For organizations operating across multiple markets, the answer is rarely just one. A business may need to navigate GDPR in Europe, CCPA and other US state laws, and separate requirements in countries such as India, Vietnam, Malaysia, and China. These laws share common principles, but their requirements, thresholds, individual rights, and enforcement mechanisms can differ significantly.
The challenge is no longer simply understanding each regulation. Organizations need to determine which laws apply to them, identify where their requirements overlap, and build a privacy program that can manage those obligations without creating separate compliance efforts for every jurisdiction.
This guide explains the major data privacy laws organizations need to understand, how recent regulatory changes are reshaping the landscape, and how businesses can build a practical approach to managing privacy requirements across multiple jurisdictions.
Key takeaways
- Data privacy laws apply based on factors such as where individuals are located, what data is processed, and how the organization operates, not simply where the company is headquartered.
- Major privacy laws share common requirements around lawful processing, individual rights, transparency, security, breach notification, and accountability.
- Organizations operating across multiple markets may need to comply with several privacy laws at the same time, each with different requirements.
- New and updated privacy regulations are making the global privacy landscape more complex, particularly across US states and emerging markets.
- A unified privacy compliance program can help organizations manage overlapping requirements through shared controls, processes, and documentation rather than separate programs for every law.
What are data privacy laws? Definition and why they exist
Data privacy laws are legal frameworks that govern how organizations collect, use, store, share, and protect personal information. They also give individuals enforceable rights over their personal data, such as the right to access, correct, or delete information held about them. The GDPR helped establish many of the principles now found in privacy laws around the world. Since it took effect in 2018, its approach to extraterritorial scope, individual rights, accountability, and financial penalties has influenced privacy legislation across multiple jurisdictions. The regulatory landscape has since expanded significantly. Organizations can now face overlapping requirements across the EU, US states, and markets such as India, Vietnam, Malaysia, and China. As a result, understanding which laws apply and where their requirements overlap has become an important part of enterprise privacy management.Global data privacy laws in 2026: A jurisdiction map
Privacy obligations are increasingly determined by where the individuals whose data you process are located, rather than simply where your organization is headquartered. A company based in the US, for example, may need to comply with GDPR, UK GDPR, India’s DPDP Rules, and Vietnam’s PDPL if it processes personal data from individuals in those jurisdictions. The following jurisdictions represent some of the major privacy frameworks organizations need to consider in 2026.1. GDPR — European Union
The GDPR applies to organizations that process personal data of individuals in the EU, including organizations based outside the EU.- In force: May 2018
- Applies to: Organizations processing EU residents’ data
- Maximum penalty: Up to €20 million or 4% of global annual turnover for serious violations
2. UK GDPR — United Kingdom
The UK GDPR governs the processing of personal data in the United Kingdom and operates alongside the Data Protection Act 2018.- In force: January 2021 following Brexit
- Applies to: Organizations processing data of UK residents
- Maximum penalty: Up to £17.5 million or 4% of global turnover
3. CCPA/CPRA — California, United States
California’s privacy framework gives consumers rights over their personal information and places additional obligations on qualifying businesses.- In force: CCPA enforced from 2023 under the CPRA framework
- Applies to: For-profit businesses that meet California’s applicable thresholds
- Maximum penalty: Up to $7,500 per intentional violation
4. US state privacy laws
Beyond California, multiple US states have enacted comprehensive privacy laws with different scopes, thresholds, and consumer rights.- In force: Various dates from 2023–2026
- Applies to: Businesses serving residents of states where they meet applicable thresholds
- Maximum penalty: Varies by state, typically ranging from $2,500 to $10,000 per violation
5. LGPD — Brazil
Brazil’s LGPD establishes requirements for processing personal data and gives individuals rights over their information.- In force: August 2020
- Applies to: Organizations processing personal data of Brazilian residents
- Maximum penalty: Up to R$50 million or 2% of Brazilian annual revenue
6. DPDP Rules — India
India’s Digital Personal Data Protection framework establishes requirements for organizations processing digital personal data relating to individuals in India.- In force: 2026 enforcement
- Applies to: Organizations processing digital personal data of Indian residents
- Maximum penalty: Up to ₹250 crore per rule breach
7. Personal Data Protection Law — Vietnam
Vietnam’s new Personal Data Protection Law establishes requirements for organizations processing personal data and introduces a broader regulatory framework for data protection.- In force: January 1, 2026
- Applies to: Organizations processing personal data of Vietnamese residents
- Penalties: Administrative fines and criminal liability for serious violations
8. Amended PDPA — Malaysia
Malaysia’s amended Personal Data Protection Act expands privacy obligations and introduces additional requirements for organizations handling personal data.- In force: 2026
- Applies to: Malaysian data users, including organizations within the expanded extraterritorial scope
- Key requirements: Mandatory DPO appointments and breach notification
9. PIPL and amended CSL — China
China’s Personal Information Protection Law (PIPL) governs the processing of personal information, while the amended Cybersecurity Law adds broader cybersecurity requirements.- PIPL in force: November 2021
- CSL amendments: January 2026
- Applies to: Organizations processing data relating to individuals in China
- Maximum PIPL penalty: Up to RMB 50 million or 5% of prior-year revenue
10. Privacy Act — Australia
Australia’s Privacy Act reforms introduce additional privacy requirements as the country’s privacy framework continues to evolve.- Effective: Staged changes across 2025–2026
- Applies to: Organizations covered by the Australian Privacy Principles
- Key changes: Stronger requirements around children’s privacy and data breaches
11. Federal PDPL — United Arab Emirates
The UAE’s federal Personal Data Protection Law establishes requirements for organizations processing personal data within its scope.- In force: January 2022
- Applies to: Organizations processing personal data of UAE residents
- Note: The DIFC operates a separate, GDPR-aligned privacy regime
12. EU AI Act and GDPR overlap — EU/EEA
The EU AI Act introduces additional obligations for organizations using certain AI systems. Where AI systems process personal data or make decisions affecting individuals, these requirements may overlap with existing GDPR obligations.- High-risk requirements: Phased enforcement, including requirements applicable from August 2026
- Applies to: Organizations deploying AI systems within the relevant scope
- Key consideration: Organizations may need to address both AI governance and data protection requirements for the same processing activity.
The US data privacy law patchwork: 23 state laws and no federal standard
Unlike the European Union, the United States does not have one comprehensive federal law governing consumer data privacy. Instead, privacy requirements come from a combination of federal sector-specific laws and state-level legislation. This means an organization operating across the US may need to consider different requirements depending on the type of data it handles and the states where its consumers are located. Federal laws such as HIPAA, GLBA, COPPA, and FCRA address specific areas, while comprehensive state privacy laws establish broader rights and obligations. As more states have introduced their own frameworks, organizations increasingly need a privacy program that can accommodate common requirements while accounting for differences between jurisdictions.California: A leading state privacy framework
California’s CCPA and CPRA have played an important role in shaping the US privacy landscape. The framework gives consumers rights over their personal information and continues to expand into areas such as automated decision-making, cybersecurity audits, and privacy risk assessments. California has also continued to develop the operational mechanisms that support these rights. The DELETE Act’s DROP platform, launched in January 2026, provides consumers with a centralized way to submit deletion requests to registered data brokers. These developments show how privacy requirements are moving beyond privacy notices and policies toward processes that organizations must be able to operate consistently and demonstrate in practice.Texas: Growing importance of state-level enforcement
Texas provides another example of how state privacy regulation is developing beyond legislation itself. The Texas Attorney General secured a settlement exceeding $1 billion with a major technology company, making it the largest US state data privacy settlement to date. The development illustrates the broader direction of the US market: state privacy laws are becoming an increasingly important part of enterprise risk management, particularly for organizations operating at scale.What the US patchwork means for organizations
The main challenge is not having to create a separate privacy program for every state. Most state laws address many of the same fundamental areas, such as consumer rights, data collection, consent, targeted advertising, data security, and transparency. What changes from state to state are the specific thresholds, definitions, exemptions, deadlines, and rights that apply. For example, one state may give consumers a particular right to opt out of profiling, while another may apply that right only to certain types of processing. A business operating nationally therefore needs to understand both the common requirements and these state-specific differences. A practical approach is to establish a common privacy framework across the organization. Core processes such as data mapping, consent management, consumer request handling, vendor oversight, and privacy risk assessments can be managed centrally, while state-specific requirements are added where necessary. This gives privacy teams one consistent operating model instead of managing 23 completely separate programs. It also makes it easier to update the program when another state introduces new requirements or an existing law changes.6 obligations common to all major data privacy laws
Although privacy laws differ in scope and terminology, most major frameworks address the same fundamental areas of data handling. These include how organizations establish a lawful basis for processing, inform individuals about their data practices, protect personal information, respond to individual rights requests, and demonstrate that their privacy obligations are being met. The important distinction is that similar obligations do not always mean identical requirements. For example, GDPR generally relies on an opt-in consent model, while CCPA/CPRA places greater emphasis on opt-out rights. Breach notification requirements also vary by jurisdiction, as do definitions of sensitive data and requirements for privacy assessments or designated privacy roles. Rather than building completely separate compliance programs for each law, organizations can establish a common set of privacy controls and then adapt them where jurisdiction-specific requirements differ.
1. Establish a lawful basis for processing
Organizations need a valid basis for collecting and using personal data. The specific requirements differ between laws: GDPR provides six legal bases under Article 6, while other frameworks use different approaches to consent, business purposes, or permitted processing. The practical requirement is the same: organizations should be able to explain why they are processing personal data and what legal basis permits them to do so.2. Support individual data rights
Major privacy laws give individuals rights over their personal information, although the specific rights vary by jurisdiction. These commonly include access, correction, deletion, portability, and the ability to object to certain types of processing. Organizations therefore need processes that can identify an individual’s data, verify requests, locate relevant records, and respond within the applicable timeframe.3. Provide clear privacy notices
Privacy laws generally require organizations to explain how they collect and use personal data. Depending on the jurisdiction, this can include information about the purpose of processing, categories of data collected, retention periods, sharing practices, and individual rights. Privacy notices therefore need to be accurate and understandable, and they should reflect what the organization actually does with personal data rather than serving as generic legal documentation.4. Protect personal data with appropriate safeguards
Privacy compliance also requires organizations to protect personal data against unauthorized access, loss, misuse, and other security risks. GDPR, for example, requires appropriate technical and organizational measures and incorporates privacy-by-design requirements. The exact controls vary by organization and jurisdiction, but common measures include access controls, encryption, vulnerability management, monitoring, retention controls, and secure data handling practices.5. Prepare for personal data breaches
Organizations need a defined process for detecting, assessing, documenting, and reporting personal data breaches. The applicable notification period depends on the jurisdiction and the circumstances of the breach. For example, GDPR requires qualifying breaches to be reported to the relevant supervisory authority within 72 hours of becoming aware of them. US state requirements can use different timelines and notification thresholds. This makes incident response an important part of privacy management, not a process that begins only after a breach has been confirmed.6. Demonstrate accountability
Privacy laws increasingly require organizations to demonstrate that they are meeting their obligations, not simply state that they are compliant. This can include maintaining processing records, conducting privacy or data protection assessments, documenting decisions, managing vendors, and maintaining appropriate policies and training records. Some jurisdictions also require specific privacy roles or assessments for organizations and processing activities that meet certain criteria. The practical goal is to ensure that an organization can provide evidence of how its privacy program operates when regulators, auditors, customers, or internal stakeholders require it.How AI is complicating data privacy law compliance in 2026
AI is changing how organizations collect, analyze, and use personal data. This creates new privacy considerations because AI systems can reuse data in ways that were not part of the original purpose for which it was collected, make decisions about individuals, and process data across multiple systems and jurisdictions. For privacy teams, the challenge is not simply adding an “AI section” to an existing privacy program. They need to understand how AI changes the way personal data is collected, used, transferred, and retained, then determine which privacy requirements apply to each use case.
1. Purpose limitation becomes harder to manage
Privacy laws generally expect organizations to use personal data for specific, stated purposes. AI can make this more difficult because data collected for one purpose may later be used to train, fine-tune, or operate an AI system for another purpose. For example, personal data originally collected to provide a customer service may later be considered for AI model training. Before doing so, the organization needs to determine whether the new use is compatible with the original purpose and whether the existing legal basis still supports it.2. Automated decision-making creates overlapping requirements
AI systems can increasingly influence decisions involving employment, credit, healthcare, education, and other areas that can significantly affect individuals. Under GDPR Article 22, organizations need to consider specific requirements when individuals are subject to solely automated decisions with significant effects. Where an AI system also falls within the EU AI Act’s high-risk categories, organizations may need to address AI-specific requirements alongside their existing GDPR obligations. This means privacy and AI governance teams need to assess the same system from both perspectives rather than treating the requirements as completely separate compliance exercises.3. AI is creating new privacy questions around sensitive data
AI systems can derive information about individuals that may be more sensitive than the data originally collected. Connecticut’s expanded privacy framework, for example, includes neural data within its broader treatment of sensitive information. This illustrates a broader issue for privacy teams: organizations need to consider not only the personal data they directly collect, but also the information AI systems can infer or derive from that data. The privacy implications may therefore change as an AI system becomes more capable of analyzing individual behavior or characteristics.4. AI can increase cross-border data transfer exposure
Many AI services rely on cloud infrastructure, external model providers, or processing environments located in different countries. When personal data is sent to these services, organizations need to understand where the data is processed and whether applicable cross-border transfer requirements are satisfied. This is particularly important when personal data originating in jurisdictions with transfer restrictions is processed in countries without an applicable adequacy decision or other recognized transfer mechanism.5. Consent management is becoming more complex
AI can also make consent management more difficult for organizations operating across multiple jurisdictions. Different laws may require different approaches to consent, opt-outs, profiling, or parental authorization. A multinational organization may therefore need its consent systems to recognize different requirements based on the individual’s location and the type of processing involved. The system should also maintain an auditable record showing what consent or preference was provided, when it was provided, and which processing activity it covered.How to comply with multiple privacy laws at once: A practical approach
Organizations operating across multiple jurisdictions do not necessarily need a completely separate privacy program for every law that applies to them. A more practical approach is to establish a common privacy framework around the requirements that different laws share, then add jurisdiction-specific controls where the requirements differ. GDPR can provide a useful baseline because it covers many of the areas addressed by other major privacy laws. However, GDPR compliance should not be treated as a substitute for reviewing other requirements. California’s opt-out rules, India’s consent requirements, and Vietnam’s cross-border transfer provisions are examples of obligations that may require additional controls.
