Privacy regimes outside the usual three, covered for companies operating in those markets.
Canada (PIPEDA)
September 21, 2026
Two federal exemption orders registered on the same day in 2004 let Alberta's and British Columbia's private-sector privacy statutes displace PIPEDA inside each province. The Acts share a name and identical fine ceilings, but only Alberta's requires breach reporting, they define employee information and treat non-profits differently, and BC has credit-reporting amendments due in 2027.
Read more →
Brazil (LGPD)
September 21, 2026
The LGPD says a controller must appoint an encarregado and publish how to reach them, and leaves the rest to the regulator. Resolution CD/ANPD No. 18 of 16 July 2024 supplies it: a written, dated and signed act of appointment, a named substitute, a minimum content for the public notice, five duties the organisation owes its encarregado, and a conflict-of-interest regime that can lead to sanctions.
Read more →
China (PIPL)
September 21, 2026
The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.
Read more →
China (PIPL)
September 21, 2026
Article 54 of China's Personal Information Protection Law has required regular compliance audits since November 2021, without saying how often, by whom or against what. The CAC's Measures for Personal Information Protection Compliance Audits, in force since 1 May 2025, supply those answers, and add a second route by which a regulator can order an outside audit at the processor's expense.
Read more →
India (DPDP Act)
September 21, 2026
The Data Protection Board of India was established by Gazette notification on 13 November 2025, with its head office in the National Capital Region. MeitY invited applications for a Chairperson and four Members in May 2026, and no appointment had been notified by 21 September 2026. This explainer covers its staffing, its digital procedure and which of its powers are not yet in force.
Read more →
India (DPDP Act)
September 21, 2026
Section 8(6) of India's Digital Personal Data Protection Act requires a Data Fiduciary to tell the Data Protection Board and each affected individual about a personal data breach, and rule 7 of the 2025 Rules fills in the content and a 72-hour clock. Both sit in the commencement tranche that starts eighteen months after 13 November 2025, while CERT-In's six-hour incident reporting already applies.
Read more →
Brazil (LGPD)
September 21, 2026
Resolution CD/ANPD No. 2 of 2022 gives micro and small enterprises, startups, non-profits and individuals acting as controllers or processors a lighter version of the LGPD: a simplified record of processing, no mandatory encarregado, and doubled deadlines. Three exclusions take it away, the ANPD can withdraw it case by case, and a 2024 regulation rewrote one deadline rule.
Read more →
Canada (PIPEDA)
September 21, 2026
The Guidelines for obtaining meaningful consent were issued jointly by the federal Privacy Commissioner and the Alberta and British Columbia commissioners in May 2018 and last modified in August 2025. They set seven principles, four elements that must be emphasised, three triggers for express consent and an under-13 position on children, and label each item an obligation or a best practice.
Read more →
Brazil (LGPD)
August 24, 2026
The Lei Geral de Proteção de Dados borrowed the GDPR's architecture and then diverged in ways that matter: ten legal bases rather than six, an automated-decision review right whose human reviewer was removed by amendment before the law took effect, and a sanctions ceiling fixed in reais. In January 2026 Brazil and the EU recognised each other as adequate.
Read more →
Canada (PIPEDA)
August 24, 2026
Canadian privacy law is a federation problem before it is a compliance problem. Which statute governs a given business turns on the province it operates in and whether its data crosses a border. This guide covers PIPEDA's Schedule 1 architecture, its breach-reporting trigger, the striking fact that the federal Commissioner cannot impose a monetary penalty, and Quebec's Law 25, which can.
Read more →
China (PIPL)
August 24, 2026
Every other regime in this series asks whether the destination country protects data adequately. China's asks a different question: how many people's information is leaving, whether any of it is sensitive, and whether the exporter runs critical information infrastructure. This guide sets out the export thresholds in the 2024 CAC Provisions, and the PIPL machinery underneath them.
Read more →
Cross-Border Transfers
August 24, 2026
Chapter V of the GDPR restricts transfers of personal data out of the EEA without ever saying what a transfer is. The European Data Protection Board filled the gap with a three-part test, and the machinery built on top — adequacy, standard clauses, impact assessments — now has imitators worldwide that share its vocabulary but not its logic.
Read more →
India (DPDP Act)
August 24, 2026
The Digital Personal Data Protection Act was passed in August 2023 and its Rules were notified in November 2025, but the commencement notification staggers the obligations over eighteen months. Meanwhile the statute leaves out a sensitive data category entirely, permits transfers unless the government forbids them, imposes duties on individuals, and rewrote India's freedom of information law.
Read more →