Data privacy regulations are legal frameworks that protect the personal data of citizens or residents within specific jurisdictions, granting individuals rights over how businesses collect, store, and use their information. These data privacy regulations can exist at the multi-national, national, state, and local levels.
Typically, data privacy regulations apply to commercial organizations and can dictate how they collect, store, and process personally identifiable information (PII). They can affect businesses operating in a location even if the business is located elsewhere.
The types of personal data that are protected, as well as how long data can be stored and what purposes it can be used for, can vary greatly for each regulation. Proper data governance is essential for compliance. Non-compliance can lead to different outcomes per guideline but can include warnings, bans on an organization’s ability to process personal data, and fines of up to millions or even billions of dollars.
More than 100 such laws now exist worldwide. This page explains how the major regulations work; for the complete reference of data privacy laws by country and U.S. state, see our dedicated guide.
Examples of Data Privacy Regulations
What is The General Data Protection Regulation (GDPR)?
GDPR is a data privacy law that protects the privacy of individuals in the European Union. It includes a list of privacy rights of individuals in the EU and also includes data protection principles that organizations processing personal data must uphold. Examples of protected data under GDPR include names, email addresses, physical addresses, ethnicity, gender, and web cookies.
GDPR principles stipulate several requirements. For example, they require that data is processed following all laws and in a way that’s fair and transparent to the individual. They also require that the purpose of processing the data be specified when it’s collected and that organizations only collect as much data as needed for that purpose. The individual’s data must be kept up-to-date for as long as the business stores it, and the data can’t be kept any longer than needed for the purpose it was collected for.
GDPR also requires that safety measures — including consent management mechanisms — are taken when processing data to preserve confidentiality and security, and restricts who within an organization can have access to personal data and who will be responsible for demonstrating compliance.
What is The California Consumer Privacy Act (CCPA)?
CCPA protects California residents, even if they’re temporarily not in the state. It gives them rights such as knowing the information a business collects and how the organization will use and share the data. It also gives them the right to delete personal data that a business collects, opt out of their information being sold, and the right to non-discrimination if they decide to exercise any of their rights under CCPA.
CCPA protects personally identifiable information (PII) as well as information that can be linked to a household such as names, emails, social security numbers, purchase history, online browsing history, geolocation data, and fingerprints.
Unlike GDPR, CCPA has more specific requirements for the businesses it applies to, such as annual gross revenue, the number of California residents it buys, receives, or sells data from, or how much of the organization’s revenue is from selling residents’ personal data.
The 2026 regulations changed what compliance requires. A CCPA regulation package that took effect January 1, 2026 made the law operational rather than declaratory: businesses must now complete a risk assessment before selling or sharing personal data, processing sensitive personal data, or deploying certain automated technologies; they must give consumers a way to confirm whether an opt-out request — including one sent through the Global Privacy Control — was honored; requests to know reach back to January 1, 2022 where data is held longer than a year; and a correction must survive a recurring source re-supplying the old value. The automated decision-making provisions (pre-use notice, access, and a right to opt out) become operative January 1, 2027, and cybersecurity audit certifications phase in from April 1, 2028 by revenue band. Applicability figures are indexed to the Consumer Price Index and reset every odd-numbered year — the revenue threshold is $26,625,000 as of January 1, 2025, not the $25 million in the original statute — so cite the CPPA’s current schedule rather than a fixed number. The same indexation reaches the statutory damages a consumer can recover under the CCPA’s data-breach private right of action: $107 to $799 per consumer per incident, up from the $100 to $750 in the original statute.
What is The Personal Information Protection and Electronic Documents Act (PIPEDA)?
PIPEDA is one of Canada’s national privacy laws, though the country also has a separate Privacy Act. It applies to all private-sector organizations operating in Canada that conduct commercial activity and handle personal information.
The act generally protects information such as names, DNA, ages, marital status, race, national or ethnic origin, medical history, education history, employment history, financial information, and identifying numbers like a social insurance number. To comply with PIPEDA, businesses must adhere to 10 principles similar to those under GDPR.
What Are U.S. State Privacy Laws?
The United States has no federal comprehensive privacy law, so the operative rules come from the states: 24 states have enacted comprehensive consumer privacy laws, 20 of them in effect as of July 2026. California’s CCPA, as amended by the CPRA, remains the broadest — it is the only state law that also covers employee and business-to-business data, and the only one enforced by a dedicated regulator, the California Privacy Protection Agency. Most other states follow the Virginia model, which grants rights to access, correct, delete, and opt out of sale, targeted advertising, and profiling, but omits GDPR-style lawful-basis and data-protection-officer requirements.
Applicability is threshold-based rather than location-based. Most state laws reach only businesses that process personal data of 100,000 or more residents of that state, or 25,000 residents when the business earns revenue from selling data — so whether a law applies depends on your customer footprint in the state, not on where the company is headquartered. Alabama, Louisiana, Oklahoma, and Vermont are the four most recent additions, taking effect between 2027 and 2028. For state-by-state effective dates, applicability thresholds, and penalty amounts, see U.S. data privacy laws by state.
How Major Data Privacy Regulations Compare
The strictest data privacy regulations by penalty are the EU’s GDPR (up to €20 million or 4% of global annual revenue) and China’s PIPL (up to ¥50 million or 5% of annual revenue). The table below compares the major regulations in force as of 2026:
| Regulation | Jurisdiction | Effective | Who It Protects | Maximum Penalty |
|---|---|---|---|---|
| GDPR (General Data Protection Regulation) | European Union / EEA | May 25, 2018 | Individuals in the EU/EEA | €20 million or 4% of global annual revenue, whichever is higher |
| CCPA/CPRA (California Consumer Privacy Act, as amended) | California, USA | Jan 1, 2020 (CPRA amendments Jan 1, 2023; 2026 regulations Jan 1, 2026) | California residents | $2,663 per violation; $7,988 per intentional violation or one involving a consumer under 16 (CPI-adjusted Jan 1, 2025; assessed per consumer — fines compound at scale) |
| PIPEDA (Personal Information Protection and Electronic Documents Act) | Canada (federal, private sector) | Fully in force Jan 1, 2004 | Canadian consumers | CAD $100,000 per offence (breach-reporting and obstruction offences only) |
| PIPL (Personal Information Protection Law) | China | Nov 1, 2021 | Individuals in China | ¥50 million or 5% of annual revenue |
| LGPD (Lei Geral de Proteção de Dados) | Brazil | Sep 18, 2020 | Individuals in Brazil | 2% of Brazil revenue, capped at R$50 million per violation |
| DPDP Act (Digital Personal Data Protection Act) | India | Enacted Aug 2023; rules phasing in through 2027 | Individuals in India | ₹250 crore (approx. US$30 million) |
Penalties are only part of the picture. These regulations also differ in the individual rights they grant — access, deletion, portability, opt-out of sale — and in cross-border transfer rules. PIPL, for example, requires security assessments before transferring personal information outside China, a data-residency constraint GDPR and CCPA do not impose.
What Data Privacy Regulations Mean for Customer Data Strategy
For marketing and data teams, privacy regulations translate into three operational requirements: capturing consent, honoring it in every channel, and deleting customer data on request.
- Consent must be enforced everywhere, not just recorded. Email, advertising, and analytics systems all need to respect the customer’s current consent state, not the state at the time of collection.
- Deletion requests must propagate. When a customer exercises their right to erasure, every system holding a copy of their record must execute it — practical only when customer data is unified rather than scattered across tools.
- Regulations reward centralized first-party data. A governed, single view of the customer — for example in a customer data platform (CDP) — makes rights fulfillment and audit trails tractable.
Common Data Privacy Compliance Mistakes
Most compliance failures start as reasonable assumptions that hold until an audit, a deletion request, or a regulator’s questionnaire tests them. Each of the four below costs less to fix as a data privacy governance control than as an enforcement response.
Treating the strictest law as a superset. Teams build a GDPR program and assume it satisfies everything else. It does not. CCPA grants an opt-out of sale and sharing that GDPR has no direct equivalent for, reaches employee and business-to-business records, and requires businesses to honor the Global Privacy Control signal; PIPL adds a mandatory government security assessment for cross-border transfers above certain thresholds, a state pre-clearance step that GDPR’s self-administered transfer mechanism (standard contractual clauses, binding corporate rules, and a documented transfer impact assessment) does not require. Fix: map obligations jurisdiction by jurisdiction against your customer footprint, then build to the union of them, not to one law.
Recording consent without recording proof. A checkbox that flips a boolean in a marketing tool cannot show what the customer agreed to. GDPR Article 7(1) puts the burden on the controller to demonstrate that consent was given — which means retaining the purpose, the timestamp, the channel, and the version of the notice the customer saw. Fix: store each consent decision as an immutable event carrying its scope and notice version, not as a mutable field on a profile.
Leaving processors and ad platforms out of scope. Liability does not transfer with the data. Under GDPR the controller remains accountable for every processor it engages, and under the CCPA an audience uploaded to an ad platform for cross-context behavioral advertising counts as sharing that consumers can opt out of, whatever the platform’s terms say. Fix: keep a current register of every vendor that receives personal data, with its contract basis and the purposes it is permitted to use the data for.
Calling pseudonymized data anonymous. Hashing an email address does not take it out of scope. GDPR Article 4(5) defines pseudonymization as processing that leaves data attributable to a person only with additional information, and Recital 26 keeps that data in scope as personal data — which is what hashed identifiers sent to ad platforms during data onboarding typically are, unless the hashing scheme genuinely forecloses re-identification on both sides. Fix: classify every identifier by whether re-identification is possible, and apply data minimization to the fields that fail that test.
FAQ
Is there a federal data privacy law in the United States?
No — the United States has no comprehensive federal consumer privacy law, so the operative rules come from the states, 24 of which have enacted comprehensive consumer privacy laws (20 in effect as of July 2026). Federal statutes address specific sectors and data types instead, such as health information under HIPAA and financial data under GLBA, leaving general consumer privacy to state law. California’s CCPA/CPRA is the broadest state law and the only one enforced by a dedicated privacy regulator.
What happens if a company violates data privacy regulations?
Violations can result in fines of up to €20 million or 4% of annual global revenue under GDPR — whichever is higher. Beyond fines, companies may face enforcement actions like bans on processing personal data, mandatory audits, and legal action from affected individuals. Reputational damage and loss of customer trust can also have long-term business impacts.
Do data privacy regulations apply to companies outside their jurisdiction?
Yes — many privacy regulations have extraterritorial reach and apply to companies processing data of residents in that jurisdiction, regardless of where the company is located. GDPR applies to any organization processing the data of individuals in the EU, and CCPA applies to businesses handling California residents’ data. This means companies worldwide must comply if they serve customers in these regions.
How often do data privacy regulations change?
Data privacy regulations evolve continuously — new laws are introduced every year at national, state, and local levels, and existing regulations are amended to address gaps. Companies should monitor regulatory developments quarterly and work with legal counsel to maintain compliance as requirements change. A customer data platform with consent enforcement and deletion propagation can help operationalize specific obligations: honoring opt-outs across channels and executing deletion requests against unified profiles. Enterprise CDPs including Salesforce Data Cloud, Adobe Real-Time CDP, and Treasure AI (formerly Treasure Data) natively support consent enforcement and deletion-request propagation across unified profiles. Compliance itself, however, remains a legal and governance function first.
Related Terms
- Data Masking — Technique for protecting PII to meet regulatory requirements
- Cookieless Tracking — Privacy-compliant alternative emerging from stricter regulations
- Data Clean Room — Enables data collaboration without exposing regulated personal data
- Consent Management — Operationalizes regulatory consent requirements across channels
This article is also available in: データプライバシー規制とは?個人情報保護法とGDPRを解説 · Leis de proteção de dados: alcance e fiscalização · Regulaciones de privacidad de datos: LFPDPPP, RGPD · Réglementations sur la protection des données : définition