Peruvian
Constitution protects the right to privacy and personal data.
Principles: Legality, purpose, proportionality, transparency,
quality, security, and accountability.
Consent: Processing requires the prior, express, informed, and unequivocal consent of the data subject, with exceptions for legal obligations, public interest, and data in the public domain.
ARCO rights: Access, rectification, cancellation, and opposition
(following the Mexican model).
Sensitive data: Enhanced protections requiring express consent,
including data on racial or ethnic origin, health, sexual life,
religious beliefs, financial data, and biometric data.
Cross-border transfers: Permitted where adequate protection is ensured, through contractual safeguards, or with the data subject's consent.
Regulatory authority: The Ministerio de Justicia y Derechos Humanos
(Ministry of Justice and Human Rights) administers the law, with the
Autoridad Nacional de Protección de Datos Personales (National Authority for Personal Data Protection) being established as the dedicated regulator.
Penalties: Administrative fines of up to 100 UIT (approximately USD
470,000 at 2025 rates).
Uruguay's Personal Data Protection Law (Ley de Protección de Datos
Personales, Law No. 18.331) was enacted on August 11, 2008, and entered into force on January 1, 2009. Key features include:
EU adequacy: Uruguay was the second Latin American country (after
Argentina) to receive EU adequacy recognition, granted by European
Commission Decision 2012/484/EU in August 2012. This determination facilitates data flows between the EU and Uruguay.
Principles: Lawfulness, purpose, consent, data quality, information,
security, proportionality, and accountability.
Habeas data: Constitutional right to access, rectify, and cancel personal data (Article 36 of the Uruguayan Constitution).
Sensitive data: Enhanced protections requiring express consent,
including data on racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, and sex life.
Cross-border transfers: Permitted where adequate protection is ensured, where the data subject consents, or where an international treaty applies. The EU adequacy determination means transfers from the
EEA to Uruguay may proceed without additional safeguards.
Regulatory authority: The Unidad Reguladora y de Control de Datos
Personales (URCDP, Regulatory and Control Unit for Personal Data) within the Ministry of Industry, Energy and Mining. The URCDP has enforcement powers, including the ability to impose fines and issue compliance orders.
Penalties: Administrative fines of up to 500,000 UYU (approximately
USD 12,000) for individuals and up to 2,000,000 UYU (approximately USD
48,000) for legal entities. These penalties have been criticized as insufficient relative to the scale of potential harm, though Uruguay's small economy and limited number of major data controllers have mitigated practical enforcement concerns.
Modernization efforts: A bill to update the 2008 law has been under consideration, proposing strengthened consent requirements, enhanced data subject rights (including data portability and the right to be forgotten), updated cross-border transfer rules, and increased penalties.

# Chapter 36: South Africa — Protection of Personal Information Act (POPIA, Act 4 of 2013, effective 2020/2021)

South Africa's Protection of Personal Information Act (POPIA, Act No.
4 of 2013) was signed into law on November 19, 2013, but its commencement was phased over several years due to the need for supporting regulations and institutional capacity. The most significant provisions, including the data processing conditions and the establishment of the Information Regulator's enforcement powers, took effect on July 1, 2020. A 12-month grace period for compliance expired on June 30, 2021, though enforcement has been gradual.
POPIA emerged from a lengthy legislative process that began with the
South African Law Reform Commission's investigation into privacy and data protection in the early 2000s. The Act is heavily influenced by the
EU Data Protection Directive (95/46/EC) and was designed to align South
Africa's data protection framework with international best practices while reflecting South Africa's constitutional commitment to privacy rights.
The right to privacy is enshrined in Section 14 of the Constitution of the Republic of South Africa, 1996, which provides that everyone has the right to privacy, including the right not to have their person or home searched, their property searched, their possessions seized, or the privacy of their communications infringed. POPIA gives legislative effect to this constitutional right in the context of personal information processing.
Personal information: Information relating to an identifiable,
living, natural person, and where it is applicable, an identifiable,
existing juristic person. The definition is broad, covering a wide range of data types, including correspondence, contact details, financial information, health information, biometric data, and behavioral data.
Special personal information: A category equivalent to the GDPR's
"special categories of personal data," covering:
Race, ethnic or social origin, political opinions, religious or philosophical beliefs.
Trade union membership.
Health, sex life, or biometric data.
Criminal behavior or unlawful conduct.
Children's personal information.
Processing of special personal information is generally prohibited unless one of the specific exceptions applies (consent, legal obligation, public interest, etc.).
Responsible party: The entity that determines the purpose and means of processing personal information. Equivalent to the GDPR's "data controller."
Operator: The entity that processes personal information on behalf of a responsible party. Equivalent to the GDPR's "data processor."
Information officer: A designated individual within the responsible party's organization who is responsible for encouraging compliance with
POPIA. The Information Officer is similar to but distinct from a Data
Protection Officer under the GDPR — the Information Officer's duties include developing and implementing compliance frameworks, conducting awareness programs, and liaising with the Information Regulator.
POPIA establishes eight conditions that must be met for personal information processing to be lawful:
Accountability: The responsible party must ensure that all conditions of lawful processing are complied with. The responsible party bears the overall responsibility for compliance.
Processing limitation: Personal information must be processed lawfully, with minimal intrusion, in a way that serves the legitimate purpose of collection. Collection must be limited to what is adequate,
relevant, and not excessive.
Purpose specification: Personal information must be collected for a specific, explicitly defined, and lawful purpose related to the function or activity of the responsible party.
Further processing limitation: Further processing must be compatible with the purpose for which the information was collected.
Information quality: The responsible party must take reasonable steps to ensure that personal information is complete, accurate, up to date,
and not misleading.
Openness: The responsible party must notify the data subject (the
Regulator in prescribed circumstances) of the collection of personal information, including the identity of the responsible party, the purpose of collection, and the data subject's rights.
Security safeguards: The responsible party must secure the integrity and confidentiality of personal information by taking appropriate,
reasonable, technical, and organizational measures to prevent loss,
unauthorized access, or unauthorized processing.
Data subject participation: Data subjects have the right to request access to their personal information, to request the correction or deletion of inaccurate or outdated information, and to object to the processing of their personal information. The responsible party must comply with such requests within a prescribed period.
POPIA grants data subjects the following rights:
Right to be informed: The right to be notified of the collection and processing of their personal information.
Right to access: The right to request access to their personal information held by a responsible party.
Right to correction and deletion: The right to request the correction or deletion of inaccurate, irrelevant, excessive, or outdated personal information.
Right to object to processing: The right to object to the processing of their personal information, including direct marketing and automated decision-making.
Right to complain to the Information Regulator: The right to lodge a complaint with the Information Regulator if they believe their rights have been violated.
Right to compensation: The right to claim compensation for damage suffered as a result of a breach of POPIA (Section 99).
Section 72 of POPIA restricts the transfer of personal information to third parties in foreign countries unless:
The receiving country has legislation providing an adequate level of protection (as determined by the Information Regulator).
The responsible party and the receiving party enter into a binding agreement providing adequate safeguards for the processing of personal information.
The data subject consents to the transfer.
The transfer is necessary for the performance of a contract between the data subject and the responsible party.
The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the responsible party and a third party.
The Information Regulator has not yet issued a formal list of countries with adequate data protection. In the interim, responsible parties must rely on contractual safeguards, consent, or the other available mechanisms.
POPIA imposes stringent restrictions on direct marketing using personal information:
Consent requirement: Processing of personal information for direct marketing requires the prior consent of the data subject, or the data subject must be an existing customer and the marketing must be related to products or services previously offered.
Opt-out mechanism: The data subject must be given the opportunity to opt out of receiving direct marketing at any time.
Existing customer exception: Responsible parties may use personal information of existing customers for direct marketing of similar products and services, provided the customer has been given a reasonable opportunity to opt out.
Electronic communications: The Electronic Communications and
Transactions Act (ECTA) imposes additional consent requirements for electronic direct marketing (email, SMS), requiring prior consent for all electronic marketing communications regardless of existing customer status.
The Information Regulator was established in 2016 as an independent body under Chapter 5 of the Promotion of Access to Information Act
(PAIA), with its POPIA enforcement powers activated in 2020. Key features:
Governance: The Information Regulator is led by a Chairperson and members appointed by the President of South Africa on the recommendation of the National Assembly. The Regulator is intended to be independent,
though its relationship with the Department of Justice and
Constitutional Development has been the subject of debate.
Functions: The Information Regulator is responsible for both POPIA
and PAIA enforcement, monitoring compliance with both statutes, issuing guidance and codes of conduct, handling complaints, and conducting assessments.
Enforcement powers: The Information Regulator may issue enforcement notices requiring compliance, conduct investigations, and refer serious violations to the Special Tribunal for adjudication and the imposition of fines. The Special Tribunal, established under POPIA, has the authority to impose administrative fines of up to R10 million
(approximately $550,000) per violation.
Challenges: The Information Regulator has faced significant resource constraints, staffing challenges, and a backlog of complaints. As of early 2025, the Regulator had received thousands of complaints but had issued a relatively small number of enforcement notices, reflecting the gap between its statutory mandate and its operational capacity.
POPIA provides for a range of penalties:
Administrative fines: Up to R10 million (approximately $550,000) for serious violations, imposed by the Special Tribunal upon referral by the
Information Regulator.
Imprisonment: Up to 10 years' imprisonment (or a fine, or both) for certain criminal offenses, including the unlawful processing of special personal information, the failure to comply with an enforcement notice,
and the obstruction of the Information Regulator's functions.
Compensation: Data subjects may claim compensation through the courts for damage suffered as a result of a POPIA violation. The burden of proof is on the responsible party to show that it was not negligent.
POPIA provides for several exemptions, including:
Processing for national security purposes: Exempt from most conditions.
Processing for law enforcement purposes: Exempt where necessary for the prevention, detection, investigation, or prosecution of offenses.
Journalistic purposes: Processing for journalistic purposes is exempt from certain conditions, subject to a public interest balancing test.
Research and statistics: Processing for research or statistical purposes is exempt from certain conditions, provided that the results are not published in an identifiable form.
Domestic purposes: Processing by a natural person in the course of purely personal or household activities.
The full text of POPIA (Act No. 4 of 2013) is available from the
South African Government Gazette (https://www.gov.za) and the
Information Regulator's website (https://www.inforegulator.org.za).
Regulations issued under POPIA, including the Information Regulator's guidance notes, are also available from the Regulator's website.

# Chapter 37: Additional African Jurisdictions

Nigeria's Data Protection Act (DPA) was signed into law on June 14,
2023, establishing Nigeria's first comprehensive data protection framework. Prior to the DPA, data protection in Nigeria was governed by the Nigeria Data Protection Regulation (NDPR) of 2019, issued by the
National Information Technology Development Agency (NITDA) as an administrative regulation. The NDPR was Nigeria's first data protection instrument but lacked the force of primary legislation, which limited its effectiveness.
Key features of the DPA:
Scope: Applies to the processing of personal data by public and private entities in Nigeria, as well as entities outside Nigeria that process personal data of individuals in Nigeria or offer goods/services to individuals in Nigeria.
Principles: Lawfulness, fairness, transparency, purpose limitation,
data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.
Consent: Processing requires valid consent, defined as any freely given, specific, informed, and unambiguous indication of the data subject's wishes. Consent may be withdrawn at any time.
Sensitive personal data: Enhanced protections for data on health,
biometrics, genetic data, racial or ethnic origin, religious or philosophical beliefs, sex life, trade union membership, and political opinions. Processing requires explicit consent.
Children's data: Processing of children's data requires the consent of a parent or legal guardian. The Act sets the age of consent at 18,
though the Nigeria Data Protection Commission (NDPC) may issue guidance on age-appropriate consent mechanisms.
Cross-border transfers: Permitted where the destination country provides an adequate level of protection, where appropriate safeguards are in place, or where the data subject consents after being informed of the risks.
Data protection impact assessment (DPIA): Required for processing that is likely to result in a high risk to the rights and freedoms of data subjects, including large-scale processing of sensitive data and systematic monitoring.
Data breach notification: Controllers must notify the NDPC within 72
hours of becoming aware of a personal data breach that poses a risk to the rights and freedoms of data subjects.
Regulatory authority: The Nigeria Data Protection Commission (NDPC),
established as an independent body under the DPA. The NDPC replaced
NITDA's regulatory functions for data protection. The NDPC is led by a
National Commissioner and has the authority to investigate complaints,
issue compliance notices, impose administrative fines, and register data controllers.
Penalties: Administrative fines of up to 2% of annual gross revenue for the preceding year for the most serious violations, or NGN 10
million (approximately $6,500), whichever is greater. Criminal penalties of up to 3 years' imprisonment and/or fines for certain offenses.
Significance: Nigeria's DPA is the most significant data protection development in Africa's most populous country (over 220 million people)
and is expected to serve as a model for other Anglophone African countries developing data protection frameworks.
Kenya's Data Protection Act (DPA, Act No. 24 of 2019) was signed into law on November 8, 2019, and entered into force in late 2019, with supporting regulations issued in subsequent years. Kenya's Constitution
(2010) establishes a right to privacy in Article 31, which provides the constitutional foundation for data protection.
Principles: Lawfulness, fairness, transparency, purpose limitation,
data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. The Act closely follows the GDPR's approach.
Consent: Processing requires consent, which must be freely given,
specific, and informed. The Act includes detailed provisions on the validity of consent.
Sensitive personal data: Enhanced protections for data on health,
ethnicity, political opinions, religious beliefs, sexual orientation,
criminal records, biometric data, and genetic data. Processing requires explicit consent, with limited exceptions.
Data subject rights: Access, rectification, erasure, data portability, objection, and restriction of processing. The Act also provides for the right not to be subject to automated decision-making.
Children's data: Processing of children's data requires the consent of a parent or guardian. The Act defines a child as a person under
18.
Cross-border transfers: Permitted where the destination country has adequate data protection laws, where appropriate contractual safeguards are in place, or where the data subject consents.
Registration requirement: Data controllers and processors must register with the Office of the Data Protection Commissioner (ODPC). The registration requirement creates a public record of data processing activities in Kenya.
Regulatory authority: The Office of the Data Protection Commissioner
(ODPC), an independent office established under the Act. The ODPC is led by the Data Protection Commissioner, appointed for a fixed term. The
ODPC has the authority to investigate complaints, issue enforcement notices, conduct audits, and impose administrative fines.
Penalties: Administrative fines of up to KES 5 million (approximately
$34,000) or up to 1% of annual gross turnover for certain violations.
Criminal penalties of up to 2 years' imprisonment and/or a fine of up to
KES 5 million for certain offenses.
Notable developments: The ODPC has been increasingly active since
2022, issuing guidance on data breach notification, cross-border transfers, and the processing of personal data in the financial sector.
The Commission has also issued decisions on complaints against telecommunications companies and financial institutions.
Egypt's Personal Data Protection Law (Law No. 151 of 2020) was published in the Official Gazette in August 2020, with its executive regulations issued in 2021. Key features:
Scope: Applies to the processing of personal data by natural and legal persons in Egypt, as well as entities outside Egypt that process personal data of individuals located in Egypt. The law covers both automated and manual processing.
Principles: Lawfulness, fairness, transparency, purpose limitation,
data minimization, accuracy, storage limitation, and security.
Sensitive data: Enhanced protections for data concerning health,
genetics, biometrics, political opinions, religious beliefs, sex life,
criminal records, and bank account data. Processing requires explicit written consent.
Consent: Processing requires consent, except where processing is necessary for legal obligations, public interest, or the exercise of legal claims.
Data subject rights: Access, correction, deletion, data portability,
restriction of processing, objection, and the right to be informed about automated decision-making.
Data localization: Personal data of Egyptian data subjects must be stored on servers located within Egypt, or in a country with an adequate level of protection. The data localization requirement has been a subject of significant debate, with critics arguing that it may impede international data flows and increase costs for businesses operating in
Egypt.
Cross-border transfers: Permitted where the destination country has adequate protection, where the data subject consents, or where appropriate contractual safeguards are in place. Transfers to countries without adequate protection require approval from the relevant regulatory authority.
Data breach notification: Controllers must notify the relevant regulatory authority within 72 hours of becoming aware of a breach that poses a risk to data subjects.
Regulatory authority: The Personal Data Protection Center (PDPC),
established within the Ministry of Communications and Information
Technology. The PDPC is responsible for administering the law,
maintaining the data controllers register, and enforcing compliance.
Penalties: Criminal penalties of up to 5 years' imprisonment and/or fines of up to EGP 20 million (approximately $400,000) for violations.
Administrative fines may also be imposed for less serious violations.
Morocco's Law 09-08 on the Protection of Individuals with Respect to the Processing of Personal Data was enacted in 2009 and represents one of the earliest data protection laws in Africa. Key features:
Scope: Applies to the processing of personal data by automated or semi-automated means in Morocco, as well as processing by non-automated means where the data is contained in a filing system.
Principles: Finality and legitimacy, proportionality, data quality,
limited retention, and security.
Consent: Processing generally requires consent, with exceptions for legal obligations, vital interests, and public interest purposes.
Sensitive data: Enhanced protections for data on racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, and sex life.
Data subject rights: Access, rectification, opposition, and deletion.
Data subjects may also object to the processing of their data for direct marketing purposes.
Cross-border transfers: Permitted with the authorization of the
Commission Nationale de Contrôle de la Protection des Données à
Caractère Personnel (CNDP), the Moroccan data protection authority,
unless the receiving country provides an adequate level of protection.
Regulatory authority: The CNDP (Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel), an independent body established by Law 09-08. The CNDP has the authority to receive complaints, conduct investigations, issue recommendations, and impose sanctions.
EU adequacy: Morocco obtained EU adequacy recognition in 2012
(Decision 2012/409/EU), making it the first African country to receive such recognition. This determination facilitates data flows between the
EU and Morocco and has supported Morocco's position as a business process outsourcing and technology services hub.
Penalties: Criminal penalties of up to 3 years' imprisonment and fines of up to MAD 300,000 (approximately $30,000) for violations.
Modernization: Morocco has been considering amendments to Law 09-08
to align with evolving international standards, including enhanced provisions on data breach notification, cross-border transfers, and the right to data portability.
Rwanda's Law N°058/2021 on the Protection of Personal Data and
Privacy was enacted in October 2021 and entered into force in 2022,
replacing earlier provisions in Law N°058/2018. Key features:
Scope: Applies to the processing of personal data by public and private entities in Rwanda, as well as entities outside Rwanda that process personal data of individuals in Rwanda.
Consent: Processing requires consent, with exceptions for legal obligations, public interest, and legitimate interests.
Sensitive data: Enhanced protections for data on health, biometrics,
genetic data, race, ethnicity, political opinions, religious beliefs,
sex life, and criminal records.
Data subject rights: Access, rectification, erasure, data portability, objection, and restriction of processing.
Cross-border transfers: Permitted where the destination country has adequate protection, where appropriate safeguards are in place, or where the data subject consents.
Data breach notification: Controllers must notify the relevant authority within 72 hours of becoming aware of a notifiable data breach.
Regulatory authority: The National Cyber Security Authority (NCSA)
and the National Intelligence and Security Services (NISS) share regulatory oversight. Rwanda does not have a dedicated independent data protection authority, which has been noted as a potential weakness in the framework.
Significance: Rwanda's data protection law reflects the country's broader strategy of positioning itself as a technology and innovation hub in East Africa, complementing its investments in digital infrastructure and e-government services.
The African Union Convention on Cyber Security and Personal Data
Protection (the Malabo Convention) was adopted by the African Union
Assembly in June 2014 at the Extraordinary Session in Malabo, Equatorial
Guinea. The Convention entered into force on June 8, 2023, following ratification by the required number of AU member states.
Dual scope: The Malabo Convention addresses both cybersecurity and personal data protection, reflecting the interconnected nature of these issues.
Data protection principles: The Convention establishes principles for the processing of personal data, including lawfulness, purpose limitation, data quality, limited retention, security, and accountability.
Data subject rights: Access, correction, deletion, and objection.
Cross-border data transfers: The Convention provides a framework for cross-border transfers within Africa, encouraging member states to develop mutual recognition arrangements.
Data protection authorities: The Convention requires member states to establish independent data protection authorities.
Signatory states: As of early 2026, over 30 AU member states have signed the Convention, though ratification by individual member states has been slow. Countries that have ratified include Angola, Burkina
Faso, Cabo Verde, Chad, Congo, Gambia, Ghana, Guinea, Madagascar, Mali,
Mauritania, Mauritius, Mozambique, Namibia, Nigeria, São Tomé and
Príncipe, Senegal, and South Africa.
Significance: The Malabo Convention represents Africa's first continent-wide instrument on data protection and cybersecurity. While it does not have direct effect in member states (which must implement it through domestic legislation), it provides a harmonized framework that can guide national lawmaking and facilitate cross-border data flows within the African Continental Free Trade Area (AfCFTA).

# Chapter 38: Middle Eastern Jurisdictions

The United Arab Emirates' Federal Decree-Law No. 45 of 2021 on the
Protection of Personal Data (the "Data Protection Law" or DPL) was issued on September 27, 2021, and its implementing regulations were issued in 2022-2023. The DPL represents the UAE's first comprehensive federal data protection framework and applies across all seven emirates.
Key features include:
Scope: Applies to the processing of personal data by controllers and processors in the UAE, as well as entities outside the UAE that process personal data of individuals in the UAE or offer goods/services to individuals in the UAE. The law covers both automated and manual processing.
Exemptions: The DPL contains broad exemptions for processing by government entities (for security, judicial, and public interest purposes), banking and financial services regulated by the Central Bank,
health data processing for public health purposes, and personal data processed by free zone entities subject to their own data protection regulations (such as DIFC and ADGM).
Principles: Lawfulness, fairness, transparency, purpose limitation,
data minimization, accuracy, storage limitation, and confidentiality and security.
Consent: Processing requires valid consent, which must be free,
specific, informed, and unambiguous. Consent may be withdrawn at any time. Several exceptions to the consent requirement apply, including processing for legal obligations, public interest, vital interests, and legitimate interests.
Sensitive data: Enhanced protections for data concerning racial or ethnic origin, political opinions, religious beliefs, health, sex life,
genetic data, and biometric data. Processing requires explicit consent.
Data subject rights: Access, correction, deletion, restriction of processing, data portability, and objection.
Cross-border transfers: Permitted where the destination country provides an adequate level of protection (as determined by the relevant
UAE authority), where appropriate contractual safeguards are in place,
where the data subject consents, or where the transfer is necessary for legal proceedings.
Data breach notification: Controllers must notify the relevant authority and affected individuals within 72 hours of becoming aware of a data breach that poses a risk to the rights and freedoms of data subjects.
Regulatory authority: The Office of the Data Protection Commissioner,
established within the UAE's Ministry of Community Development (later transferred to the Digital Government Authority). The Commissioner has the authority to issue regulations, investigate complaints, and impose administrative penalties.
Penalties: Administrative fines for violations, as specified in the implementing regulations. The law also provides for criminal penalties in certain cases, including the unauthorized disclosure of personal data.
The Dubai International Financial Centre (DIFC) enacted its own comprehensive data protection law — DIFC Data Protection Law No. 5 of
2020 (DPL No. 5), effective October 1, 2020. This is a separate legal regime applicable to entities registered or operating within the DIFC
free zone. Key features include:
GDPR-inspired: DPL No. 5 closely follows the GDPR's structure,
concepts, and terminology, including the concepts of controllers,
processors, data subject rights, and the lawful bases for processing.
Registration requirement: Data controllers and processors must register with the DIFC Commissioner of Data Protection.
Regulatory authority: The Commissioner of Data Protection, an independent authority established within the DIFC.
Penalties: Administrative fines of up to USD 100,000 for the most serious violations.
Significance: The DIFC's comprehensive data protection framework positions the free zone as a regional hub for data-intensive businesses and financial services requiring EU-equivalent data protection standards.
The Abu Dhabi Global Market (ADGM) enacted its Data Protection
Regulations 2021 (DPR 2021), effective January 1, 2022, replacing the earlier 2018 regulations. Key features include:
GDPR alignment: DPR 2021 closely aligns with the UK GDPR
(post-Brexit), providing data protection standards that are recognized as adequate by the UK government.
Registration requirement: Data controllers must register with the
ADGM Registration Authority.
Regulatory authority: The ADGM Financial Services Regulatory
Authority (FSRA), which serves as the data protection supervisory authority within the ADGM.
UK adequacy: The UK has recognized the ADGM as providing an adequate level of data protection, facilitating data flows between the ADGM and the UK.
Saudi Arabia's Personal Data Protection Law (PDPL, نظام حماية
البيانات الشخصية) was approved by Royal Decree No. M/85 on September 9,
2023, and entered into force on September 14, 2023, with a one-year grace period for compliance expiring on September 14, 2024. The PDPL
replaces the earlier regulatory framework under the Kingdom's E-Commerce
Law and the National Data Management Office's (NDMO) data localization requirements.
Scope: Applies to the processing of personal data within Saudi
Arabia, as well as processing outside Saudi Arabia that targets individuals in the Kingdom or monitors their behavior.
Principles: Transparency, purpose limitation, data minimization,
accuracy, limited retention, security, and accountability.
Consent: Processing requires consent, which must be given by a documented statement of will. Consent must be specific and informed. The data subject may withdraw consent at any time.
Sensitive data: Enhanced protections for data concerning race,
ethnicity, health, sex life, biometrics, genetic data, and religious beliefs. Processing of sensitive data requires explicit consent.
Children's data: Processing of children's data (individuals under 13)
requires the consent of a parent or legal guardian.
Data localization: Personal data of Saudi data subjects must be stored within the Kingdom, subject to limited exceptions. Cross-border transfers require approval from the Saudi Data and Artificial
Intelligence Authority (SDAIA) unless the destination country provides an adequate level of protection.
Cross-border transfers: Permitted where the destination country has adequate protection, where the data subject consents after being informed, or where the transfer is necessary for legal or contractual obligations.
Data breach notification: Controllers must notify SDAIA within 72
hours of becoming aware of a data breach that poses a risk to data subjects.
Regulatory authority: The Saudi Data and Artificial Intelligence
Authority (SDAIA), which was established in 2019 and serves as the primary data protection authority. SDAIA has issued implementing regulations and guidance.
Penalties: Fines of up to SAR 5 million (approximately $1.3 million)
per violation. Criminal penalties may also apply for certain offenses.
Repeat violators may face doubled penalties.
Significance: The PDPL is a landmark development in Saudi Arabia's digital transformation agenda (Vision 2030) and reflects the Kingdom's commitment to establishing a modern data governance framework. The law is particularly significant given the scale of Saudi Arabia's digital economy and its position as the largest economy in the Gulf Cooperation
Council (GCC).
Israel's Protection of Privacy Law, 5741-1981, is one of the world's oldest data protection statutes, predating the OECD Privacy Guidelines
(1980) by only one year. Despite its age, the law has been amended incrementally and remains the primary data protection framework in
Israel, supplemented by extensive regulations and secondary legislation.
Key features of the existing framework:
Database registration: Owners of databases containing personal information must register their databases with the Registrar of
Databases (part of the Ministry of Justice's Law, Information and
Technology Authority).
Consent: The use of personal information generally requires the data subject's consent, with exceptions for certain categories of databases
(such as employee databases, patient databases, and subscriber databases) where specific rules apply.
Privacy protection regulations: The Privacy Protection Regulations
(Data Security), 5777-2017, impose comprehensive data security obligations on database owners, including requirements for risk assessments, security policies, employee training, access controls,
encryption, and incident response plans.
Data breach notification: The 2017 regulations require database owners to notify the Registrar of Databases and affected individuals within 72 hours of becoming aware of a security breach that compromises personal information.
Sensitive databases: Certain categories of databases (such as those containing health information, biometric data, or sensitive financial information) require the explicit consent of the data subject for each use of the data.
EU adequacy: Israel was the first non-European country to receive EU
adequacy recognition, granted in 2011 (Decision 2011/61/EU). This determination facilitates data flows between the EU and Israel and has been reaffirmed in subsequent reviews.
Regulatory authority: The Law, Information and Technology Authority
(LITA, formerly the Law, Information and Technology Division) within the
Ministry of Justice, and the Registrar of Databases. Israel's data protection authority has been criticized as under-resourced and lacking independence relative to the scope of its mandate.
Penalties: Criminal penalties of up to 5 years' imprisonment for offenses including unauthorized disclosure of personal information and the use of personal information for unauthorized purposes.
Administrative fines under the 2017 data security regulations.
2024 Proposed Amendment (Privacy Protection Bill): A comprehensive amendment bill has been under consideration in the Knesset (Israel's parliament) since 2022, with significant revisions in 2024. The proposed amendment would:
Modernize consent requirements to align with current international standards.
Introduce explicit data subject rights (access, correction, erasure,
data portability, and the right to be forgotten).
Establish clearer rules for cross-border data transfers.
Strengthen the independence and enforcement powers of the data protection authority.
Introduce provisions on automated decision-making and profiling.
Increase administrative penalties.
Require data protection impact assessments for high-risk processing.
The amendment bill has faced delays due to political instability and competing legislative priorities. As of early 2026, the bill has not been enacted, though there is broad consensus on the need for modernization.
Qatar's Law No. 13 of 2016 on the Protection of Personal Data Privacy was enacted in 2016 and represents Qatar's primary data protection framework. Key features include:
Scope: Applies to the processing of personal data in Qatar by electronic or other means, including the collection, recording, storage,
organization, modification, use, disclosure, transfer, and destruction of personal data.
Consent: Processing requires consent, which must be informed,
specific, and voluntary. Consent may be withdrawn at any time.
Sensitive data: Enhanced protections for data concerning health, sex life, political opinions, religious beliefs, race, ethnicity, and genetic data.
Data subject rights: Access, correction, completion, and deletion of personal data.
Cross-border transfers: Permitted where the data subject consents,
where the destination country provides adequate protection, or where the transfer is necessary for legal obligations.
Data breach notification: Data controllers must notify the Ministry of Transport and Communications (MOTC) and affected individuals within 3
days of becoming aware of a data breach.
Regulatory authority: The Ministry of Transport and Communications
(MOTC), which is responsible for administering the law and enforcing compliance. Qatar does not have a dedicated independent data protection authority.
Penalties: Administrative fines, imprisonment of up to 3 years,
and/or fines of up to QAR 5 million (approximately $1.4 million) for violations.
Notable developments: Qatar's preparations for the 2022 FIFA World
Cup drove significant investment in data protection compliance,
including the issuance of guidance on personal data processing in the context of the tournament's digital infrastructure.
Bahrain's Personal Data Protection Law (Law No. 30 of 2018) was enacted in 2018 and represents Bahrain's first comprehensive data protection framework. Key features include:
Scope: Applies to the processing of personal data by public and private entities in Bahrain, as well as entities outside Bahrain that process personal data of individuals in Bahrain.
Consent: Processing generally requires consent, with exceptions for legal obligations, public interest, and legitimate interests.
Sensitive data: Enhanced protections for data on health, biometrics,
genetics, race, ethnicity, political opinions, religious beliefs, sex life, and criminal records.
Cross-border transfers: Permitted where adequate protection is ensured, where the data subject consents, or where the transfer is necessary for legal obligations. Bahrain requires data localization for certain categories of data.
Regulatory authority: The Ministry of Information Affairs is responsible for administering the law, with the Personal Data Protection
Directorate serving as the operational unit. Bahrain does not have an independent data protection authority.
Penalties: Administrative fines of up to BHD 500,000 (approximately
$1.3 million) for violations, as well as criminal penalties for certain offenses including the unauthorized disclosure of personal data.
Significance: Bahrain's data protection law reflects the country's position within the GCC's broader movement toward comprehensive data governance, alongside Saudi Arabia, the UAE, and Qatar. Bahrain's relatively small economy and well-developed financial services sector have made the law particularly relevant for fintech and digital banking operations.

# Chapter 39: Russia — Federal Law on Personal Data (152-FZ, 2006/Amended)

Russia's Federal Law on Personal Data (Федеральный закон "О
персональных данных", FZ-152) was adopted on July 27, 2006, and entered into force on January 26, 2007. The law established Russia's first comprehensive framework for the protection of personal data, replacing the fragmented provisions that had existed in various sectoral statutes.
FZ-152 has been amended numerous times since its adoption, with several amendments having far-reaching consequences for data processing in Russia and for international data flows:
2015 amendments: Introduced mandatory data localization requirements
(the most significant provision of the law), requiring personal data of
Russian citizens to be stored on servers physically located within the territory of the Russian Federation.
2018 amendments: Strengthened consent requirements and introduced provisions on the deletion of personal data upon request.
2019 amendments: The Sovereign Internet Law (FZ-90) introduced provisions on the technical infrastructure for maintaining internet connectivity in the event of external interference, with significant implications for data routing and government control over internet traffic.
2022-2023 amendments: Introduced enhanced requirements for the processing of biometric data and expanded the authority of Roskomnadzor
(the Federal Service for Supervision of Communications, Information
Technology and Mass Media) to enforce data protection law.
Russia's constitutional framework also protects privacy rights.
Article 23 of the Constitution of the Russian Federation guarantees the right to privacy, personal and family secrets, and the protection of one's honor and good name. Article 24 guarantees the right to the secrecy of correspondence, telephone conversations, postal, telegraph,
and other communications, and prohibits the collection, storage, use,
and dissemination of information about a person's private life without their consent.
Personal data (персональные данные): Any information relating directly or indirectly to an identified or identifiable natural person
(data subject). The definition is broad and covers both digital and analog records.
Data subject (субъект персональных данных): The natural person to whom personal data relates.
Data operator (оператор): The state body, municipal body, legal entity, or natural person that independently or jointly with other persons organizes the processing of personal data, as well as determines the purposes of processing, the composition of personal data to be processed, and the actions performed with the personal data.
Data processor (обработчик): The person that processes personal data on behalf of and under the instructions of the data operator.
Categories of personal data: FZ-152 classifies personal data into several categories, including general personal data, special categories of personal data, biometric personal data, and other categories subject to heightened protection.
The data localization requirement, introduced by the 2015 amendments and effective September 1, 2015, is the most distinctive and internationally consequential feature of Russia's data protection framework:
Mandatory storage in Russia: Data operators (including foreign companies processing personal data of Russian citizens) must store personal data of Russian citizens on servers physically located within the territory of the Russian Federation.
Interpretation: The data localization requirement has been interpreted to require the primary database or repository of Russian citizens' personal data to be located in Russia. Replication or backup of data outside Russia for technical purposes may be permitted, but the primary storage must be within Russian territory.
Enforcement: Roskomnadzor has enforced the data localization requirement against both domestic and international companies. Notable enforcement actions include:
LinkedIn (2016): LinkedIn was blocked in Russia for failing to comply with the data localization requirement. The block remains in effect as of early 2026, making Russia one of the few countries to block a major international social media platform for data localization violations.
Facebook/Instagram (2022): Blocked following Russia's invasion of
Ukraine, though the stated reasons were broader than data localization.
GoDaddy (2022): Fined for violating data localization requirements.
Various fines (2023-2025): Roskomnadzor has imposed numerous fines on international companies, including Booking.com, Twitch, Pinterest, and various media organizations, for data localization violations.
Impact: The data localization requirement has been a significant factor in the decisions of international companies regarding their operations in Russia. Companies that maintain operations in Russia have invested in local server infrastructure, while others have scaled back or exited the Russian market.
FZ-152 establishes that the processing of personal data requires the consent of the data subject, which must be:
Written: Consent must be in writing (including electronic form).
Informed: The data subject must be informed of the purposes, methods,
and scope of processing, as well as the identity of the data operator.
Specific: Consent must be specific to the processing activities contemplated.
Revocable: The data subject may withdraw consent at any time by submitting a written request to the data operator. Upon withdrawal, the data operator must cease processing and destroy the personal data within a prescribed period (generally 10 days for general data and 30 days for certain categories).
Exceptions to the consent requirement: Processing without consent is permitted in cases including:
Processing for purposes established by federal law (including law enforcement, national security, and tax administration).
Processing of data made publicly available by the data subject.
Processing necessary for the performance of a contract to which the data subject is a party.
Processing for statistical, scientific, or other research purposes with mandatory anonymization.
Special categories of personal data (специальные категории
персональных данных): Data concerning race, nationality, political views, religious or philosophical beliefs, health status, and intimate life. Processing of special categories generally requires the explicit written consent of the data subject.
Biometric personal data (биометрические персональные данные):
Information that characterizes the physiological and biological features of a person, based on which their identity can be established (including fingerprints, facial images, iris scans, and voice recordings). The 2018
and subsequent amendments introduced particularly stringent requirements for biometric data:
Processing requires the explicit written consent of the data subject.
Biometric data may be used only for the specific purposes for which consent was obtained.
Biometric data must be stored in a manner that prevents its use for purposes other than those specified in the consent.
The 2023 amendments introduced additional requirements for the processing of biometric data by government agencies, including the establishment of centralized biometric databases.
Public biometric data systems: Russia has established centralized biometric identification systems, including the Unified Biometric System
(Единая биометрическая система, EBS), which is used for remote identity verification in banking and government services. Participation in the
EBS requires the data subject's consent, and the system is administered by the Ministry of Digital Development, Communications and Mass
Media.
Federal Law No. 90-FZ of May 1, 2019, commonly referred to as the
Sovereign Internet Law (Закон о суверенном интернете), establishes the legal and technical framework for Russia's ability to maintain internet connectivity independently of external infrastructure. Key provisions include:
Technical infrastructure: The law requires telecommunications operators to install equipment (Technical Measures for Countering
Threats, TMTU) that enables Roskomnadzor to centrally manage internet traffic routing in the event of external threats.
DNS management: The law provides for the creation of a national
Domain Name System (DNS) infrastructure that can function independently of international DNS root servers.
Traffic routing: In the event of a perceived external threat to internet connectivity, the law authorizes the government to centrally manage internet traffic routing, effectively enabling a "kill switch" or controlled isolation of the Russian internet (Runet) from the global internet.
Implications for data flows: The Sovereign Internet Law has significant implications for cross-border data flows and the ability of international companies to provide services in Russia. Combined with the data localization requirements, it creates a legal and technical framework that enables substantial government control over data flows in and out of Russia.
FZ-152 permits the cross-border transfer of personal data subject to certain conditions:
The transfer must ensure that the rights of data subjects are protected.
Prior to transfer, the data operator must inform the data subject of the destination and the applicable legal framework.
Transfers are generally prohibited to countries that do not provide adequate protection for personal data, unless the data subject has given written consent.
The data localization requirement (Article 18) must be satisfied before any cross-border transfer — that is, the primary copy of the personal data must remain in Russia.
Roskomnadzor maintains a list of countries that provide adequate data protection. As of early 2026, the list includes several CIS countries and a limited number of other jurisdictions. The list does not include the United States, most EU member states, or China, meaning that transfers to these countries require the data subject's explicit consent and compliance with the data localization requirement.
Roskomnadzor (Федеральная служба по надзору в сфере связи,
информационных технологий и массовых коммуникаций) is the primary enforcement authority for FZ-152 and Russia's broader internet governance framework. Key enforcement powers include:
Registration of data processing: Data operators must notify
Roskomnadzor of their data processing activities. Roskomnadzor maintains a public register of data operators.
Inspections and audits: Roskomnadzor may conduct scheduled and unscheduled inspections of data operators' compliance with FZ-152.
Blocking orders: Roskomnadzor has the authority to order the blocking of websites and online services that violate Russian law, including data protection law.
Fines: Since 2023, Roskomnadzor has been empowered to impose administrative fines for data protection violations, including data localization violations. Fines range from RUB 100,000 to RUB 18 million
(approximately $1,100 to $200,000), with increased fines for repeat violations.
Court referral: For the most serious violations, Roskomnadzor may refer cases to the courts for criminal prosecution or administrative penalties.
FZ-152 provides for the following penalties:
Administrative fines: Since 2023, Roskomnadzor may impose administrative fines directly for data protection violations. Fines range from RUB 100,000 to RUB 18 million depending on the severity of the violation and the status of the violator (individuals, legal entities, or government bodies). Repeat violations within one year may result in doubled fines.
Criminal penalties: Criminal liability may arise under the Russian
Criminal Code for certain data protection offenses, including the unlawful collection and use of personal data (Article 137), the violation of privacy (Article 138), and the failure to protect personal data leading to its unlawful distribution (Article 272). Criminal penalties include fines, correctional labor, and imprisonment of up to 4
years for serious offenses.
Website blocking: Roskomnadzor may order the blocking of websites and online services that violate data protection requirements, as demonstrated by the blocking of LinkedIn in 2016.
Russia's data protection framework must be understood in the context of the broader political environment following the 2022 invasion of
Ukraine and the resulting international sanctions. Key developments include:
Exit of international companies: Many major international technology companies have exited or significantly scaled back their Russian operations, reducing the practical reach of Russia's data protection framework.
Increased government control: The Russian government has expanded its surveillance and control capabilities, including through the System for
Operative Investigative Activities (СОРМ) and the Yarovaya Law (2016),
which require telecommunications providers to store communications data for extended periods and to assist law enforcement in decryption.
Strengthened data localization enforcement: Roskomnadzor has intensified enforcement of data localization requirements, using the departure of international companies as an opportunity to assert regulatory authority over remaining operators.
Isolation from international data governance frameworks: Russia's participation in international data governance forums, including the
Council of Europe, has been suspended or terminated, reducing opportunities for regulatory cooperation and mutual recognition.
The full text of FZ-152 (as amended) is available in Russian from the
Russian Legal Information Portal (http://pravo.gov.ru) and the
ConsultantPlus legal database (http://www.consultant.ru). Roskomnadzor's guidance and enforcement decisions are available from the Roskomnadzor website (https://rkn.gov.ru).

# Chapter 40: Russia — Sovereign Internet Law & Additional CIS Jurisdictions

Kazakhstan's Law on Personal Data and Their Protection (Закон
Республики Казахстан "О персональных данных и их защите") was enacted on
May 21, 2013, and entered into force on November 21, 2013. The law established Kazakhstan's framework for the protection of personal data and is administered by the Ministry of Digital Development, Innovations and Aerospace Industry.
Consent-based framework: Processing generally requires the consent of the data subject, with exceptions for legal obligations, public interest, and contractual necessity.
Data subject rights: Access, correction, deletion, and objection.
Data subjects may also request information about the processing of their personal data.
Data localization: Kazakhstan introduced data localization requirements in 2021-2022, requiring that personal data of Kazakhstani citizens be stored on servers located within the territory of
Kazakhstan, or in countries that provide adequate data protection as determined by the authorized body.
Cross-border transfers: Permitted where the destination country provides adequate protection, where the data subject consents, or where the transfer is necessary for the performance of a contract.
Registration requirement: Data operators must register their data processing activities with the authorized body.
Regulatory authority: The Ministry of Digital Development,
Innovations and Aerospace Industry is the primary regulatory authority,
with the Committee on Legal Statistics and Special Accounts of the
General Prosecutor's Office having oversight of criminal enforcement.
Kazakhstan does not have a dedicated independent data protection authority.
Penalties: Administrative fines for violations, as specified in the
Code of Administrative Offences. Criminal penalties may apply for the unlawful processing of personal data under certain circumstances.
Digital Kazakhstan program: Kazakhstan's broader digital transformation strategy (the Digital Kazakhstan state program) has emphasized the development of data governance infrastructure, including the creation of government data sharing platforms and the promotion of data-driven innovation.
Modernization efforts: Kazakhstan has been considering amendments to its personal data law to align with evolving international standards,
including enhanced provisions on data breach notification, automated decision-making, and the establishment of a more independent data protection authority.
Belarus's Law on Personal Data Protection (Закон Республики Беларусь
"О защите персональных данных") was enacted on November 10, 2008, and entered into force on March 15, 2009. Key features include:
Consent-based framework: Processing generally requires the consent of the data subject, with exceptions for legal obligations, national security, public health, and statistical purposes.
Data subject rights: Access, correction, and deletion of personal data.
Special categories: Enhanced protections for data concerning health,
racial or ethnic origin, political opinions, religious beliefs, and sex life.
Data localization: Belarus has introduced data localization requirements, particularly for government data and data in certain sensitive sectors. The requirements have been strengthened in recent years through amendments to the law and related regulations.
Cross-border transfers: Permitted where the destination country provides adequate protection, where the data subject consents, or where the transfer is necessary for legal obligations.
Registration requirement: Data operators must register their databases containing personal data with the Operational and Analytical
Center under the President of the Republic of Belarus.
Regulatory authority: The Operational and Analytical Center under the
President of the Republic of Belarus (ОАЦ) is the primary body responsible for overseeing data protection compliance. The Ministry of
Communications and Informatization and the State Inspectorate for
Personal Data Protection also play roles in enforcement. Belarus does not have a fully independent data protection authority.
Penalties: Administrative fines for data protection violations under the Code of Administrative Offences of the Republic of Belarus. Criminal penalties may apply for the unlawful collection and distribution of personal data under the Criminal Code, including imprisonment of up to 3
years for the unlawful use of computer information.
Political context: Belarus's data protection framework operates within an environment of extensive state surveillance and limited internet freedom. The government maintains broad authority to access and monitor electronic communications under national security legislation,
which significantly limits the practical effectiveness of data protection rights.
International isolation: Following the political crisis of 2020 and the Russian invasion of Ukraine in 2022, Belarus has been increasingly isolated from international data governance frameworks, limiting opportunities for regulatory cooperation and the development of cross-border data transfer mechanisms.

# Chapter 41: Council of Europe — Budapest Convention on Cybercrime (2001)

## 41.1 Background and Historical Development of the Convention

### 41.1.1 Genesis of the Convention

The Budapest Convention on Cybercrime, formally the **Convention on Cybercrime**, is the **world's first international treaty dedicated specifically to cybercrime**. Drafted under the auspices of the **Council of Europe**, it was opened for signature on **23 November 2001** in Budapest, Hungary — hence its colloquial name, the "Budapest Convention."

The historical impetus for the Convention traces back to the **late 1990s**. As the Internet achieved global reach, governments increasingly recognised that traditional legal frameworks were ill-equipped to address the growing sophistication of cyber-enabled crime. In 1995, the United States Department of Justice first raised the need for international cybercrime legislation; in the years that followed, the Council of Europe joined and ultimately led the relevant discussions.

### 41.1.2 Negotiation Process and Signature

The negotiation of the Convention spanned several years and was undertaken jointly by the Council of Europe's **50 member states** together with non-member states including the **United States, Canada, and Japan**. The Convention was formally opened for signature in November 2001. As of **2025**, the Convention counts **64 Parties**, comprising Council of Europe member states and non-member states such as the United States, Canada, Japan, and Australia.

### 41.1.3 Legal Status and Significance

The Budapest Convention is the **first global framework establishing legal standards and international cooperation mechanisms for cybercrime**. Its core objectives are threefold:

1. **Harmonisation of domestic law**: requiring Parties to criminalise nine categories of cybercrime offences under their national criminal law;
2. **Establishment of investigative powers**: empowering law enforcement authorities to deploy effective investigative measures, including data preservation and real-time interception of data;
3. **Facilitation of international cooperation**: instituting a 24/7 network (Article 35) for urgent assistance.

The Convention is widely regarded as the **"gold standard"** in the field of cybercrime law. Despite the controversies discussed below, it remains the most influential international instrument in this domain.

---

## 41.2 Core Provisions: The Nine Categories of Cybercrime Offences

Chapter II of the Convention (Articles 2–10) sets out **nine categories of cybercrime offences** that must be criminalised under the domestic law of each Party. These provisions constitute the substantive criminal law core of the Convention.

### 41.2.1 Illegal Access (Article 2)

**Definition**: The intentional access to the whole or any part of a computer system without right.

**Essential elements**:
- **Without right**: the person accessing the system lacks lawful authority to do so;
- **Intentional**: mere negligent access does not satisfy the *mens rea* requirement;
- **Whole or any part**: this encompasses access to an entire system or to any component thereof, such as a particular file directory.

**Optional reservations** (which a Party may adopt):
- Requiring that the access be undertaken with the intent of obtaining computer data;
- Requiring a dishonest intent;
- Requiring that the access involve a connection to another computer system and that security measures have been infringed.

**Illustrative examples**: A hacker cracking a password to enter a government database; an employee using a colleague's credentials to access the company intranet.

### 41.2.2 Illegal Interception (Article 3)

**Definition**: The intentional interception without right, made by technical means, of non-public transmissions of computer data to, from or within a computer system.

**Essential elements**:
- **Interception**: includes wiretapping, packet capture, and analogous surveillance techniques;
- **Non-public nature**: according to the Council of Europe's Explanatory Report, computer data are of a non-public nature if, at the time of transmission, there is no intention to make them publicly available — even where the transmission is effected via a public network;
- **Scope of transmission**: embraces transmissions within a single system, transmissions between systems, and transmissions directed at the public that have not yet been made accessible to the public.

**Rationale**: This provision safeguards the confidentiality of computer data and combats "network eavesdropping."

**Illustrative examples**: Deploying a packet sniffer to capture emails on a local area network; intercepting data packets transmitted over Wi-Fi.

### 41.2.3 Data Interference (Article 4)

**Definition**: The intentional damaging, deletion, deterioration, alteration or suppression of computer data without right.

**Essential elements**:
- **Modes of commission**: damaging, deleting, deteriorating, altering, or suppressing;
- **Object**: computer data, including both data proper and computer programs;
- **"Without right" requirement**: the absence of authorisation is required; however, even an authorised user (such as a system administrator) who maliciously deletes data may fall within the scope of the offence.

**Rationale**: This provision protects the integrity of computer data and the availability of computer programs.

**Illustrative examples**: A virus that deletes files; ransomware that encrypts user data; a hacker altering website content.

### 41.2.4 System Interference (Article 5)

**Definition**: The intentional serious hindering without right of the functioning of a computer system by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing computer data.

**Essential elements**:
- **Modes of commission**: similar to those under the data interference offence, but directed at the functioning of a computer system;
- **"Serious hindering" threshold**: according to the Council of Europe's Explanatory Report, any transmission of computer data that is capable of causing a "significant adverse effect" on another person's computer system is treated as "serious hindrance";
- **Distinction from data interference**: data interference targets the data themselves; system interference targets the functionality of the system.

**Illustrative examples**: A distributed denial-of-service (DDoS) attack rendering a server inoperative; malware consuming system resources to the point of system collapse.

### 41.2.5 Misuse of Devices (Article 6)

**Definition**: The production, sale, procurement for use, import, distribution or otherwise making available, or possession, of the following items — with the intent that they be used for the purpose of committing any of the offences established in Articles 2–5:
- Computer programs (including viruses, Trojans, and hacking tools);
- Computer passwords, access codes, or similar data by which a computer system may be accessed.

**Essential elements**:
- **Intent/purpose**: the conduct must be undertaken with a view to committing an offence prescribed under the Convention;
- **Types of items**: encompassing hardware devices, software programs, and access credentials;
- **Chain of circulation**: all stages — production, sale, procurement, import, distribution, and possession — are covered.

**Rationale**: This provision exemplifies the criminalisation of preparatory conduct, targeting the circulation of cybercrime tools at the pre-offence stage.

**Controversy**: Critics observe that the provision may be susceptible to overbroad interpretation, potentially impinging upon the legitimate activities of security researchers and reverse engineers.

### 41.2.6 Computer-Related Forgery (Article 7)

**Definition**: The intentional input, alteration, deletion, or suppression of computer data, resulting in inauthentic data with the intent that they be considered or acted upon for legal purposes as if they were authentic, regardless of whether or not the data are directly readable and intelligible. A Party may require a fraudulent or similar dishonest intent.

**Essential elements**:
- **Purpose**: fraudulent or illegal;
- **Effect**: the data are treated as authentic, i.e. as documents carrying legal effect;
- **Distinction from data interference**: data interference does not require a fraudulent purpose, nor does it engage the question of the "authenticity" of the data.

**Illustrative examples**: Altering the amount stated in an electronic contract; fabricating an electronic invoice.

### 41.2.7 Computer-Related Fraud (Article 8)

**Definition**: The intentional and without right causing of a loss of property to another person by:
- Any input, alteration, deletion or suppression of computer data; or
- Any interference with the functioning of a computer system;
with fraudulent or dishonest intent of procuring, without right, an economic benefit for oneself or for another person.

**Essential elements**:
- **Purpose**: the unlawful acquisition of property or a pecuniary advantage;
- **Means**: analogous to computer-related forgery, but emphasising "fraud" rather than "forgery";
- **Distinction from forgery**: fraud centres on "unlawful acquisition," whereas forgery centres on "data authenticity."

**Illustrative examples**: A hacker altering a bank account balance; obtaining credit card details through phishing.

### 41.2.8 Offences Related to Child Pornography (Article 9)

**Definition**: The following intentional conduct without right:
- Producing child pornography for the purpose of its distribution through a computer system;
- Offering or making available child pornography through a computer system;
- Distributing or transmitting child pornography through a computer system;
- Procuring child pornography through a computer system for oneself or for another person;
- Possessing child pornography in a computer system or on a computer-data storage medium.

**Essential elements**:
- **Child**: as defined by the domestic law of each Party, ordinarily a person under 18 years of age;
- **Pornographic material**: including images, video recordings, and textual descriptions that visually depict sexually explicit conduct;
- **Modes of commission**: producing, offering, distributing, transmitting, procuring, and possessing.

**Rationale**: This is the sole provision in the Convention directed at a specific category of content, reflecting the priority the international community places on the protection of children.

### 41.2.9 Offences Related to Copyright and Related Rights (Article 10)

**Definition**: The infringement of copyright and related rights as defined under the domestic law of each Party, where such acts are committed wilfully, on a commercial scale, and by means of a computer system.

**Essential elements**:
- **Copyright infringement**: including the unauthorised reproduction, distribution, and public performance of protected works;
- **Commercial scale**: non-commercial personal use falls outside the scope of the offence;
- **Related rights**: encompassing performers' rights, producers' rights in phonograms, and broadcasting organisations' rights.

**Optional reservation**: A Party may reserve the right not to apply this provision in whole or in part.

**Controversy**: This provision was the subject of considerable debate during the negotiations, given the significant disparities among States in the scope and enforcement of copyright protection.

---

## 41.3 Investigative Powers and Procedural Measures

Chapter III of the Convention (Articles 14–21) prescribes the **procedural powers necessary for the investigation of cybercrime**, including:

### 41.3.1 Expedited Preservation of Stored Computer Data (Article 16)

Requires the owner or person in control of a computer system or computer data to **preserve** specified computer data for a period of up to 90 days, in order to ensure their availability for investigative or prosecutorial purposes.

### 41.3.2 Real-Time Collection of Traffic Data (Article 17)

Empowers law enforcement authorities to **collect or record, in real time**, traffic data associated with specified communications transmitted by means of a computer system.

**Key distinction**:
- **Traffic data**: data relating to the origin, destination, route, time, date, size, and duration of a communication;
- **Content data**: the substance or meaning of the communication itself.

### 41.3.3 Interception of Content Data (Article 18)

Empowers law enforcement authorities to **intercept, in real time**, the content of specified communications transmitted by means of a computer system.

**Heightened safeguards**: This power typically requires a more rigorous authorisation standard (such as judicial approval), given that content interception entails a more significant intrusion upon the right to privacy.

---

## 41.4 International Cooperation Framework

Chapter IV of the Convention (Articles 23–35) establishes the **international cooperation framework** and is one of the most innovative features of the Convention.

### 41.4.1 The 24/7 Network (Article 35)

The Convention requires each Party to designate a **24/7 point of contact** for urgent assistance. This was the first mechanism of its kind at the global level.

**Functions**:
- In urgent situations, such as an ongoing cyberattack, to facilitate the rapid preservation or production of electronic evidence;
- To serve as the initial point of contact for mutual legal assistance requests;
- To share cyber-threat intelligence.

**Practice**: The majority of 24/7 points of contact are housed within specialised police or prosecutorial agencies. As of 2025, the network spans all 64 Parties.

### 41.4.2 Extradition and Mutual Legal Assistance

The Convention requires Parties to incorporate the offences established under the Convention into their **extradition treaties**, and to treat such offences as extraditable even in the absence of a bilateral extradition treaty.

**Challenges**: The extradition of cybercriminals faces difficulties arising from jurisdictional conflicts (such as the difficulty of determining the *locus delicti*) and the principle of dual criminality.

---

## 41.5 The Second Additional Protocol (2025)

In 2025, the Council of Europe adopted the **Second Additional Protocol to the Budapest Convention**, further strengthening the international cooperation regime.

### 41.5.1 Principal Additions

1. **Enhanced cooperation mechanisms**: introducing expedited mutual legal assistance procedures, particularly in emergency situations;
2. **Data preservation obligations**: requiring Internet service providers (ISPs) to retain specified categories of data for investigative purposes;
3. **Direct cross-border access to data**: permitting, under prescribed conditions, a Party to obtain data directly from a server located in the territory of another Party.

### 41.5.2 Controversy

The Second Additional Protocol has drawn concern from human rights organisations, which argue that it may **undermine data protection and privacy rights**. Several non-governmental organisations have submitted joint submissions recommending:
- That no new compulsory mechanism for subscriber information production be introduced without the involvement of authorities on both sides;
- That the scope of Article 4 be clarified so as to exclude the disproportionate acquisition of data concerning a person's use of a service.

---

## 41.6 Criticism and Controversies

Notwithstanding its wide acceptance, the Budapest Convention has attracted significant criticism.

### 41.6.1 Geographic Limitations

The Convention has been characterised as largely confined to **European States**, having failed to secure broad global consensus and enforcement. **China, Russia, India, and Brazil**, among others, have **not signed** the Convention.

**Reasons**:
- **Eurocentrism**: The Convention was negotiated under the leadership of the Council of Europe, without the participation of States from the Global South;
- **Sovereignty concerns**: Certain States view provisions of the Convention — such as Article 32 on transborder access to stored computer data — as encroaching upon national sovereignty;
- **Divergent human rights standards**: The Convention requires Parties to safeguard "human rights and fundamental freedoms" (Preamble), yet understandings of human rights differ significantly across legal traditions.

### 41.6.2 Relationship with the UN Convention Against Cybercrime

In December 2024, the **United Nations General Assembly** adopted the **United Nations Convention Against Cybercrime**, the first cybercrime treaty negotiated by consensus among all UN member states.

**Comparative overview**:

| Aspect | Budapest Convention | UN Convention |
|--------|---------------------|---------------|
| Negotiating forum | Council of Europe (50+ states) | United Nations (193 states) |
| Binding force | Binding only on Parties | Binding on all UN member states upon entry into force |
| Substantive focus | Nine categories of offences + investigative powers | Broader scope, including preventive measures and technical assistance |
| Entry into force | Upon ratification by 3 states | Upon ratification by 40 states |

**Impact**: The UN Convention may, in time, supplement or even supplant the Budapest Convention, particularly among States of the Global South.

### 41.6.3 Human Rights and Surveillance Concerns

A number of **human rights organisations** and **major technology companies** have objected to the Budapest Convention — and particularly to the Second Additional Protocol — on the following grounds:
- The Convention lacks robust safeguards against the abuse of digital investigation and digital forensics powers;
- It facilitates expanded surveillance and data access, thereby undermining trust in computing and digital technologies;
- The absence of an independent oversight mechanism may permit governmental abuse of power.

---

## 41.7 Significance and Implications for China

### 41.7.1 China's Non-Signatory Status

China has **not signed** the Budapest Convention. The principal reasons include:
1. **Non-participation in the negotiations**: China did not take part in the drafting and negotiation of the Convention and considers it inappropriate to accede to a treaty in whose formation it had no role;
2. **Sovereignty concerns**: Certain provisions of the Convention — such as those on transborder access to data and the 24/7 network — are perceived as potentially eroding national sovereignty;
3. **Divergent legal systems**: Chinese criminal law adheres to the principle of *nullum crimen sine lege* (no crime without law), and the mandatory criminalisation of all nine categories of offences under the Convention may not align seamlessly with the existing corpus of Chinese criminal legislation.

### 41.7.2 Alignment of Chinese Cybercrime Legislation with the Convention

Although China is not a signatory, its domestic cybercrime legislation — including the *Criminal Law Amendment (IX)*, the *Cybersecurity Law*, and the *Data Security Law* — exhibits a high degree of **substantive alignment** with the Convention. For example:
- The offence of **illegal intrusion into a computer information system** (Article 285 of the Criminal Law) corresponds to Article 2 of the Convention;
- The offence of **illegally obtaining computer information system data** corresponds to Article 3 of the Convention;
- The offence of **damaging a computer information system** (Article 286 of the Criminal Law) corresponds to Articles 4 and 5 of the Convention.

### 41.7.3 International Cooperation in Practice

China pursues international cooperation against cybercrime principally through **bilateral mutual legal assistance treaties (MLATs)** and the **Shanghai Cooperation Organisation (SCO)** framework, rather than through the Budapest Convention's 24/7 network.

**Challenges**: In respect of cross-border electronic evidence gathering, Chinese law enforcement agencies may be unable to access the Convention's mechanisms directly, potentially limiting the efficiency of investigations.

---

## 41.8 Conclusion and Outlook

The Budapest Convention represents a **milestone** in the international governance of cybercrime. Its definition of nine categories of offences, its authorisation of investigative powers, and its innovative mechanisms — above all the 24/7 network — have exerted a profound influence on global cybercrime governance.

Nevertheless, the Convention faces a **legitimacy crisis**:
- Its geographic limitations (Eurocentrism);
- Human rights and surveillance concerns;
- The emergence of a competing UN convention.

Looking ahead, the international governance of cybercrime is likely to follow a **dual-track trajectory**:
- **Europe and allied states**: continuing to operate under the Budapest Convention;
- **States of the Global South**: gravitating toward the UN Convention.

As a major cyber power, China must strike a balance between **safeguarding sovereignty** and **engaging in global governance**, and may play a more prominent role through the framework of the **UN Convention**.

---

*Word count (Chinese original): approximately 6,200 characters*
*Principal sources: Council of Europe official documents, Sogou Lawyer, United Nations News, academic literature*
*Date of preparation: 26 June 2026*
# Chapter 42: Council of Europe — Convention 108+ (Modernised Convention for the Protection of Individuals)

Convention 108 (Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data) was adopted by the
Council of Europe on January 28, 1981, making it the first legally binding international instrument on data protection. It has been ratified by 55 states, including all Council of Europe member states and several non-member states (Uruguay, Argentina, Japan, Tunisia, Morocco,
Mauritius, Senegal, Cabo Verde, Burkina Faso, and others).
Convention 108 was modernized through an amending protocol —
Convention 108+ (Protocol CETS No. 223) — which was opened for signature on October 10, 2018, and entered into force on October 1, 2023.
Convention 108+ updates the original Convention to address the challenges posed by modern data processing technologies, including big data, artificial intelligence, and ubiquitous computing.
Convention 108+ establishes the following fundamental principles for data protection:
Lawfulness and fairness: Personal data must be processed fairly and lawfully.
Purpose limitation: Personal data must be collected for specified,
explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
Data minimization: Personal data must be adequate, relevant, and not excessive in relation to the purposes for which they are processed.
Accuracy: Personal data must be accurate and, where necessary, kept up to date. Reasonable steps must be taken to ensure that inaccurate data are erased or rectified without delay.
Retention limitation: Personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data are processed.
Security: Appropriate security measures must be taken against unauthorized access to, or accidental loss of, personal data.
Rights of data subjects: Data subjects have the right to know the existence of automated personal data files, to obtain confirmation of whether personal data concerning them are being processed, and to obtain the data. Data subjects also have the right to obtain the rectification or erasure of inaccurate data.
Supervisory authority: Each Party shall establish one or more independent supervisory authorities responsible for ensuring compliance with the Convention's principles.
Convention 108+ introduces several provisions that were not present in the original Convention:
Explicit reference to new technologies: The modernised Convention explicitly addresses the challenges of automated decision-making,
profiling, big data analytics, and other modern processing technologies.
Strengthened data subject rights: Including the right to object to processing, the right to data portability (in certain circumstances),
and enhanced rights in the context of automated decision-making.
Enhanced supervisory authority requirements: Including requirements for the independence, resources, and powers of supervisory authorities.
Cross-border data transfer rules: Enhanced provisions on the conditions for transfers of personal data to other states, including adequacy-based transfers and transfer mechanisms with appropriate safeguards.
Accountability: A new obligation for data controllers to demonstrate compliance with the Convention's principles.
Data breach notification: New provisions requiring the notification of personal data breaches to supervisory authorities and, in certain circumstances, to affected individuals.
Sensitive data: Enhanced protections for special categories of personal data, with a requirement that processing be justified by substantial public interest or consent.
Convention 108 and Convention 108+ are significant for several reasons:
Global reach: With 55+ ratifying states, Convention 108 has a broader geographic reach than the GDPR, encompassing countries in Europe,
Africa, Latin America, and Asia that are not covered by EU data protection law.
Influence on national legislation: The Convention has served as a model for the development of national data protection laws around the world, particularly in Africa and Latin America, where many countries have adopted frameworks based on Convention 108's principles.
Bridging function: Convention 108+ serves as a bridge between the
GDPR and the data protection frameworks of non-EU countries, providing a common set of principles that can facilitate cross-border data flows and regulatory cooperation.
Institutional framework: The Convention's Consultative Committee
(T-PD) provides a forum for ongoing cooperation and the development of guidance on data protection issues of common concern.
Convention 108+ and the GDPR are complementary instruments:
Convention 108+ applies to all 46 Council of Europe member states
(including non-EU members such as the United Kingdom, Turkey, and the
Western Balkans) and to non-member states that have ratified the
Convention.
The GDPR applies to EU and EEA member states and has extraterritorial effect.
The two instruments share the same fundamental principles, and
Convention 108+ has been updated to align with the GDPR's key provisions.
The full text of Convention 108 (1981) and Convention 108+ (2018
amending protocol) are available from the Council of Europe's Treaty
Office
(https://www.coe.int/en/web/conventions/full-list/-/conventions/treaty/108).
The Consultative Committee's guidance documents and the Convention's explanatory reports are also available.

# Chapter 43: OECD Privacy Guidelines (2013) & AI Principles (2019)

The OECD Guidelines on the Protection of Privacy and Transborder
Flows of Personal Data were first adopted in 1980 and represented the first international instrument to establish principles for the protection of personal data and the regulation of transborder data flows. The Guidelines were significantly revised in 2013 to address the challenges of the digital economy.
The 2013 Privacy Guidelines establish eight basic principles:
Collection Limitation Principle: There should be limits to the collection of personal data, and data should be obtained by lawful and fair means and, where appropriate, with the knowledge or consent of the data subject.
Data Quality Principle: Personal data should be relevant to the purposes for which they are to be used and should be accurate, complete,
and up to date as is necessary for those purposes.
Purpose Specification Principle: The purposes for which personal data are collected should be specified not later than at the time of data collection, and the subsequent use of data should be limited to the fulfillment of those purposes or such others as are not incompatible with those purposes.
Use Limitation Principle: Personal data should not be disclosed, made available, or otherwise used for purposes other than those specified in accordance with the Purpose Specification Principle, except with the consent of the data subject or by the authority of law.
Security Safeguards Principle: Personal data should be protected by reasonable security safeguards against such risks as loss or unauthorized access, destruction, use, modification, or disclosure.
Openness Principle: There should be a policy of openness about developments, practices, and policies with respect to personal data.
Means should be readily available to establish the existence and nature of personal data and the main purposes of their use, as well as the identity and usual residence of the data controller.
Individual Participation Principle: Individuals should have the right to obtain from a data controller, or otherwise, confirmation of whether or not the data controller has data relating to them; to have communicated to them, data relating to them within a reasonable time; to be given reasons if a request is denied; and to be able to challenge such a denial.
Accountability Principle: Data controllers should be accountable for complying with measures that give effect to the principles stated above.
The Guidelines address transborder data flows through the principle that member countries should refrain from restricting transborder flows of personal data between themselves and another member country, except where the re-import of data would circumvent domestic privacy legislation and the other country does not provide substantially equivalent privacy protections. This "free flow with equivalent protection" principle has been enormously influential in shaping international approaches to cross-border data transfers.
The OECD Privacy Guidelines have served as the foundational reference for virtually every subsequent data protection framework worldwide,
including the EU Data Protection Directive, the GDPR, the APEC Privacy
Framework, and numerous national laws. The 2013 revision introduced several updates, including:
Clarification of the application of the principles in the context of the digital economy, including online services, social media, and mobile applications.
Enhanced emphasis on the Accountability Principle, including the adoption of privacy management programs.
Recognition of the role of privacy seals, certification, and other trust-building mechanisms.
Guidance on the application of the principles to data controllers and data processors.
Provisions on the global implementation of the Guidelines by non-OECD
member countries.
The OECD Recommendation on Artificial Intelligence was adopted on May
22, 2019, and updated in May 2024. It was endorsed by the G20 in June
2019, making it the first intergovernmental standard on AI. The AI
Principles establish five complementary values-based principles and recommendations for responsible AI:
Inclusive growth, sustainable development, and well-being: AI should benefit people and the planet by complementing human ingenuity and creativity, and by contributing to inclusive growth, sustainable development, and well-being.
Human-centered values and fairness: AI systems should be designed in a way that respects the rule of law, human rights, democratic values,
and diversity. They should include appropriate safeguards — for example,
enabling human intervention where necessary and appropriate — to ensure a fair and just society.
Transparency and explainability: People should be informed when they are interacting with an AI system and when they are significantly affected by an AI system. AI systems should be transparent and explainable in a manner that is appropriate to their use and context.
Robustness, security, and safety: AI systems must function appropriately and not pose unreasonable safety risks. They should be robust, secure, and safe throughout their entire lifecycle, and their resilience should be regularly assessed.
Accountability: Organizations and individuals developing, deploying,
or operating AI systems should be held accountable for their proper functioning in line with the above principles. Mechanisms should be in place to audit AI systems for compliance with these principles,
including through diverse external checks and oversight.
The AI Principles also include recommendations for governments on:
Facilitating investment in AI research and development.
Fostering a digital ecosystem for AI.
Shaping an enabling policy environment for AI.
Building human capacity and preparing for labor market transformation.
Cooperating across borders to advance trustworthy AI.
The OECD AI Principles have been adopted as the foundation for AI
governance frameworks worldwide, including:
The G20 AI Principles (endorsed June 2019).
The UNESCO Recommendation on the Ethics of AI (2021).
The EU AI Act (which draws on the OECD's risk-based approach).
National AI strategies in over 60 countries.
The OECD has also established the AI Policy Observatory (OECD.AI),
which serves as a global hub for AI policy analysis, data, and best practices. The Observatory tracks AI policies across over 60 countries and provides resources for policymakers developing AI governance frameworks.
The 2024 update to the AI Principles added new provisions addressing:
The environmental impact of AI systems.
The use of AI in disinformation campaigns and its implications for democracy.
The challenges of generative AI, including large language models and foundation models.
The role of AI in the public sector and government services.
The full text of the OECD Privacy Guidelines (2013) and the OECD AI
Principles (2019, updated 2024) are available from the OECD website
(https://www.oecd.org). The OECD AI Policy Observatory is accessible at https://oecd.ai.

# Chapter 44: United Nations

The United Nations Group of Governmental Experts (GGE) on
Developments in the Field of Information and Telecommunications in the
Context of International Security has been the primary UN forum for developing norms of responsible state behavior in cyberspace since 2004.
The GGE has produced consensus reports in 2010, 2013, and 2015, with the
2015 report representing the most significant consensus achievement.
The 2015 report, adopted by consensus by all GGE members, established the following key norms:
Sovereignty: States have sovereignty over the ICT infrastructure within their territory.
Due diligence: States should not knowingly allow their territory to be used for internationally wrongful acts using ICTs.
Peaceful settlement: States should settle their international disputes in cyberspace by peaceful means.
Self-defense: The right of self-defense recognized in the UN Charter applies to cyber operations.
Non-intervention: States should not intervene in the internal affairs of other states through the use of ICTs.
International humanitarian law: International humanitarian law applies to the use of ICTs in armed conflict.
Human rights: States must respect human rights and fundamental freedoms in cyberspace.
Cybercrime cooperation: States should cooperate in combating cybercrime.
Critical infrastructure protection: States should take reasonable steps to ensure the integrity of critical infrastructure.
CERT cooperation: States should encourage the establishment of
Computer Emergency Response Teams (CERTs) and promote cooperation between them.
The 2015 consensus was widely regarded as a landmark achievement,
establishing for the first time that existing international law applies to cyberspace. However, subsequent GGE sessions (2017 and 2021) failed to reach consensus, primarily due to disagreements between Western democracies (emphasizing human rights, accountability, and the applicability of international humanitarian law) and Russia and China
(emphasizing state sovereignty, information security, and restrictions on the use of ICTs for political purposes).
The United Nations Open-Ended Working Group (OEWG) on Developments in the Field of Information and Telecommunications in the Context of
International Security was established by UN General Assembly Resolution
73/27 in 2018 as a complementary process to the GGE, with all UN member states invited to participate. The OEWG produced a consensus report in
2021 that largely reaffirmed the 2015 GGE norms while adding provisions on:
Confidence-building measures.
Capacity building.
Regular institutional dialogue.
The involvement of civil society, academia, and the private sector in the norm-setting process.
A second OEWG (2023-2025) continued the dialogue, with ongoing discussions on the implementation of agreed norms, the development of additional norms for specific technologies (including AI and quantum computing), and the establishment of a regular institutional mechanism for cyber discussions at the UN.
The OEWG reports (2021 and 2025) have contributed to the development of international cyber norms in several ways:
Broadened participation: The OEWG format has enabled all UN member states to participate, providing a more inclusive forum than the GGE
(which has a fixed membership of approximately 25 states).
Multi-stakeholder engagement: The OEWG has formally involved civil society, academia, and the private sector in its deliberations,
reflecting the recognition that cybersecurity is not solely a state-to-state matter.
Implementation focus: The OEWG has placed greater emphasis on the practical implementation of agreed norms, including through voluntary reporting by states on their domestic cybersecurity policies and practices.
Institutionalization: Both OEWG reports have called for the establishment of a regular institutional mechanism for cyber discussions at the UN, which would enable ongoing dialogue and the progressive development of norms beyond the ad hoc GGE/OEWG format.
The push for a UN Cybercrime Convention began with a resolution adopted by the UN General Assembly in December 2019, initiated by Russia and supported by China and other states. Resolution 74/247 established an Ad Hoc Committee to elaborate a comprehensive international convention on countering the use of information and communications technologies for criminal purposes. The Ad Hoc Committee conducted seven negotiating sessions between 2021 and 2025.
The proposed Convention has been one of the most contentious international treaty negotiations in recent years, with deep divisions between two blocs:
Human rights advocates and Western democracies have argued that the
Convention should focus narrowly on cybercrime and include robust safeguards for human rights, privacy, and the rule of law. They have expressed concern that the Convention could be used to justify expanded surveillance capabilities, the criminalization of legitimate expression,
and cross-border law enforcement cooperation without adequate safeguards.
Russia, China, and their supporters have argued that the Convention should address a broad range of cyber-related criminal activities,
including "information crimes" and content-related offenses. They have sought provisions that would strengthen state sovereignty over internet governance and facilitate cross-border cooperation in criminal investigations.
As finalized by the Ad Hoc Committee in 2025, the proposed Convention includes provisions on:
Criminalization: Establishing domestic criminal offenses for a range of cybercrime activities, including illegal access, data interference,
system interference, computer-related fraud, and child sexual exploitation material. Content-related offenses were a major point of contention, with the final text including provisions on child sexual exploitation material and "terrorism" content while avoiding broader content regulation.
International cooperation: Establishing a framework for mutual legal assistance, extradition, and joint investigations for cybercrime offenses. The cooperation framework includes provisions on emergency requests and the direct cooperation between law enforcement agencies of different states, which human rights organizations have criticized as potentially enabling bypass of domestic judicial oversight.
Procedural measures: Establishing powers for the investigation of cybercrime offenses, including the preservation, search, and seizure of electronic evidence, and the interception of communications data. The final text includes some safeguards for human rights, including requirements for judicial authorization and proportionality, though critics argue that the safeguards are insufficient.
Human rights safeguards: Article 5 of the proposed Convention includes a general clause requiring states to implement the Convention in a manner that protects human rights and fundamental freedoms.
However, the effectiveness of this safeguard depends on domestic judicial oversight and the political will of individual states.
Prevention and awareness: Provisions on public awareness campaigns,
training for law enforcement, and technical assistance for developing countries.
The Ad Hoc Committee concluded its work in early 2025, and the draft
Convention was presented to the UN General Assembly for adoption. The
Convention was adopted by the General Assembly in late 2025, and will be opened for signature in 2026. It will enter into force after ratification by the required number of states.
Significance: The UN Cybercrime Convention will be the first global treaty on cybercrime, potentially superseding the Budapest Convention as the primary international framework for cybercrime cooperation. However,
its practical impact will depend on:
The number and identity of states that ratify it (the United States and the EU have expressed reservations but have indicated a willingness to ratify with appropriate reservations).
The quality of domestic implementing legislation.
The development of implementing rules and guidance by the Conference of States Parties.
The willingness of states to cooperate under the Convention's framework.
Concerns: Human rights organizations (including Amnesty
International, Human Rights Watch, and the EFF) have expressed serious concern that the Convention could be used by authoritarian states to justify expanded surveillance, the criminalization of dissent, and cross-border repression. The long-term impact of the Convention will depend on the strength of its implementation safeguards and the willingness of states parties to uphold human rights protections.
The UN Guiding Principles on Business and Human Rights (2011), while not specifically focused on cyber issues, have been increasingly applied to the digital context, including data protection, platform governance,
and AI ethics. The Principles establish the corporate responsibility to respect human rights, which includes the responsibility of technology companies to respect the right to privacy and other rights in the digital sphere.
The UN General Assembly has adopted several resolutions on the right to privacy in the digital age (most recently Resolution 78/189 in 2023),
affirming that the same rights that people have offline must also be protected online. The resolutions call on states to review their procedures, practices, and legislation regarding surveillance of communications, and to ensure that surveillance measures are necessary,
proportionate, and subject to adequate oversight.
UNESCO adopted the Recommendation on the Ethics of AI in November
2021, the first global normative instrument on AI ethics. The
Recommendation provides a framework for the ethical development and deployment of AI, with emphasis on human rights, environmental sustainability, diversity, and inclusiveness. It complements the OECD AI
Principles and has been endorsed by all 193 UNESCO member states.

# Chapter 45: APEC Cross-Border Privacy Rules (CBPR)

The APEC Cross-Border Privacy Rules (CBPR) system is a voluntary,
enforceable code of conduct for businesses that handle personal data across borders within the Asia-Pacific Economic Cooperation (APEC)
region. The CBPR system was developed by the APEC Electronic Commerce
Steering Group (ECSG) and endorsed by APEC Economic Leaders in 2011. The system became operational in 2012, with the first certifications issued in 2014.
The CBPR system was designed to address a fundamental challenge in the Asia-Pacific region: the lack of a comprehensive regional data protection framework comparable to the EU's GDPR or the Council of
Europe's Convention 108. While some APEC member economies (including
Japan, South Korea, Singapore, and Australia) have comprehensive data protection laws, others (including the United States and several
Southeast Asian economies) rely on a patchwork of sectoral laws and self-regulatory frameworks. The CBPR system provides a mechanism for businesses to demonstrate compliance with a common set of privacy standards, regardless of differences in domestic legal frameworks.
The CBPR system is based on the APEC Privacy Framework, first adopted in 2005 and updated in 2015. The Privacy Framework establishes nine principles for the protection of personal data:
Preventing harm: Personal information should be protected in ways that prevent harm to the individuals concerned.
Notice: Individuals should be provided with clear and easily understood information about the collection and use of their personal information.
Collection limitation: Collection of personal information should be limited to what is necessary for the purposes identified.
Uses of personal information: Personal information should be used only for the purposes identified and should not be further used without appropriate consent or legal authority.
Choice: Where appropriate, individuals should be provided with choices regarding the collection and use of their personal information.
Integrity of personal information: Personal information should be accurate, complete, and kept up to date as necessary.
Security safeguards: Personal information should be protected by reasonable security safeguards against loss, unauthorized access, use,
modification, or disclosure.
Access: Individuals should be provided with reasonable access to their personal information and the ability to correct it.
Accountability: Organizations that collect personal information should be accountable for complying with measures that give effect to the principles.
The CBPR system operates through a three-tier certification structure:
Businesses seeking CBPR certification must:
Self-assess: Conduct a self-assessment of their data protection practices against the CBPR requirements.
Engage an Accountability Agent: Submit to an independent assessment by an APEC-recognized Accountability Agent (a private-sector certification body authorized by the APEC CBPR system to conduct assessments). Accountability Agents include TRUSTe (now TrustArc), BSI
Group, and other recognized certification bodies.
Certification: Upon successful assessment, the business receives an
APEC Business Privacy Certificate, valid for a period specified by the
Accountability Agent (typically 1-3 years, subject to annual monitoring).
The CBPR system provides for enforcement through:
Accountability Agent enforcement: Accountability Agents may investigate complaints, issue compliance recommendations, and, in the case of serious or repeated violations, suspend or revoke certification.
Domestic enforcement: APEC member economies may designate a Domestic
Enforcement Agency (DEA) with the authority to investigate complaints and take enforcement action against certified businesses operating within their jurisdiction. As of early 2026, the following economies have designated DEAs: the United States (FTC), Canada (OPC), Japan
(PPC), South Korea (PIPC), Singapore (PDPC), Australia (OAIC), Chinese
Taipei, Mexico (INAI), and the Philippines (NPC).
Cross-border enforcement: DEAs may cooperate in the investigation and resolution of complaints that involve cross-border data flows, including the referral of complaints to the DEA of the economy in which the business is headquartered.
The APEC Privacy Recognition Arrangement (PRA), established in 2015,
provides a framework for the mutual recognition of CBPR certifications across participating economies. Under the PRA, a business certified under the CBPR system in one economy is recognized as meeting the CBPR
requirements in all other participating economies. The PRA was further strengthened in 2022 with the introduction of enhanced cooperation mechanisms between DEAs.
As of early 2026, the following APEC member economies participate in the CBPR system:
Full participants (with certified businesses): United States, Canada,
Japan, South Korea, Singapore, Australia, Mexico, Chinese Taipei, and the Philippines.
Economies in the process of joining: Thailand, Vietnam, Malaysia,
Indonesia, and others have expressed interest in joining the CBPR
system.
The United States is the largest participant in the CBPR system, with the FTC serving as the Domestic Enforcement Agency. US participation is significant because the United States lacks a comprehensive federal privacy law, making the CBPR system one of the few mechanisms through which US businesses can demonstrate compliance with internationally recognized privacy standards. The FTC has actively enforced CBPR
certifications, bringing enforcement actions against businesses that have made false CBPR certification claims.
Japan's participation in the CBPR system complements the EU-Japan mutual adequacy arrangement, providing Japanese businesses with a mechanism to demonstrate privacy compliance in the Asia-Pacific region while also maintaining compliance with the EU adequacy requirements.
The CBPR system has been criticized on several grounds:
Voluntary nature: Participation is voluntary, and the system covers only businesses that choose to seek certification. The majority of businesses in the APEC region are not certified.
Enforcement gaps: While DEAs have enforcement authority, the CBPR
system lacks the comprehensive enforcement mechanisms of regulatory frameworks like the GDPR. Enforcement is limited to certified businesses and depends on the capacity and willingness of individual DEAs.
Coverage limitations: The CBPR system covers only cross-border transfers of personal data between participating economies. It does not address the full range of data protection issues (such as data subject rights, automated decision-making, or data breach notification) that are covered by comprehensive data protection laws.
Limited adoption: Despite being in operation for over a decade, the
CBPR system has achieved relatively modest adoption, with a few hundred certified businesses worldwide. This has raised questions about the system's scalability and relevance.
The CBPR system can be compared with other cross-border data transfer mechanisms:
EU adequacy decisions: The EU adequacy framework provides a unilateral determination by the European Commission that a third country provides adequate protection. The CBPR system, by contrast, is a multilateral, voluntary framework.
APEC CBPR vs. EU SCCs: The CBPR system provides a certification-based mechanism for demonstrating compliance, while the EU's Standard
Contractual Clauses (SCCs) provide a contractual mechanism. The CBPR
system is less formal and more flexible but provides less legal certainty.
APEC CBPR vs. Convention 108+: Convention 108+ provides a legally binding treaty framework for data protection, while the CBPR system is a voluntary code of conduct. Convention 108+ has broader geographic coverage but is limited to states that have ratified the Convention.
The CBPR system requirements, the APEC Privacy Framework, and the
Privacy Recognition Arrangement are available from the APEC CBPR website
(https://www.apec.org/groups/committee-on-trade-and-investment/electronic-commerce-steering-group).
Accountability Agent certification processes and requirements are available from the respective Accountability Agents (TrustArc, BSI
Group, etc.).

# Chapter 46: African Union — Malabo Convention on Cyber Security and Personal Data Protection

The African Union Convention on Cyber Security and Personal Data
Protection (the Malabo Convention) was adopted by the African Union
Assembly at its Extraordinary Session in Malabo, Equatorial Guinea, on
June 27, 2014. The Convention entered into force on June 8, 2023,
following ratification by the required number of AU member states (15
ratifications).
The Malabo Convention is significant as the first continent-wide treaty addressing both cybersecurity and personal data protection in
Africa. It reflects the African Union's recognition that cybersecurity and data protection are interconnected issues that require a coordinated regional approach, particularly in the context of the African
Continental Free Trade Area (AfCFTA) and the continent's rapid digitalization.
The Convention is divided into two main parts:
Part One addresses cybersecurity, including:
Establishment of national computer emergency response teams (CERTs).
The Convention requires member states to establish national CERTs and to cooperate through the Africa CERT forum.
Cybercrime offenses. The Convention establishes a list of cybercrime offenses that member states must criminalize, including illegal access,
illegal interception, data interference, system interference,
computer-related fraud, and offenses related to child pornography. The cybercrime provisions are broadly similar to those in the Budapest
Convention, though the Malabo Convention includes some additional offenses (such as offenses related to racist and xenophobic content)
that are not included in the Budapest Convention.
International cooperation. The Convention establishes a framework for mutual legal assistance, extradition, and joint investigations for cybercrime offenses. The cooperation framework is designed to complement the Budapest Convention's framework and to provide additional mechanisms for intra-African cooperation.
Capacity building. The Convention provides for technical assistance,
training, and capacity building for member states, recognizing the significant disparities in cybersecurity capacity across the continent.
Part Two addresses personal data protection, including:
Definitions. The Convention defines personal data, sensitive data,
the data subject, the data controller, and the data processor.
Principles. The Convention establishes principles for the lawful processing of personal data, including lawfulness, fairness, purpose limitation, data minimization, accuracy, storage limitation, security,
and accountability. These principles are closely aligned with the principles established by Convention 108 and the OECD Privacy
Guidelines.
Data subject rights. The Convention provides for the right of access,
the right to rectification, the right to erasure, the right to object,
and the right to compensation.
Sensitive data. Enhanced protections for data on health, sex life,
race, ethnicity, political opinions, religious beliefs, and biometric data.
Cross-border transfers. The Convention permits cross-border transfers where adequate protection is ensured, where the data subject consents,
or where an international agreement provides adequate safeguards.
Data protection authorities. The Convention requires member states to establish independent data protection authorities with enforcement powers.
Domestic implementation. The Convention requires member states to adopt domestic legislation implementing the Convention's provisions.
The Malabo Convention is designed to complement rather than replace existing international instruments:
Convention 108/108+: Many African countries that are members of both the African Union and the Council of Europe (or have ratified Convention
108 independently) are parties to both instruments. The Malabo
Convention's data protection provisions are broadly consistent with
Convention 108, enabling states to implement both instruments through a single domestic legislative framework.
Budapest Convention: Several African states are parties to the
Budapest Convention. The Malabo Convention's cybercrime provisions complement the Budapest Convention by providing additional mechanisms for intra-African cooperation.
ECOWAS Supplementary Act: The Economic Community of West African
States (ECOWAS) Supplementary Act A/SA.1/01/10 on Personal Data
Protection provides a regional data protection framework for West Africa that predates the Malabo Convention. The Malabo Convention provides a continent-wide framework that builds on and is consistent with the
ECOWAS Supplementary Act.
As of early 2026, 18 AU member states have ratified the Malabo
Convention, including Angola, Burkina Faso, Cabo Verde, Chad, Congo,
Gambia, Ghana, Guinea, Madagascar, Mali, Mauritania, Mauritius,
Mozambique, Namibia, Nigeria, São Tomé and Príncipe, Senegal, and South
Africa. An additional 15+ states have signed but not yet ratified.
The pace of ratification has been slow, reflecting challenges including:
Limited legislative capacity: Many African states face resource constraints that limit their ability to enact and implement comprehensive data protection legislation.
Competing priorities: Data protection and cybersecurity legislation competes with other legislative priorities in many African countries.
Coordination challenges: The dual scope of the Convention
(cybersecurity and data protection) means that ratification requires coordination between multiple government ministries and agencies.
The African Union Commission has supported the ratification and implementation process through technical assistance programs, regional workshops, and the development of model legislation.
The full text of the Malabo Convention is available from the African
Union Commission's website (https://au.int) in English, French, Arabic,
and Portuguese.

# Chapter 47: Regional Coordination Frameworks and Global Trends

## 47.1 Overview

In the preceding 46 chapters, this volume has systematically examined the cyber legal frameworks of major jurisdictions and nations around the world. Yet the inherently cross-border nature of cyberspace dictates that no single country's laws can independently resolve global problems — viruses do not respect national boundaries, data flows disregard borders, and the origin of a cyberattack may lie thousands of miles away. Accordingly, **regional legal coordination frameworks** constitute an indispensable third tier in the architecture of cyber law governance, which, together with domestic legislation and global treaties, forms a three-tiered pyramid of cyberspace governance.

This chapter focuses on regional coordination frameworks **not addressed as standalone chapters** in the preceding 46: the Association of Southeast Asian Nations (ASEAN), the Shanghai Cooperation Organisation (SCO), the Community of Latin American and Caribbean States (CELAC), the Gulf Cooperation Council (GCC), and the Economic Community of West African States (ECOWAS) — examining their regional legal coordination efforts in the fields of cybersecurity and data protection. While these frameworks may lack the full binding force of instruments such as the GDPR or the Budapest Convention, they play an increasingly significant role in promoting intra-regional legal convergence, establishing mechanisms for cross-border law enforcement cooperation, and harmonising technical standards.

> **Reader's Guide**: This chapter does not duplicate coverage of jurisdictions already addressed in dedicated chapters. For the legal frameworks of specific jurisdictions, please refer to the following chapters:
> - Brazil LGPD → Chapter 33
> - Argentina LPDP → Chapter 34
> - South Africa POPIA → Chapter 35 (separate dedicated chapter)
> - India DPDPA → Chapter 30
> - Middle Eastern data protection laws → Chapter 38
> - African Union Malabo Convention → Chapter 46 (survey of African jurisdictions)
> - Commonwealth of Independent States (CIS) jurisdictions → Appendix VI

---

## 47.2 ASEAN — Soft-Law-Driven Digital Governance Coordination

### 47.2.1 The Governance Model for ASEAN Cyber Law Harmonisation

The Association of Southeast Asian Nations (ASEAN) comprises ten Member States (Brunei Darussalam, Cambodia, Indonesia, Lao PDR, Malaysia, Myanmar, the Philippines, Singapore, Thailand, and Viet Nam), with a combined population exceeding 660 million, and represents one of Asia's most dynamic digital economy markets. Nevertheless, the wide disparities among ASEAN Member States in legal systems, levels of economic development, and degrees of digitalisation — ranging from advanced economies such as Singapore with comprehensive data protection legislation to developing nations still constructing foundational cyber legal frameworks — present unique challenges for ASEAN cyber law harmonisation.

ASEAN has adopted a fundamentally different approach to cyber law harmonisation from that of the European Union: **rather than pursuing legally binding regional regulations** (such as the GDPR), it promotes voluntary legal coordination among Member States through **soft-law instruments** — framework documents, digital partnerships, and capacity-building initiatives.

### 47.2.2 The ASEAN Digital Masterplan

The **ASEAN Digital Masterplan 2025** is ASEAN's core policy framework in the field of digital governance, adopted at the ASEAN Digital Ministers' Meeting in 2021. The Masterplan sets forth eight desired outcomes, of which those directly relevant to cyber law include:

1. **Advancing data governance cooperation**: establishing the ASEAN Data Classification Framework to provide a technical benchmark for harmonising Member States' policies on cross-border data flows
2. **Strengthening cybersecurity capacity-building**: leveraging the ASEAN-Singapore Cybersecurity Centre of Excellence to enhance Member States' cyber incident response capabilities
3. **Promoting personal data protection**: providing a model template for Member States' data protection legislation through the ASEAN Digital Data Governance Framework

### 47.2.3 ASEAN Framework on Personal Data Protection

ASEAN adopted the **ASEAN Framework on Personal Data Protection** in 2016. While non-binding in character, the Framework provides Member States with a reference benchmark for data protection legislation. The Framework affirms the following core principles: consent, notification, purpose limitation, data integrity, security safeguards, access and correction, accountability, and limitation on cross-border transfers.

### 47.2.4 ASEAN Cybersecurity Cooperation

In the field of cybersecurity, ASEAN has established the following key cooperation mechanisms:

- **ASEAN CERT (Computer Emergency Response Team)** : coordinating Member States' cyber incident response
- **ASEAN Cybersecurity Cooperation Strategy (2017–2020)** and its successor iterations: covering the combatting of cybercrime, critical information infrastructure protection (CIIP), and capacity-building
- **ASEAN Network Security Action Council**: promoting regional coordination of cybersecurity policies

### 47.2.5 Assessment and Outlook

The **strength** of the ASEAN model lies in its respect for Member States' legal sovereignty and developmental pace, avoiding the compliance burden of a one-size-fits-all approach. Its **limitation** lies in the absence of enforcement power — should a Member State elect not to implement the recommendations contained in framework documents, ASEAN lacks any legal mechanism to compel compliance. Going forward, the extent to which the model provisions of the ASEAN Digital Data Governance Framework are absorbed into Member States' domestic legislation will serve as the key yardstick for testing the efficacy of this soft-law model.

---

## 47.3 Shanghai Cooperation Organisation (SCO) — Cybersecurity and the Information Space Order

### 47.3.1 The SCO's Distinctive Position in Cyber Governance

The Shanghai Cooperation Organisation (SCO), comprising eight Member States (China, India, Kazakhstan, Kyrgyzstan, Pakistan, Russia, Tajikistan and Uzbekistan), has adopted a **markedly different normative stance** in the field of cyber governance from that of Western-led frameworks.

The SCO's core governance philosophy is founded upon the concepts of "**information space sovereignty**" and "**cyber sovereignty**," which are highly consistent in conception with China's Cybersecurity Law and Russia's Sovereign Internet Law.

### 47.3.2 Core SCO Cybersecurity Instruments

The **Agreement on Cooperation in Ensuring International Information Security** among SCO Member States (signed in 2009, entered into force in 2012) remains to this day the foundational institutional pillar of SCO cybersecurity cooperation. The Agreement's core content includes:

1. **Catalogue of information security threats**: the threats recognised under the Agreement encompass information weaponisation, cyber terrorism, cybercrime, and the use of ICT to subvert the political or economic systems of other states
2. **Principle of information space sovereignty**: explicit recognition of each state's jurisdiction within its own information space
3. **Cooperation mechanisms**: establishing mechanisms for information exchange, joint investigations, and the training of law enforcement personnel

### 47.3.3 International Code of Conduct

Since 2011, SCO Member States have jointly submitted multiple iterations of an **International Code of Conduct for Information Security** to the United Nations General Assembly. The 2021 version had expanded to include over 60 co-sponsors. The Code of Conduct's core propositions include:

- **Sovereign jurisdiction of states over their information space**
- **Opposition to the use of ICT to intervene in the internal affairs of other states**
- **Opposition to the militarisation of cyberspace in any form**
- **Advocacy for the formulation of global cyberspace rules within the framework of the United Nations**

While the Code of Conduct has not yet attained the status of a formal treaty, it carries significant normative influence in international legal debates and constitutes an essential instrument for understanding a "non-Western" perspective on cyber governance.

### 47.3.4 Data Protection and Data Localisation

The data protection laws of SCO Member States exhibit notable commonalities as well as divergences:

| Dimension | China (PIPL) | Russia (152-FZ) | Kazakhstan | Pakistan (2023 PDPB) |
|-----------|-------------|-----------------|------------|-----------------------|
| Core legislation | PIPL 2021 | Federal Law No. 152-FZ (2006) | Law on Personal Data Protection (2013) | PDPB 2023 |
| Data localisation | Partially mandatory (CIIOs, important data) | Fully mandatory (all personal data of Russian citizens) | Partially mandatory | Conditionally restricted |
| Extraterritorial reach | Art. 3 (jurisdiction over processing of personal data of natural persons within China conducted abroad) | Limited | Limited | Limited |

The SCO has not yet established unified data protection standards at the organisational level. However, the data localisation policies of its Member States have, in practice, already exerted a substantial impact on regional data flow patterns — the investments in data localisation infrastructure by Russian and Chinese enterprises are emerging as a significant external driver of digital transformation across SCO Member States.

---

## 47.4 Gulf Cooperation Council (GCC) — The Emergence of Unified Data Law

### 47.4.1 Institutional Characteristics of GCC Digital Governance

The Gulf Cooperation Council (GCC) comprises six Member States (Saudi Arabia, the United Arab Emirates, Qatar, Kuwait, Bahrain, and Oman), representing the most concentrated hub of digital economic development in the Middle East.

> For details of individual Member States' data protection laws, please refer to Chapter 38 (Saudi Arabia PDPL / UAE PDPL / Qatar / Bahrain, etc.).

GCC digital governance is characterised by two important institutional features: first, a **"central-free zone" dual-track model** (for instance, the UAE's DIFC and ADGM free zones each possess independent legal systems); and second, an **increasing demand for a unified regional data law** — the six Member States' economies are deeply integrated (the GCC Customs Union and Common Market), yet their data protection laws operate in silos.

### 47.4.2 Progress on the GCC Unified Data Protection Law

GCC Member States commenced deliberations in 2018 on a **GCC Unified Personal Data Protection Law**, aimed at establishing a unified data protection legal standard for the Gulf region. The draft draws upon the core principles of the GDPR and the respective legislative experience of GCC States, and seeks to address the fragmentation of data protection laws across the six Member States.

However, the unified law currently remains at the drafting and discussion stage. Principal obstacles include: divergences among Member States regarding data localisation provisions; the absence of consensus on a mechanism for cross-GCC data transfers; and differing positions among Member States on whether a unified regulatory body at the GCC level should be established.

### 47.4.3 Unified Cybersecurity Framework

In the cybersecurity domain, GCC coordination is more advanced than in data protection. The **GCC National CERTs** (Computer Emergency Response Teams) have established coordination mechanisms and are promoting regional cooperation in the following areas: cybersecurity standards for critical infrastructure (GCC Cybersecurity Standards for Critical Infrastructure); joint cybersecurity exercises; and the sharing of intelligence and information security threat information.

---

## 47.5 Community of Latin American and Caribbean States (CELAC) and the Ibero-American Framework

### 47.5.1 Overview

The Community of Latin American and Caribbean States (CELAC) comprises 33 Member States and serves as the principal platform for regional policy coordination in digital governance and cybersecurity within Latin America. In addition, the **Ibero-American Data Protection Network** (Red Iberoamericana de Protección de Datos, hereinafter "RIPD") provides a specialised technical cooperation framework for privacy protection in the region.

> For details of specific Member States' data protection laws, please refer to Chapter 33 (Brazil LGPD), Chapter 34 (Argentina / Mexico LPDP), and the relevant portions of Chapters 31–32.

### 47.5.2 CELAC Digital Governance Framework

At its Sixth Summit in 2021, CELAC adopted the **Agenda Digital CELAC**, which set forth a number of priority areas for regional digital cooperation. In the realm of cyber law, key policy directions include: regional harmonisation of data protection laws across CELAC States; capacity-building in cybersecurity, with particular attention to the high-frequency ransomware attacks and transnational cybercrime confronting the Latin American and Caribbean region; and bridging the digital divide, encompassing internet infrastructure and digital literacy education.

### 47.5.3 The Ibero-American Data Protection Network (RIPD)

Established in 2003 and composed of the data protection authorities of Latin American countries, Spain, Portugal, Andorra and others, the RIPD is the earliest and most active professional data protection network in Latin America and the Caribbean. The RIPD's activities include: regular annual conferences and thematic working groups; the promotion of harmonised standards and terminology; and transnational support for the capacity-building of Member States' data protection authorities.

The RIPD has played an irreplaceable role in advancing convergence among Latin American countries in terminology, standards and legal principles — from Brazil's LGPD to Argentina's LPDP, from Mexico's LFPDPPP to Chile's 2023 amendments, the coordinating influence of the RIPD is clearly discernible in the common genetic code of Latin American data protection law.

---

## 47.6 Economic Community of West African States (ECOWAS) and African Data Governance

### 47.6.1 The ECOWAS Supplementary Act

The Economic Community of West African States (ECOWAS), composed of 15 Member States, adopted in 2010 a legally binding **ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection**.

> For the Malabo Convention at the African Union level, please refer to Chapter 46.

This Supplementary Act constitutes secondary legislation within the ECOWAS legal system. It is **directly binding** on all ECOWAS Member States and requires that they:

1. **Establish a data protection legal framework**: adopt domestic data protection legislation within a specified period following the Act's entry into force
2. **Establish an independent data protection authority**: create or designate a body responsible for data protection oversight
3. **Recognise the fundamental rights of data subjects**: the right of access, the right to object, the right of rectification, and the right to erasure
4. **Restrict cross-border data flows**: impose conditions on the transfer of data to non-ECOWAS Member States

### 47.6.2 Implementation Challenges

The implementation of the ECOWAS Supplementary Act faces practical obstacles: insufficient legislative capacity among Member States, resulting in slow progress in transposing the Act into domestic law; inadequate enforcement capacity of regional data protection bodies; and the dual scarcity of technical infrastructure and human resources, which renders the regulation of cross-border data transfers difficult to enforce in practice.

Nonetheless, as the only legally binding regional data protection instrument at the sub-regional level in Africa, the ECOWAS Supplementary Act carries significant theoretical and practical value as an exploration of a "top-down plus South-South cooperation" model for data protection legislation.

---

## 47.7 Comparative Analysis of Regional Coordination Mechanisms

### 47.7.1 Four Models of Coordination

Global regional cyber law harmonisation manifests in four principal models:

| Model | Exemplar | Legal Binding Force | Institutional Character |
|-------|----------|-------------------|------------------------|
| **Supranational legislative model** | GDPR (EU) | Binding | Unified regulation, unified enforcement authority, sanctioning powers exercisable |
| **Sub-regional direct-binding model** | ECOWAS Supplementary Act | Binding | Sub-regional law directly binding Member States, but weaker enforcement mechanisms |
| **Soft-law harmonisation model** | ASEAN Frameworks, RIPD | Non-binding | Framework documents, standard promotion, capacity-building, voluntary adoption |
| **Political declaration model** | SCO Code of Conduct | Non-binding | Joint political statements of position, normative influence, no pursuit of direct legal binding force |

The coexistence of these four models is no accident, but rather a direct projection onto the field of data governance of the differing legal traditions, levels of economic development, and political systems of the respective regions.

### 47.7.2 The Paradox of "Fragmentation" and "Convergence" in Cyber Governance

A review of the development of regional cyber law coordination mechanisms from a global perspective reveals a central paradox: **fragmentation alongside convergence**.

**Dimensions of convergence**:
- Data protection principles — transparency, purpose limitation, security safeguards, accountability — have become the common language of virtually all regional frameworks
- Data subject rights architecture — the right of access, right of rectification, right to erasure, right to data portability, right to object — are highly consistent across mainstream frameworks
- The regulatory authority model — the establishment of independent data protection authorities has been universally adopted across major regional frameworks

**Dimensions of fragmentation**:
- Data localisation requirements — from fully mandatory (Russia) to wholly non-mandatory (most African states), divergences are pronounced
- Government access to data — from strict limitations (GDPR) to broad exemptions (India DPDPA), reflecting differing calibrations of "national security versus personal privacy"
- Cross-border data flow mechanisms — from adequacy decisions (EU) to white-list models (India), from no requirements (most African states) to stringent restrictions (certain GCC States)

The international community has yet to reach consensus on a "global baseline standard for data governance" — the GDPR serves as a de facto global reference standard, but there exists a structural tension between its extraterritorial reach and normative diffusion on the one hand, and the firm assertion of data sovereignty by individual states on the other.

---

## 47.8 Emerging Issues and Future Trends

### 47.8.1 The Regionalisation of Artificial Intelligence Governance

As the cross-border training and deployment of AI models becomes the norm, regional coordination frameworks are beginning to extend into AI governance:

- ASEAN has adopted the **ASEAN Guide on AI Governance and Ethics** (2024), setting forth seven principles for trustworthy AI
- The EU is advancing the **EU AI Act**, whose extraterritorial reach will produce a cumulative effect with that of the GDPR
- The African Union is developing a **Continental AI Strategy for Africa**

### 47.8.2 Experiments with Data Free Flow Zones

New-generation trade agreements, including the Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP) and the Digital Economy Partnership Agreement (DEPA), are beginning to embed "data free flow" provisions within the trade agreement framework, thereby constructing regional data governance mechanisms carried by trade agreements. This model is referred to as the "**trade law pathway**" — distinct from the "human rights protection pathway" (epitomised by the GDPR), it embeds data flows within a broader framework of trade liberalisation.

### 47.8.3 Technical Standards as Invisible Coordination

Where legal harmonisation proceeds slowly, technical standards (ISO 27701, SOC 2, Cloud Security Alliance frameworks) are becoming de facto instruments of regional coordination. Even where an enterprise's home jurisdiction lacks data protection legislation, if its commercial counterparties require ISO 27701 certification, that enterprise has already been drawn by "technical standards" into the orbit of legal standards such as the GDPR. This "**technical standards plus contractual obligations**" non-legal convergence pathway exerts an increasingly pronounced normative transmission effect in regions — such as ASEAN and Africa — that lack strongly binding regional legal instruments.

---

## 47.9 Conclusion

Regional legal coordination frameworks constitute the critical middle tier linking domestic legislation and global cyber governance. From ASEAN's soft-law harmonisation to the SCO's political declarations, from ECOWAS's sub-regional legislation to the GCC's draft unified law, different regions are engaged in an exploration characterised by "plurality of methods and convergence of objectives" in the fields of data protection, cybersecurity and digital governance.

The future of the global cyber legal order depends as much on the legal evolution of a handful of super-jurisdictions (EU, US, CN) as on the success of regional coordination mechanisms in building bridges between "respect for the legal sovereignty of states" and "the establishment of a transnational governance order." In particular, the rise of AI governance will propel regional legal coordination into an entirely new phase — a phase in which the boundaries between **technology ethics**, **trade policy** and **data protection** will become increasingly blurred, and the institutional forms of regional coordination frameworks will accelerate their evolution accordingly.

---

> **Chapter References**: For analysis of specific jurisdictions, please refer to the following chapters:
> 
> | Jurisdiction | Chapter | Jurisdiction | Chapter |
> |-------------|---------|-------------|---------|
> | Brazil LGPD | Ch. 33 | Argentina LPDP | Ch. 34 |
> | India DPDPA | Ch. 30 | Middle East Data Prot. Laws | Ch. 38 |
> | AU Malabo Convention | Ch. 46 | CIS Jurisdictions | App. VI |
> | EU GDPR | Ch. 22 | China PIPL | Ch. 23 |
> | US Sectoral Laws | Chs. 24–29 | UK UK GDPR | Ch. 39 |
> | Japan APPI | Ch. 28 | Korea PIPA | Ch. 29 |
> | Canada PIPEDA | Ch. 37 | Australia Privacy Act | Ch. 31 |
> | Russia 152-FZ | Ch. 40 | Budapest Convention | Ch. 41 |

# Appendix I: Master Table of Data Protection Authorities Worldwide

> This table compiles data protection regulatory authorities from major jurisdictions worldwide, grouped by region. Each entry includes the jurisdiction, authority name (Chinese + English/original), year established, official website, key enforcement powers, and penalty cap. Penalty caps are based on the current law of each jurisdiction; some jurisdictions adopt a percentage-of-turnover model, while others adopt a fixed-amount model, as noted in the table.

---

## I. European Union (EU)

### EU-Level

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| EU | European Data Protection Board (EDPB) | 2018 | edpb.europa.eu | GDPR consistency guidance, dispute resolution via binding decisions, coordination of national DPAs | No direct fines; indirectly influences national DPA fines through binding decisions |
| EU | European Data Protection Supervisor (EDPS) | 2001 | edps.europa.eu | Supervise processing of personal data by EU institutions, participate in EDPB decision-making | Administrative fines on EU institutions, capped in line with GDPR (€10 million or 2% of global annual turnover) |

### EU Member State DPAs

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| Ireland | Data Protection Commission (DPC) | 2014 (predecessor 1988) | dataprotection.ie | GDPR enforcement, lead authority for cross-border processing under one-stop-shop mechanism, investigation and sanctions | €20 million or 4% of global annual turnover (GDPR standard) |
| France | Commission Nationale de l'Informatique et des Libertés (CNIL) | 1978 | cnil.fr | GDPR enforcement, data processing authorization, warnings and sanctions | €20 million or 4% of global annual turnover (GDPR standard) |
| Germany (Federal) | Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) | 1978 (reorganized 2016) | bfdi.bund.de | Supervision of federal body data processing, GDPR enforcement (federal level) | €20 million or 4% of global annual turnover (GDPR standard) |
| Germany (States) | State Data Protection Authorities (Datenschutzbehörden der Länder), e.g., BayLDA (Bavaria), LDI NRW (North Rhine-Westphalia), etc. | Varies by state (1969–2001) | State-specific sites, e.g., lda.bayern.de | State-level GDPR enforcement, private sector supervision | €20 million or 4% of global annual turnover (GDPR standard) |
| Luxembourg | Commission Nationale pour la Protection des Données (CNPD) | 2002 | cnpd.lu | GDPR enforcement, data processing notification, cross-border cooperation | €20 million or 4% of global annual turnover (GDPR standard) |
| Italy | Garante per la protezione dei dati personali (Garante) | 1996 (reorganized 2024 as Garante per la protezione dei dati personali) | garanteprivacy.it | GDPR enforcement, data processing authorization, temporary processing restrictions | €20 million or 4% of global annual turnover (GDPR standard) |
| Spain | Agencia Española de Protección de Datos (AEPD) | 1994 | aepd.es | GDPR enforcement, LOPDGDD enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Netherlands | Autoriteit Persoonsgegevens (AP) | 2016 (predecessor 2001) | autoriteitpersoonsgegevens.nl | GDPR enforcement, UAVG enforcement, investigation and sanctions | €20 million or 4% of global annual turnover (GDPR standard) |
| Austria | Österreichische Datenschutzbehörde (DSB) | 2000 (reorganized 2018) | dsb.gv.at | GDPR enforcement, DSG enforcement | €20 million or 4% of global annual turnover (GDPR standard) |
| Belgium | Autorité de la protection des données / Gegevensbeschermingsautoriteit (APD/GBA) | 2019 (predecessor 1993) | autoriteprotectiondonnees.be | GDPR enforcement, investigation, sanctions | €20 million or 4% of global annual turnover (GDPR standard) |
| Bulgaria | Commission for Personal Data Protection (CPDP) | 2002 | cpdp.bg | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Croatia | Agencija za zaštitu osobnih podataka (AZOP) | 2003 | azop.hr | GDPR enforcement, data processing supervision | €20 million or 4% of global annual turnover (GDPR standard) |
| Cyprus | Office of the Commissioner for Personal Data Protection | 2002 | dataprotection.gov.cy | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Czech Republic | Úřad pro ochranu osobních údajů (ÚOOÚ) | 2000 | uoou.gov.cz | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Denmark | Datatilsynet | 2000 (reorganized 2019) | datatilsynet.dk | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Estonia | Andmekaitse Inspektsioon (AKI) | 1999 | aki.ee | GDPR enforcement, data processing supervision | €20 million or 4% of global annual turnover (GDPR standard) |
| Finland | Office of the Data Protection Ombudsman | 1995 | tietosuoja.fi | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Greece | Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων) | 1997 | dpa.gr | GDPR enforcement, data processing authorization | €20 million or 4% of global annual turnover (GDPR standard) |
| Hungary | National Authority for Data Protection and Freedom of Information (NAIH) | 2012 | naih.hu | GDPR enforcement, freedom of information supervision | €20 million or 4% of global annual turnover (GDPR standard) |
| Latvia | Datu Valsts Inspekcija (DVI) | 2001 | dvi.gov.lv | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Lithuania | Valstybinė duomenų apsaugos inspekcija (VDAI) | 2002 | vdai.lrv.lt | GDPR enforcement, data processing supervision | €20 million or 4% of global annual turnover (GDPR standard) |
| Malta | Office of the Information and Data Protection Commissioner (IDPC) | 2003 | idpc.org.mt | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Poland | Urząd Ochrony Danych Osobowych (UODO) | 2019 (predecessor 1998) | uodo.gov.pl | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Portugal | Comissão Nacional de Proteção de Dados (CNPD) | 1998 | cnpd.pt | GDPR enforcement, data processing authorization | €20 million or 4% of global annual turnover (GDPR standard) |
| Romania | National Supervisory Authority for Personal Data Processing (ANSPDCP) | 2005 | dataprotection.ro | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |
| Slovakia | Úrad na ochranu osobných údajov Slovenskej republiky | 2001 | dataprotection.gov.sk | GDPR enforcement, data processing supervision | €20 million or 4% of global annual turnover (GDPR standard) |
| Slovenia | Information Commissioner of the Republic of Slovenia (IP-RS) | 2005 | ip-rs.si | GDPR enforcement, information access supervision | €20 million or 4% of global annual turnover (GDPR standard) |
| Sweden | Integritetsskyddsmyndigheten (IMY) | 2000 (renamed 2023) | imy.se | GDPR enforcement, data processing registration | €20 million or 4% of global annual turnover (GDPR standard) |

---

## II. Other European Jurisdictions

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| Iceland | Persónuvernd / Icelandic Data Protection Authority | 2000 | personuvernd.is | GDPR (EEA-applicable) enforcement, data processing supervision | €20 million or 4% of global annual turnover (GDPR standard, applicable via EEA Agreement) |
| Liechtenstein | Datenschutzstelle (DSS) | 2002 | datenschutzstelle.li | GDPR (EEA-applicable) enforcement, DSG enforcement | €20 million or 4% of global annual turnover (GDPR standard, applicable via EEA Agreement) |
| Norway | Datatilsynet | 2001 | datatilsynet.no | GDPR (EEA-applicable) enforcement, Personal Data Act enforcement | €20 million or 4% of global annual turnover (GDPR standard, applicable via EEA Agreement) |
| Switzerland | Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (FDPIC) | 1993 (expanded powers after revDSG effective 2023) | edoeb.admin.ch | revDSG enforcement (effective 1 September 2023), cross-border cooperation | Up to CHF 50 million (revDSG Art. 31; criminal fines for serious violations) |
| United Kingdom | Information Commissioner's Office (ICO) | 1984 (GDPR/UK GDPR applicable from 2018) | ico.org.uk | UK GDPR and DPA 2018 enforcement, investigation, sanctions | £17.5 million or 4% of global annual turnover (whichever is higher) |

---

## III. North America

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| United States (Federal) | Federal Trade Commission (FTC) | 1914 | ftc.gov | Section 5 enforcement against unfair/deceptive acts, consent orders, consumer data protection | Up to $51,744 per violation (2024 inflation-adjusted; cumulative for continuing violations) |
| United States (California) | California Attorney General + California Privacy Protection Agency (CPPA) | 2020 (CPPA 2021) | oag.ca.gov / cppa.ca.gov | CCPA/CPRA enforcement, administrative penalties, civil actions | $2,749 per violation (general), $7,500 per intentional violation; CPPA may impose administrative fines under CPRA |
| United States (Other States) | State Attorneys General | Varies by state | State AG websites | Enforcement of state privacy laws (e.g., Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, etc.) | Varies by state, typically $7,500–$50,000 per violation |
| Canada (Federal) | Office of the Privacy Commissioner of Canada (OPC) | 1983 | priv.gc.ca | PIPEDA enforcement, investigation, recommendations (direct penalty powers to take effect under CPPA upon enactment) | No direct fining power under current PIPEDA; under CPPA up to 5% of global turnover or CAD $25 million (whichever is higher) |
| Canada (Quebec) | Commission d'accès à l'information du Québec (CAI) | 1982 | cai.gouv.qc.ca | Quebec Law 25 enforcement, data processing supervision | CAD $25,000–$100,000 (enterprises up to CAD $25 million or 2% of turnover) |
| Mexico | Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) | 2015 (predecessor IFAI 2003) | inai.org.mx | LFPDPPP enforcement, data processing supervision, dispute resolution | Up to MXN $320,000 per violation (approx. $16,000); additional penalties for serious cases |

---

## IV. Asia-Pacific

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| China | Cyberspace Administration of China (CAC) | 2014 | cac.gov.cn | Enforcement of PIPL, DSL, CSL; cross-border data transfer security assessment; algorithm regulation | Up to 5× illegal gains or 5% of turnover (PIPL Art. 66); up to revocation of business license |
| China | Ministry of Industry and Information Technology (MIIT) | 2008 | miit.gov.cn | Data security regulation in telecoms and internet sectors; APP violation enforcement | Warnings and fines under the Data Security Law and departmental rules |
| China | Ministry of Public Security (MPS) | — (data security enforcement powers since CSL 2017) | mps.gov.cn | Cybersecurity multi-level protection, data security enforcement, criminal investigation | Administrative fines + criminal prosecution |
| Japan | Personal Information Protection Commission (PIPC) | 2016 (predecessor 2003) | ppc.go.jp | APPI enforcement, data processing supervision, cross-border transfer approval | Up to ¥100 million (legal persons; increased to ¥100 million by 2022 amendment); additional penalties for non-compliance after corrective order |
| South Korea | Personal Information Protection Commission (PIPC) | 2011 (reorganized and strengthened 2023) | pipc.go.kr | PIPA enforcement, data processing supervision, dispute mediation | Up to 3% of turnover (introduced by 2023 amendment); administrative fines |
| Singapore | Personal Data Protection Commission (PDPC) | 2013 | pdpc.gov.sg | PDPA enforcement, data processing supervision, DPO registration management | SGD $1 million or 10% of organization's annual turnover (whichever is higher, after 2022 amendment) |
| India | Ministry of Electronics and Information Technology (MeitY) + Data Protection Board of India (DPBI, progressively established from 2025) | 2023 (DPDP Act passed) | meity.gov.in | DPDP Act 2023 enforcement, data processing supervision, cross-border transfer management | ₹250 crore (approx. $30 million); DPBI may impose administrative fines |
| Australia | Office of the Australian Information Commissioner (OAIC) | 2010 | oaic.gov.au | Privacy Act 1988 enforcement, APP principles enforcement, data breach notification | For serious or repeated interference: up to AUD $50 million, 30% of turnover, or 3× value of benefit (whichever is higher, after 2022 amendment) |
| New Zealand | Office of the Privacy Commissioner (OPC NZ) | 1993 (Privacy Act 2020 amended) | privacy.org.nz | Privacy Act 2020 enforcement, data breach notification, investigation | Up to NZD $10,000 (individuals); compliance notices for organizations; fines for non-compliance with compliance notices |
| Chinese Taipei (Taiwan) | Personal Data Protection Commission (under establishment) + sector-specific competent authorities | 2012 (dedicated authority under 2023 amendment, under establishment) | dpa.gov.tw (under establishment) | Personal Data Protection Act enforcement, sector-specific enforcement by competent authorities | NTD $20,000–$5,000,000 (depending on violation type); up to NTD $10,000,000 after amendment |
| Hong Kong SAR (China) | Office of the Privacy Commissioner for Personal Data (PCPD) | 1996 | pcpd.org.hk | PDPO enforcement, investigation, enforcement notices | Up to HKD $1,000,000 and 5 years' imprisonment (enhanced after 2021 amendment; non-compliance with enforcement notice) |
| Malaysia | Jabatan Perlindungan Data Peribadi (JPDP / Department of Personal Data Protection) | 2013 (elevated to department status 2024) | jpdp.gov.my | PDPA 2010 enforcement, data processing registration, cross-border transfer management | Up to MYR $500,000 and/or 3 years' imprisonment (criminal penalties); 2024 amendment proposes introduction of administrative fines |
| Thailand | Personal Data Protection Committee (PDPC Thailand) | 2022 (PDPA fully effective) | pdpc.or.th | PDPA enforcement, data processing supervision, dispute resolution | Up to THB $5,000,000 (approx. $140,000); administrative fines up to THB $5,000,000 |
| Philippines | National Privacy Commission (NPC) | 2016 | privacy.gov.ph | DPA 2012 enforcement, data processing registration, investigation | Up to PHP $5,000,000 (approx. $90,000) and imprisonment of 1–6 years (criminal); administrative fines separate |
| Indonesia | Lembaga Pelindungan Data Pribadi (under establishment; Ministry of Communication and Information Technology serving as interim) | 2022 (PDP Law passed) | kominfo.go.id | PDP Law 2022 enforcement, data processing supervision, cross-border transfer management | Up to IDR $2 billion (approx. $130,000); administrative fines up to 2% of turnover |
| Vietnam | Department of Cybersecurity and High-Tech Crime Prevention (MPS) + Personal Data Protection Committee (under establishment) | 2023 (PDPD promulgated) | bocongan.gov.vn | PDPD (Personal Data Protection Decree) enforcement, cross-border transfer management | Administrative fines up to VND $150,000,000 (approx. $6,000) or 5% of global turnover (depending on violation severity) |

---

## V. Latin America

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| Brazil | Autoridade Nacional de Proteção de Dados (ANPD) | 2020 | gov.br/anpd | LGPD enforcement, data processing supervision, cross-border transfer management | 2% of turnover (per violation); simple violations up to 2% of turnover |
| Argentina | Agencia de Acceso a la Información Pública (AAIP) | 2001 (reorganized 2017) | argentia.gob.ar/aaip | PDPA (Ley 25.326) enforcement, data processing registration | ARS $1,000,000–$5,000,000 (approx. $1,000–$5,000); doubled for serious cases |
| Chile | Consejo para la Transparencia (CPLT — data protection functions) | 2009 (DPA functions added by 2024 amendment) | consejotransparencia.cl | Law 19.628 (2024 amended) enforcement, data processing supervision | Up to UTM $5,000 (approx. CLP $310,000,000 / $320,000); increased after 2024 amendment |
| Colombia | Delegatura de Protección de Datos Personales (under the Superintendencia de Industria y Comercio, SIC) | 2012 | sic.gov.co | Ley 1581 de 2012 enforcement, data processing registration, investigation | Up to COP $40,000,000 (approx. $10,000); additional daily fines may apply |
| Peru | Autoridad Nacional de Protección de Datos Personales (under MINCETUR) | 2013 | mincetur.gob.pe | Ley 29733 enforcement, data processing registration | Up to UIT $100 (approx. PEN $5,150 / $1,350); doubled for serious cases |

---

## VI. Africa

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| South Africa | Information Regulator (IR) | 2016 (POPIA fully effective 2021) | inforegulator.org.za | POPIA enforcement, PAIA enforcement, data breach notification | Up to ZAR $10,000,000 (administrative fine) or 10 years' imprisonment (criminal) |
| Nigeria | Nigeria Data Protection Commission (NDPC) | 2023 (predecessor NDPB 2020) | ndpc.gov.ng | NDPA 2023 enforcement, data processing supervision | Up to NGN $10,000,000 (first violation) or 2% of global turnover (whichever is higher) |
| Kenya | Office of the Data Protection Commissioner (ODPC) | 2019 | odpc.go.ke | DPA 2019 enforcement, data processing registration, cross-border transfer management | Up to KES $5,000,000 (approx. $35,000) or 1% of turnover (whichever is higher) |
| Egypt | Egyptian Personal Data Protection Center (under the National Telecommunications Regulatory Authority, NTRA) | 2020 (PDPL passed; phased implementation from 2025) | ntra.gov.eg | PDPL 2020 enforcement, data processing supervision | Up to EGP $5,000,000 (approx. $160,000); doubled for serious cases |
| Morocco | Commission nationale de contrôle de la protection des Données à caractère Personnel (CNDP) | 2009 | cnp.ma | Law 09-08 enforcement, data processing authorization, cross-border transfer management | Up to MAD $1,000,000 (approx. $100,000); criminal prosecution separate |
| Rwanda | National Cyber Security Authority (NCSA) / data protection function; independent DPO under establishment from 2025 | 2021 (NCSA established); DPO under preparation 2025 | ncsa.gov.rw | Law N°058/2021 enforcement, data processing supervision | Up to RWF $20,000,000 (approx. $15,000) or 1% of turnover |

---

## VII. Middle East

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| United Arab Emirates | UAE Data Office (federal level, regulated by the Ministry of Presidential Affairs) | 2022 (PDPL passed) | uae-dataoffice.gov.ae (under development) | PDPL federal law enforcement, data processing supervision, cross-border transfer management | Up to AED $5,000,000 (approx. $1,360,000); administrative fines may accumulate |
| UAE (DIFC) | Office of the Data Protection Commissioner, DIFC | 2007 (DPL amended 2020) | dpcomms.difc.ae | DIFC DPL 2020 enforcement, data processing registration | Up to USD $1,000,000; additional penalties for continuing violations |
| UAE (ADGM) | Office of Data Protection, ADGM | 2015 (DPR amended 2021) | adgm.com | ADGM DPR 2021 enforcement, data processing supervision | Up to USD $28,000; higher fines for serious violations |
| Saudi Arabia | Saudi Data and Artificial Intelligence Authority (SDAIA) | 2019 | sdaia.gov.sa | PDPL enforcement, data processing supervision, cross-border transfer management | Up to SAR $5,000,000 (approx. $1,330,000); up to SAR $10,000,000 for serious violations |
| Israel | Privacy Protection Authority (PPA — under the Ministry of Justice) | 1981 (reorganized 2007) | privacy.gov.il | Privacy Protection Law 1981 enforcement, data processing registration, cross-border transfer management | Up to ILS $1,200,000 (approx. $330,000); criminal prosecution separate |
| Qatar | Qatar Data Protection Office (under the Ministry of Communications and Information Technology, MCIT) | 2016 (PDPPL effective 2019) | mcit.gov.qa | PDPPL enforcement, data processing supervision | Up to QAR $5,000,000 (approx. $1,370,000); administrative fines may accumulate |
| Bahrain | Personal Data Protection Authority (PDPA Bahrain — under the Ministry of Transportation and Telecommunications) | 2019 | pdpa.bh | PDPL 2018 enforcement, data processing supervision, dispute resolution | Up to BHD $50,000 (approx. $133,000); additional penalties for continuing violations |

---

## VIII. Commonwealth of Independent States (CIS)

| Jurisdiction | Authority Name | Year Est. | Website | Key Enforcement Powers | Penalty Cap |
|------|---------|---------|------|-----------|---------|
| Russia | Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor) | 2008 | rkn.gov.ru | FZ-152 Personal Data Law enforcement, data processing registration, data localization enforcement, blocking of non-compliant websites | Administrative fines up to RUB $18,000,000 (substantially increased by 2024 amendment; for legal entities); 1%–3% of turnover may be imposed |
| Kazakhstan | Data protection department under the Ministry of Digital Development, Innovations and Aerospace Industry | 2019 (new Personal Information Law effective 2022) | mdai.gov.kz | Personal Information Law enforcement, data processing supervision, cross-border transfer management | Up to KZT $5,000,000 (approx. $11,000); higher amounts for serious cases |
| Belarus | National Center for Personal Data Protection of Belarus (НЦЗД) | 2021 | cpdp.by | Law No. 99-Z Personal Data Law enforcement, data processing registration, data localization enforcement | Up to BYN $100,000 (approx. $30,000); administrative fines may accumulate |

---

## IX. International Organizations

| Jurisdiction | Authority Name | Year Est. | Website | Key Functions | Penalty Cap |
|------|---------|---------|------|---------|---------|
| Council of Europe (CoE) | Consultative Committee of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108/108+ Committee) | 1981 (Convention 108); 2018 (108+ amended) | coe.int/en/web/data-protection | Supervision of Convention 108+ global data protection treaty, contracting party review, guidance issuance | No direct fining power; promotes compliance through contracting party review and political pressure |
| OECD | Working Party on Security and Privacy in the Digital Economy (WPSPDE) | 1980 (OECD Privacy Guidelines); revised 2013 | oecd.org/sti/ieconomy/privacy.htm | Development and revision of OECD Privacy Guidelines, policy research, member country recommendations | No direct fining power; policy recommendations and soft law constraints |
| United Nations (UN) | UNCTAD Data Protection and Privacy Working Group + UN Special Rapporteur on Big Data and Privacy | N/A (multiple parallel mechanisms) | unctad.org | Global data governance research, developing-country capacity building, privacy protection advocacy under human rights framework | No direct fining power; recommendations and reports under human rights mechanisms |

---

## Notes

1. **GDPR Penalty Cap Notes**: Under GDPR Article 83, for the most serious violations (e.g., breach of basic data processing principles, data subject rights), the penalty cap is €20 million or 4% of a company's global annual turnover for the preceding financial year, whichever is higher. For other violations, the cap is €10 million or 2% of turnover. Member States may adjust specific application standards within the GDPR framework through domestic legislation.

2. **United States Penalty Notes**: The United States lacks a unified federal data protection law. The FTC enforces under Section 5 of the FTC Act, with per-violation fine amounts adjusted for inflation. State privacy law penalty standards vary; this table lists only the major states.

3. **China Penalty Notes**: PIPL Article 66 provides that serious violations may be punished by fines of 1 to 5 times the illegal gains; where there are no illegal gains or the amount is less than CNY ¥100,000, a fine of up to CNY ¥1,000,000 may be imposed. For severe cases, a fine of up to CNY ¥50,000,000 or up to 5% of the preceding year's turnover may be imposed, along with orders to suspend business and revoke licenses.

4. **Authorities Under Establishment**: The India DPBI, Indonesia PDP Authority, Chinese Taipei Personal Data Protection Commission, Chile DPA, Egypt PDP Center, and other authorities are at various stages of establishment. This table is based on the current laws of each jurisdiction and annotates those "under establishment."

5. **Data Update Point**: Data in this table is current as of June 2026. Laws in each jurisdiction continue to be amended, and penalty caps may change due to legal amendments or inflation adjustments. Please verify against the latest legal texts when using this table.

---

> **Sources**: Official websites of the European Data Protection Board (EDPB), national DPA official websites, DLA Piper "Data Protection Laws of the World," and current data protection legal texts of each country. This table is for academic research reference and does not constitute legal advice.


# Appendix II: Cross-Jurisdictional Comparison Charts

> **Note**: This appendix presents global cyber law jurisdictions in tabular form for horizontal comparison, intended to provide a quick reference tool for researchers and practitioners. The legal provisions in each table are as of 31 December 2025; subsequent amendments may affect the table contents. Legal terms retain English equivalents for cross-referencing. The table contents are academic summaries and do not constitute legal advice.

---

## Table II-1: Extraterritorial Scope Comparison

| Jurisdiction | Legal Basis | Extraterritoriality Clause | Trigger Condition | Scope of Application | Exemptions |
|------|----------|-------------|----------|----------|------|
| **EU** | GDPR (2018) | Art. 3(2) | (a) Offering goods or services to data subjects in the EU (whether or not for payment); (b) Monitoring data subjects' behavior within the EU | Controllers or processors established outside the EU, insofar as their processing activities relate to the above | Where Art. 3(2) does not apply, exemptions under public international law (e.g., diplomatic immunity); purely personal or household activities exempt (Art. 2(2)(c)) |
| **China** | PIPL (2021) | Art. 3(2) | (a) Processing for the purpose of providing products or services to natural persons within China; (b) Analyzing or assessing the behavior of natural persons within China; (c) Other circumstances provided by laws and administrative regulations | Organizations and individuals outside China engaged in the above activities processing personal information of natural persons within China | Requests for personal information from foreign judicial or law enforcement authorities require approval of competent authorities (Art. 41); diplomats enjoy corresponding privileges and immunities |
| **Brazil** | LGPD (2020) | Art. 3 | (a) Personal data collected or processed within Brazil; (b) Processing for the purpose of offering goods or services to individuals in Brazil; (c) Processing of personal data collected within Brazil | Data processing occurring outside Brazil but related to offering goods or services to individuals in Brazil | Purely personal purposes, artistic/journalistic/academic purposes (Art. 4 exemption), provided rights and freedoms are safeguarded |
| **United States** | CCPA/CPRA (2020/2023) | No explicit extraterritoriality clause | Criterion of "doing business in California," essentially requiring physical presence or targeted activities in California | Applies to for-profit entities meeting any of the following thresholds: annual gross revenue >$25 million; processes personal information of ≥100,000 California residents; derives ≥50% of annual revenue from selling personal information | Non-profit organizations, HIPAA-covered entities, GLBA-covered financial institutions, etc. (CCPA §1798.145) |
| **Council of Europe** | Convention 108+ (2018 amendment) | Art. 4 | Contracting Parties may exercise jurisdiction extraterritorially where the data processor has habitual residence or place of business within its territory | Protection of data subjects within the territory of the Contracting Party, regardless of where the processor is located | Contracting Parties may declare reservations; cross-border data flows regulated separately under Art. 14 |

---

## Table II-2: Cross-Border Data Transfer Mechanisms Comparison

| Transfer Mechanism | GDPR (EU) | PIPL (China) | LGPD (Brazil) | CCPA (United States) | UK GDPR (United Kingdom) | 152-FZ (Russia) |
|----------|-------------|-------------|-------------|-------------|----------------|-----------------|
| **Adequacy Decision / White List** | ✅ Art. 45: European Commission determines third country provides adequate level of protection | ✅ Art. 38: CAC determines that a country/region meets protection standards and publishes "white list" | ✅ Art. 33: ANPD determines third country or international organization provides adequate protection | ❌ No dedicated cross-border transfer mechanism; no adequacy decision system | ✅ Art. 45: UK Secretary of State determines adequacy (EU/EEA etc. already recognized) | ❌ No adequacy decision system; principle of domestic storage |
| **Standard Contractual Clauses (SCCs)** | ✅ Art. 46(2)(c); European Commission issued SCC templates (2021 new version) | ✅ Art. 38: CAC formulates standard contractual clauses | ✅ Art. 33(VIII): ANPD formulates SCCs or specific contractual clauses | ❌ No such mechanism | ✅ Art. 46(2)(c); UK ICO issued UK SCC (UK Addendum + EU SCC or UK IDTA) | ❌ No SCC mechanism |
| **Binding Corporate Rules (BCRs)** | ✅ Art. 47: Intra-group transfers within multinational enterprise groups, subject to DPA approval | ❌ BCR mechanism not expressly provided | ⚠️ ANPD may authorize specific transfer mechanisms; no formal BCR rules issued yet | ❌ No such mechanism | ✅ Art. 47; ICO may approve BCRs | ❌ No BCR mechanism |
| **Certification Mechanism** | ✅ Art. 46(2)(f): Approved certification mechanism + binding commitments | ✅ Art. 38: Personal Information Protection Certification by professional bodies | ⚠️ ANPD may establish certification mechanism, still under development | ❌ No such mechanism | ✅ Art. 46(2)(f); UKAS and other certification systems | ❌ No such mechanism |
| **Data Subject Consent** | ✅ Art. 49(1)(a): Explicit, specific consent (strictly limited) | ✅ Art. 39: Obtaining separate individual consent (higher standard required) | ✅ Art. 33(VII): Explicit and specific consent | ⚠️ No dedicated cross-border transfer consent mechanism; general consent applies to "sale" of personal information | ✅ Art. 49(1)(a) | ❌ Consent not recognized as independent basis for cross-border transfer |
| **Security Assessment** | ⚠️ Not a standalone mechanism, but may form part of Transfer Impact Assessment before transfer | ✅ Art. 38: CIIO and processors handling personal information reaching CAC-prescribed volumes must apply for security assessment | ⚠️ ANPD may require impact reports, not a formal security assessment mechanism | ❌ No such mechanism | ⚠️ Same as GDPR; TIA (Transfer Impact Assessment) is a practical requirement before transfer | ✅ Centered on Roskomnadzor approval, substantively constituting a security assessment |
| **Special Circumstances/Derogations** | ✅ Art. 49: Vital interests, public interest, legal claims, important interests, etc. | ✅ Art. 38: Contract performance necessity, public health emergencies, protection of life and health, etc. | ✅ Art. 33: Vital interests of Brazilian citizens, public interest, contract necessity, etc. | — | ✅ Same as GDPR Art. 49 derogations | ✅ Limited to foreign judicial or law enforcement requests requiring approval (152-FZ Art. 6) |

---

## Table II-3: Data Subject Rights Comparison

| Right Type | EU GDPR | UK GDPR | CN PIPL | BR LGPD | US CCPA | JP APPI | KR PIPA | SG PDPA | IN DPDPA | AU Privacy Act | RU 152-FZ |
|----------|---------|---------|---------|---------|---------|---------|---------|---------|----------|-----------------|-----------|
| **Right to be informed** | ✅ Arts. 13–14 | ✅ Same as GDPR | ✅ Arts. 17, 44 | ✅ Arts. 9, 20 | ✅ §1798.100 | ✅ Arts. 18, 27 | ✅ Arts. 15, 30 | ✅ Arts. 11–14 | ✅ Art. 11 | ✅ APP 1, 5 | ✅ Arts. 18, 20 |
| **Right of access** | ✅ Art. 15 | ✅ Same as GDPR | ✅ Art. 45 | ✅ Art. 19 | ✅ §1798.100 | ✅ Art. 33 | ✅ Art. 35 | ✅ Art. 21 | ✅ §11(1) | ✅ APP 12 | ✅ Arts. 15, 20 |
| **Right to rectification** | ✅ Art. 16 | ✅ Same as GDPR | ✅ Art. 46 | ✅ Art. 18 | ✅ §1798.106 | ✅ Art. 34 | ✅ Art. 36 | ✅ Art. 22 | ✅ §11(2) | ✅ APP 13 | ✅ Art. 21 |
| **Right to erasure** | ✅ Art. 17 | ✅ Same as GDPR | ✅ Art. 47 | ✅ Art. 18 | ✅ §1798.105 | ⚠️ Limited; Art. 33-2 (suspension of use) | ⚠️ Limited; Art. 36 (request to stop processing) | ⚠️ Limited; Art. 22 (correction/deletion of erroneous data) | ⚠️ Limited; §11(3) (correction/deletion) | ⚠️ Limited; APP 11 (destruction or de-identification) | ⚠️ Limited; Art. 21 |
| **Right to restriction of processing** | ✅ Art. 18 | ✅ Same as GDPR | ❌ Not expressly provided | ⚠️ Art. 18 implied (request to suspend processing) | ❌ None | ❌ None | ⚠️ Art. 36 (suspension of processing) | ❌ None | ❌ None | ❌ None | ❌ None |
| **Right to data portability** | ✅ Art. 20 | ✅ Same as GDPR | ✅ Art. 45(3) | ✅ Art. 18 | ✅ §1798.100(d) | ❌ None | ❌ None | ✅ Art. 22 (data portability obligation, 2021 amendment) | ❌ None | ❌ None | ❌ None |
| **Right to object** | ✅ Art. 21 | ✅ Same as GDPR | ✅ Art. 44 (reject automated decision-making) | ✅ Art. 20 | ✅ §1798.120 (opt-out of sale/sharing) | ⚠️ Art. 33-2 (request to stop use) | ✅ Art. 37 | ⚠️ Art. 21 (withdrawal of consent) | ❌ None | ⚠️ Limited; may withdraw consent | ❌ None |
| **Automated decision-making** | ✅ Art. 22 | ✅ Same as GDPR | ✅ Art. 24 | ✅ Art. 20 | ✅ §1798.185(a)(16) (CCPA regulations) | ❌ No explicit provision | ⚠️ Implied by Art. 37 | ⚠️ Limited | ❌ No explicit provision | ❌ No explicit provision | ❌ None |
| **Right against profiling** | ✅ Art. 22 (included in automated decision-making) | ✅ Same as GDPR | ✅ Art. 24 (rejection of automated decision-making includes profiling) | ✅ Art. 20 | ⚠️ Limited; §1798.185(a)(16) | ❌ None | ❌ None | ❌ None | ❌ None | ❌ None | ❌ None |

> **Note**: ⚠️ indicates the law contains an approximate or limited provision but differs from the full definition of the right. Blank entries indicate the jurisdiction has no clearly corresponding provision.

---

## Table II-4: Penalty Cap Comparison

| Jurisdiction | Legal Basis | Administrative Fine Cap | Criminal Penalties | Personal Liability |
|------|----------|-------------|----------|----------|
| **EU** | GDPR | ✅ Cap: €20 million or 4% of global annual turnover, whichever is higher (Art. 83(5)); minor violations: €10 million or 2% (Art. 83(4)) | ❌ GDPR itself does not create criminal penalties; Member States may legislate separately | ⚠️ Indirect: Member State domestic law may impose liability on responsible persons (DPO, management) |
| **China** | PIPL | ✅ Cap: CNY ¥50,000,000 or 5% of preceding year's turnover; illegal gains may be confiscated (Art. 66) | ✅ Criminal Law Art. 253a: Crime of Infringing Citizens' Personal Information, up to 7 years' imprisonment and fine | ✅ Directly responsible personnel may be fined ¥100,000–¥1,000,000; may be prohibited from serving as directors, supervisors, or senior management for a certain period |
| **Brazil** | LGPD | ✅ Cap: BRL $50,000,000 (approx. $10,000,000) or 2% of turnover; simple violations up to 2% of turnover per item, capped at BRL $10,000,000 (Art. 52) | ❌ LGPD itself does not create criminal penalties | ✅ Fines up to 50% of illegal gains may be borne by responsible persons; responsible persons may be prohibited from participating in data processing activities |
| **United States (California)** | CCPA/CPRA | ✅ Civil penalties: up to $7,500 per intentional violation, $2,500 per non-intentional violation; CPPA may impose direct fines (§1798.155) | ❌ No criminal penalties | ⚠️ No direct personal liability; but management may face internal corporate liability or securities law-related liability |
| **United Kingdom** | UK GDPR | ✅ Same as GDPR standard: cap £17.5 million or 4% of global annual turnover, whichever is higher (DPA 2018 s. 157) | ❌ UK GDPR itself does not create criminal penalties; DPA 2018 creates several criminal offences (e.g., unlawful obtaining of data, up to 2 years' imprisonment) | ✅ ICO may pursue director liability (DPA 2018 s. 156); specific criminal offences may target individuals |
| **Japan** | APPI | ✅ Administrative fine cap: ¥100,000,000 (for legal persons); up to ¥1,000,000 fine for individuals (Art. 84) | ✅ Criminal penalties: unlawful provision of personal information, imprisonment up to 1 year; unlawful acquisition, imprisonment up to 1 year (Arts. 83–84) | ✅ Individuals directly subject to criminal penalties; corporate representatives and managers may also be fined |
| **South Korea** | PIPA | ✅ Cap: 3% of global turnover as administrative fine (2023 amendment); personal information infringement-related fines capped at 3% | ✅ Criminal penalties: unlawful processing of personal information, up to 5 years' imprisonment or fine of up to KRW ₩50,000,000 | ✅ Directly responsible personnel subject to criminal prosecution; joint punishment of legal persons and individuals |
| **Singapore** | PDPA | ✅ Cap: SGD $1,000,000 or 10% of organization's annual turnover, whichever is higher (2021 amendment, s. 48J) | ❌ PDPA itself does not create criminal penalties | ⚠️ No direct individual administrative fines; but criminal liability may target individuals (e.g., false statements) |
| **India** | DPDPA (2023) | ✅ Cap: ₹250 crore (approx. $300,000,000) (Art. 33); up to this cap per breach | ❌ DPDPA itself does not create criminal penalties | ⚠️ Individual administrative fines not explicitly provided; Data Protection Board may penalize data processors |
| **South Africa** | POPIA | ✅ Administrative fine cap: ZAR $10,000,000–$50,000,000 or imprisonment, depending on severity (Arts. 107–109) | ✅ Criminal penalties: unlawful processing, imprisonment of 1–10 years or fine | ✅ Responsible persons (Information Officer) and directly responsible personnel may be held criminally liable |
| **Russia** | 152-FZ | ✅ Administrative fines: RUB ¥50,000–¥15,000,000 for legal persons (depending on violation type, Administrative Offenses Code Art. 13.11) | ✅ Criminal penalties: unlawful collection and dissemination of personal information under Criminal Code Art. 137, up to 4 years' imprisonment | ✅ Individuals subject to administrative fines and criminal liability; legal persons subject to high administrative fines |

---

## Table II-5: AI Governance Risk Classification Comparison

| Dimension | EU AI Act (2024) | China Interim Measures on Generative AI (2023) | Singapore Model AI Governance Framework (2020/2024) | US Executive Order 14110 (2023) |
|------|-------------------|-------------------------------|----------------------------------------------|----------------------|
| **Risk Classification System** | Four-tier classification: (1) Unacceptable risk (prohibited); (2) High risk; (3) Limited risk (transparency obligations); (4) Minimal risk (no additional obligations) | No formal classification system adopted; distinguishes "generative AI services" from general AI, imposing uniform obligations on generative AI; requires filing based on "service classification" | No mandatory classification; adopts an Accountability Framework, recommending self-determined risk levels based on impact assessments; latest version adds generative AI guidance | Centered on "dual-use foundation models"; uses compute threshold (10^26 FLOPs) to identify high-impact models; no formal classification system |
| **High-Risk System Obligations** | High-risk systems must satisfy: risk management system (Art. 9), data governance, technical documentation, record-keeping, transparency, human oversight, accuracy/robustness/cybersecurity requirements, CE conformity assessment, registration, post-market monitoring | Lawful and compliant training data; security assessment (linked to CAC Algorithm Recommendation Provisions); marking of generated content; protection of personal privacy; establishment of complaint mechanisms | Voluntary recommendations: model impact assessment, documentation, monitoring, feedback channels, human intervention; strengthened testing and governance recommended for high-impact uses | Requires developers of the most powerful models to report safety testing results (red team testing), key metrics, and cybersecurity measures to the government; Department of Commerce may require reporting |
| **Prohibited AI Practices** | Art. 5 expressly prohibits: subliminal manipulation, exploitation of vulnerabilities, social scoring, individual risk assessment predicting crime, untargeted facial recognition databases, emotion inference in workplace/education settings, biometric categorization (sensitive attributes), real-time remote biometric identification in public spaces (except law enforcement) | No explicit prohibition list; but Art. 4 requires generative AI not to produce content violating laws and administrative regulations, substantively prohibiting illegal content generation | No prohibited practices list; oriented toward "responsible use," recommending avoidance of harmful uses | No explicit prohibited practices; indirectly regulated through safety testing reporting mechanisms; focuses on CBRN (Chemical, Biological, Radiological, Nuclear) risks |
| **Generative AI Special Rules** | Art. 50 amendment (2024): Generative AI must label AI-generated content; deepfakes must be disclosed; systemic risk assessment obligations for General Purpose AI Models (Arts. 51–55) | Entire text aimed at generative AI: lawful sources of training data, training data rules annotation, generated content marking, security assessment, content moderation, user real-name registration, algorithm filing | 2024 update adds dedicated generative AI chapter: recommends content disclosure, source labeling, safety testing, bias reduction, prevention of harmful outputs | "Dual-use foundation models" cover generative AI: developers must report training information and safety testing results to the Department of Commerce; intellectual property issues to be studied separately by the Copyright Office |

---

## Table II-6: International Cybercrime Offense Comparison

| Offense Type | Budapest Convention (Convention on Cybercrime) | UN Cybercrime Convention (2025) | China Criminal Law | US CFAA (18 U.S.C. §1030) | UK CMA (Computer Misuse Act 1990) |
|----------|----------------------------------------|--------------------------|----------|----------------------------|-----------------------------------|
| **Illegal access** | Art. 2: Intentional, unauthorized access to the whole or any part of a computer system; requires security measures (e.g., password protection) | Art. 6: Intentional unauthorized access to ICT systems; broader scope covering cloud computing and IoT | Art. 285: Crime of Illegally Intruding into Computer Information Systems (state affairs, national defense, cutting-edge science and technology, up to 3 years); Art. 285(2): Crime of Illegally Obtaining Computer Information System Data (up to 7 years) | §1030(a)(2): Unauthorized access to a protected computer to obtain information; §1030(a)(5): Unauthorized access causing damage | s. 1: Unauthorized access to computer material (summary offence, up to 6 months; indictment, up to 5 years) |
| **Illegal interception** | Art. 3: Unauthorized interception by technical means of non-public transmissions of computer data | Art. 7: Intentional interception of non-public transmissions of ICT systems; technology-neutral, covering all types of communications | ⚠️ No standalone "illegal interception of computer data" offense; Art. 253a Crime of Infringing Citizens' Personal Information may partially cover | ⚠️ No standalone offense; may be prosecuted under the Wiretap Act (18 U.S.C. §2511) | ⚠️ No standalone offense; may be prosecuted under RIPA 2000 for unlawful interception |
| **Data interference** | Art. 4: Unauthorized damaging, deletion, deterioration, alteration, or suppression of computer data | Art. 9: Intentional damaging, deletion, alteration, or suppression of ICT system data | Art. 286(1): Crime of Destroying Computer Information Systems (up to 5 years; 5+ years for serious consequences); Art. 286(2): Crime of Destroying Computer Information System Data | §1030(a)(5)(A): Knowingly and without authorization, intentionally transmitting a program, code, or command causing intentional damage | s. 3: Unauthorized act with intent to impair the operation of computer data (indictment, up to 10 years; involving national security, 14 years) |
| **System interference** | Art. 5: Unauthorized serious hindering of the functioning of a computer system by inputting, transmitting, damaging, deleting, deteriorating, altering, or suppressing computer data | Art. 8: Intentional serious hindering of the functioning of an ICT system | Art. 286(1): Crime of Destroying Computer Information System Functions (up to 5 years; 5+ years for serious consequences) | §1030(a)(5)(B): Reckless conduct causing damage; DDoS may be covered under §1030(a)(5)(A) | s. 3 (as above); s. 3ZA: Act with intent to impair the operation of a computer system (indictment, up to 10 years) |
| **Misuse of devices** | Art. 6: Production, use, possession, distribution of devices used to commit the above offenses (including passwords, access codes, programs) | Art. 11: Manufacture, acquisition, use, distribution of ICT devices or tools used for offenses | Art. 285(3): Crime of Providing Programs or Tools for Intruding into or Illegally Controlling Computer Information Systems (up to 3 years; up to 7 years for serious cases) | §1030(a)(6): Trafficking in passwords or similar information with intent to defraud | ⚠️ No direct corresponding provision; may be prosecuted under s. 3 or s. 1; 2022 reform proposal recommends adding "misuse of devices" provision |
| **Computer-related forgery** | Art. 7: Unauthorized input, alteration, deletion, or suppression of computer data resulting in inauthentic data being considered authentic | Art. 12: Intentional input, alteration, or deletion of data causing false data to be considered authentic | Art. 287: Using computers to commit financial fraud, theft, embezzlement, misappropriation of public funds, etc., punished according to relevant provisions from a heavier basis; may constitute accomplice to forgery offenses | ⚠️ No standalone offense; may be prosecuted under §1030(a)(4) (fraudulent obtaining) or general fraud offenses | ⚠️ No standalone offense; may be prosecuted under the Forgery and Counterfeiting Act 1981 |
| **Computer-related fraud** | Art. 8: Unauthorized input, alteration, deletion, or suppression of data causing loss of property to another, with intent to procure economic benefit for oneself or another | Art. 13: Input or alteration of data with fraudulent intent causing loss of property to another | Art. 287: Using computers to commit financial fraud (punished from a heavier basis under Arts. 192, 193, 224, etc.); Art. 266 Crime of Fraud (up to life imprisonment) | §1030(a)(4): Knowingly and without authorization, with intent to defraud, obtaining anything of value | ⚠️ No standalone offense; may be prosecuted under Fraud Act 2006 ss. 2–4 |

---

## Table II-7: Critical Infrastructure Designation Criteria Comparison

| Dimension | EU NIS2 (2024) | China Cybersecurity Law (2016) + CII Security Protection Regulations (2021) | US EO 13800 (2017) + PPD-21 | UK NIS Regulations (2018) | Australia SOCI Act (2018) |
|------|-----------------|---------------------------------------------------------------|------------------------------|----------------------------|------------------------|
| **CI Definition** | "Essential and Important Entities"; scope expanded from "operators of essential services" to entities "important to the functioning of society" | Critical Information Infrastructure (CII): important network facilities and information systems whose destruction, loss of function, or data leakage may seriously endanger national security, national economy and people's livelihood, or the public interest | Critical Infrastructure (CI): physical or virtual systems and assets vital to the United States whose incapacitation or destruction would have a debilitating effect on national security, economic security, public health, or safety | OES (Operators of Essential Services): those providing essential services critical to the maintenance of vital societal/economic activities | Critical Infrastructure Assets (CI Assets): physical facilities, supply chains, information technology systems, or communications networks of significance to national security, defense, or socio-economic development |
| **Sectors Covered** | Enumerated sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, etc.; newly added: postal, courier, chemicals, manufacturing, food, research institutions, etc. | Critical sectors: public communications and information services, energy, transport, water conservancy, finance, public services, e-government, national defense science and technology industry, etc. (Regulations Art. 2) | 16 critical infrastructure sectors: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Defense Industrial Base, Emergency Services, Energy, Financial Services, Food and Agriculture, Government Facilities, Healthcare and Public Health, Information Technology, Nuclear Reactors, Materials and Waste, Transportation Systems, and Water and Wastewater Systems | Essential service sectors: Energy, Transport, Banking, Financial Infrastructure, Health, Drinking Water, Digital Infrastructure (NIS Reg. Schedule 1) | 10 sectors: Communications, Energy, Financial Services, Data Storage/Processing, Healthcare, Manufacturing, Food & Grocery, Transport, Water Industry, Higher Education & Research |
| **Designation Process** | Competent authorities of Member States designate Essential Entities (size-threshold entities automatically apply) and Important Entities; EU harmonised criteria + Member State discretion | State CAC, jointly with State Council telecommunications authorities and public security authorities, designates CII (Regulations Art. 6); sector regulators propose, State CAC makes final designation | CISA (Cybersecurity and Infrastructure Security Agency) coordinates designation; Sector Risk Management Agencies (SRMAs) assist; operates through sectoral coordination | Competent Authorities by sector identify and designate OES; considers factors such as service dependencies and cross-border impact | Minister for Home Affairs designates in consultation with states/territories; considers national security, defense, economic factors; ministerial declaration |
| **Obligations** | Risk management measures: security governance, incident handling, business continuity, supply chain security, security training, encryption/access control; incident reporting: early warning within 24 hours, detailed report within 72 hours, final report within 1 month | Security protection obligations (CSL Art. 34): dedicated security management bodies and responsible persons; regular security education and skills training; disaster recovery and backup; emergency plans and drills; security incident reporting | Risk management framework (NIST CSF as benchmark); sector-specific plans; information sharing and collaboration; supply chain risk management; incident reporting (voluntary + partially mandatory) | Security obligations: take appropriate and proportionate technical and organizational measures to manage risks; prevent and minimize incident impact; significant security incident reporting (early report within 4 hours, detailed report within 72 hours); annual audit | Obligations: Risk Management Plan; incident reporting obligations; information sharing; compliance with government-issued guidance; security preparedness |

---

## Table II-8: Data Localization Requirements Comparison

| Jurisdiction | Primary Legal Basis | Applicable Data Types | Local Storage Requirement | Cross-Border Transfer Conditions | Exemptions |
|------|-------------|-------------|-------------|-------------|------|
| **China** | CSL Art. 37; DSL Art. 31; PIPL Arts. 38–40; Measures for Security Assessment of Cross-Border Data Transfer | (1) Personal information and important data collected by CIIOs; (2) Personal information processed by handlers reaching CAC-prescribed volumes (1,000,000 persons); (3) Important data | ✅ CIIOs and volume-threshold handlers shall in principle store data domestically; important data shall be stored domestically | Must satisfy one of: security assessment (CIIO/volume-threshold/important data), personal information protection certification, standard contract, or other statutory conditions; provision to foreign judicial/law enforcement authorities requires approval | Contract performance necessity, public health emergencies, protection of life and health, and other statutory exemptions (PIPL Art. 38); international trade/cross-border tourism scenarios (exemptions under Cross-Border Transfer Assessment Measures) |
| **Russia** | 152-FZ Art. 18(5); 2014 Federal Law No. 242-FZ amendment | Personal data of Russian citizens | ✅ When collecting personal data of Russian citizens, databases must be located within Russian territory ("primary storage" requirement) | Cross-border transfers must satisfy: clear purpose, security assurance, data subject rights protection; Roskomnadzor may prohibit transfers to countries with insufficient protection | Publicly available data, international treaty obligations, one-off record operations, and other limited exemptions |
| **India** | RBI Data Localization Directive (2018); DPDP Act (2023) Art. 16 | (1) Payment system data (RBI Directive); (2) Government may designate specific categories of data for localization under DPDPA | ✅ Payment data must be stored within Indian territory (RBI Directive); DPDPA authorizes government to restrict cross-border transfers | DPDPA: Permits cross-border transfers to countries/regions notified as permitted by the government (white list model), but government may impose restrictions | Partial payment data may be transferred cross-border but must be mirrored in India; government may exempt specific categories under DPDPA |
| **EU** | GDPR Arts. 44–49 | Non-personal data: no mandatory localization; Personal data: transfer based on adequacy decisions or safeguards | ❌ No mandatory data localization requirement; data may flow freely within EU/EEA | Must satisfy: adequacy decision (Art. 45), SCCs/BCRs/certification (Art. 46), derogations (Art. 49); TIA required before transfer | Adequacy decision countries (e.g., Japan, UK, etc.) allow free transfer; public security/national security exceptions |
| **Brazil** | LGPD Art. 33 | Personal data (no sector-specific mandatory localization) | ❌ No mandatory data localization requirement | Must satisfy: adequacy decision, SCCs, BCRs, certification, consent, contract necessity, etc. (Art. 33); ANPD may require safeguards in specific circumstances | ANPD has not yet published adequacy decision list; consent and contract necessity may serve as transfer basis |
| **Saudi Arabia** | PDPL (2021/2023 amendment) + Implementing Regulations (2024) | Personal data | ⚠️ Implementing Regulations Art. 26: Specific circumstances (e.g., government entity data) require domestic storage in Saudi Arabia; general personal data not subject to mandatory localization | Must satisfy: white list country transfer, SCCs, BCRs, certification, data subject consent, contract necessity, etc.; SDAIA issues transfer guidance | White list countries (to be published); fulfillment of international obligations, government approval scenarios |

---

> **Disclaimer**: The tables in this appendix are compiled from publicly available legal texts and academic materials, intended to provide a comparative reference framework for research purposes, and do not constitute any legal opinion or advice. Laws in each country are subject to ongoing amendment; specific application should be based on the latest legal texts and interpretations of competent authorities. For practical operations, please consult qualified legal counsel.


---

# Appendix III: Glossary of Cyber Law Terminology

> This glossary compiles over 200 core terms in global cyber law, covering data protection, cybersecurity, cybercrime, platform governance, AI governance, e-commerce, intellectual property, and international jurisdiction. Each entry includes the English term, definition, source jurisdiction(s) where relevant, and notes on terminological differences among China, the United States, and the European Union.

## A. Data Protection Core Concepts

**1. Personal Data**
- Definition: Any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Source: EU General Data Protection Regulation (GDPR), Article 4(1).
- Jurisdiction(s): EU.
- **Comparative Note:** U.S. law typically uses the term "personally identifiable information" (PII), whose scope is narrower than GDPR's "personal data." China's Personal Information Protection Law (PIPL) uses "personal information," defined as "all kinds of information related to an identified or identifiable natural person recorded by electronic or other means" (PIPL Art. 4), which aligns more closely with the GDPR definition.

**2. Personally Identifiable Information (PII)**
- Definition: Information that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, biometric records, etc.
- Source: U.S. National Institute of Standards and Technology (NIST) SP 800-122; U.S. Privacy Act of 1974, § 552a.
- Jurisdiction(s): United States.
- **Comparative Note:** PII is a core concept under U.S. law, but its scope does not fully overlap with GDPR's "personal data." The GDPR has a broader reach, encompassing online identifiers such as IP addresses and cookie identifiers, whereas the definition of PII under U.S. law varies across different regulatory frameworks (e.g., HIPAA, GLBA, CCPA).

**3. Personal Information**
- Definition: All kinds of information related to an identified or identifiable natural person recorded by electronic or other means, excluding information that has been anonymized.
- Source: China's Personal Information Protection Law (PIPL), Article 4(1).
- Jurisdiction(s): China.

**4. Sensitive Personal Information**
- Definition: Personal information that, once leaked or unlawfully used, is likely to infringe upon the personal dignity of a natural person or endanger personal or property safety, including biometric data, religious beliefs, special status, medical and health information, financial accounts, location and movement tracking data, as well as personal information of minors under the age of fourteen.
- Source: China's Personal Information Protection Law (PIPL), Article 28.
- Jurisdiction(s): China.
- **Comparative Note:** This corresponds to "special categories of personal data" under the GDPR (Art. 9), but China's sensitive personal information has a broader scope, for example by including the personal information of minors. The United States lacks a unified concept of "sensitive information," addressing such data separately in sector-specific statutes such as HIPAA (health information) and GLBA (financial information).

**5. Special Categories of Personal Data**
- Definition: Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.
- Source: GDPR, Article 9(1).
- Jurisdiction(s): EU.

**6. Data Subject**
- Definition: An identified or identifiable natural person to whom personal data relates.
- Source: GDPR, Article 4(1); China's PIPL refers to the corresponding concept as "individual" (个人).
- Jurisdiction(s): EU / China.
- **Comparative Note:** China's PIPL uses "individual" (个人) rather than "data subject" (Art. 4). U.S. law generally uses "consumer" or "individual"; for instance, the CCPA employs the "consumer" concept.

**7. Data Controller**
- Definition: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Source: GDPR, Article 4(7).
- Jurisdiction(s): EU.
- **Comparative Note:** China's PIPL uses the concept of "personal information handler" (Art. 4), merging the roles of controller and processor under the single "handler" concept. U.S. law lacks a unified "controller" concept, employing terms such as "covered entity" or "service provider" in different statutes.

**8. Data Processor**
- Definition: A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
- Source: GDPR, Article 4(8).
- Jurisdiction(s): EU.
- **Comparative Note:** China's PIPL does not strictly distinguish between "controller" and "processor"; instead, it regulates analogous scenarios through the concept of "entrusted processing" under Articles 20–21. U.S. law has no corresponding concept.

**9. Personal Information Handler**
- Definition: An organization or individual that independently determines the purposes and means of processing in personal information processing activities.
- Source: China's Personal Information Protection Law (PIPL), Article 4(2).
- Jurisdiction(s): China.
- **Comparative Note:** This concept incorporates the core characteristics of the GDPR's "controller" but does not introduce the independent legal status of the GDPR's "processor." Entrusted parties that process personal information do so in accordance with the requirements of the entrusting party (PIPL Art. 21).

**10. Processing**
- Definition: Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- Source: GDPR, Article 4(2); China's PIPL, Article 4(2), contains similar provisions.
- Jurisdiction(s): EU / China.

**11. Anonymization**
- Definition: The processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject, and cannot be re-attributed to that data subject through additional information.
- Source: GDPR, Article 4(5).
- Jurisdiction(s): EU.
- **Comparative Note:** Under the GDPR, anonymized data falls outside the scope of the Regulation. China's PIPL, Article 4, expressly provides that "information that has been anonymized" is not personal information. U.S. law lacks a uniform provision on the legal effect of anonymization.

**12. De-identification**
- Definition: The process by which personal information is processed so that specific natural persons cannot be identified without the use of additional information.
- Source: China's Personal Information Protection Law (PIPL), Article 51; cf. GDPR, Article 4(5), concept of "pseudonymization."
- Jurisdiction(s): China / EU.
- **Comparative Note:** China's "de-identification" roughly corresponds to GDPR's "pseudonymization," but individuals may still be re-identified with additional information. Under U.S. HIPAA, "de-identification" is governed by two standards: the Expert Determination method and the Safe Harbor method (45 CFR § 164.514).

**13. Pseudonymization**
- Definition: The processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures.
- Source: GDPR, Article 4(5).
- Jurisdiction(s): EU.

**14. Personal Data Breach**
- Definition: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
- Source: GDPR, Article 4(12).
- Jurisdiction(s): EU.
- **Comparative Note:** China's Cybersecurity Law, Article 42, uses the formulation "leakage, damage, or loss of personal information." U.S. state data breach notification laws (e.g., California Civil Code § 1798.82) employ the concept of "breach of security."

**15. Data Protection Impact Assessment (DPIA)**
- Definition: An assessment of the impact of the envisaged processing operations on the protection of personal data, designed to ensure that risks associated with the processing operations are addressed in a proportionate manner.
- Source: GDPR, Article 35.
- Jurisdiction(s): EU.
- **Comparative Note:** China's PIPL, Article 55, mandates a "personal information protection impact assessment." The applicable circumstances are similar to those triggering a DPIA but broader in scope, including the processing of sensitive information, automated decision-making, and entrusted processing scenarios.

**16. Personal Information Protection Impact Assessment (PIPIA)**
- Definition: An assessment, conducted before carrying out certain personal information processing activities, of the legality, legitimacy, and necessity of the purposes and means of processing, the impact on individual rights and interests, and the associated security risks, together with a record of the processing activities.
- Source: China's Personal Information Protection Law (PIPL), Articles 55–56.
- Jurisdiction(s): China.

**17. Data Protection Officer (DPO)**
- Definition: A person designated by the controller or processor to assist with GDPR compliance, responsible for monitoring compliance, providing advisory guidance, and serving as the point of contact for communications with supervisory authorities and data subjects.
- Source: GDPR, Articles 37–39.
- Jurisdiction(s): EU.
- **Comparative Note:** China's PIPL, Article 52, requires the designation of a "personal information protection officer," whose duties are similar to those of a DPO. The United States has no uniform DPO requirement.

**18. Personal Information Protection Officer**
- Definition: The responsible person designated by a personal information handler that processes personal information in quantities reaching thresholds specified by the national cyberspace administration authority, charged with supervising personal information processing activities and the protective measures adopted.
- Source: China's Personal Information Protection Law (PIPL), Article 52.
- Jurisdiction(s): China.

**19. Data Protection Authority (DPA)**
- Definition: An independent public authority established by a Member State pursuant to the GDPR, responsible for monitoring the application of the Regulation in order to protect the fundamental rights and freedoms of natural persons.
- Source: GDPR, Articles 4(21) and 51.
- Jurisdiction(s): EU.
- **Comparative Note:** In China, the Cyberspace Administration of China (CAC) and relevant departments are responsible for the overall coordination, supervision, and enforcement of personal information protection (PIPL Art. 60). The United States lacks a unified data protection authority; the Federal Trade Commission (FTC) exercises certain oversight functions within the consumer protection framework.

**20. Automated Decision-Making**
- Definition: A decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects the data subject.
- Source: GDPR, Article 22(1); China's PIPL, Article 24.
- Jurisdiction(s): EU / China.

---

## B. Data Subject Rights

**21. Right to be Informed**
Definition: The data subject has the right to receive, at the time personal data is collected, information concerning the identity of the controller, the purposes of processing, the retention period of the data, and other relevant details.
Source: GDPR Arts. 13–14; China PIPL Art. 17 (notification obligation).
Jurisdiction: EU / China.

**22. Right of Access**
Definition: The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, to obtain access to the personal data and certain supplementary information.
Source: GDPR Art. 15; China PIPL Art. 45 (right to consult and copy).
Jurisdiction: EU / China.
[Differential note] The U.S. CCPA grants consumers a "Right to Know" covering the categories and specific pieces of personal information collected over the preceding 12 months (Cal. Civ. Code § 1798.110), but its scope is less comprehensive than that of the GDPR.

**23. Right to Rectification**
Definition: The data subject has the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her, and to have incomplete personal data completed.
Source: GDPR Art. 16; China PIPL Art. 46 (right to correction and supplementation).
Jurisdiction: EU / China.

**24. Right to Erasure ("Right to be Forgotten")**
Definition: The data subject has the right to obtain from the controller the erasure of personal data concerning him or her without undue delay, and the controller has the obligation to erase such personal data without undue delay.
Source: GDPR Art. 17.
Jurisdiction: EU.
[Differential note] China's PIPL Art. 47 provides a "Right to Delete Personal Information," which covers circumstances similar to the GDPR but with greater specificity. The U.S. CCPA provides a "Right to Delete" (Cal. Civ. Code § 1798.105) but with broader exemptions. The GDPR's "right to be forgotten" concept has generated extensive discussion worldwide.

**25. Right to Restriction of Processing**
Definition: The data subject has the right to obtain from the controller restriction of processing in certain specified circumstances.
Source: GDPR Art. 18.
Jurisdiction: EU.

**26. Right to Data Portability**
Definition: The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller.
Source: GDPR Art. 20; China PIPL Art. 45(3).
Jurisdiction: EU / China.
[Differential note] China's PIPL Art. 45(3) provides that where an individual requests the transfer of personal information, the personal information handler shall provide a pathway for such transfer. The U.S. CCPA did not originally provide for an express right to data portability, but the CPRA amendments added certain data portability requirements.

**27. Right to Object**
Definition: The data subject has the right to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her (including processing based on profiling).
Source: GDPR Art. 21.
Jurisdiction: EU.

**28. Right to Object to Automated Decision-Making**
Definition: The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
Source: GDPR Art. 22; China PIPL Art. 24(2).
Jurisdiction: EU / China.
[Differential note] China's PIPL requires that when a decision significantly affecting an individual's rights and interests is made through automated decision-making, the individual has the right to request an explanation from the personal information handler and the right to refuse a decision made solely by automated means (Art. 24(3)).

**29. Right to Withdraw Consent**
Definition: The data subject has the right to withdraw his or her consent at any time, and the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
Source: GDPR Art. 7(3); China PIPL Art. 16.
Jurisdiction: EU / China.

**30. Right to Lodge a Complaint**
Definition: The data subject has the right to lodge a complaint with a supervisory authority if he or she considers that the processing of personal data relating to him or her infringes the GDPR.
Source: GDPR Art. 77.
Jurisdiction: EU.

**31. Right to Judicial Remedy**
Definition: The data subject has the right to an effective judicial remedy against a legally binding decision of a supervisory authority, and against a controller or processor for infringements of his or her rights under the GDPR.
Source: GDPR Arts. 78–79.
Jurisdiction: EU.

**32. Right to Compensation**
Definition: Any person who has suffered material or non-material damage as a result of an infringement of the GDPR shall have the right to receive compensation from the controller or processor for the damage suffered.
Source: GDPR Art. 82.
Jurisdiction: EU.

**33. Right to Access and Copy Personal Information**
Definition: An individual has the right to consult and copy his or her personal information from the personal information handler.
Source: China Personal Information Protection Law, Art. 45.
Jurisdiction: China.

**34. Right to Portability of Personal Information**
Definition: Where an individual requests the transfer of personal information to a personal information handler designated by him or her, and the conditions prescribed by the national cyberspace administration are met, the personal information handler shall provide a pathway for such transfer.
Source: China Personal Information Protection Law, Art. 45(3).
Jurisdiction: China.

**35. Right to Delete Personal Information**
Definition: In certain specified circumstances, the personal information handler shall proactively delete personal information; if the personal information handler fails to do so, the individual has the right to request deletion.
Source: China Personal Information Protection Law, Art. 47.
Jurisdiction: China.

**36. Right to Explanation**
Definition: Where a decision significantly affecting an individual's rights and interests is made through automated decision-making, the individual has the right to require the personal information handler to provide an explanation.
Source: China Personal Information Protection Law, Art. 24(3).
Jurisdiction: China.

**37. Rights of Deceased Persons' Personal Information**
Definition: Upon the death of a natural person, his or her close relatives may, for their own lawful and legitimate interests, exercise the rights of access, copying, rectification, deletion, and other rights provided in this Chapter with respect to the deceased person's relevant personal information.
Source: China Personal Information Protection Law, Art. 49.
Jurisdiction: China.
[Differential note] The GDPR does not apply to deceased persons (Recital 27), leaving member states free to legislate separately. Some U.S. state laws contain similar provisions.

---

## C. Lawful Bases for Data Processing

**38. Consent**
Definition: Any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Source: GDPR Arts. 4(11), 6(1)(a).
Jurisdiction: EU.
[Differential note] China's PIPL Arts. 13–14 require that consent be "fully informed, voluntary and explicit," and that processing of sensitive personal information requires "separate consent." U.S. law generally adopts an "opt-out" mechanism, as distinguished from the EU's "opt-in" model.

**39. Separate Consent**
Definition: When a personal information handler processes sensitive personal information, provides personal information to overseas recipients, or engages in certain other specified activities, it shall obtain the individual's separate consent.
Source: China Personal Information Protection Law, Arts. 29, 39.
Jurisdiction: China.
[Differential note] "Separate consent" is a distinctive requirement under China's PIPL. While the GDPR requires "explicit consent" for special categories of data, "separate consent" emphasizes that the consent act must be separated from other consent acts, imposing a more stringent standard.

**40. Contractual Necessity**
Definition: Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Source: GDPR Art. 6(1)(b); China PIPL Art. 13(1)(ii).
Jurisdiction: EU / China.

**41. Legal Obligation**
Definition: Processing is necessary for compliance with a legal obligation to which the controller is subject under EU or Member State law.
Source: GDPR Art. 6(1)(c); China PIPL Art. 13(1)(iii).
Jurisdiction: EU / China.

**42. Vital Interests**
Definition: Processing is necessary in order to protect the vital interests of the data subject or of another natural person.
Source: GDPR Art. 6(1)(d); China PIPL Art. 13(1)(iv).
Jurisdiction: EU / China.

**43. Public Interest**
Definition: Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Source: GDPR Art. 6(1)(e); China PIPL Art. 13(1)(v).
Jurisdiction: EU / China.

**44. Legitimate Interests**
Definition: Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject (in particular where the data subject is a child).
Source: GDPR Art. 6(1)(f).
Jurisdiction: EU.
[Differential note] "Legitimate interests" is a lawful basis specific to the GDPR; China's PIPL does not include this concept. U.S. law does not have a comparable general framework of lawful bases for processing.

**45. Profiling**
Definition: Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
Source: GDPR Art. 4(4); China PIPL Art. 24.
Jurisdiction: EU / China.

**46. Explicit Consent**
Definition: For the processing of special categories of personal data, the data subject's explicit consent must be obtained.
Source: GDPR Art. 9(2)(a).
Jurisdiction: EU.

**47. Opt-in**
Definition: The active consent of the data subject must be obtained prior to the collection or processing of personal data.
Source: GDPR consent standard (Art. 7).
Jurisdiction: EU.
[Differential note] The EU GDPR adopts an opt-in model, whereas most U.S. laws (such as the CCPA) adopt an opt-out model, under which processing is permitted by default and the individual has the right to opt out.

**48. Opt-out**
Definition: Personal data may be processed without prior consent, but the data subject has the right to opt out of such processing at any time.
Source: U.S. CCPA (Cal. Civ. Code § 1798.120); FTC Fair Credit Reporting Act (FCRA).
Jurisdiction: United States.

---

## D. Cross-Border Data Transfers

**49. Adequacy Decision**
Definition: A decision adopted by the European Commission establishing that a third country, a territory or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection of personal data.
Source: GDPR Art. 45.
Jurisdiction: EU.

**50. Standard Contractual Clauses (SCCs)**
Definition: Standard contractual clauses adopted by the European Commission or a supervisory authority, serving as a lawful mechanism for cross-border transfers of personal data.
Source: GDPR Art. 46(2)(c); European Commission Implementing Decision 2021/914.
Jurisdiction: EU.
[Differential note] China's Measures on Standard Contracts for the Cross-border Transfer of Personal Information also provide for a similar "standard contract" mechanism, but with different applicable conditions and content.

**51. Binding Corporate Rules (BCRs)**
Definition: Approved internal data transfer rules of an enterprise group for the cross-border transfer of personal data within the enterprise group.
Source: GDPR Art. 47.
Jurisdiction: EU.

**52. Standard Contract for Cross-border Transfer of Personal Information**
Definition: A standard contract entered into between a personal information handler and an overseas recipient when the handler provides personal information abroad.
Source: China Measures on Standard Contracts for the Cross-border Transfer of Personal Information (2023), Art. 4.
Jurisdiction: China.

**53. Security Assessment for Cross-border Data Transfer**
Definition: Critical information infrastructure operators, personal information handlers that process personal information reaching the prescribed volume, and certain other handlers shall, before providing personal information or important data abroad, submit a security assessment for cross-border data transfer to the national cyberspace administration.
Source: China Measures on Security Assessment for Cross-border Data Transfer (2022), Art. 4; PIPL Art. 38.
Jurisdiction: China.
[Differential note] This is a distinctive prior-review mechanism of Chinese law. The EU GDPR does not have a comparable compulsory administrative assessment procedure; instead it ensures transfer security through mechanisms such as SCCs and BCRs.

**54. Personal Information Protection Certification**
Definition: Personal information protection certification conducted by an institution accredited by the national cyberspace administration, serving as one of the lawful conditions for the cross-border provision of personal information.
Source: China Personal Information Protection Law, Art. 38(1)(ii).
Jurisdiction: China.

**55. Appropriate Safeguards**
Definition: When transferring personal data to a third country, the controller or processor shall provide appropriate safeguards to protect the rights of data subjects.
Source: GDPR Art. 46.
Jurisdiction: EU.

**56. Supplementary Measures**
Definition: Where standard contractual clauses are insufficient to ensure that data receive adequate protection in a third country, the controller or processor shall adopt additional technical, contractual or organisational measures.
Source: European Data Protection Board (EDPB) Recommendations on Supplementary Measures for EU–U.S. Data Transfers (2020).
Jurisdiction: EU.

**57. Data Localization**
Definition: Legal and regulatory requirements mandating that specified data be stored and processed within a particular jurisdiction.
Source: China Cybersecurity Law, Art. 37 (personal information and important data collected and generated by critical information infrastructure operators within China shall be stored domestically); Russia Federal Law No. 242-FZ on Personal Data.
Jurisdiction: China / Russia.
[Differential note] The EU GDPR does not mandate data localization, but requires adequate protection when data is transferred abroad. The United States generally does not require data localization, though certain sectors (such as health data) have relevant restrictions.

**58. Important Data**
Definition: Data that, if tampered with, destroyed, leaked, illegally acquired, or illegally used, may endanger national security or the public interest.
Source: China Data Security Law, Art. 21; Measures on Security Assessment for Cross-border Data Transfer, Art. 19.
Jurisdiction: China.
[Differential note] "Important data" is a concept unique to Chinese law; no exact equivalent exists in EU or U.S. law.

**59. Core Data**
Definition: Data concerning national security, the lifelines of the national economy, important aspects of people's livelihood, and major public interests.
Source: China Data Security Law, Art. 21.
Jurisdiction: China.

**60. Cross-border Data Transfer / Data Export**
Definition: An act by which a personal information handler provides personal information to an overseas recipient.
Source: China Personal Information Protection Law, Art. 38.
Jurisdiction: China.

---

## E. Data Security & Compliance

**61. Data Security**
Definition: The adoption of necessary measures to ensure that data is in a state of effective protection and lawful use, and that the capacity to maintain a sustained state of security exists.
Source: China Data Security Law, Art. 3(1).
Jurisdiction: China.

**62. Data Classification and Grading**
Definition: The classification and graded protection of data according to the importance of the data in economic and social development, as well as the degree of harm that would result to national security, the public interest, or the lawful rights and interests of individuals or organisations if the data were tampered with, destroyed, leaked, illegally acquired, or illegally used.
Source: China Data Security Law, Art. 21.
Jurisdiction: China.
[Differential note] Data classification and grading is a core feature of China's data security regime; neither the EU nor the United States has a comparable unified classification and grading system.

**63. Data Security Risk Assessment**
Definition: Those engaging in data processing activities shall, in accordance with laws and regulations, establish and strengthen a full-process data security management system, organise and conduct data security education and training, and adopt corresponding technical measures and other necessary measures to safeguard data security.
Source: China Data Security Law, Art. 27.
Jurisdiction: China.

**64. Data Trading**
Definition: Data trading venues provide premises and facilities for data trading, organise and supervise data trading activities, and perform self-regulatory management duties.
Source: China Data Security Law, Art. 33.
Jurisdiction: China.

**65. Data Intermediary Services**
Definition: Intermediary activities that provide matchmaking, assessment, clearing and other services for data trading parties.
Source: China Data Security Law, Art. 33.
Jurisdiction: China.

**66. Privacy by Design**
Definition: The integration of privacy protection considerations into the design of systems, products and services from the outset of their development.
Source: GDPR Art. 25.
Jurisdiction: EU.
[Differential note] China's PIPL does not use the "privacy by design" concept, but Art. 51 requires handlers to adopt corresponding technical measures and other necessary measures to ensure the security of personal information.

**67. Privacy by Default**
Definition: The controller shall implement appropriate technical and organisational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed.
Source: GDPR Art. 25(2).
Jurisdiction: EU.

**68. Data Minimisation Principle**
Definition: Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
Source: GDPR Art. 5(1)(c); China PIPL Art. 6.
Jurisdiction: EU / China.

**69. Purpose Limitation Principle**
Definition: Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
Source: GDPR Art. 5(1)(b); China PIPL Art. 6.
Jurisdiction: EU / China.

**70. Storage Limitation Principle**
Definition: Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
Source: GDPR Art. 5(1)(e); China PIPL Art. 47.
Jurisdiction: EU / China.

**71. Integrity and Confidentiality Principle**
Definition: Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
Source: GDPR Art. 5(1)(f); China PIPL Art. 51.
Jurisdiction: EU / China.

**72. Accountability Principle**
Definition: The controller shall be responsible for, and be able to demonstrate compliance with, the GDPR's data protection principles.
Source: GDPR Art. 5(2).
Jurisdiction: EU.

**73. Lawfulness, Fairness and Transparency Principle**
Definition: Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.
Source: GDPR Art. 5(1)(a); China PIPL Arts. 5–7.
Jurisdiction: EU / China.

**74. Accuracy Principle**
Definition: Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate are erased or rectified without delay.
Source: GDPR Art. 5(1)(d); China PIPL Art. 46.
Jurisdiction: EU / China.

**75. Privacy Impact Assessment (PIA)**
Definition: A systematic process for evaluating the impact of proposed systems and projects on individual privacy.
Source: U.S. E-Government Act of 2002 § 208; NIST SP 800-122.
Jurisdiction: United States.
[Differential note] PIA is a term used by U.S. government agencies. It is functionally similar to the GDPR's DPIA and China's PIPIA but differs in scope of application.

**76. Records of Processing Activities (ROPA)**
Definition: Each controller and processor shall maintain a record of processing activities under its responsibility.
Source: GDPR Art. 30.
Jurisdiction: EU.

---

## F. Cybersecurity

**77. Cybersecurity**
- Definition: The ability to maintain a network in a stable and reliable operating state, and to safeguard the integrity, confidentiality, and availability of network data, by taking necessary measures to prevent attacks, intrusions, interference, sabotage, and unlawful use of networks, as well as accidental incidents.
- Source: Cybersecurity Law of the People's Republic of China, Art. 2.
- Jurisdiction: China.

**78. Critical Information Infrastructure (CII)**
- Definition: Important network facilities and information systems in key industries and sectors—including public communications and information services, energy, transportation, water conservancy, finance, public services, e-government, and national defense science, technology and industry—as well as other facilities and systems the destruction, loss of function, or data leakage of which may seriously endanger national security, the national economy and people's livelihood, or the public interest.
- Source: Cybersecurity Law of the People's Republic of China, Art. 31; Regulations on the Security Protection of Critical Information Infrastructure, Art. 2.
- Jurisdiction: China.
- **Comparative Note:** The United States uses the concept of "Critical Infrastructure," defined by the Homeland Security Act and Presidential Executive Orders, with a broader scope encompassing both physical and cyber facilities.

**79. Critical Infrastructure**
- Definition: Systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on national security, economic security, or public health or safety.
- Source: Homeland Security Act of 2002 (U.S.), §2(4); Presidential Executive Order EO 13010.
- Jurisdiction: United States.

**80. Critical Information Infrastructure Operator (CIIO)**
- Definition: An entity that operates critical information infrastructure.
- Source: Cybersecurity Law of the People's Republic of China, Art. 31; Regulations on the Security Protection of Critical Information Infrastructure, Art. 2.
- Jurisdiction: China.

**81. Network Operator**
- Definition: The owner, manager, or provider of network services of a network.
- Source: Cybersecurity Law of the People's Republic of China, Art. 76(3).
- Jurisdiction: China.

**82. Multi-Level Protection Scheme (MLPS)**
- Definition: A legal requirement that network operators implement a tiered security protection regime categorized into five levels based on the required degree of protection.
- Source: Cybersecurity Law of the People's Republic of China, Art. 21; Regulations on the Multi-Level Protection Scheme for Cybersecurity.
- Jurisdiction: China.
- **Comparative Note:** MLPS is a graded cybersecurity protection regime unique to China; the United States has no comparable industry-wide tiered protection scheme.

**83. Security Incident**
- Definition: An actual or suspected event that compromises the confidentiality, integrity, or availability of information or an information system.
- Source: NIST SP 800-61; Cybersecurity Law of the People's Republic of China, Art. 25.
- Jurisdiction: United States / China.

**84. Cybersecurity Incident**
- Definition: An event that, due to human causes, software or hardware defects or failures, natural disasters, or similar factors, causes harm to networks, information systems, or the data therein, and produces negative social impact.
- Source: National Cybersecurity Incident Response Plan of the People's Republic of China (2017); Cybersecurity Law, Art. 25.
- Jurisdiction: China.

**85. Security Vulnerability**
- Definition: A flaw or weakness in an information system, system security procedure, internal control, or implementation that could be exploited or triggered to produce a security breach.
- Source: NIST SP 800-40; Cybersecurity Law of the People's Republic of China, Art. 22.
- Jurisdiction: United States / China.

**86. Vulnerability Disclosure**
- Definition: The process of notifying relevant parties of security vulnerability information discovered in software or systems.
- Source: NIST SP 800-40; Provisions on the Administration of Security Vulnerabilities in Network Products of the People's Republic of China (2021).
- Jurisdiction: United States / China.

**87. Cybersecurity Review**
- Definition: A review conducted where the procurement of network products and services by critical information infrastructure operators, or the data processing activities undertaken by data processors, affects or may affect national security.
- Source: Cybersecurity Review Measures of the People's Republic of China (Revised 2022), Art. 2.
- Jurisdiction: China.
- **Comparative Note:** Cybersecurity Review is a regime unique to China. The United States achieves similar objectives through mechanisms such as CFIUS (Committee on Foreign Investment in the United States) review and ICT supply chain review, but the scope and procedures differ.

**88. Supply Chain Security**
- Definition: Measures to ensure that the supply chain for information and communications technology products and services is protected against threats such as malicious tampering and backdoor implantation.
- Source: Executive Order on Securing the Information and Communications Technology and Services Supply Chain (EO 13873, U.S.); Cybersecurity Law of the People's Republic of China, Arts. 22–23.
- Jurisdiction: United States / China.

**89. Real-Name Registration System**
- Definition: A requirement that network operators, when handling network access for users, domain name registration services, fixed-line or mobile telephone network access formalities, or providing services such as information publication and instant messaging, shall require users to provide their true identity information.
- Source: Cybersecurity Law of the People's Republic of China, Art. 24.
- Jurisdiction: China.
- **Comparative Note:** The real-name registration system is a regime unique to China; neither the United States nor the European Union has a comparable industry-wide mandatory real-name requirement.

**90. Log Retention**
- Definition: The obligation of network operators to retain relevant network logs, as required, for a period of not less than six months.
- Source: Cybersecurity Law of the People's Republic of China, Art. 21(3).
- Jurisdiction: China.

**91. Security Audit**
- Definition: An independent assessment of the security controls of an information system to determine whether they satisfy security requirements.
- Source: NIST SP 800-53; Cybersecurity Law of the People's Republic of China, Art. 21.
- Jurisdiction: United States / China.

**92. Penetration Testing**
- Definition: A method of security assessment that evaluates an information system by simulating the means employed by an attacker.
- Source: NIST SP 800-115.
- Jurisdiction: United States.

**93. Encryption**
- Definition: The application of cryptographic techniques to convert plaintext data into ciphertext data, in order to protect the confidentiality of the data.
- Source: NIST FIPS 140-3; Cryptography Law of the People's Republic of China, Art. 2.
- Jurisdiction: United States / China.

**94. Cryptography**
- Definition: Technologies, products, and services that use specified transformations to encrypt, protect, or securely authenticate data and other information.
- Source: Cryptography Law of the People's Republic of China, Art. 2.
- Jurisdiction: China.

**95. Commercial Cryptography**
- Definition: Cryptography used for information that does not involve state secrets and for information systems that do not contain state secrets.
- Source: Cryptography Law of the People's Republic of China, Art. 3.
- Jurisdiction: China.

---

## G. Cybercrime

**96. Cybercrime**
- Definition: Criminal acts committed by utilizing information and communications technology, or directed against ICT systems.
- Source: Council of Europe Convention on Cybercrime (Budapest Convention), Art. 1; United Nations Convention on Cybercrime (adopted 2024).
- Jurisdiction: International.

**97. Illegal Access to a Computer System**
- Definition: The intentional, unauthorized access to the whole or any part of a computer system.
- Source: Council of Europe Convention on Cybercrime (Budapest Convention), Art. 2; Criminal Law of the People's Republic of China, Art. 285 (Offense of Illegally Intruding into a Computer Information System).
- Jurisdiction: International / China.
- **Comparative Note:** The U.S. Computer Fraud and Abuse Act (CFAA, 18 U.S.C. §1030) uses the concepts of "access without authorization" and "exceeds authorized access."

**98. Illegal Interception**
- Definition: The interception, made without right and by technical means, of non-public transmissions of computer data.
- Source: Council of Europe Convention on Cybercrime (Budapest Convention), Art. 3.
- Jurisdiction: International.

**99. Data Interference**
- Definition: The intentional, unauthorized damaging, deletion, deterioration, alteration, or suppression of computer data.
- Source: Council of Europe Convention on Cybercrime (Budapest Convention), Art. 4; Criminal Law of the People's Republic of China, Art. 286 (Offense of Sabotaging a Computer Information System).
- Jurisdiction: International / China.

**100. System Interference**
- Definition: The serious hindering of the functioning of a computer system by inputting, transmitting, damaging, deleting, deteriorating, altering, or suppressing computer data.
- Source: Council of Europe Convention on Cybercrime (Budapest Convention), Art. 5.
- Jurisdiction: International.

**101. Misuse of Devices**
- Definition: The production, provision, distribution, or other making available of devices (including computer programs) or passwords, access codes, or similar means designed or adapted for committing cyber crimes.
- Source: Council of Europe Convention on Cybercrime (Budapest Convention), Art. 6; Criminal Law of the People's Republic of China, Art. 285(3) (Offense of Providing Programs or Tools for Intruding into or Illegally Controlling Computer Information Systems).
- Jurisdiction: International / China.

**102. Computer-Related Forgery / Computer Fraud**
- Definition: Fraudulent acts committed by means of a computer, with the purpose of unlawful appropriation.
- Source: Criminal Law of the People's Republic of China, Art. 287 (providing that financial fraud, theft, embezzlement, misappropriation of public funds, theft of state secrets, or other crimes committed using a computer shall be convicted and punished in accordance with the relevant provisions of the Law); U.S. CFAA (18 U.S.C. §1030(a)(4)).
- Jurisdiction: China / United States.

**103. Phishing**
- Definition: A social engineering attack technique in which the perpetrator masquerades as a trustworthy entity to induce victims to disclose sensitive information.
- Source: Identity Theft and Assumption Deterrence Act (U.S., 18 U.S.C. §1028).
- Jurisdiction: United States.

**104. Ransomware**
- Definition: Malicious software that encrypts a victim's data and demands payment of a ransom in exchange for restoring access.
- Source: The U.S. Computer Fraud and Abuse Act applies to such attacks; in China, accountability is pursued under Art. 286 of the Criminal Law.
- Jurisdiction: United States / China.

**105. Identity Theft**
- Definition: The unauthorized use of another person's identifying information to commit fraud or other criminal acts.
- Source: Identity Theft and Assumption Deterrence Act (U.S., 18 U.S.C. §1028); Criminal Law of the People's Republic of China, Art. 253-1 (Offense of Infringing on Citizens' Personal Information).
- Jurisdiction: United States / China.

**106. Denial of Service (DoS) Attack**
- Definition: An attack that intentionally renders a computer system or network service unavailable to its legitimate users.
- Source: U.S. CFAA (18 U.S.C. §1030(a)(5)); Criminal Law of the People's Republic of China, Art. 286.
- Jurisdiction: United States / China.

**107. Distributed Denial of Service (DDoS) Attack**
- Definition: A denial of service attack launched simultaneously through multiple compromised computer systems.
- Source: U.S. CFAA; Criminal Law of the People's Republic of China, Art. 286.
- Jurisdiction: United States / China.

**108. Malware**
- Definition: Software designed to gain unauthorized access to, or to cause damage to, a computer system.
- Source: NIST SP 800-83.
- Jurisdiction: United States.

**109. Botnet**
- Definition: A network of large numbers of infected computers remotely controlled by an attacker.
- Source: Commentary on Art. 6 of the Council of Europe Convention on Cybercrime (Budapest Convention).
- Jurisdiction: International.

**110. Online Fraud**
- Definition: Fraudulent acts committed by means of the Internet.
- Source: Criminal Law of the People's Republic of China, Art. 266 (Offense of Fraud); Art. 287-1 (Offense of Illegally Using Information Networks).
- Jurisdiction: China.

**111. Crime of Assisting Information Network Criminal Activities**
- Definition: The act of knowingly providing technical support—such as Internet access, server hosting, network storage, or communications transmission—or providing assistance such as advertising, promotion, or payment settlement, for another person's use of information networks to commit crimes.
- Source: Criminal Law of the People's Republic of China, Art. 287-2.
- Jurisdiction: China.
- **Comparative Note:** This is a sui generis offense under Chinese criminal law. It resembles the U.S. doctrine of "aiding and abetting" (18 U.S.C. §2), but the scope of application and elements differ.

**112. Crime of Infringing on Citizens' Personal Information**
- Definition: The act, in violation of relevant state regulations, of selling or providing citizens' personal information to others, or stealing or otherwise illegally obtaining citizens' personal information, where the circumstances are serious.
- Source: Criminal Law of the People's Republic of China, Art. 253-1.
- Jurisdiction: China.

**113. Crime of Refusing to Fulfill Information Network Security Management Obligations**
- Definition: The act of a network service provider failing to fulfill information network security management obligations prescribed by laws or administrative regulations, refusing to take corrective measures after being ordered to do so by the regulatory authority, resulting in serious consequences.
- Source: Criminal Law of the People's Republic of China, Art. 286-1.
- Jurisdiction: China.

---

## H. Platform Liability and Content Governance

**114. Internet Platform**
- Definition: Infrastructure that uses network information technology to provide users with services such as information publication, transactions, social networking, and entertainment.
- Source: Administrative Measures for Internet Information Services of the People's Republic of China, Art. 2; EU Digital Services Act (DSA), Art. 3.
- Jurisdiction: China / EU.

**115. Very Large Online Platform (VLOP)**
- Definition: An online platform whose average monthly active recipients in the European Union exceeds 45 million.
- Source: EU Digital Services Act (DSA), Art. 33.
- Jurisdiction: EU.
- **Comparative Note:** VLOP is a concept specific to the DSA; neither Chinese nor U.S. law has a directly corresponding concept. China's Guidelines for Internet Platform Classification and Tiered Regulation classify platforms into super platforms, large platforms, and small-to-medium platforms.

**116. Super Platform**
- Definition: Under China's platform classification framework, a platform possessing an ultra-large user base, ultra-high business volume, ultra-strong restrictive power, and ultra-strong control capability.
- Source: Guidelines for Internet Platform Classification and Tiered Regulation of the People's Republic of China (Draft for Comment, 2021).
- Jurisdiction: China.
- **Comparative Note:** The criteria for a "Super Platform" are: no fewer than 500 million annual active users in China in the preceding year; core business involving at least two types of platform business; and a market capitalization of no less than RMB 1 trillion at year-end. These criteria differ from the EU VLOP definition.

**117. Safe Harbor Principle**
- Definition: A rule under which a network service provider is exempt from liability for damages arising from user-generated infringing content, provided specified conditions are met.
- Source: U.S. Digital Millennium Copyright Act (DMCA), §512; EU Directive on Electronic Commerce (2000/31/EC), Arts. 12–15.
- Jurisdiction: United States / EU.
- **Comparative Note:** China's Regulation on the Protection of the Right of Communication Through Information Network, Arts. 20–23, also adopts the "safe harbor" rule, though the specific conditions and procedures for its application differ.

**118. Red Flag Rule**
- Definition: A rule providing that a network service provider may not invoke the safe harbor defense when it is aware or should be aware that a user is engaged in infringing conduct (because the infringement is as obvious as a red flag).
- Source: U.S. DMCA, §512; Regulation on the Protection of the Right of Communication Through Information Network of the People's Republic of China, Art. 23.
- Jurisdiction: United States / China.

**119. Notice-and-Takedown Mechanism**
- Definition: A mechanism whereby, upon receiving a notice of infringement from a rights holder, a network service provider shall promptly remove or disable access to the allegedly infringing content or link.
- Source: U.S. DMCA, §512(c); Regulation on the Protection of the Right of Communication Through Information Network of the People's Republic of China, Art. 14.
- Jurisdiction: United States / China.

**120. Content Moderation**
- Definition: The practice by online platforms of reviewing, screening, and managing user-generated content.
- Source: EU DSA, Art. 3(t); Provisions on the Ecological Governance of Online Information Content of the People's Republic of China, Art. 8.
- Jurisdiction: EU / China.

**121. Illegal Content**
- Definition: Under the DSA, content that is related to a criminal offense or tortious act under EU or Member State law, or that may violate EU law under EU law.
- Source: EU DSA, Art. 3(h).
- Jurisdiction: EU.

**122. Harmful Content**
- Definition: Content that, while not necessarily illegal, may cause negative effects on individuals or society.
- Source: EU DSA, Preamble ¶11; Provisions on the Ecological Governance of Online Information Content of the People's Republic of China, Art. 7.
- Jurisdiction: EU / China.
- **Comparative Note:** The DSA distinguishes between "illegal content" and "harmful content," applying different governance obligations to each. Chinese law does not strictly distinguish between the two, instead classifying content as "illegal information" and "undesirable information."

**123. Illegal Information**
- Definition: Information that opposes the fundamental principles established by the Constitution, endangers national security, harms national honor and interests, incites ethnic hatred, undermines ethnic unity, infringes upon the lawful rights and interests of others, or similar categories of information.
- Source: Administrative Measures for Internet Information Services of the People's Republic of China, Art. 15.
- Jurisdiction: China.

**124. Undesirable Information**
- Definition: Content containing uncivilized language, exaggerated or misleading headlines, sensationalized coverage of scandals or gossip, inappropriate commentary on natural disasters or accidents, or similar material.
- Source: Provisions on the Ecological Governance of Online Information Content of the People's Republic of China, Art. 7.
- Jurisdiction: China.

**125. Algorithmic Recommendation**
- Definition: The use of algorithmic technologies—including content generation and synthesis, personalized push, ranking and curation, retrieval and filtering, and scheduling and decision-making algorithms—to provide information to users.
- Source: Provisions on the Administration of Algorithmic Recommendation in Internet Information Services of the People's Republic of China, Art. 2.
- Jurisdiction: China.

**126. Algorithmic Transparency**
- Definition: The obligation of online platforms to explain, in a clear and unambiguous manner, the main parameters used by their recommender systems to users.
- Source: EU DSA, Art. 27; Provisions on the Administration of Algorithmic Recommendation in Internet Information Services of the People's Republic of China, Art. 16.
- Jurisdiction: EU / China.

**127. Algorithmic Bias**
- Definition: Unfair or discriminatory outcomes produced by algorithmic systems in their processing.
- Source: EU Artificial Intelligence Act (AI Act), Art. 10; Provisions on the Administration of Algorithmic Recommendation in Internet Information Services of the People's Republic of China, Art. 6.
- Jurisdiction: EU / China.

**128. Deepfake**
- Definition: Digital content, such as images, audio, or video, generated or manipulated using artificial intelligence technologies so as to appear authentic.
- Source: Provisions on the Administration of Deep Synthesis in Internet Information Services of the People's Republic of China, Art. 2; EU AI Act, Art. 50.
- Jurisdiction: China / EU.

**129. Deep Synthesis**
- Definition: Technologies that utilize deep learning, virtual reality, and other synthesis-generation algorithms to produce network information such as text, images, audio, video, and virtual scenes.
- Source: Provisions on the Administration of Deep Synthesis in Internet Information Services of the People's Republic of China, Art. 2.
- Jurisdiction: China.
- **Comparative Note:** China uses the concept of "deep synthesis," which is broader in scope than the term "deepfake" commonly used in Western jurisdictions, encompassing both legitimate and illicit synthesis technologies.

**130. Filter Bubble / Information Cocoon**
- Definition: The phenomenon whereby algorithmic recommendation causes users to receive only information consistent with their existing views, thereby forming an information silo or isolation effect.
- Source: Eli Pariser (2011); implicitly addressed by the Provisions on the Administration of Algorithmic Recommendation in Internet Information Services of the People's Republic of China, Art. 6.
- Jurisdiction: International.

**131. Platform Monopoly**
- Definition: Conduct by an Internet platform that abuses its market dominance to restrict competition.
- Source: Anti-Monopoly Law of the People's Republic of China, Art. 22; EU Digital Markets Act (DMA).
- Jurisdiction: China / EU.

**132. Gatekeeper**
- Definition: A large platform that provides core platform services in digital markets and serves as an important gateway between business users and consumers.
- Source: EU Digital Markets Act (DMA), Art. 3.
- Jurisdiction: EU.
- **Comparative Note:** The "Gatekeeper" is the core concept of the DMA. China's Anti-Monopoly Law does not include an equivalent concept, though the Anti-Monopoly Guidelines for the Platform Economy address similar concerns.

**133. Self-Preferencing**
- Definition: Conduct by a platform that gives preferential treatment—for example, in search ranking or recommendations—to its own products or services, thereby harming the interests of competitors.
- Source: EU DMA, Art. 6(5); Anti-Monopoly Guidelines for the Platform Economy of the People's Republic of China.
- Jurisdiction: EU / China.

**134. Big Data Price Discrimination**
- Definition: Conduct by an operator that uses algorithms, data, or other means to apply differential pricing to consumers.
- Source: Personal Information Protection Law of the People's Republic of China, Art. 24(1); Provisions on the Administration of Algorithmic Recommendation in Internet Information Services, Art. 21.
- Jurisdiction: China.
- **Comparative Note:** "Big data price discrimination" is a term specific to China, referring to differential pricing based on user profiling. The EU and the United States indirectly regulate such conduct through competition law and consumer protection law.

**135. Digital Services Act (DSA)**
- Definition: An EU regulation establishing single market rules for digital intermediary services, setting out obligations on content governance, transparency, and related matters for online platforms.
- Source: Regulation (EU) 2022/2065 (Digital Services Act).
- Jurisdiction: EU.

**136. Digital Markets Act (DMA)**
- Definition: An EU regulation aimed at ensuring fair competition in digital markets, imposing specific obligations on "gatekeeper" platforms.
- Source: Regulation (EU) 2022/1925 (Digital Markets Act).
- Jurisdiction: EU.

---

## I. AI Governance

**137. AI System**
- Definition: A machine system designed to operate with varying degrees of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, recommendations, content, or decisions that can influence physical or virtual environments.
- Source: EU AI Act (Regulation (EU) 2024/1689), Article 3(1).
- Jurisdiction: EU.

**138. Artificial Intelligence (AI)**
- Definition: Theories, methods, technologies, and application systems that use machines to simulate, extend, and augment human intelligence.
- Source: China's *New Generation Artificial Intelligence Development Plan* (Guofa [2017] No. 35).
- Jurisdiction: China.
- [Comparative Note] The EU AI Act provides a detailed legal definition of "AI system." China has not yet uniformly defined "artificial intelligence" in any dedicated legislation, though various departmental rules and standards touch upon the concept.

**139. Generative AI**
- Definition: Artificial intelligence technology that generates content such as text, audio, images, and video based on algorithms, models, and rules.
- Source: China's *Interim Measures for the Administration of Generative Artificial Intelligence Services*, Article 2.
- Jurisdiction: China.

**140. Foundation Model**
- Definition: An AI model trained on large-scale data that can be adapted to a broad range of tasks.
- Source: EU AI Act, Article 3(25); U.S. *Blueprint for an AI Bill of Rights* (2022).
- Jurisdiction: EU / United States.
- [Comparative Note] The EU AI Act uses the concept of "General-Purpose AI Model." China uses the concept of "foundation model" or "large model." U.S. scholarship commonly uses "foundation model."

**141. General Purpose AI (GPAI)**
- Definition: An AI model that displays significant generality in its capabilities, is capable of competently performing a wide variety of distinct tasks, and can be integrated into a variety of downstream systems or applications.
- Source: EU AI Act, Article 3(63).
- Jurisdiction: EU.

**142. High-Risk AI System**
- Definition: An AI system that may pose a significant risk of harm to health, safety, or fundamental rights and must comply with the strict obligations set out in the AI Act.
- Source: EU AI Act, Article 6 and Annexes I–III.
- Jurisdiction: EU.
- [Comparative Note] The EU AI Act establishes a risk-based classification system (unacceptable risk, high risk, limited risk, minimal risk). China adopts a "sector-by-sector" management approach, e.g., the *Interim Measures for the Administration of Generative AI Services* specifically regulates generative AI.

**143. Unacceptable Risk**
- Definition: An AI system presenting a clear threat to the safety, livelihood, or fundamental rights of persons, which is prohibited under the AI Act.
- Source: EU AI Act, Article 5.
- Jurisdiction: EU.

**144. AI Transparency**
- Definition: The requirement that AI systems and their outputs be understandable and traceable to human beings.
- Source: EU AI Act, Article 13; China's *Interim Measures for the Administration of Generative AI Services*, Article 17.
- Jurisdiction: EU / China.

**145. AI Explainability**
- Definition: The requirement that the decision-making process of an AI system be capable of being understood and explained by humans.
- Source: EU AI Act, Article 13; OECD AI Principles.
- Jurisdiction: International.

**146. Human Oversight**
- Definition: AI systems shall be designed and operated in such a way that natural persons can exercise effective oversight during their use.
- Source: EU AI Act, Article 14; China's *Governance Principles for the New Generation of Artificial Intelligence* (2019).
- Jurisdiction: EU / China.

**147. Algorithmic Discrimination**
- Definition: Unfair or differential treatment produced by algorithmic systems when making decisions concerning different groups based on protected attributes (such as race, sex, age, etc.).
- Source: U.S. *Blueprint for an AI Bill of Rights*, Principle 2; EU AI Act, Article 10.
- Jurisdiction: United States / EU.

**148. Automated Decision System**
- Definition: A process of making, or facilitating the making of, decisions through a computational system without human intervention.
- Source: U.S. *Algorithmic Accountability Act* (2022 draft); GDPR, Article 22.
- Jurisdiction: United States / EU.

**149. AI Ethics**
- Definition: Moral principles and values guiding the research, development, and application of artificial intelligence.
- Source: OECD AI Principles (2019); UNESCO *Recommendation on the Ethics of Artificial Intelligence* (2021); China's *Governance Principles for the New Generation of Artificial Intelligence* (2019).
- Jurisdiction: International.

**150. AI Governance**
- Definition: The legal, policy, and institutional framework regulating the development, deployment, and use of artificial intelligence systems.
- Source: EU AI Act; China's *Interim Measures for the Administration of Generative AI Services*; U.S. *Blueprint for an AI Bill of Rights*.
- Jurisdiction: International.

**151. AI Filing / Registration**
- Definition: Where a provider offers generative AI services with public opinion attributes or social mobilization capacity, it shall conduct a security assessment and complete algorithm filing formalities in accordance with relevant state provisions.
- Source: China's *Interim Measures for the Administration of Generative AI Services*, Article 17; *Provisions on the Administration of Algorithmic Recommendations in Internet Information Services*, Article 24.
- Jurisdiction: China.
- [Comparative Note] AI filing is a system unique to China; the EU and the United States have no comparable filing requirement. The EU AI Act requires high-risk AI systems to undergo conformity assessment before being placed on the market.

**152. Algorithm Filing**
- Definition: Providers of algorithm-based recommendation services possessing public opinion attributes or social mobilization capacity shall submit filing information through the algorithm filing system within ten working days from the date of providing services.
- Source: China's *Provisions on the Administration of Algorithmic Recommendations in Internet Information Services*, Article 24.
- Jurisdiction: China.

**153. AI Watermarking**
- Definition: Technology for embedding identifiable markings in AI-generated content to distinguish AI-generated content from human-created content.
- Source: EU AI Act, Article 50(4); China's *Interim Measures for the Administration of Generative AI Services*, Article 12.
- Jurisdiction: EU / China.

**154. Synthetic Media**
- Definition: Media content generated or substantially modified using artificial intelligence technology, including text, images, audio, and video.
- Source: EU AI Act, Article 3(1); China's *Provisions on the Administration of Deep Synthesis in Internet Information Services*.
- Jurisdiction: EU / China.

**155. Human-in-the-Loop**
- Definition: A design model in which AI systems preserve human intervention and control at critical decision points.
- Source: EU AI Act, Article 14(4)(a).
- Jurisdiction: EU.

**156. Human-on-the-Loop**
- Definition: A design model in which humans may supervise and intervene in the operation of the AI system, but not every decision requires human confirmation.
- Source: EU AI Act, Article 14(4)(b).
- Jurisdiction: EU.

---

## J. E-commerce & Consumer Protection

**157. Electronic Commerce**
- Definition: Business activities of selling goods or providing services through information networks such as the internet.
- Source: China's *Electronic Commerce Law*, Article 2; EU *E-Commerce Directive* (Directive 2000/31/EC), Article 2.
- Jurisdiction: China / EU.

**158. E-commerce Platform Operator**
- Definition: A legal person or unincorporated organization that provides services such as online business premises, transaction matching, and information posting for two or more transacting parties in electronic commerce, enabling them to conduct transactions independently.
- Source: China's *Electronic Commerce Law*, Article 9.
- Jurisdiction: China.
- [Comparative Note] The EU Digital Services Act (DSA) uses the concept of "online platform." Section 230 of the U.S. Communications Decency Act uses the concept of "interactive computer service."

**159. Intra-platform Operator**
- Definition: An operator that sells goods or provides services through an e-commerce platform.
- Source: China's *Electronic Commerce Law*, Article 9.
- Jurisdiction: China.

**160. Electronic Contract**
- Definition: A contract concluded in the form of data messages as an expression of the parties' intent.
- Source: China's *Civil Code*, Article 469; *Electronic Signature Law*, Article 3; United Nations *Convention on the Use of Electronic Communications in International Contracts*.
- Jurisdiction: China / International.

**161. Electronic Signature**
- Definition: Data in electronic form contained in or attached to a data message, used to identify the signatory and to indicate the signatory's approval of the content therein.
- Source: China's *Electronic Signature Law*, Article 2; EU eIDAS Regulation, Article 3(10); U.S. ESIGN Act.
- Jurisdiction: China / EU / United States.

**162. Digital Signature**
- Definition: A type of electronic signature generated using asymmetric cryptographic technology, capable of verifying the signatory's identity and the integrity of the data.
- Source: EU eIDAS Regulation, Article 3(12); China's *Electronic Signature Law*, Articles 13–14.
- Jurisdiction: EU / China.

**163. Reliable Electronic Signature**
- Definition: An electronic signature that simultaneously meets the following conditions is deemed reliable: (i) the electronic signature creation data is, when used for electronic signature, exclusively attributable to the electronic signatory; (ii) at the time of signing, the electronic signature creation data is controlled solely by the electronic signatory; (iii) any alteration to the electronic signature after signing is detectable; (iv) any alteration to the content and form of the data message after signing is detectable.
- Source: China's *Electronic Signature Law*, Article 13.
- Jurisdiction: China.
- [Comparative Note] China's "reliable electronic signature" broadly corresponds to the "qualified electronic signature" under the EU eIDAS Regulation, but the certification standards differ.

**164. Electronic Authentication Service**
- Definition: Activities providing authenticity and reliability verification to parties involved in electronic signatures.
- Source: China's *Electronic Signature Law*, Article 16.
- Jurisdiction: China.

**165. Online Dispute Resolution (ODR)**
- Definition: A mechanism for resolving cross-border e-commerce disputes through electronic means.
- Source: EU ODR Regulation (Regulation (EU) No. 524/2013); UNCITRAL *Technical Notes on Online Dispute Resolution*.
- Jurisdiction: EU / International.

**166. Consumer Right of Withdrawal**
- Definition: In a distance contract, the consumer has the right to return the goods within 14 days of receipt without stating any reasons.
- Source: China's *Law on the Protection of Consumer Rights and Interests*, Article 25; EU *Consumer Rights Directive* (Directive 2011/83/EU), Article 9.
- Jurisdiction: China / EU.

**167. Algorithmic Price Discrimination**
- Definition: Conduct by which an operator uses technology such as algorithms and data to subject consumers to differential pricing.
- Source: China's *Personal Information Protection Law*, Article 24; *Provisions on the Administration of Algorithmic Recommendations in Internet Information Services*, Article 21.
- Jurisdiction: China.
- [Comparative Note] See also "big data-enabled price discrimination against existing customers" (大数据杀熟).

**168. Bundling / Tying**
- Definition: Conduct by which an operator, when selling goods, bundles them with or attaches unreasonable trading conditions.
- Source: China's *Electronic Commerce Law*, Article 19; China's *Anti-Monopoly Law*, Article 22.
- Jurisdiction: China / International.

**169. Fake Reviews and Click Farming**
- Definition: Conduct involving the manipulation of an intra-platform operator's credit rating and sales volume through fake transactions, fake reviews, and similar practices.
- Source: China's *Electronic Commerce Law*, Article 17; *Anti-Unfair Competition Law*, Article 8.
- Jurisdiction: China.
- [Comparative Note] "Fake reviews and click farming" (*shuadan chaoxin*) is a term unique to China. The U.S. Federal Trade Commission (FTC) regulates fake reviews under Section 5 of the FTC Act, and equivalent provisions exist under the EU *Unfair Commercial Practices Directive*.

**170. Exclusivity Requirement**
- Definition: An exclusive dealing arrangement under which a platform requires an operator to operate exclusively on its own platform.
- Source: China's *Anti-Monopoly Law*, Article 22; *Electronic Commerce Law*, Article 22; *Anti-Monopoly Guidelines on the Platform Economy*.
- Jurisdiction: China.
- [Comparative Note] "Pick one of two" (*er xuan yi*) is a term unique to the Chinese cyber law context. The EU prohibits gatekeepers from imposing exclusivity requirements under Article 5(3) of the Digital Markets Act (DMA). The United States regulates such conduct through antitrust law (Sherman Act §1).

**171. Micro Business**
- Definition: A small-scale e-commerce operator whose annual transaction volume does not exceed the prescribed threshold.
- Source: China's *Electronic Commerce Law*, Article 10 (circumstances exempting registration).
- Jurisdiction: China.

---

## K. Intellectual Property & Digital Content

**172. Digital Copyright**
- Definition: Copyright and related rights enjoyed in works within the digital environment.
- Source: WIPO *Copyright Treaty* (WCT, 1996); China's *Copyright Law*, Article 10.
- Jurisdiction: International / China.

**173. Right of Communication through Information Network**
- Definition: The right to make a work available to the public by wire or wireless means, such that members of the public may access the work from a place and at a time individually chosen by them.
- Source: China's *Copyright Law*, Article 10(1)(xii).
- Jurisdiction: China.
- [Comparative Note] China's "right of communication through information network" corresponds to the "Right of Making Available to the Public" under Article 8 of the WIPO Copyright Treaty, and to the rights of "distribution" and "public performance/display" under Section 106(3) of the U.S. Copyright Act.

**174. Technological Protection Measures (TPM)**
- Definition: Technical measures used to prevent or restrict unauthorized access to or use of works without the permission of the right holder.
- Source: U.S. DMCA, Section 1201; China's *Copyright Law*, Articles 49–50; WIPO *Copyright Treaty*, Article 11.
- Jurisdiction: International.

**175. Digital Rights Management (DRM)**
- Definition: Technical systems and tools used to control, restrict, or manage the use of digital content, designed to protect copyright and related rights.
- Source: U.S. DMCA, Section 1201; EU *Information Society Copyright Directive* (Directive 2001/29/EC), Article 6; China's *Copyright Law*, Article 50.
- Jurisdiction: International.

**176. Takedown Notice**
- Definition: A notice sent by a right holder to a network service provider requesting the removal of allegedly infringing content.
- Source: U.S. DMCA, Section 512(c)(3); China's *Regulation on the Protection of the Right of Communication through Information Network*, Article 14.
- Jurisdiction: United States / China.

**177. Counter-Notice**
- Definition: A statement submitted by the alleged infringing user to the network service provider, asserting that the content does not constitute infringement and requesting its restoration.
- Source: U.S. DMCA, Section 512(g)(3); China's *Regulation on the Protection of the Right of Communication through Information Network*, Article 17.
- Jurisdiction: United States / China.

**178. Open Source License**
- Definition: A license that authorizes users to freely use, modify, and distribute the source code of software.
- Source: GNU General Public License (GPL); MIT License; Apache License 2.0.
- Jurisdiction: International.

**179. Creative Commons License (CC License)**
- Definition: A standardized license agreement that permits creators to grant others permission to use their works while retaining certain rights.
- Source: Creative Commons Corporation (2001); relevant to China's *Copyright Law*, Article 24 (fair use).
- Jurisdiction: International.

**180. Domain Name**
- Definition: A hierarchical character-based name used to identify and locate computers on the internet.
- Source: ICANN domain name registration system; China's *Measures on the Administration of Internet Domain Names*, Article 2.
- Jurisdiction: International.

**181. Cybersquatting**
- Definition: The bad-faith registration or use of a domain name that is identical or confusingly similar to another's trademark, name, or other identifier.
- Source: U.S. *Anticybersquatting Consumer Protection Act* (ACPA, 15 U.S.C. §1125(d)); WIPO *Uniform Domain-Name Dispute-Resolution Policy* (UDRP).
- Jurisdiction: United States / International.

**182. Uniform Domain-Name Dispute-Resolution Policy (UDRP)**
- Definition: A domain name dispute resolution mechanism established by ICANN, applicable to disputes concerning top-level domains.
- Source: ICANN UDRP (1999); WIPO Arbitration and Mediation Center Rules.
- Jurisdiction: International.

**183. Software Patent**
- Definition: Patent protection granted for software-related inventions.
- Source: U.S. *Patent Act*, Section 101 (35 U.S.C. §101); European Patent Convention (EPC), Article 52; China's *Patent Law*, Article 2.
- Jurisdiction: International.
- [Comparative Note] U.S. examination standards for software patents evolved after *Alice Corp. v. CLS Bank* (2014). The EU does not grant patents for "computer programs as such," but software inventions with technical character may be patentable. China requires that a software patent application possess a technical solution with technical character.

**184. Algorithm Patent**
- Definition: Patent protection granted for algorithm-related inventions.
- Source: U.S. *Patent Act*, Section 101; China's *Patent Examination Guidelines*, Part II, Chapter 9.
- Jurisdiction: United States / China.

**185. Database Right (Sui Generis Right)**
- Definition: A *sui generis* right providing special protection for the investment of database makers in the collection, verification, and presentation of data.
- Source: EU *Database Directive* (Directive 96/9/EC), Article 7.
- Jurisdiction: EU.
- [Comparative Note] The database right is a *sui generis* right unique to the EU. The United States and China have no comparable protection scheme, though China may provide limited protection through Article 2 of its *Anti-Unfair Competition Law*.

---

## L. International Law & Jurisdiction

**186. Cyber Sovereignty / Network Sovereignty**
- Definition: The jurisdiction exercised by a state over matters within its cyberspace, including the right to manage its network infrastructure, network activities, and network information.
- Source: China's *Cybersecurity Law*, Article 1; UN Group of Governmental Experts on Information Security Report (2015); *Tallinn Manual 2.0*, Rule 1.
- Jurisdiction: International.
- [Comparative Note] China emphasizes the principle of "cyber sovereignty" as the foundation of its cyber law. The United States and the EU emphasize a "multi-stakeholder" governance model, though in practice they also exercise jurisdiction in cyberspace.

**187. Long-arm Jurisdiction**
- Definition: The doctrine by which a court exercises jurisdiction over a defendant not domiciled within the forum, provided the defendant has "minimum contacts" with the forum state.
- Source: *International Shoe Co. v. Washington*, 326 U.S. 310 (1945); state long-arm statutes.
- Jurisdiction: United States.
- [Comparative Note] Long-arm jurisdiction is a concept unique to U.S. law and is widely applied in cybersecurity and data protection contexts, e.g., the CLOUD Act. China and the EU exercise jurisdiction through the territorial principle and the effects doctrine.

**188. Data Warrant / Production Order**
- Definition: A legal order requiring an electronic communication service provider or remote computing service provider to disclose stored communications content or records.
- Source: U.S. *Stored Communications Act* (18 U.S.C. §2703); CLOUD Act (2018).
- Jurisdiction: United States.

**189. CLOUD Act (Clarifying Lawful Overseas Use of Data Act)**
- Definition: Legislation permitting U.S. law enforcement authorities to compel U.S.-based communications service providers to produce data stored overseas by court order, and establishing a framework for executive agreements with other countries.
- Source: U.S. CLOUD Act (2018), codified at 18 U.S.C. §2713.
- Jurisdiction: United States.
- [Comparative Note] The CLOUD Act has generated extensive international jurisdictional controversy. The EU has established a comparable mechanism through the *e-Evidence Regulation*. Article 36 of China's *Data Security Law* requires that organizations and individuals within China shall not provide data stored within China to foreign judicial or law enforcement authorities without approval from the competent Chinese authority.

**190. Electronic Evidence**
- Definition: Information stored, transmitted, or processed in electronic form that is capable of proving the facts of a case.
- Source: China's *Criminal Procedure Law*, Article 50; EU *e-Evidence Regulation* (adopted 2023); U.S. *Federal Rules of Evidence*, Rule 901.
- Jurisdiction: International.

**191. Tallinn Manual**
- Definition: A non-binding academic guide on international law applicable to cyberspace, compiled under the auspices of the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE).
- Source: *Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations* (2017).
- Jurisdiction: International.

**192. Budapest Convention on Cybercrime**
- Definition: The first international convention on cybercrime, developed by the Council of Europe, establishing rules on substantive criminal law, procedural law, and international cooperation.
- Source: Council of Europe *Convention on Cybercrime* (ETS No. 185, 2001).
- Jurisdiction: International.
- [Comparative Note] The United States is a party to the Budapest Convention. China has not acceded to it and instead champions the development of a UN Convention on Cybercrime. In 2024, the UN General Assembly adopted the *United Nations Convention Against Cybercrime*.

**193. UN Convention Against Cybercrime**
- Definition: A multilateral cybercrime convention developed under the auspices of the United Nations, aimed at strengthening international cooperation among states in preventing and combating cybercrime.
- Source: UN General Assembly Resolution A/RES/78/249 (adopted 2024).
- Jurisdiction: International.
- [Comparative Note] This Convention was actively promoted by China, Russia, and other states. It differs from the Budapest Convention on issues including jurisdiction and data production.

**194. Appropriate Jurisdiction**
- Definition: In cross-border data protection and cybersecurity cases, the rules determining which state's courts or regulatory authorities are competent to adjudicate the dispute.
- Source: GDPR, Article 3 (territorial scope); Brussels I Regulation (Regulation (EU) No. 1215/2012).
- Jurisdiction: EU.

**195. Territorial Principle**
- Definition: The fundamental principle of international law that a state exercises jurisdiction over persons, things, and acts within its territory.
- Source: *Charter of the United Nations*, Article 2(1); ICJ jurisprudence; for cyberspace application, see *Tallinn Manual 2.0*, Rule 1.
- Jurisdiction: International.

**196. Effects Doctrine**
- Definition: The principle that a state may exercise jurisdiction over acts committed by foreign nationals outside its territory that produce a substantial effect within the state.
- Source: U.S. antitrust case law (*Hartford Fire Insurance Co. v. California*, 509 U.S. 764 (1993)); China's *Anti-Monopoly Law*, Article 2.
- Jurisdiction: United States / China.

**197. Active Personality Principle**
- Definition: The principle that a state exercises jurisdiction over acts committed by its nationals abroad.
- Source: General principle of international law; *Tallinn Manual 2.0*, Rule 2.
- Jurisdiction: International.

**198. Passive Personality Principle**
- Definition: The principle that a state exercises jurisdiction over foreign nationals who commit crimes against its nationals outside its territory.
- Source: Principle of international law; *Tallinn Manual 2.0*, Rule 3.
- Jurisdiction: International.

**199. Universal Jurisdiction**
- Definition: The principle that a state may exercise jurisdiction over certain crimes that seriously harm the common interests of the international community, irrespective of the location of the crime or the nationality of the perpetrator.
- Source: Principle of international law; *Rome Statute*, Article 4.
- Jurisdiction: International.

**200. Data Protection Adequacy**
- Definition: A finding that a third country ensures a level of protection of personal data that is essentially equivalent to that of the EU, thereby permitting the free transfer of personal data from the EU to that country.
- Source: GDPR, Article 45.
- Jurisdiction: EU.
- [Comparative Note] The EU has adopted adequacy findings for Japan, South Korea, the United Kingdom, and others. The 2023 EU–U.S. Data Privacy Framework (DPF) established a new adequacy finding. China has not yet obtained an EU adequacy finding.

**201. Data Privacy Framework (DPF)**
- Definition: The new personal data transfer framework between the EU and the United States, replacing the prior Privacy Shield and Safe Harbor frameworks.
- Source: European Commission Implementing Decision 2023/1795 (Data Privacy Framework Adequacy Decision).
- Jurisdiction: EU / United States.

**202. Privacy Shield**
- Definition: The EU–U.S. personal data transfer framework (2016), invalidated by the Court of Justice of the European Union in *Schrems II*.
- Source: European Commission Decision 2016/1250; CJEU Case C-311/18 (*Schrems II*, 16 July 2020).
- Jurisdiction: EU / United States.

**203. Safe Harbor (Data Protection)**
- Definition: The first EU–U.S. personal data transfer framework (2000), invalidated by the Court of Justice of the European Union in *Schrems I*.
- Source: European Commission Decision 2000/520; CJEU Case C-362/14 (*Schrems I*, 6 October 2015).
- Jurisdiction: EU / United States.

**204. Schrems Cases**
- Definition: A series of lawsuits brought by Austrian privacy activist Max Schrems against Facebook, resulting in the successive invalidation of the EU–U.S. data transfer frameworks (Safe Harbor and Privacy Shield).
- Source: CJEU Case C-362/14 (*Schrems I*, 2015); Case C-311/18 (*Schrems II*, 2020).
- Jurisdiction: EU.

**205. Data Localization Requirement**
- Definition: A legal requirement in certain jurisdictions that specified data must be stored and processed within that jurisdiction.
- Source: China's *Cybersecurity Law*, Article 37; EU GDPR (does not mandate localization but requires protection for data exports); Russia's *Personal Data Law*, Article 18(5).
- Jurisdiction: Multiple countries.
- [Comparative Note] China's data localization requirements are the most stringent, applying to CIIOs and processors handling personal information reaching prescribed volumes. The EU does not mandate localization, substituting outbound transfer protection mechanisms. The United States generally does not require data localization.

**206. Internet Governance**
- Definition: The multi-layered governance system concerning the coordination of internet technologies, policy-making, and global governance.
- Source: WSIS *Geneva Declaration of Principles* (2003); ICANN mission; UN GGE reports.
- Jurisdiction: International.
- [Comparative Note] In internet governance, China supports a "government-led" multilateral governance model, while the United States and the EU favor a "multi-stakeholder" governance model.

**207. Multistakeholder Governance**
- Definition: A model of internet governance in which governments, the private sector, the technical community, civil society, and other stakeholders jointly participate.
- Source: WSIS *Tunis Agenda* (2005), para. 34; ICANN governance framework.
- Jurisdiction: International.

**208. Interoperability**
- Definition: The ability of different systems, products, or services to communicate with each other and exchange data.
- Source: EU DMA, Article 6(7) (mandatory interoperability requirements); IEEE standard definitions.
- Jurisdiction: EU.

**209. Digital Sovereignty**
- Definition: The capacity of a state to make autonomous decisions in the digital domain and to control critical digital infrastructure, technologies, and data.
- Source: EU *Digital Decade Strategy* (2030 targets); China's *Cybersecurity Law*, Article 1.
- Jurisdiction: EU / China.
- [Comparative Note] The EU emphasizes "technological sovereignty." China emphasizes "cyber sovereignty" and "data sovereignty." The connotations and implementation paths differ. The United States seldom uses the concept of "digital sovereignty," favoring instead a free and open global internet.

**210. Cyber Espionage**
- Definition: The act of secretly obtaining sensitive information from the government, organizations, or individuals of another state through cyber means.
- Source: International law (not expressly prohibited); *Tallinn Manual 2.0*, Rule 4 and commentary; UN GGE 2015 Report.
- Jurisdiction: International.
- [Comparative Note] Cyber espionage occupies a grey zone in international law. Economic cyber espionage (theft of trade secrets for commercial gain) is widely condemned. China and the United States reached an agreement in 2015 not to engage in cyber-enabled theft of intellectual property.

---

---



---

# Appendix IV: Language Key — Source Text Languages & Translation Status

## I. General Principles

This volume (*Global Cyber Law Compendium*, Volume I) covers 47 chapters across the cyber law legislation of more than 30 jurisdictions worldwide. In light of the diversity of source languages among these jurisdictions, translation quality and terminological consistency directly affect the accuracy of legal interpretation. This Appendix systematically records the source language of each major statute, the availability of official English translations, the translation sources adopted in this volume, and any known terminological controversies.

## II. Table of Source Text Languages & Translation Status for Major Legislation

### (A) European Union

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 1 | 通用数据保护条例 | Regulation (EU) 2016/679 (GDPR) | English (and all 24 official EU languages) | Yes — published in the Official Journal (OJ) in all 24 languages; the English version is one of the authoritative texts | OJ L 127/1, 4.5.2016, English version | "Personal data" (GDPR context) and "personal information" (PIPL context) are used interchangeably in Chinese scholarship; this volume uses each jurisdiction's own term |
| 2 | 电子隐私指令 | Directive 2002/58/EC (ePrivacy Directive) | English (same as above) | Yes | OJ L 201/37, 31.7.2002, English version | Chinese translation of "cookie consent" is not uniform; this volume adopts "Cookie同意" |
| 3 | 数字市场法 | Regulation (EU) 2022/1925 (DMA) | English | Yes | OJ L 265/1, 12.10.2022, English version | "Gatekeeper" is rendered as "守门人"; some scholarship uses "看门人"; this volume standardises on "守门人" |
| 4 | 数字服务法 | Regulation (EU) 2022/2065 (DSA) | English | Yes | OJ L 277/1, 27.10.2022, English version | "Very large online platform" (VLOP) is translated as "超大型在线平台" |
| 5 | 人工智能法 | Regulation (EU) 2024/1689 (AI Act) | English | Yes | OJ L, 2024/1689, 12.6.2024, English version | "Foundation model" was replaced with "general-purpose AI model" in the final text; translated as "通用AI模型" |
| 6 | 数字运营韧性法 | Regulation (EU) 2022/2554 (DORA) | English | Yes | OJ L 333/1, 27.12.2022, English version | "ICT third-party service provider" is translated as "ICT第三方服务提供者" |
| 7 | 网络与信息系统安全指令（第二版） | Directive (EU) 2022/2555 (NIS2) | English | Yes | OJ L 333/80, 27.12.2022, English version | "Essential entities" is translated as "基本实体"; "important entities" as "重要实体" |
| 8 | 数据法案 | Regulation (EU) 2023/2854 (Data Act) | English | Yes | OJ L, 2023/2854, English version | "Data holder" is translated as "数据持有者"; conceptual overlap with "data controller" exists |
| 9 | 数字身份框架 | Regulation (EU) 2024/1183 (eIDAS 2.0) | English | Yes | OJ L, 2024/1183, English version | "European Digital Identity Wallet" is translated as "欧洲数字身份钱包" |

### (B) United Kingdom

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 10 | 英国通用数据保护条例 | UK GDPR | English | Yes (original text is in English) | Original text at legislation.gov.uk | Retained post-Brexit version; divergences from the EU GDPR are noted throughout this volume |
| 11 | 数据保护法2018 | Data Protection Act 2018 (DPA 2018) | English | Yes (original text is in English) | Original text at legislation.gov.uk | — |
| 12 | 在线安全法2023 | Online Safety Act 2023 | English | Yes (original text is in English) | Original text at legislation.gov.uk | "User-to-user service" is translated as "用户间服务"; some scholarship uses "用户生成内容服务" |
| 13 | 计算机滥用法1990 | Computer Misuse Act 1990 | English | Yes (original text is in English) | Original text at legislation.gov.uk | "Unauthorised access" is translated as "未授权访问" |

### (C) Switzerland

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 14 | 联邦数据保护法（2023修订） | Bundesgesetz über den Datenschutz (revFADP/DSG) | German (also French and Italian) | Yes — official English translation published by Swiss federal authorities | Official English translation at fedlex.admin.ch | "Data protection authority" maps to the Swiss Federal Data Protection and Information Commissioner (FDPIC), which is not an independent body and differs conceptually from DPAs in other jurisdictions |

### (D) United States

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 15 | 计算机欺诈和滥用法 | Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030 | English | Yes (original text is in English) | Original text at Cornell Law Institute LII | — |
| 16 | 电子通信隐私法 | Electronic Communications Privacy Act (ECPA) | English | Yes (original text is in English) | Original text | "Electronic communication service" is translated as "电子通信服务" |
| 17 | 儿童在线隐私保护法 | Children's Online Privacy Protection Act (COPPA) | English | Yes (original text is in English) | Original text | — |
| 18 | 健康保险流通与责任法案 | Health Insurance Portability and Accountability Act (HIPAA) | English | Yes (original text is in English) | Original text | "Protected Health Information" (PHI) is translated as "受保护健康信息" |
| 19 | 格拉姆-布里奇-利利法案 | Gramm-Leach-Bliley Act (GLBA) | English | Yes (original text is in English) | Original text | "Nonpublic personal information" is translated as "非公开个人信息" |
| 20 | 通信规范法第230条 | Section 230 of the Communications Decency Act (47 U.S.C. § 230) | English | Yes (original text is in English) | Original text | "Interactive computer service" is translated as "交互式计算机服务" |
| 21 | 加州消费者隐私法/加州隐私权利法 | California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) | English | Yes (original text is in English) | Original text | "Sale of personal information" — the scope of "sale" is broader than the ordinary Chinese term "出售", encompassing "exchange for valuable consideration" |
| 22 | 加州在线安全法 | California Age-Appropriate Design Code Act (CAADCA) | English | Yes (original text is in English) | Original text | — |

### (E) China

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 23 | 网络安全法 | 《中华人民共和国网络安全法》 (Cybersecurity Law of the PRC) | Chinese | Yes — official English translation by the NPC | Official English translation at the NPC website | "Network operator" is translated as "网络运营者"; distinct from "operator of essential services" under NIS2 |
| 24 | 数据安全法 | 《中华人民共和国数据安全法》 (Data Security Law of the PRC) | Chinese | Yes — official English translation by the NPC | Official English translation at the NPC website | "Important data" is translated as "重要数据"; a China-specific concept distinct from "special categories of data" under the GDPR |
| 25 | 个人信息保护法 | 《中华人民共和国个人信息保护法》 (PIPL) | Chinese | Yes — official English translation by the NPC | Official English translation at the NPC website | See the dedicated terminological discussion below |
| 26 | 网络数据安全管理条例 | 《网络数据安全管理条例》 (Regulations on the Security Management of Network Data) | Chinese | No (no official English translation) | Self-translated by this volume with reference to scholar translations (Shang Jiangang et al.) | "Network data" is translated as "网络数据"; this is at the administrative regulation level |
| 27 | 生成式人工智能服务管理暂行办法 | 《生成式人工智能服务管理暂行办法》 (Interim Measures for the Management of Generative Artificial Intelligence Services) | Chinese | No (no official English translation) | Self-translated by this volume with reference to CAC English press releases | "Generative AI service" translation is consistent; "暂行办法" is translated as "Interim Measures" |
| 28 | 数据出境安全评估办法 | 《数据出境安全评估办法》 (Measures for the Security Assessment of Data Export) | Chinese | No (no official English translation) | Self-translated by this volume | "Data export" is translated as "数据出境"; terminological difference exists with "cross-border data transfer" |
| 29 | 个人信息出境标准合同办法 | 《个人信息出境标准合同办法》 (Measures for the Standard Contract for the Export of Personal Information) | Chinese | No (no official English translation) | Self-translated by this volume | Functionally corresponds to the SCCs under the GDPR, but at a different level of legal force |
| 30 | 关键信息基础设施安全保护条例 | 《关键信息基础设施安全保护条例》 (Regulations on the Security and Protection of Critical Information Infrastructure) | Chinese | No (no official English translation) | Self-translated by this volume | "Critical Information Infrastructure" (CII) translation is broadly consistent |

### (F) Japan

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 31 | 个人信息保护法 | 個人情報保護法 (Act on the Protection of Personal Information, APPI) | Japanese | Yes — official English translation by the PPC | Official English translation by the Personal Information Protection Commission (PPC) | "個人情報" is translated as "Personal Information", consistent with PIPL and distinct from "personal data" under the GDPR |

### (G) South Korea

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 32 | 个人信息保护法 | 개인정보 보호법 (Personal Information Protection Act, PIPA) | Korean | Yes — official English translation by the PIPC | Official English translation by the Personal Information Protection Commission (PIPC) | "개인정보" corresponds to "Personal Information" |

### (H) Singapore

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 33 | 个人数据保护法 | Personal Data Protection Act 2012 (PDPA) | English | Yes (original text is in English) | Original text at PDPC website | — |

### (I) India

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 34 | 数字个人数据保护法 | Digital Personal Data Protection Act 2023 (DPDPA) | English | Yes (original text is in English) | Original text at MeitY website | "Data Fiduciary" is translated as "数据受托人"; "Data Principal" as "数据委托人"; a distinctive Indian law terminological framework |

### (J) Australia

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 35 | 隐私法1988 | Privacy Act 1988 | English | Yes (original text is in English) | Original text at the Federal Register of Legislation | "APP entity" is translated as "APP实体", denoting an entity subject to the Australian Privacy Principles |

### (K) Brazil

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 36 | 通用数据保护法（巴西） | Lei Geral de Proteção de Dados (LGPD) | Portuguese | No (no official English translation) | This volume adopts the unofficial English translation by Privacidade & Dados, cross-checked | "Titular" is translated as "数据主体" (data subject), corresponding to "data subject" under the GDPR; "Controlador" corresponds to "controller" |

### (L) Argentina

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 37 | 个人数据保护法 | Ley de Protección de Datos Personales (LPDP, Ley 25.326) | Spanish | No (no official English translation) | This volume adopts the English translation by the AAIP (non-official but authoritative) | "Datos personales" corresponds to "personal data" |

### (M) South Africa

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 38 | 个人信息保护法 | Protection of Personal Information Act 4 of 2013 (POPIA) | English | Yes (original text is in English) | Original text at the Information Regulator website | "Responsible party" is translated as "责任方", corresponding to "controller" under the GDPR |

### (N) Russia

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 39 | 个人数据法 | Федеральный закон № 152-ФЗ (Federal Law No. 152-FZ) | Russian | No (no official English translation) | This volume adopts the English translation from the Garant database, cross-checked | "Оператор" is translated as "operator", corresponding to "controller" under the GDPR rather than "processor" |
| 40 | 主权互联网法 | Федеральный закон № 90-ФЗ (Federal Law No. 90-FZ) | Russian | No (no official English translation) | Self-translated by this volume with reference to third-party English translations (Meduza / Recontext) | "Устойчивый интернет" is translated as "stable Internet" or "sovereign Internet"; the latter is more commonly used |

### (O) Canada

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 41 | 个人信息保护与电子文件法 | Personal Information Protection and Electronic Documents Act (PIPEDA) | English / French | Yes (both official languages) | Original text at the Justice Laws Website | — |

### (P) International Treaties & Frameworks

| No. | Statute Name (Chinese) | Statute Name (Original/English) | Source Language | Official English Translation Available? | Translation Source Adopted in This Volume | Terminological Notes |
|-----|------------------------|--------------------------------|-----------------|----------------------------------------|-------------------------------------------|----------------------|
| 42 | 网络犯罪公约（布达佩斯公约） | Convention on Cybercrime (Budapest Convention), ETS No. 185 | English / French | Yes (both languages are authoritative) | Original text at the Council of Europe | "Service provider" is translated as "服务提供者" |
| 43 | 个人数据自动化处理个人保护公约（108+公约） | Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108+) | English / French | Yes | Original text at the Council of Europe | "Data subject" is translated as "数据主体" |
| 44 | 非洲联盟网络安全与个人数据保护公约（马拉博公约） | African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) | English / French | Yes | Original text at the AU | Few signatories; implementation progress is limited |
| 45 | APEC跨境隐私规则 | APEC Cross-Border Privacy Rules (CBPR) | English | Yes (original text is in English) | Original text at the APEC website | "Accountable person" is translated as "问责人"; partially overlaps with but is not identical to the "accountability" concept under the GDPR |
| 46 | 全球跨境隐私规则 | Global Cross-Border Privacy Rules (Global CBPR) | English | Yes (original text is in English) | Original text at the GBF website | An expanded version of the APEC CBPR |
| 47 | 海牙公约选择法院协议 | Hague Convention on Choice of Court Agreements (2005) | English / French | Yes | Original text at the Hague Conference on Private International Law | Cross-referenced with respect to data jurisdiction |

## III. Notes on Core Terminology Translation Controversies

### (A) "Personal Data" vs. "Personal Information"

| Jurisdiction | Original Term | Translation Adopted in This Volume | Notes |
|-------------|---------------|------------------------------------|-------|
| EU (GDPR) | Personal data | 个人数据 | Defined in Article 4(1) GDPR as any information relating to an identified or identifiable natural person |
| UK (UK GDPR) | Personal data | 个人数据 | Retains the EU GDPR definition |
| Switzerland (FADP) | Personendaten / Personal data | 个人数据 | Swiss law uses "personal data", consistent with the GDPR |
| China (PIPL) | 个人信息 | 个人信息 | Defined in Article 4 PIPL; substantively similar to the GDPR but uses a different term |
| China (Data Security Law) | 数据 | 数据 | A broader concept, not limited to personal data |
| USA (CCPA) | Personal information | 个人信息 | The CCPA definition covers information that identifies a consumer or household; scope differs from the GDPR |
| Japan (APPI) | 個人情報 (Personal Information) | 个人信息 | Consistent with PIPL terminology |
| South Korea (PIPA) | 개인정보 (Personal Information) | 个人信息 | Consistent with PIPL terminology |
| Brazil (LGPD) | Dado pessoal (Personal data) | 个人数据 | Consistent with GDPR terminology |
| India (DPDPA) | Personal data | 个人数据 | Consistent with GDPR terminology |

**Core controversy:** The GDPR regime uses "personal data", whereas the China–Japan–South Korea–United States regime uses "personal information" / "个人信息". The two terms have substantively similar but not identical definitions within their respective jurisdictions. This volume uses each jurisdiction's own term when discussing that jurisdiction, and uses the combined form "个人数据/个人信息" (personal data / personal information) when engaging in cross-jurisdictional comparison.

### (B) "Data Controller" vs. "Data Processor"

| Jurisdiction | Original Controller Term | Controller Translation | Original Processor Term | Processor Translation |
|-------------|--------------------------|------------------------|-------------------------|-----------------------|
| EU (GDPR) | Controller | 控制者 | Processor | 处理者 |
| UK (UK GDPR) | Controller | 控制者 | Processor | 处理者 |
| China (PIPL) | 个人信息处理者 | 个人信息处理者 (Personal Information Handler) | 受托人 | 受托人 (Entrusted Person) |
| Japan (APPI) | 事業者 (Business operator) | 事业者 | 委託先 (Trustee) | 受托方 |
| South Korea (PIPA) | 개인정보처리자 | 个人信息处理者 | 위탁받은 자 | 受托人 |
| Brazil (LGPD) | Controlador | 控制者 | Operador | 操作者 |
| India (DPDPA) | Data Fiduciary | 数据受托人 | Data Processor | 数据处理者 |
| South Africa (POPIA) | Responsible party | 责任方 | Operator | 操作者 |

**Core controversy:** The PIPL does not directly adopt the controller/processor dichotomy; instead it constructs the processing relationship using "个人信息处理者" (Personal Information Handler, encompassing controller-like functions) and "受托人" (Entrusted Person, corresponding to processor). India's DPDPA introduces a fiduciary law framework, employing "Data Fiduciary / Data Principal", which differs fundamentally from the terminological frameworks of other jurisdictions. When engaging in cross-jurisdictional comparison, this volume consistently annotates the correspondences while preserving each jurisdiction's native terminology.

### (C) "Data Protection Officer" (DPO)

| Jurisdiction | Original Term | Translation Adopted in This Volume | Notes |
|-------------|---------------|------------------------------------|-------|
| EU (GDPR) | Data Protection Officer (DPO) | 数据保护官 | Articles 37–39 GDPR |
| UK (UK GDPR) | Data Protection Officer (DPO) | 数据保护官 | Retains the EU GDPR framework |
| China (PIPL) | 个人信息保护负责人 | 个人信息保护负责人 (Person in Charge of Personal Information Protection) | Article 52 PIPL; duties are similar to a DPO but with different appointment thresholds |
| Japan (APPI) | 個人情報保護管理者 | 个人信息保护管理者 (Personal Information Protection Manager) | Required under the amended APPI; differs from the DPO |
| South Korea (PIPA) | 개인정보보호책임자 | 个人信息保护负责人 | Similar to the PRC terminology |

**Core controversy:** DPO regimes across jurisdictions differ with respect to the conditions for appointment, the scope of responsibilities, and safeguards for independence. The PIPL's "个人信息保护负责人" (Person in Charge of Personal Information Protection) conceptually corresponds to a DPO, but differs in terms of appointment thresholds and the allocation of legal liability. This volume uses "数据保护官 (DPO)" as a generic concept and uses each jurisdiction's own term when discussing that specific jurisdiction.

### (D) "Adequacy Decision"

| Jurisdiction | Original Term | Translation Adopted in This Volume | Notes |
|-------------|---------------|------------------------------------|-------|
| EU (GDPR) | Adequacy decision | 充分性认定 | Article 45 GDPR |
| UK | Adequacy regulations | 充分性法规 | The UK makes adequacy determinations through independent regulations |
| Switzerland | Angemessenheitsbeschluss / Adequacy decision | 充分性认定 | Corresponds to the EU system |
| China (PIPL) | 认可 | 认可 (Recognition) | Article 38 PIPL uses "认可"; narrower in scope than "adequacy", applying only to specific countries / regions |

**Core controversy:** The EU's "adequacy decision" is an adequacy finding regarding the level of data protection in a third country, whereas the "认可" (Recognition) mechanism under Article 38 PIPL for cross-border transfers is functionally similar but differs in procedure and standards. This volume uses "认可" when discussing Chinese law and "充分性认定" when discussing EU law, and annotates the functional correspondence between the two in comparative law discussions.

### (E) "Standard Contractual Clauses" (SCCs)

| Jurisdiction | Original Term | Translation Adopted in This Volume | Notes |
|-------------|---------------|------------------------------------|-------|
| EU (GDPR) | Standard Contractual Clauses (SCCs) | 标准合同条款 | Multiple sets of SCCs issued by the European Commission |
| China (PIPL) | 标准合同 | 标准合同 (Standard Contract) | Article 38 PIPL; the Standard Contract for the Export of Personal Information issued by the CAC |
| UK | International Data Transfer Agreement (IDTA) | 国际数据传输协议 | Independently developed by the UK post-Brexit |
| Switzerland | Binding Corporate Rules / Standard Contractual Clauses | 标准合同条款 | The Swiss FDPIC recognises EU SCCs and has issued a national version |

**Core controversy:** The PIPL's "标准合同" (Standard Contract) functionally corresponds to the EU SCCs but differs in terms of legal force (departmental rules vs. Commission decision) and conditions of application (requiring a security assessment or certification vs. standalone application). The UK replaced the EU SCCs with the IDTA post-Brexit, adding a "Transfer Risk Assessment" requirement. This volume uses each jurisdiction's own terminology when discussing that specific jurisdiction.

### (F) Other Significant Terminological Controversies

| Contested Term | Notes |
|---------------|-------|
| "Data localisation" / "数据本地化" | Chinese law uses "境内存储" (domestic storage); Russian law uses "первоначальная запись" (initial recording); the concepts are similar but differ in scope |
| "Cross-border data transfer" / "数据出境" | Chinese law uses "数据出境" (data export), emphasising the act of data leaving national borders; the GDPR uses "cross-border transfer", emphasising transfer between controllers |
| "Lawful basis" / "合法事由" | Article 6 GDPR uses "lawful basis"; Article 13 PIPL uses "合法事由" (lawful grounds); the enumerated circumstances are not fully aligned |
| "Special categories of data" / "敏感个人信息" | Article 9 GDPR "special categories of data" covers race, religious belief, etc.; Article 28 PIPL "敏感个人信息" (sensitive personal information) covers biometric data, religious belief, medical health, financial accounts, etc.; the scope is not fully overlapping |
| "Pseudonymisation" / "假名化" | The GDPR uses "pseudonymisation"; Chinese law has no directly equivalent concept; some scholarship translates it as "去标识化", but this is conflated with "de-identification" |
| "De-identification" / "去标识化" | The CCPA / CPRA uses "de-identification"; the PIPL does not directly use this concept, but the Data Security Law and related standards reference it |

## IV. Translation Methodology Notes

### (A) Translation Principles

1. **Fidelity to the original text:** Based on the official texts of each jurisdiction, with priority given to official English translations (where available).
2. **Terminological consistency:** A single concept within the same jurisdiction is rendered using a single translation; when engaging in cross-jurisdictional comparison, terminological correspondences are annotated.
3. **Functional equivalence:** Where no exact terminological equivalent exists, a functionally equivalent translation is employed and the differences are explained in annotations.
4. **Awareness of the hierarchy of legal force:** A distinction is drawn among statutes (法律), administrative regulations (法规), departmental rules (部门规章), technical standards (技术标准), and other levels, with the level annotated in the translation.

### (B) Treatment of Legislation Without an Official English Translation

For Chinese administrative regulations and departmental rules (such as the *Regulations on the Security Management of Network Data* and the *Measures for the Security Assessment of Data Export*) as well as legislation from Russia, Brazil, Argentina, and other countries, this volume adopts the following approach:

1. Reference to authoritative scholarly translations (e.g., translations by Shang Jiangang, Gao Fuping, and other scholars)
2. Cross-comparison of multiple translation versions
3. Independent translation by the volume's editorial team, reviewed by legal experts
4. Annotation as "Self-translated by this volume" in the table above

### (C) Effective Date of Versions

The translation status of the legislation listed in this Appendix is current as of 1 March 2025. For legislation amended after this date, the translation status may have changed, and readers should refer to the latest official texts.

---

*Appendix V: Jurisdictional Index follows.*


---

# Appendix V: Index of Laws by Jurisdiction

## I. Alphabetical Index by Jurisdiction

| No. | Jurisdiction | Primary Laws (with year of enactment) | Regulatory Authority | Chapter Reference |
|-----|-------------|--------------------------------------|---------------------|-------------------|
| 1 | Argentina | LPDP (Ley 25.326, 2000); LPDP Amendments (Ley 27.551, 2020) | National Agency for Access to Public Information (AAIP) | Ch. 31 |
| 2 | Australia | Privacy Act 1988; Online Safety Act 2021; Spam Act 2003 | Office of the Australian Information Commissioner (OAIC); eSafety Commissioner | Ch. 28 |
| 3 | Brazil | LGPD (Lei 13.709/2018); Brazilian Internet Civil Rights Framework (Marco Civil da Internet, Lei 12.965/2014) | National Data Protection Authority (ANPD) | Ch. 33 |
| 4 | Canada | PIPEDA (2000); Personal Information Protection Act (BC, AB, QC); Cyber Security Act 2014 | Office of the Privacy Commissioner (OPC); Provincial Privacy Commissioners | Ch. 27 |
| 5 | China (PRC) | Cybersecurity Law (2016); Data Security Law (2021); PIPL (2021); Regulations on the Administration of Network Data Security (2024); Interim Measures on Generative AI (2023) | Cyberspace Administration of China (CAC); Ministry of Industry and Information Technology (MIIT); Ministry of Public Security (MPS) | Ch. 18–22 |
| 6 | European Union | GDPR (2016); ePrivacy Directive (2002); DMA (2022); DSA (2022); AI Act (2024); DORA (2022); NIS2 (2022); Data Act (2023); eIDAS 2.0 (2024) | European Data Protection Board (EDPB); European Data Protection Supervisor (EDPS); European Commission; Digital Services Coordinators (DSC) | Ch. 1–9 |
| 7 | India | DPDPA (2023); IT Act 2000 (Section 43A and SPD Rules 2011); Digital India Act (draft) | Ministry of Electronics and Information Technology (MeitY); Data Protection Board of India (DPB, established under DPDPA) | Ch. 30 |
| 8 | Japan | APPI (2003, amended 2022); APPI Enforcement Order; Telecommunications Business Act | Personal Information Protection Commission (PPC) | Ch. 24 |
| 9 | South Korea | PIPA (2011, amended 2023); Act on Promotion of Information and Communications Network Utilization (Network Act); Credit Information Act | Personal Information Protection Commission (PIPC); Korea Communications Commission (KCC) | Ch. 25 |
| 10 | New Zealand | Privacy Act 2020; Harmful Digital Communications Act 2015 | Office of the Privacy Commissioner (OPC) | Ch. 29 |
| 11 | Russia | 152-FZ (2006, repeatedly amended); Sovereign Internet Law (2019); Law on Information (149-FZ) | Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor) | Ch. 34 |
| 12 | Singapore | PDPA (2012); Cybersecurity Act 2018; Electronic Transactions Act 2010 | Personal Data Protection Commission (PDPC); Cyber Security Agency (CSA) | Ch. 26 |
| 13 | South Africa | POPIA (Act 4 of 2013); Cybercrimes Act 2020; ECT Act 2002 | Information Regulator | Ch. 35 |
| 14 | Switzerland | FADP (revDSG, amended 2023); Telecom Surveillance Act (BÜPF) | Federal Data Protection and Information Commissioner (FDPIC) | Ch. 17 |
| 15 | Türkiye | KVKK (Law No. 6698, 2016); Law on Regulation of Electronic Commerce | Personal Data Protection Authority (KVKK) | Ch. 43 |
| 16 | United Kingdom | UK GDPR; DPA 2018; Online Safety Act 2023; Computer Misuse Act 1990; PECR | Information Commissioner's Office (ICO); Office of Communications (Ofcom) | Ch. 10–12 |
| 17 | United States | CFAA (1986); ECPA (1986); COPPA (1998); HIPAA (1996); GLBA (1999); Section 230 (1996); CCPA (2018) / CPRA (2020) | Federal Trade Commission (FTC); HHS Office for Civil Rights (OCR); State Attorneys General (AG) | Ch. 13–16 |

### Supplementary Jurisdictions

| No. | Jurisdiction | Primary Laws (with year of enactment) | Regulatory Authority | Chapter Reference |
|-----|-------------|--------------------------------------|---------------------|-------------------|
| 18 | UAE | Federal Decree-Law No. 45 of 2021 (PDPL); Cybercrime Law (Federal Decree-Law No. 34/2021) | UAE Data Office | Ch. 41 |
| 19 | Indonesia | PDP Law (Law No. 27/2022); Electronic Information and Transactions Law (ITE Law) | Ministry of Communications and Informatics (Kominfo) | Ch. 36 |
| 20 | Mexico | Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP, 2010); Federal Data Protection Law for the Public Sector | National Institute for Transparency, Access to Information and Personal Data Protection (INAI) | Ch. 44 |
| 21 | Saudi Arabia | Personal Data Protection Law (PDPL, 2021 / amended 2023); Anti-Cyber Crime Law | Saudi Data and Artificial Intelligence Authority (SDAIA) | Ch. 42 |
| 22 | Thailand | PDPA (2019, effective 2022); Cybersecurity Act 2019 | Office of the Personal Data Protection Committee (PDPC Office); National Cyber Security Committee (NCSC) | Ch. 38 |
| 23 | Philippines | Data Privacy Act 2012 (RA 10173); Cybercrime Prevention Act 2012 | National Privacy Commission (NPC) | Ch. 39 |
| 24 | Vietnam | PDPD (Decree 13/2023); Cybersecurity Law 2018 | Ministry of Public Security; Ministry of Information and Communications | Ch. 37 |
| 25 | Israel | Protection of Privacy Law 1981 (amended 2021); Protection of Privacy Regulations | Privacy Protection Authority (PPA) | Ch. 40 |

## II. Index by Region

### (A) Europe

| Jurisdiction | Primary Laws | Regulatory Authority | Chapter |
|-------------|-------------|---------------------|---------|
| European Union | GDPR; ePrivacy Directive; DMA; DSA; AI Act; DORA; NIS2; Data Act; eIDAS 2.0 | EDPB; EDPS; European Commission; DSC | Ch. 1–9 |
| United Kingdom | UK GDPR; DPA 2018; Online Safety Act 2023; Computer Misuse Act 1990 | ICO; Ofcom | Ch. 10–12 |
| Switzerland | FADP (amended 2023); BÜPF | FDPIC | Ch. 17 |
| Russia | 152-FZ; Sovereign Internet Law; 149-FZ Law on Information | Roskomnadzor | Ch. 34 |
| Türkiye | KVKK (2016); E-Commerce Law | KVKK Authority | Ch. 43 |

### (B) Americas

| Jurisdiction | Primary Laws | Regulatory Authority | Chapter |
|-------------|-------------|---------------------|---------|
| United States | CFAA; ECPA; COPPA; HIPAA; GLBA; Section 230; CCPA/CPRA | FTC; OCR; State AGs | Ch. 13–16 |
| Canada | PIPEDA; Provincial privacy laws; Cyber Security Act | OPC; Provincial Privacy Commissioners | Ch. 27 |
| Brazil | LGPD; Marco Civil da Internet | ANPD | Ch. 33 |
| Argentina | LPDP (Ley 25.326); Amendments (Ley 27.551) | AAIP | Ch. 31 |
| Mexico | LFPDPPP (2010); Public Sector Data Protection Law | INAI | Ch. 44 |

### (C) Asia-Pacific

| Jurisdiction | Primary Laws | Regulatory Authority | Chapter |
|-------------|-------------|---------------------|---------|
| China | Cybersecurity Law; Data Security Law; PIPL; Regulations on the Administration of Network Data Security; Interim Measures on Generative AI | CAC; MIIT; MPS | Ch. 18–22 |
| Japan | APPI (2003 / amended 2022); Telecommunications Business Act | PPC | Ch. 24 |
| South Korea | PIPA; Network Act; Credit Information Act | PIPC; KCC | Ch. 25 |
| Singapore | PDPA (2012); Cybersecurity Act; Electronic Transactions Act | PDPC; CSA | Ch. 26 |
| India | DPDPA (2023); IT Act; Digital India Act (draft) | MeitY; DPB | Ch. 30 |
| Australia | Privacy Act 1988; Online Safety Act 2021; Spam Act 2003 | OAIC; eSafety Commissioner | Ch. 28 |
| New Zealand | Privacy Act 2020; Harmful Digital Communications Act 2015 | OPC | Ch. 29 |
| Indonesia | PDP Law (2022); ITE Law | Kominfo | Ch. 36 |
| Vietnam | PDPD (Decree 13/2023); Cybersecurity Law | Ministry of Public Security; Ministry of Information and Communications | Ch. 37 |
| Thailand | PDPA (2019); Cybersecurity Act | PDPC Office; NCSC | Ch. 38 |
| Philippines | Data Privacy Act 2012; Cybercrime Prevention Act | NPC | Ch. 39 |

### (D) Middle East & Africa

| Jurisdiction | Primary Laws | Regulatory Authority | Chapter |
|-------------|-------------|---------------------|---------|
| South Africa | POPIA (2013); Cybercrimes Act 2020; ECT Act | Information Regulator | Ch. 35 |
| Israel | Protection of Privacy Law 1981 (amended 2021) | PPA | Ch. 40 |
| UAE | PDPL (2021); Cybercrime Law (2021) | UAE Data Office | Ch. 41 |
| Saudi Arabia | PDPL (2021/2023); Anti-Cyber Crime Law | SDAIA | Ch. 42 |

### (E) International Treaties & Multilateral Frameworks

| Treaty / Framework | Full Name | Administrative Body | Chapter Reference |
|-------------------|-----------|-------------------|-------------------|
| Budapest Convention | Convention on Cybercrime (ETS No. 185) | Council of Europe | Ch. 45 |
| Convention 108+ | Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108+) | Council of Europe | Ch. 46 |
| Malabo Convention | African Union Convention on Cyber Security and Personal Data Protection | African Union (AU) | Ch. 47 |
| APEC CBPR | APEC Cross-Border Privacy Rules | APEC | Ch. 45 (International Frameworks section) |
| Global CBPR | Global Cross-Border Privacy Rules | Global CBPR Forum (GBF) | Ch. 45 (International Frameworks section) |
| Hague Choice of Court Convention | Hague Convention on Choice of Court Agreements (2005) | Hague Conference on Private International Law (HCCH) | Ch. 46 (Jurisdiction section) |

## III. Usage Instructions

1. **Chapter mapping:** Chapter numbers in this index correspond to the chapter numbers in the main body of this Volume (Volume I). Certain jurisdictions span multiple chapters due to extensive coverage (e.g., the European Union occupies Chapters 1–9, China occupies Chapters 18–22, and the United States occupies Chapters 13–16). Jurisdictions covered in a single chapter are indicated by a single chapter number.

2. **Scope of listed laws:** The "Primary Laws" column lists only the most central cyber-law-related legislation of each jurisdiction and is not exhaustive. Administrative regulations, implementing rules, and technical standards are discussed in detail within the corresponding chapters.

3. **Regulatory authority abbreviations:** Regulatory authority names are provided with their full English names on first occurrence, after which common abbreviations may be used. A complete abbreviation cross-reference table is provided in Appendix II.

4. **Laws with multi-jurisdictional effect:** For laws that have effect in multiple jurisdictions (e.g., GDPR as extended to third countries via adequacy decisions), this index lists them only under the originating legislative jurisdiction, while their extraterritorial effect is discussed in the main text.

5. **Currency:** This index reflects the state of law as of March 1, 2025. For subsequent legislative updates, please refer to the revision log in Appendix III.

---

# Appendix VI: Other Commonwealth of Independent States (CIS) Jurisdictions — Data Protection Law (Summary)

---
## Glossary of Key Terms
| English | Chinese (Recommended) | Russian | Notes |
| Personal Data / Personal Information | 个人数据 / 个人信息 | Персональные данные | CIS laws predominantly use "персональные данные" (literal: personal data); China's legal system uses the corresponding "个人信息" (PIPL) and "个人数据" (DSPA) |
| Data Subject | 数据主体 | Субъект персональных данных | CIS legal term for the data owner / information subject |
| Data Operator / Data Controller | 数据运营者 / 数据控制者 | Оператор персональных данных | Kazakhstan and Belarus both use "оператор" (operator) |
| Data Processing | 数据处理 | Обработка персональных данных | |
| Consent | 同意 | Согласие | |
| Data Localization | 数据本地化 | Локализация данных / Требования о хранении данных на территории | Also referred to as "data residency requirements" |
| Cross-border Transfer | 跨境传输 | Трансграничная передача данных | |
| Registration Requirement | 登记要求 | Требование о регистрации | |
| Regulatory Authority | 监管机构 | Уполномоченный орган | |
| Adequate Protection | 充分保护 | Достаточная защита | |
| Special Categories of Data | 特殊类别数据 | Специальные категории данных | Corresponds to the GDPR concept of "special categories of data" |
| Administrative Fine | 行政罚款 | Административный штраф | |
| Code of Administrative Offences | 行政违法法典 | Кодекс об административных правонарушениях | |
| Criminal Code | 刑法典 | Уголовный кодекс | |
| Public Interest | 公共利益 | Общественный интерес / Публичный интерес | |
| National Security | 国家安全 | Национальная безопасность | |
| Contractual Necessity | 合同必要性 | Договорная необходимость | |
| State Inspectorate | 国家监察局 | Государственная инспекция | |
| Operational and Analytical Center (OAC) | 运营分析中心 | Оперативно-аналитический центр (ОАЦ) | Belarus-specific institutional abbreviation |

---
## VI.1 Kazakhstan — Law on Personal Data and Its Protection

**Full Russian Title:** Закон Республики Казахстан «О персональных данных и их защите»

**Enacted:** 21 May 2013 | **Effective:** 21 November 2013 | **Latest Amendments:** 2021–2022 (data localization provisions)

**Supervisory Authority:** Ministry of Digital Development, Innovation and Aerospace Industry (Министерство цифрового развития, инноваций и аэрокосмической промышленности)

### Original Text Cross-Reference
### Refined English Translation

Kazakhstan's Law on Personal Data and Its Protection (Republic of Kazakhstan Code «О персональных данных и их защите») was enacted on 21 May 2013 and entered into force on 21 November 2013. The law establishes Kazakhstan's personal data protection framework, with enforcement administered by the Ministry of Digital Development, Innovation and Aerospace Industry.

---
### VI.1.1 Core Elements of the Legal Framework

| Element | Original Text | English Translation | Russian Equivalent |
| Consent Framework | Consent-based framework | **Consent-based framework**: Processing requires, in principle, the data subject's consent | Согласие на обработку |
| Statutory Exceptions | Legal obligations, public interest, contractual necessity | **Statutory exceptions**: legal obligations, public interest, and contractual necessity | Законные обязательства, общественный интерес, договорная необходимость |
| Data Subject Rights | Access, correction, deletion, objection | **Data subject rights**: rights of access, correction, deletion, and objection; data subjects also have the right to be informed about the processing of their personal data | Доступ, исправление, удаление, возражение |
| Data Localization | Data localization (2021–2022) | **Data localization requirements** (introduced 2021–2022): personal data of Kazakhstani citizens must be stored on servers located within Kazakhstan, or on servers in countries/regions recognized by the authorized body as providing adequate data protection | Локализация данных / хранение на территории РК |
| Cross-border Transfers | Cross-border transfers | **Cross-border transfers**: permitted where the destination country provides adequate protection, the data subject consents, or the transfer is necessary for the performance of a contract | Трансграничная передача данных |
| Registration Requirement | Registration requirement | **Registration requirement**: data operators must register their data processing activities with the authorized body | Регистрация в уполномоченном органе |
| Regulatory Authority | Regulatory authority | **Regulatory authority**: the Ministry of Digital Development, Innovation and Aerospace Industry serves as the primary regulatory authority; the Committee on Legal Statistics and Special Accounts under the Prosecutor General's Office oversees criminal enforcement. Kazakhstan currently has **no dedicated independent data protection authority** | Министерство цифрового развития / Комитет правовой статистики |
| Penalties | Penalties | **Penalties**: violations are subject to administrative fines under the Code of Administrative Offences; in specific circumstances, criminal liability for unlawful processing of personal data may be imposed under the Criminal Code | Административные штрафы / Уголовная ответственность |

---
### VI.1.2 Digitalization Strategy and Modernization

**"Digital Kazakhstan" Program | Digital Kazakhstan Program**

**Refined English Translation:**

The "Digital Kazakhstan" national program, as part of Kazakhstan's broader digital transformation strategy, emphasizes the development of data governance infrastructure, including the construction of government data-sharing platforms and the promotion of data-driven innovation.

**Modernization Efforts**

**Refined English Translation:**

Kazakhstan is considering amendments to its personal data legislation to align with evolving international standards. Areas of reform include strengthened data breach notification provisions, rules on automated decision-making, and the establishment of a more independent data protection authority.

---
## VI.2 Belarus — Law on Personal Data Protection

> ⚠️ **Date Correction:** The original English text noted "Law on Personal Data Protection (2021, effective 2022)," but the law was initially enacted in 2008 (effective 2009); 2021 was the year of its amendments.

**Full Russian Title:** Закон Республики Беларусь «О защите персональных данных» (2008 version; as amended in 2021)

**Original Enactment:** 10 November 2008 | **Original Effective Date:** 15 March 2009 | **2021 Amendments Effective:** 2022

**Supervisory Authority:** Operational and Analytical Center under the Administration of the President of the Republic of Belarus (OAC)

### Original Text Cross-Reference
### Refined English Translation

Belarus's Law on Personal Data Protection (Закон Республики Беларусь «О защите персональных данных») was enacted on 10 November 2008 and entered into force on 15 March 2009; the law was amended in 2021, with the amended version taking effect in 2022. Key features are as follows:

---
### VI.2.1 Core Elements of the Legal Framework

| Element | Original Text | English Translation | Russian Equivalent |
| Consent Framework | Consent-based framework | **Consent-based framework**: processing requires, in principle, the data subject's consent, with exceptions including legal obligations, national security, public health, and statistical purposes | Согласие / законные основания для обработки |
| Data Subject Rights | Access, correction, deletion | **Data subject rights**: rights of access, correction, and deletion | Доступ, исправление, удаление |
| Special Categories of Data | Special categories | **Special categories of data**: **enhanced protection** is afforded to data concerning health, racial or ethnic origin, political opinions, religious beliefs, and sexual life | Специальные категории данных |
| Data Localization | Data localization | **Data localization**: particularly for government data and specified sensitive industry sectors; requirements have been further strengthened in recent years through amendments to the law and related regulations | Локализация / хранение на территории Беларуси |
| Cross-border Transfers | Cross-border transfers | **Cross-border transfers**: permitted where the destination country provides adequate protection, the data subject consents, or the transfer is necessary for the performance of a legal obligation | Трансграничная передача |
| Registration Requirement | Registration requirement | **Registration requirement**: data operators must register their databases containing personal data with the Operational and Analytical Center under the Administration of the President of the Republic of Belarus | Регистрация баз данных в ОАЦ |
| Regulatory Authority | Regulatory authority | **Regulatory authority**: the Operational and Analytical Center (OAC) under the Presidential Administration is the principal body responsible for supervising data protection compliance; the Ministry of Communications and Informatization and the State Inspectorate for Personal Data Protection also participate in enforcement. **Belarus does not have a fully independent personal data protection authority** | ОАЦ / Министерство связи / Государственная инспекция |
| Penalties | Penalties | **Penalties**: administrative fines are imposed under the Code of Administrative Offences of the Republic of Belarus; criminal liability may be pursued under the Criminal Code for unlawful collection and dissemination of personal data, including the offence of unlawful use of computer information, punishable by **up to 3 years' imprisonment** | Административные штрафы / Уголовная ответственность (до 3 лет лишения свободы) |

---
### VI.2.2 Political Context and International Isolation

**English Original**

**Refined English Translation:**

Belarus's data protection framework operates within an environment of pervasive government surveillance and restricted internet freedom. The government retains broad powers to access and monitor electronic communications under national security legislation, substantially limiting the practical effectiveness of data protection rights.

---
> Following the political crisis of 2020 and the Russian invasion of Ukraine in 2022, Belarus has been increasingly isolated from international data governance frameworks, limiting opportunities for regulatory cooperation and the development of cross-border data transfer mechanisms.

**Refined English Translation:**

Following the political crisis of 2020 and the Russian invasion of Ukraine in 2022, Belarus has become increasingly isolated from international data governance frameworks, constraining opportunities for regulatory cooperation and the development of cross-border data transfer mechanisms.

---
## VI.3 Uzbekistan — Law on Personal Data (2019)

**Uzbek:** Shaxsiy ma'lumotlar to'g'risida Qonun | **Russian Equivalent:** Закон о персональных данных

**Regulatory Authority:** Agentlik of Information and Mass Communications / Агентство информации и массовых коммуникаций (Agency of Information and Mass Communications)

### Refined English Translation

Uzbekistan's Law on Personal Data, enacted in 2019, constitutes the foundational legislation for personal data protection in the country.

| Element | Content | Notes |
| Legal Framework | **Consent-based framework**: the collection and processing of personal data require the data subject's explicit consent | Consent is the primary legal basis |
| Registration Requirement | **Mandatory registration**: data operators must register their data processing activities with the **Agency of Information and Mass Communications** (Agentlik of Information and Mass Communications) | This is a distinctive feature of Uzbekistan's data protection regime |
| Data Subject Rights | Rights of access, correction, and deletion | Basic rights framework |
| Penalties | Administrative fines; criminal liability may be pursued for serious violations | Pursuant to Uzbekistan's administrative and criminal law |
| Cross-border Transfers | Subject to conditions such as adequate protection in the destination country or data subject consent | Similar to other CIS countries |
| Full Text | Available in Uzbek and Russian (official translation) | For professional legal translation, reference to the official text of the Ministry of Justice of Uzbekistan is recommended |

> **Note:** The content in this section is compiled from the English original table of contents summary and publicly available sources. A complete Chinese translation of Uzbekistan's Law on Personal Data requires the work of a professional legal translator qualified in the Uzbek language.

---
## VI.4 Kyrgyzstan — Law on Personal Data (2023)

**Kyrgyz:** Жеке маалымат жөнүндө Мыйзам | **Russian Equivalent:** Закон о персональных данных

**Effective Date:** 2023 (most recent legislation)

### Refined English Translation

Kyrgyzstan's Law on Personal Data, enacted in 2023, is the foundational legislation for the country's data protection regime.

| Element | Content | Notes |
| Legal Framework | **Consent-based framework**: data processing requires the data subject's valid consent | The 2023 law supersedes previous relevant provisions |
| Data Subject Rights | Rights of access, correction, deletion, and objection | Aligned with generally accepted international standards |
| Special Data Categories | Enhanced protection for special categories of data | Including sensitive data relating to health, religion, ethnicity, etc. |
| Data Localization | Local storage required in specified circumstances | Specific scope subject to the implementation of the law |
| Cross-border Transfers | Permitted subject to conditions such as adequate protection or data subject consent | Mechanism similar to other Central Asian countries |
| Regulatory Authority | The competent authority is being established or designated under the new law | Further refinement anticipated under the 2023 legislation |
| Penalties | Administrative fines; criminal liability for serious violations | Pursuant to relevant Kyrgyz codes |
| Full Text | Available in Kyrgyz and Russian | For professional legal translation, reference to the official text of the Ministry of Justice of Kyrgyzstan is recommended |

> **Note:** The content in this section is compiled from the English original table of contents summary and publicly available sources. Kyrgyzstan's 2023 Law on Personal Data is relatively recent; a complete Chinese translation requires the work of a professional legal translator qualified in the Kyrgyz or Russian language.

---
## VI.5 Georgia — Law on Personal Data Protection (2011)

**Georgian:** პერსონალურ მონაცემთა დაცვის შესახებ საქართველოს კანონი | **Official English Text:** Available

**Supervisory Authority:** Personal Data Protection Service of Georgia

**Special Status:** Georgia is the only South Caucasus country to have signed an Association Agreement with the European Union (EU–Georgia Association Agreement), which requires Georgia to align its data protection regime with EU standards and carries a strong international human rights dimension.

### Refined English Translation

Georgia's Law on Personal Data Protection, enacted in 2011, is the foundational legislation for personal data protection in the country and represents a relatively well-developed institutional framework within the South Caucasus region.

| Element | Content | Notes |
| Legal Framework | **Consent framework + legal bases**: processing requires a lawful basis, including data subject consent, legal obligation, contract performance, vital interests, and public tasks | Framework closely aligned with the GDPR |
| Data Subject Rights | Rights of access, correction, deletion, data portability, and objection | Relatively comprehensive rights framework |
| Special Categories of Data | Enhanced protection for sensitive data concerning race, ethnicity, religion, health, sexual life, etc. | Consistent with international standards |
| Data Localization | Currently no comprehensive mandatory data localization requirement | Consistent with EU standards |
| Cross-border Transfers | Subject to adequacy decisions, standard contractual clauses, or other lawful mechanisms | Modeled on EU GDPR transfer mechanisms |
| Regulatory Authority | **Personal Data Protection Service of Georgia**: an independent regulatory authority responsible for enforcement, complaint handling, and public education | The only independent data protection supervisory authority in the South Caucasus |
| Penalties | Administrative fines; criminal liability for serious violations | Fines vary according to the severity of the violation |
| EU–Georgia Association Agreement | The data protection obligations under the EU–Georgia Association Agreement require Georgia to align its domestic regime with the EU legal framework | This is a key driver of the modernization of Georgia's data protection regime |
| Full Text | Available in Georgian and English (official) | The English official text is publicly available and constitutes the best reference |

---
## VI.6 Horizontal Comparison of Data Protection Laws Across CIS Jurisdictions

| Comparative Dimension | Kazakhstan | Belarus | Uzbekistan | Kyrgyzstan | Georgia |
| **Year of Legislation** | 2013 (amended 2021–22) | 2008 (amended 2021/22) | 2019 | 2023 | 2011 |
| **Legal Framework** | Consent + statutory exceptions | Consent + statutory exceptions | Consent framework | Consent framework | Consent + multiple legal bases |
| **Data Localization** | ✅ Mandatory (introduced 2021–22) | ✅ Mandatory (certain sectors) | Registration regime | Specified circumstances | ❌ No comprehensive mandatory requirement |
| **Independent Regulatory Authority** | ❌ None (Ministry of Digital Development) | ❌ None (OAC) | Agency of Information and Mass Communications | To be refined | ✅ Personal Data Protection Service |
| **Special Category Protection** | Not expressly legislated | ✅ Health, race, religion, politics | Present in regulations | Present in regulations | ✅ Comprehensive regime |
| **Criminal Penalties** | ✅ Specific circumstances | ✅ Up to 3 years' imprisonment | ✅ | ✅ | ✅ |
| **Cross-border Transfer Mechanism** | Adequacy / consent / contract | Adequacy / consent / legal obligation | Adequacy / consent | Adequacy / consent | Adequacy / SCCs / other lawful mechanisms |
| **EU / International Standards Alignment** | Under consideration | Internationally isolated | Limited | Limited | ✅ EU Association Agreement obligations |
| **Official Text Languages** | Kazakh + Russian | Belarusian + Russian | Uzbek + Russian | Kyrgyz + Russian | Georgian + English |

---
### Terminology Precision Improvements

| Issue Type | Original Treatment | Refined |
| Institutional Name | "Operation Analysis and Analytics Center" (mistranslated) | "Operational and Analytical Center" (Оперативно-аналитический центр, OAC) |
| Institutional Name | "Committee on Legal Statistics and Special Accounts" (literal translation) | "Committee on Legal Statistics and Special Accounts under the Prosecutor General's Office" (Комитет правовой статистики и специальных счетов) |
| Institutional Name | "Ministry of Communications and Informatization" | "Ministry of Communications and Informatization" (Министерство связи и информатизации) |
| Legislative Year | Belarus noted as "2021, effective 2022" (conflating original enactment year) | Corrected to "enacted 2008 / effective 2009; amended 2021 / amended version effective 2022" |
| Technical Term | "State Inspectorate for Personal Data Protection" | "State Inspectorate for Personal Data Protection" (Государственная инспекция по защите персональных данных) |
