Skip to main content

Research-driven insights for ever- evolving industries

Get our thoughts on complex business challenges that companies face today. Our blogs are always backed by maximum research, professional experience, and diverse service expertise. We create blogs with intuitive ideas and a sharp focus on business needs.

How many data privacy laws apply to your organization right now?

How many data privacy laws apply to your organization right now?

For organizations operating across multiple markets, the answer is rarely just one. A business may need to navigate GDPR in Europe , CCPA and other US state laws, and separate requirements in countries such as India, Vietnam, Malaysia, and China. These laws share common principles, but their requirements, thresholds, individual rights, and enforcement mechanisms can differ significantly. The challenge is no longer simply understanding each regulation. Organizations need to determine which laws apply to them, identify where their requirements overlap, and build a privacy program that can manage those obligations without creating separate compliance efforts for every jurisdiction. This guide explains the major data privacy laws organizations need to understand, how recent regulatory changes are reshaping the landscape, and how businesses can build a practical approach to managing privacy requirements across multiple jurisdictions. Key takeaways Data privacy laws apply based on factors such as where individuals are located, what data is processed, and how the organization operates, not simply where the company is headquartered. Major privacy laws share common requirements around lawful processing, individual rights, transparency, security, breach notification, and accountability. Organizations operating across multiple markets may need to comply with several privacy laws at the same time, each with different requirements. New and updated privacy regulations are making the global privacy landscape more complex, particularly across US states and emerging markets. A unified privacy compliance program can help organizations manage overlapping requirements through shared controls, processes, and documentation rather than separate programs for every law. What are data privacy laws? Definition and why they exist Data privacy laws are legal frameworks that govern how organizations collect, use, store, share, and protect personal information. They also give individuals enforceable rights over their personal data, such as the right to access, correct, or delete information held about them. The GDPR helped establish many of the principles now found in privacy laws around the world. Since it took effect in 2018, its approach to extraterritorial scope, individual rights, accountability, and financial penalties has influenced privacy legislation across multiple jurisdictions. The regulatory landscape has since expanded significantly. Organizations can now face overlapping requirements across the EU, US states, and markets such as India, Vietnam, Malaysia, and China. As a result, understanding which laws apply and where their requirements overlap has become an important part of enterprise privacy management. Global data privacy laws in 2026: A jurisdiction map Privacy obligations are increasingly determined by where the individuals whose data you process are located, rather than simply where your organization is headquartered. A company based in the US, for example, may need to comply with GDPR, UK GDPR, India’s DPDP Rules, and Vietnam’s PDPL if it processes personal data from individuals in those jurisdictions. The following jurisdictions represent some of the major privacy frameworks organizations need to consider in 2026. 1. GDPR — European Union The GDPR applies to organizations that process personal data of individuals in the EU, including organizations based outside the EU. In force: May 2018 Applies to: Organizations processing EU residents' data Maximum penalty: Up to €20 million or 4% of global annual turnover for serious violations 2. UK GDPR — United Kingdom The UK GDPR governs the processing of personal data in the United Kingdom and operates alongside the Data Protection Act 2018. In force: January 2021 following Brexit Applies to: Organizations processing data of UK residents Maximum penalty: Up to £17.5 million or 4% of global turnover 3. CCPA/CPRA — California, United States California's privacy framework gives consumers rights over their personal information and places additional obligations on qualifying businesses. In force: CCPA enforced from 2023 under the CPRA framework Applies to: For-profit businesses that meet California's applicable thresholds Maximum penalty: Up to $7,500 per intentional violation 4. US state privacy laws Beyond California, multiple US states have enacted comprehensive privacy laws with different scopes, thresholds, and consumer rights. In force: Various dates from 2023–2026 Applies to: Businesses serving residents of states where they meet applicable thresholds Maximum penalty: Varies by state, typically ranging from $2,500 to $10,000 per violation 5. LGPD — Brazil Brazil's LGPD establishes requirements for processing personal data and gives individuals rights over their information. In force: August 2020 Applies to: Organizations processing personal data of Brazilian residents Maximum penalty: Up to R$50 million or 2% of Brazilian annual revenue 6. DPDP Rules — India India's Digital Personal Data Protection framework establishes requirements for organizations processing digital personal data relating to individuals in India. In force: 2026 enforcement Applies to: Organizations processing digital personal data of Indian residents Maximum penalty: Up to ₹250 crore per rule breach 7. Personal Data Protection Law — Vietnam Vietnam's new Personal Data Protection Law establishes requirements for organizations processing personal data and introduces a broader regulatory framework for data protection. In force: January 1, 2026 Applies to: Organizations processing personal data of Vietnamese residents Penalties: Administrative fines and criminal liability for serious violations 8. Amended PDPA — Malaysia Malaysia's amended Personal Data Protection Act expands privacy obligations and introduces additional requirements for organizations handling personal data. In force: 2026 Applies to: Malaysian data users, including organizations within the expanded extraterritorial scope Key requirements: Mandatory DPO appointments and breach notification 9. PIPL and amended CSL — China China's Personal Information Protection Law (PIPL) governs the processing of personal information, while the amended Cybersecurity Law adds broader cybersecurity requirements. PIPL in force: November 2021 CSL amendments: January 2026 Applies to: Organizations processing data relating to individuals in China Maximum PIPL penalty: Up to RMB 50 million or 5% of prior-year revenue 10. Privacy Act — Australia Australia's Privacy Act reforms introduce additional privacy requirements as the country's privacy framework continues to evolve. Effective: Staged changes across 2025–2026 Applies to: Organizations covered by the Australian Privacy Principles Key changes: Stronger requirements around children's privacy and data breaches 11. Federal PDPL — United Arab Emirates The UAE's federal Personal Data Protection Law establishes requirements for organizations processing personal data within its scope. In force: January 2022 Applies to: Organizations processing personal data of UAE residents Note: The DIFC operates a separate, GDPR-aligned privacy regime 12. EU AI Act and GDPR overlap — EU/EEA The EU AI Act introduces additional obligations for organizations using certain AI systems. Where AI systems process personal data or make decisions affecting individuals, these requirements may overlap with existing GDPR obligations. High-risk requirements: Phased enforcement, including requirements applicable from August 2026 Applies to: Organizations deploying AI systems within the relevant scope Key consideration: Organizations may need to address both AI governance and data protection requirements for the same processing activity. The US data privacy law patchwork: 23 state laws and no federal standard Unlike the European Union, the United States does not have one comprehensive federal law governing consumer data privacy. Instead, privacy requirements come from a combination of federal sector-specific laws and state-level legislation. This means an organization operating across the US may need to consider different requirements depending on the type of data it handles and the states where its consumers are located. Federal laws such as HIPAA, GLBA, COPPA, and FCRA address specific areas, while comprehensive state privacy laws establish broader rights and obligations. As more states have introduced their own frameworks, organizations increasingly need a privacy program that can accommodate common requirements while accounting for differences between jurisdictions. California: A leading state privacy framework California's CCPA and CPRA have played an important role in shaping the US privacy landscape. The framework gives consumers rights over their personal information and continues to expand into areas such as automated decision-making, cybersecurity audits, and privacy risk assessments. California has also continued to develop the operational mechanisms that support these rights. The DELETE Act's DROP platform, launched in January 2026, provides consumers with a centralized way to submit deletion requests to registered data brokers. These developments show how privacy requirements are moving beyond privacy notices and policies toward processes that organizations must be able to operate consistently and demonstrate in practice. Texas: Growing importance of state-level enforcement Texas provides another example of how state privacy regulation is developing beyond legislation itself. The Texas Attorney General secured a settlement exceeding $1 billion with a major technology company, making it the largest US state data privacy settlement to date. The development illustrates the broader direction of the US market: state privacy laws are becoming an increasingly important part of enterprise risk management , particularly for organizations operating at scale. What the US patchwork means for organizations The main challenge is not having to create a separate privacy program for every state. Most state laws address many of the same fundamental areas, such as consumer rights, data collection, consent, targeted advertising, data security, and transparency. What changes from state to state are the specific thresholds, definitions, exemptions, deadlines, and rights that apply. For example, one state may give consumers a particular right to opt out of profiling, while another may apply that right only to certain types of processing. A business operating nationally therefore needs to understand both the common requirements and these state-specific differences. A practical approach is to establish a common privacy framework across the organization. Core processes such as data mapping, consent management, consumer request handling, vendor oversight, and privacy risk assessments can be managed centrally, while state-specific requirements are added where necessary. This gives privacy teams one consistent operating model instead of managing 23 completely separate programs. It also makes it easier to update the program when another state introduces new requirements or an existing law changes. 6 obligations common to all major data privacy laws Although privacy laws differ in scope and terminology, most major frameworks address the same fundamental areas of data handling. These include how organizations establish a lawful basis for processing, inform individuals about their data practices, protect personal information, respond to individual rights requests, and demonstrate that their privacy obligations are being met. The important distinction is that similar obligations do not always mean identical requirements. For example, GDPR generally relies on an opt-in consent model, while CCPA/CPRA places greater emphasis on opt-out rights. Breach notification requirements also vary by jurisdiction, as do definitions of sensitive data and requirements for privacy assessments or designated privacy roles. Rather than building completely separate compliance programs for each law, organizations can establish a common set of privacy controls and then adapt them where jurisdiction-specific requirements differ. 1. Establish a lawful basis for processing Organizations need a valid basis for collecting and using personal data. The specific requirements differ between laws: GDPR provides six legal bases under Article 6, while other frameworks use different approaches to consent, business purposes, or permitted processing. The practical requirement is the same: organizations should be able to explain why they are processing personal data and what legal basis permits them to do so. 2. Support individual data rights Major privacy laws give individuals rights over their personal information, although the specific rights vary by jurisdiction. These commonly include access, correction, deletion, portability, and the ability to object to certain types of processing. Organizations therefore need processes that can identify an individual's data, verify requests, locate relevant records, and respond within the applicable timeframe. 3. Provide clear privacy notices Privacy laws generally require organizations to explain how they collect and use personal data. Depending on the jurisdiction, this can include information about the purpose of processing, categories of data collected, retention periods, sharing practices, and individual rights. Privacy notices therefore need to be accurate and understandable, and they should reflect what the organization actually does with personal data rather than serving as generic legal documentation. 4. Protect personal data with appropriate safeguards Privacy compliance also requires organizations to protect personal data against unauthorized access, loss, misuse, and other security risks. GDPR, for example, requires appropriate technical and organizational measures and incorporates privacy-by-design requirements. The exact controls vary by organization and jurisdiction, but common measures include access controls, encryption, vulnerability management, monitoring, retention controls, and secure data handling practices. 5. Prepare for personal data breaches Organizations need a defined process for detecting, assessing, documenting, and reporting personal data breaches. The applicable notification period depends on the jurisdiction and the circumstances of the breach. For example, GDPR requires qualifying breaches to be reported to the relevant supervisory authority within 72 hours of becoming aware of them. US state requirements can use different timelines and notification thresholds. This makes incident response an important part of privacy management, not a process that begins only after a breach has been confirmed. 6. Demonstrate accountability Privacy laws increasingly require organizations to demonstrate that they are meeting their obligations, not simply state that they are compliant. This can include maintaining processing records, conducting privacy or data protection assessments, documenting decisions, managing vendors, and maintaining appropriate policies and training records. Some jurisdictions also require specific privacy roles or assessments for organizations and processing activities that meet certain criteria. The practical goal is to ensure that an organization can provide evidence of how its privacy program operates when regulators, auditors, customers, or internal stakeholders require it. How AI is complicating data privacy law compliance in 2026 AI is changing how organizations collect, analyze, and use personal data. This creates new privacy considerations because AI systems can reuse data in ways that were not part of the original purpose for which it was collected, make decisions about individuals, and process data across multiple systems and jurisdictions. For privacy teams, the challenge is not simply adding an "AI section" to an existing privacy program. They need to understand how AI changes the way personal data is collected, used, transferred, and retained, then determine which privacy requirements apply to each use case. 1. Purpose limitation becomes harder to manage Privacy laws generally expect organizations to use personal data for specific, stated purposes. AI can make this more difficult because data collected for one purpose may later be used to train, fine-tune, or operate an AI system for another purpose. For example, personal data originally collected to provide a customer service may later be considered for AI model training. Before doing so, the organization needs to determine whether the new use is compatible with the original purpose and whether the existing legal basis still supports it. 2. Automated decision-making creates overlapping requirements AI systems can increasingly influence decisions involving employment, credit, healthcare, education, and other areas that can significantly affect individuals. Under GDPR Article 22, organizations need to consider specific requirements when individuals are subject to solely automated decisions with significant effects. Where an AI system also falls within the EU AI Act's high-risk categories, organizations may need to address AI-specific requirements alongside their existing GDPR obligations. This means privacy and AI governance teams need to assess the same system from both perspectives rather than treating the requirements as completely separate compliance exercises. 3. AI is creating new privacy questions around sensitive data AI systems can derive information about individuals that may be more sensitive than the data originally collected. Connecticut's expanded privacy framework, for example, includes neural data within its broader treatment of sensitive information. This illustrates a broader issue for privacy teams: organizations need to consider not only the personal data they directly collect, but also the information AI systems can infer or derive from that data. The privacy implications may therefore change as an AI system becomes more capable of analyzing individual behavior or characteristics. 4. AI can increase cross-border data transfer exposure Many AI services rely on cloud infrastructure , external model providers, or processing environments located in different countries. When personal data is sent to these services, organizations need to understand where the data is processed and whether applicable cross-border transfer requirements are satisfied. This is particularly important when personal data originating in jurisdictions with transfer restrictions is processed in countries without an applicable adequacy decision or other recognized transfer mechanism. 5. Consent management is becoming more complex AI can also make consent management more difficult for organizations operating across multiple jurisdictions. Different laws may require different approaches to consent, opt-outs, profiling, or parental authorization. A multinational organization may therefore need its consent systems to recognize different requirements based on the individual's location and the type of processing involved. The system should also maintain an auditable record showing what consent or preference was provided, when it was provided, and which processing activity it covered. How to comply with multiple privacy laws at once: A practical approach Organizations operating across multiple jurisdictions do not necessarily need a completely separate privacy program for every law that applies to them. A more practical approach is to establish a common privacy framework around the requirements that different laws share, then add jurisdiction-specific controls where the requirements differ. GDPR can provide a useful baseline because it covers many of the areas addressed by other major privacy laws. However, GDPR compliance should not be treated as a substitute for reviewing other requirements. California's opt-out rules, India's consent requirements, and Vietnam's cross-border transfer provisions are examples of obligations that may require additional controls. 1. Map where personal data is collected Start by identifying every jurisdiction where the organization collects or processes personal data. This includes more than customer information. Employee records, website visitors, user accounts, marketing data, and information processed by third-party services may also bring an organization within the scope of a privacy law. The goal is to establish the geographic scope of the privacy program before reviewing individual requirements. Once the organization knows where its data subjects are located, it can determine which laws may apply to each processing activity. 2. Identify the laws that apply The next step is to determine which privacy laws apply in each jurisdiction. This requires looking beyond the organization's headquarters because many privacy laws can apply to organizations operating outside the jurisdiction. Consider factors such as the location of data subjects, the type and volume of personal data processed, organizational size or revenue thresholds, the purpose of processing, and whether data is sold, shared, or transferred across borders. Documenting these criteria creates a clear record of why a particular law is considered applicable. 3. Build a complete data inventory A privacy program cannot be effective if the organization does not know what personal data it holds or how that data moves through the business. The data inventory should identify what is collected, why it is collected, where it is stored, who can access it, who receives it, and how long it is retained. This inventory becomes the foundation for other privacy activities. It helps teams determine the requirements that apply to specific processing activities, respond to data subject requests, review retention practices, and identify where personal data is shared with third parties. 4. Review the lawful basis for processing After mapping processing activities, review the legal basis that supports each one under the applicable privacy laws. The same activity may have different requirements depending on the jurisdiction, particularly when consent, sensitive data, or targeted advertising is involved. For example, an organization may rely on a particular legal basis under GDPR while needing to meet different consent or opt-out requirements under a US state privacy law. Maintaining a documented record of these decisions makes it easier to demonstrate why each processing activity is permitted. 5. Standardize consent and privacy preferences Consent mechanisms should be designed to support the requirements of all relevant jurisdictions rather than being treated as a single global setting. Depending on where the individual is located and what processing is involved, the organization may need to support different consent, opt-out, profiling, or targeted advertising requirements. A centralized consent management approach can help maintain these differences without requiring completely separate systems. It should record what preference the individual provided, when it was provided, which processing it applies to, and which jurisdictional requirements governed the interaction. 6. Align vendor and processor agreements Third-party providers can introduce additional privacy obligations because vendors may collect, store, analyze, or transfer personal data on the organization's behalf. Organizations therefore need to understand not only their own processing activities but also how personal data moves through their vendor ecosystem. Review vendor and processor agreements for requirements covering data processing, security measures, sub-processors, breach notification, data deletion, and international transfers. Where several privacy laws apply, the agreements should address the relevant requirements rather than relying on a generic privacy clause. 7. Set the shortest applicable breach notification window Organizations operating across jurisdictions may face different breach notification deadlines for the same incident. Waiting to determine the applicable deadline after an incident occurs can leave the response team with very little time to assess the breach and meet regulatory requirements. A practical approach is to design the internal incident response process around the shortest applicable notification window. This gives the organization more time to investigate, determine which jurisdictions are affected, prepare the required notifications, and coordinate communications with regulators and affected individuals. Conclusion Data privacy compliance is no longer a matter of meeting the requirements of one regulation. Organizations operating across markets need to understand which laws apply to their data, where those requirements overlap, and where local rules require additional controls. A practical privacy program starts with visibility. Organizations need to know what personal data they collect, why they process it, where it moves, who has access to it, and which legal requirements govern those activities. From there, common controls can be applied across jurisdictions while allowing for differences in consent, individual rights, breach notification, and cross-border data transfers. As privacy regulations continue to evolve, organizations that treat privacy as an ongoing governance capability will be better positioned to manage regulatory change without repeatedly rebuilding their compliance programs. Need help managing privacy requirements across multiple jurisdictions? Terralogic's cybersecurity experts can help organizations assess their privacy posture, strengthen data protection processes, and build a scalable approach to regulatory compliance. Talk with our team to explore how you can build a privacy program aligned with your business, data environment, and regulatory obligations. Frequently Asked Questions (FAQs) 1. What are data privacy laws? Data privacy laws are legal frameworks that govern how organizations collect, use, store, share, and protect personal information about individuals. They also give individuals enforceable rights over their data, including rights to access, delete, or correct personal information. These laws commonly address lawful processing, transparency, individual rights, security safeguards, breach notification, and organizational accountability. Major examples include the GDPR, UK GDPR, CCPA/CPRA, US state privacy laws, Brazil's LGPD, India's DPDP Rules, Vietnam's PDPL, Malaysia's PDPA, and China's PIPL. 2. Which data privacy law applies to my organization? The privacy laws that apply to an organization depend largely on where the individuals whose data is being processed are located, as well as the organization's activities and whether it meets specific legal thresholds. Many modern privacy laws can apply to organizations outside the jurisdiction where the law was enacted. For example, an organization may need to consider GDPR when processing EU residents' data, UK GDPR for UK residents, CCPA/CPRA for qualifying California businesses, and other state or national laws when processing data in those jurisdictions. Organizations serving individuals across multiple markets may therefore need to comply with several privacy laws at the same time. 3. What are the key data privacy laws in the US in 2026? The United States does not have a comprehensive federal data privacy law. Instead, organizations must navigate state-level privacy laws alongside federal laws that apply to specific sectors or types of data. California's CCPA/CPRA, Texas's TDPSA, Virginia's VCDPA, Colorado's CPA, and Connecticut's CTDPA are among the major state frameworks. Indiana, Kentucky, and Rhode Island also introduced comprehensive privacy laws that took effect in January 2026. Federal laws such as HIPAA, GLBA, COPPA, and FCRA continue to apply to specific sectors and types of information. 4. What is the difference between GDPR and US data privacy laws? GDPR and US state privacy laws differ in several important areas, particularly their approach to consent, scope, enforcement, and individual rights. GDPR generally uses an opt-in approach for consent, while many US state laws place greater emphasis on consumers' rights to opt out of specific activities such as targeted advertising or the sale of personal data. The laws also differ in which organizations and types of data they cover, the rights available to individuals, and how violations are enforced. Organizations operating in both the EU and US therefore need to assess the requirements of each applicable jurisdiction rather than assuming that compliance with one framework satisfies the other.

Secure Your Data Today

Build a scalable, future-proof privacy program with our expert team.