Data Privacy Laws Around the World

The Global Privacy Patchwork

Meet Elena, a small business owner from Barcelona. Last year, she received an email from a company she’d never heard of, containing details about her purchasing habits. Confused and concerned, Elena filed a complaint using her rights under Europe’s privacy law, GDPR. Within weeks, the company had to explain how they got her data, delete it, and pay a fine. That’s GDPR in action – often called the gold standard of privacy laws since 2018.

Now consider James in California. When he noticed a fitness app was selling information about his running routes to advertisers, he used his rights under the California Consumer Privacy Act (CCPA) to opt out. The company had to stop selling his data but could still collect it – showing the different approach American laws take.

Across the globe, countries have created their own privacy rulebooks:

  • Brazil follows its General Data Protection Law (LGPD)
  • China enforces its Personal Information Protection Law (PIPL)
  • Australia relies on its Privacy Act from 1988
  • The Philippines has one of Asia’s strictest frameworks with its Data Privacy Act

The list keeps growing. Florida and Oregon introduced new privacy laws taking effect in July 2024, adding more pieces to this global puzzle.

As of January 2025, 144 countries have enacted national data privacy laws, covering approximately 82% of the world’s population. Countries create these rules to answer questions like: Who owns your data? What can companies do with it? How do you delete it if you change your mind?

It’s important to know under which laws is your data protected, so let’s tour the globe’s privacy rulebooks and make a bit of a comparison among the most significant data privacy laws!

Comparison of Major Data Privacy Laws Worldwide

1. Scope and Applicability

Europe’s GDPR, Brazil’s LGPD, and China’s PIPL all work the same way: if a company handles personal info from someone in those regions (like a German email address or a Brazilian phone number), the rules apply no matter where the company is based. California’s CCPA is a little different—it mostly affects businesses operating in California, but even global companies have to follow it if they deal with Californians.

Sector-specific laws like HIPAA (healthcare, USA) and GLBA (financial institutions, USA) focus on protecting sensitive industry-specific data.

2. Consent and Data Subject Rights

GDPR, LGPD, and PIPL emphasise explicit consent for data collection, while CCPA allows businesses to collect data unless consumers opt out. GDPR and LGPD grant broad data subject rights, including the right to access, rectify, and erase data. The California Privacy Rights Act (CPRA), an extension of CCPA, introduces more GDPR-like provisions, strengthening consumer rights.

India’s Digital Personal Data Protection Act (DPDP) also requires explicit consent but is more lenient in enforcement. Singapore’s Personal Data Protection Act (PDPA) takes a balanced approach, permitting implied consent in some business contexts.

3. Cross-Border Data Transfers

GDPR imposes strict cross-border transfer rules, allowing data transfers only to countries with adequate data protection measures. China’s PIPL is even stricter, mandating that certain critical data must be stored within China and restricting overseas transfers. In contrast, CCPA has fewer restrictions on cross-border data flow but requires businesses to disclose how they share consumer data.

4. Enforcement and Penalties

GDPR has the most stringent penalties, imposing fines of up to 4% of global annual revenue or €20 million, whichever is higher. PIPL allows fines of up to 5% of a company’s annual revenue. The CCPA/CPRA penalises companies $7,500 per intentional violation but lacks the same global enforcement power as GDPR.

HIPAA and GLBA have industry-specific penalties, with HIPAA violations reaching $1.5 million per category per year. Kenya’s DPA and Thailand’s PDPA also impose fines, but their enforcement mechanisms are still evolving.

5. Emerging Trends and Future Developments

The EU AI Act introduces privacy measures for artificial intelligence, ensuring AI systems respect fundamental rights. The UK’s Data Protection and Digital Information Bill seeks to revise GDPR-based regulations for post-Brexit data governance. Meanwhile, the expansion of laws in India, Kenya, and Thailand signals a growing global trend toward stronger data privacy protections.

pCloud’s Secret Weapon—Two Homes for Your Data

When you sign up for pCloud, you pick your data’s address.

  • 🇺🇸 Dallas, Texas: Ideal for users who prefer U.S.-based services.
  • 🇪🇺 Luxembourg, EU: Perfect for GDPR devotees (or anyone who wants Swiss-level privacy).

We let you be the boss, as you select your data’s home during signup. No tech jargon, no drama. Compliance? Sorted. pCloud follows local laws so you don’t have to sweat the small print. After all, privacy isn’t a location—it’s a decision. We just make that decision easy.

Data privacy laws aren’t just for governments or corporations. They’re for you—the person uploading family photos, work files, or that novel you’ve been drafting.

With pCloud, you’re not just choosing a storage provider. You’re choosing freedom, control, and peace of mind.

Ready to plant your flag?
👉 Sign up for pCloud and decide where your data lives. Because in a world of invisible rules, you deserve to see the map.

Spread the word: