General Data Protection Regulation (GDPR)
A comprehensive regulation that sets a high standard for data protection and privacy for all individuals within the European Union and the European Economic Area.
Laws filed under this category in plain English.
A comprehensive regulation that sets a high standard for data protection and privacy for all individuals within the European Union and the European Economic Area.
A state-level law that grants California residents significant control over the personal information that businesses collect about them.
The federal privacy law for private-sector organizations in Canada that sets out rules for how businesses must handle personal information in commercial activities.
Brazil's comprehensive data protection law that regulates the processing of personal data of individuals in Brazil, regardless of the processor's location.
The primary piece of Australian legislation protecting the privacy of individuals and regulating how personal information is handled by government agencies and private organizations.
A comprehensive regulation that governs data protection and privacy for all individuals within the European Union and the European Economic Area, also addressing the transfer of personal data outside these areas.
A law that governs the collection, use, and disclosure of personal data by organizations in Singapore, ensuring that individuals' data is protected while recognizing the need of organizations to use data for legitimate purposes.
One of the world's strictest data protection laws, regulating the processing of personal information by both public and private sector entities in South Korea.
A comprehensive data privacy law that gives individuals control over their personal data and regulates how businesses process that data.
The primary EU regulation on data protection. Key Terms: 1. Data Subject: The individual whose personal data is being processed. 2. Data Controller: The entity determining the purposes and means of processing data. 3. Right to Erasure: The right for individuals to have their data deleted.
A state statute intended to enhance privacy rights and consumer protection for residents of California. Key Terms: 1. Personal Information: Information that identifies or relates to a particular consumer. 2. Sale: Any transfer of personal info for monetary or other valuable consideration. 3. Opt-out: The right to stop a business from selling your information.
Brazil's comprehensive data protection law. Key Terms: 1. Treatment: Any operation carried out with personal data (collection, storage, use). 2. Anonymization: Use of technical means to ensure data cannot be linked to an individual. 3. Legal Basis: A justification required by law to process personal data.
Legislation to promote the protection of personal information processed by public and private bodies. Key Terms: 1. Responsible Party: The entity that decides why and how to process data. 2. Operator: A person who processes data for a responsible party. 3. De-identify: To delete information that identifies a data subject.
The federal privacy law for private-sector organizations in Canada. Key Terms: 1. Commercial Activity: Any transaction or act that is of a commercial character. 2. Meaningful Consent: Organizations must state why they need data in a way people can understand. 3. Personal Information: Info about an identifiable individual.
A comprehensive data protection law that regulates how personal data of individuals in the EU is collected, used, and stored by businesses.
A landmark law that provides California residents with various rights regarding how businesses handle their personal information, including the right to know what data is collected and the right to delete it.
Establishes a framework for personal data protection in Virginia, requiring businesses to conduct data protection assessments and providing consumers with rights to access and correct their data.
The CPA grants Colorado residents rights over their personal data and places specific duties on data controllers regarding data security and transparency.
A federal law that required the creation of national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge.
Imposes requirements on operators of websites or online services directed to children under 13 years of age regarding the collection of personal information.
Brazil's comprehensive data protection law that regulates the processing of personal data of individuals in Brazil, regardless of where the data processor is located.
A unified legal framework for the use and processing of personal data of individuals located in Brazil, regardless of where the data processor is located.
A consumer-friendly privacy law that outlines the responsibilities of data controllers and processors while providing residents with data control.
A comprehensive data protection framework that governs how the personal data of individuals in the EU can be collected, used, and processed by organizations worldwide.
Provides California residents with greater control over the personal information that businesses collect about them, including the right to opt-out of the sale of their data.
Federal law that required the creation of national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge.
Brazil's primary data protection law which regulates the processing of personal data of all individuals located in Brazil, regardless of where the data processor is headquartered.
A comprehensive data privacy and security law that imposes obligations onto organizations anywhere, so long as they target or collect data related to people in the EU.
Establishes a framework for personal data rights in Virginia, requiring businesses to provide consumers with notice and the ability to opt-out of certain data uses.
Provides Colorado residents with rights regarding their personal data and requires entities to follow specific data protection duties.
The federal privacy law for private-sector organizations in Canada that sets out ground rules for how businesses must handle personal information.
A comprehensive data privacy law that regulates how companies collect, use, and store personal data of individuals within the European Union, imposing strict requirements on data handling and cross-border transfers.
A state statute intended to enhance privacy rights and consumer protection for residents of California, providing residents with control over their personal information.
Governs the collection, use, and storage of biometric identifiers and information by private entities in Illinois.
The federal privacy law for private-sector organizations in Canada that sets out ground rules for how businesses handle personal information in the course of commercial activity.
A comprehensive data protection law that unifies over 40 different statutes in Brazil to regulate the processing of data of individuals within the country.
A state-level privacy framework that provides Virginia consumers with specific rights and requires businesses to adhere to data minimization and security practices.
A comprehensive data protection framework that governs how the personal data of individuals in the EU is collected, used, and stored, applying to any organization worldwide that targets or collects data from EU residents.
A state statute intended to enhance privacy rights and consumer protection for residents of California, giving them more control over the personal information businesses collect.
Brazil's primary data protection law which creates a legal framework for the use of personal data of individuals regardless of where the data processor is located.
The federal privacy law for private-sector organizations in Canada that sets out ground rules for how businesses must handle personal information in the course of commercial activity.
A comprehensive data privacy law in Virginia that grants consumers rights over their data and imposes duties on businesses to protect that data.
The central data privacy law in Japan that regulates the handling of personal information by business operators, including cross-border data transfers.
A comprehensive data privacy law that regulates how companies collect, use, and share the personal data of individuals within the EU.
Provides California residents with significant control over the personal data that businesses collect about them.
A comprehensive data privacy law that regulates how personal data of individuals in the EU is collected and processed.
Provides California residents with the right to know what personal information is being collected and the right to stop its sale.
A comprehensive privacy law that regulates how the personal data of individuals in the EU is collected, used, and protected, applying to any organization worldwide that targets or collects data from EU residents.
A state statute intended to enhance privacy rights and consumer protection for residents of California, giving them more control over the personal information that businesses collect about them.
Brazil's primary data protection law that creates a legal framework for the use of personal data of individuals in Brazil, regardless of where the data processor is located.
A federal law governing how private-sector organizations collect, use, and disclose personal information in the course of for-profit, commercial activities in Canada.
One of the world's strictest data protection regimes, governing the processing of personal information by almost all entities and individuals in South Korea.
The central data privacy law in Japan that regulates the handling of personal information by private enterprises.
A comprehensive data protection framework that sets a high standard for how the personal data of EU citizens is collected, processed, and stored by organizations worldwide.
A state-level law that provides California residents with various rights regarding their personal information and regulates how businesses handle that data.
Governs the collection, storage, and usage of biometric identifiers, such as fingerprints, facial scans, and retina scans by private entities.
Brazil's comprehensive regulatory framework for the protection of personal data, heavily inspired by the GDPR.
Applies to private-sector organizations across Canada that collect, use, or disclose personal information in the course of commercial activities.
The primary law in Japan regulating the handling of personal data by business operators, including cross-border data transfers.
Federal privacy law for private-sector organizations in Canada that sets out rules for how businesses handle personal information in the course of commercial activity.
A comprehensive data protection framework that governs how the personal data of individuals in the EU is collected, processed, and stored.
A state statute intended to enhance privacy rights and consumer protection for residents of California.
Regulates the collection of personal information from children under the age of 13 by operators of websites and online services.
Brazil's comprehensive data protection law that creates a legal framework for the use of personal data of individuals in Brazil.
Imposes requirements on operators of websites or online services directed to children under 13 years of age regarding data collection.
A comprehensive data protection law that regulates how the personal data of EU citizens is collected, used, and protected globally.
A state-level law providing California residents with increased control and transparency regarding their personal information held by businesses.
Federal legislation governing how private-sector organizations handle personal information during commercial activities.
Brazil's primary legal framework for the protection of personal data, largely modeled after the European GDPR.
A federal law designed to protect the privacy of children under the age of 13 by regulating websites and online services.
Establishes national standards for the protection of certain health information, ensuring patient records are kept confidential.
A federal law that sets the rules for how private-sector organizations collect, use, and disclose personal information in the course of commercial business.
South Africa's primary data protection law that regulates the processing of personal information by public and private bodies.
A state-level law giving Utah residents more control over their personal data when interacting with large-scale businesses.
A comprehensive data privacy statute that mandates strict data minimization and provides residents with specific data control rights.
The baseline law for personal data protection in Singapore, governing the collection, use, and disclosure of data by organizations.
Grants California consumers robust control over the personal information that businesses collect about them.
A comprehensive data protection framework that governs how the personal data of individuals in the EU is collected, used, and protected, applying to any organization worldwide that targets or collects data related to people in the EU.
Brazil's comprehensive data protection law that aligns closely with the GDPR, establishing rules for the processing of personal data of individuals located in Brazil.
Federal standards to protect individuals' medical records and other personal health information, applying to health plans, health care clearinghouses, and health care providers.
Provides California residents with transparency and control over how businesses collect and use their personal information, including the right to opt-out of data sales.
A comprehensive state privacy law that grants Virginia consumers rights over their data and imposes obligations on data controllers and processors.
Establishes a framework for personal data protection in Colorado, requiring businesses to implement security safeguards and honor consumer privacy requests.
The primary federal law regulating how Australian government agencies and many private sector organizations handle personal information.
Japan's core privacy law regulating the handling of personal information by private enterprises, significantly amended to align with international standards.
Thailand's first comprehensive data protection law, modeled after the GDPR, governing the collection, use, and disclosure of personal data.