Hunton Andrews Kurth LLP | Aaron P Simpson, Lisa J Sotto and Michael La Marca

European Union | Global | OECD | United Kingdom | USA

This introduction aims to highlight the main developments in the international privacy and data protection arena in the past year. The first introduction to this publication in 2013 noted the rapid growth of privacy and data protection laws across the globe and reflected on the commercial and social pressures giving rise to these global developments. Those economic and social pressures have not diminished since that first edition, and they are increasingly triggering new initiatives from legislators to regulate the use of personal information.

The exponential increase of privacy and data protection rules fuels the idea that personal information has become the new ‘oil’ of today’s data-driven economies, with laws governing its use becoming ever more significant.

The same caveat as in previous editions still holds true today: as privacy and data protection rules are constantly evolving, any publication on the topic is likely to be outdated shortly after it is circulated. Therefore, anyone looking at a new project that involves the jurisdictions covered in this publication should verify whether there have been new legislative or regulatory developments since the date of writing.

Convergence of laws

In previous editions of this publication, the variation in the types and content of privacy and data protection laws across jurisdictions has been highlighted. It has also been noted that, although privacy and data protection laws in different jurisdictions are far from identical, they often focus on similar principles and common themes.

Policymakers from various parts of the world have been advocating the need for convergence between the different families of laws and international standards since the early days of data protection law. The thought was that, gradually, the different approaches would begin to coalesce and that global standards on data protection would emerge over time. While there is little doubt that convergent approaches to data protection would benefit both businesses and consumers, truly global privacy and data protection standards, at this time, remain illusory.

Data protection rules are inevitably influenced by legal traditions, cultural and social values, and technological developments, which differ from one part of the world to another. Global businesses should consider this, especially if they are looking to introduce or change business processes across regions that involve the processing of personal information (eg, about consumers or employees). Although it makes absolute sense for global businesses to implement common standards for privacy and data protection throughout their organisation, regardless of where personal information is collected or further processed, there will always be differences in local laws and practices that will need to be carefully considered.

International instruments

There are a number of international instruments that continue to have a significant influence on the development of privacy and data protection laws.

The main international instruments are:

  • the Convention for the Protection of Individuals with regard to the Automatic Processing of Personal Data (Convention 108+) of the Council of Europe;
  • the OECD Privacy Recommendations and Guidelines (OECD Guidelines);
  • the European Union General Data Protection Regulation (GDPR);
  • the Asia-Pacific Economic Cooperation (APEC) Privacy Framework (the Framework); and
  • the African Union Convention on Cyber Security and Personal Data Protection.

Convention 108 was initially adopted in 1981 but was revised in 2018 to more closely reflect the data protection norms prevailing at that time. The newly adopted form is known as Convention 108+. Prior to its 2018 update, Convention 108 had been ratified by 53 countries; in June 2018, Cape Verde and Mexico became the fifth and sixth non-European countries, after Mauritius, Uruguay, Senegal and Tunisia, to ratify Convention 108; in 2023, the Republic of Moldova signed the modified Convention 108+, and France, Iceland and Argentina ratified it. As of the time of writing, 45 countries have signed and 23 countries have ratified the modified Convention 108+. Among other things, the modified Convention now includes genetic and biometric data as additional categories of sensitive data, a modernised approach to data subject rights (by recognising a right not to be subjected to automated decision-making without the data subject’s views being taken into account, and that individuals should be entitled to understand the underlying reasoning behind such processing), and explicitly requires signatories to clearly set forth the available legal bases for processing personal data. Convention 108+ also requires each party to establish an independent authority to ensure compliance with data protection principles and sets out rules on international data transfers. Convention 108+ is open to signature by any country and claims to be the only instrument providing binding standards with the potential to be applied globally. It has arguably become the backbone of data protection laws in Europe and beyond.

The OECD Guidelines are not subject to a formal process of adoption but were put in place by the Council of the OECD in 1980. Like Convention 108, the OECD Guidelines have been reviewed and revisions were agreed in July 2013. Where mostly European countries have acceded to Convention 108, the OECD covers a wider range of countries, including the United States, which has accepted the Guidelines.

Convention 108+ (and its predecessor Convention 108) and the OECD Guidelines originally date from the 1980s. By the 1990s, the EU was becoming increasingly concerned about divergences in data protection laws across EU member states and the possibility that these divergences could impact intra-EU trade. The EU, therefore, passed the Data Protection Directive 95/46/EC, which was implemented by the EU member states with a view to creating an EU-wide framework for harmonising data protection rules. Data Protection Directive 95/46/EC remained the EU’s governing instrument for data protection until the GDPR came into force on 25 May 2018.

In 2004, these instruments were joined by a newer international instrument in the form of the APEC Privacy Framework, which was updated in 2015. Although it was subject to criticism when it was launched, the Framework has been influential in advancing the privacy debate in the Asia-Pacific region. The Framework aims to promote a flexible approach to privacy and data protection across the 21 APEC member economies while fostering cross-border flows of personal information. In November 2011, APEC leaders endorsed the Cross-Border Privacy Rules (CBPR) system, which is a voluntary accountability-based system to facilitate privacy-respecting flows of personal information among APEC economies. The APEC CBPR system is considered a counterpart to the European Union’s system of binding corporate rules (BCRs) for data transfers outside the EU. As of the date of publication, nine economies participate in the APEC CBPR system: the United States, Mexico, Japan, Canada, Singapore, the Republic of Korea, Australia, Taiwan and the Philippines.

In June 2014, the African Union adopted a Convention on Cyber Security and Personal Data Protection as the first legal framework for cybersecurity and personal data protection on the African continent. Its goal is to address the need for harmonised legislation in the area of cybersecurity in the member states of the African Union, and to establish in each member state mechanisms to combat privacy violations. To date, the Convention has been signed by 18 African countries and ratified by 14. It has been reported that a number of African countries have drafted data protection laws based on the Convention.

The European approach

For more than 20 years, data protection laws have been a salient feature of European legal systems. Prior to the GDPR, each EU member state introduced legislation based on the Data Protection Directive 95/46/EC, which made it mandatory for member states to transpose the Directive’s data protection principles into their national laws. In the same way, EU member state rules on electronic communications, marketing and the use of cookies continue to follow the requirements of EU Directive 2002/58/EC on privacy and electronic communications.

Prior to the GDPR, the data protection laws of the EU member states, the European Free Trade Association (Iceland, Liechtenstein and Norway) and EFTA-country Switzerland broadly followed the same pattern since they were all based on or at least inspired by the Data Protection Directive 95/46/EC. However, because the Data Protection Directive 95/46/EC was not directly applicable, the laws adopted diverged in many areas. This led to inconsistencies, which created complexity, legal uncertainty and additional costs for businesses, which were required to comply with, in many cases, 31 different data protection laws in Europe.

This was one of the primary reasons why the European Commission introduced its EU Data Protection Reform in January 2012, which included the GDPR as well as a Data Protection Directive for the police and criminal justice sector (the Police and Criminal Justice Data Protection Directive). The GDPR establishes a single set of rules directly applicable throughout the EU, intended to streamline compliance for companies doing business in the EU. The European Commission estimated that the GDPR could lead to cost savings for businesses of around €2.3 billion a year.

After four years of negotiations, in 2015, the European Parliament, the Council of the EU and the European Commission reached a compromise on a new and arguably more harmonised data protection framework for the EU. The Council and the Parliament adopted the GDPR (EU 2016/679) and the Police and Criminal Justice Data Protection Directive (EU 2016/680) in April 2016, and the official texts were published the following month. While the GDPR entered into force in 2016, it became effective in 2018. The Police and Criminal Justice Data Protection Directive entered into force in May 2016, and EU member states had until May 2018 to transpose it into their national laws.

The GDPR has been one of the most significant developments in the history of EU and international data protection law. The impact of the GDPR is not confined to businesses based in the EU, as it applies to any processing of personal information conducted from outside the EU that involves the offering of goods or services to individuals in the EU or the monitoring of individuals in the EU as well.

All EU member states have now enacted local data protection laws to supplement the GDPR in a range of areas (eg, sensitive data processing and data processing for employment purposes), with Slovenia becoming the last to do so in January 2023. However, these legislative initiatives at the member state level are not aligned and, therefore, businesses find themselves – once again – in a situation where they must comply with different member state laws in addition to the GDPR. Furthermore, many data protection authorities in the EU have published their own guidance and recommendations on how to comply with the GDPR, regardless of the guidelines that are being adopted at the EU level (by representatives of the EU member state data protection authorities known as the European Data Protection Board). This variety of guidance and recommendations at the EU and member state levels has triggered confusion for businesses that must comply with the GDPR.

In 2016, the European Commission launched a public consultation on the review of the ePrivacy Directive. This review, which was intended to pursue consistency between the ePrivacy Directive and the GDPR, raised questions about whether it is still necessary and meaningful to have separate rules on electronic privacy now that the GDPR has been adopted. Following the 2016 consultation, on 10 January 2017, the European Commission adopted a proposal for a Regulation on Privacy and Electronic Communications (the ePrivacy Regulation), which was intended to replace the ePrivacy Directive. The proposal was forwarded simultaneously to the European Parliament, the Council and member state parliaments, as well as to the Committee of the Regions and the Economic and Social Committee for review and adoption. The goal was to have the final text adopted by May 2018, when the GDPR became applicable, but that goal was not achieved. On 11 February 2025, after multiple rounds of revisions to the proposed ePrivacy Regulation, the European Commission stated in its 2025 Commission work programme that it would withdraw the proposal. The European Commission explained that the measure had become outdated given more recent developments in technology and in the broader legislative framework. As of May 2026, the European Commission has not introduced a replacement for the withdrawn ePrivacy Regulation.

In addition to revamping the legal framework for general data protection, there has been an increased focus on cybersecurity in the EU. Since the adoption of its EU Cybersecurity Strategy in 2013, the European Commission has made laudable efforts to better protect Europeans online, which culminated in an action plan to further strengthen the EU’s cyber resilience by establishing a contractual public-private partnership (PPP) with industry in July 2016. In addition, in July 2016, the European Parliament adopted the Network and Information Security (NIS) Directive, which aims to protect critical infrastructure in sectors such as energy, transport, banking and health, as well as key internet services. Businesses in these critical sectors must take additional security measures and notify serious data incidents to the relevant authorities. The NIS Directive entered into force in August 2016 and EU member states had until May 2018 to transpose the NIS Directive into their national laws.

In June 2020, the European Commission launched a public consultation on the revision of the NIS Directive. The European Commission considered a revision to be necessary, as cybersecurity capabilities in EU member states remain unequal despite the progress made with the NIS Directive, and the level of protection in the EU is insufficient. In addition, the rapid digitalisation of society has expanded the threat landscape and presents new challenges, requiring adaptive and innovative responses. In December 2020, a new legislative proposal was presented by the European Commission (NIS 2 Directive), and in May 2022, the European Parliament and the Council of the EU reached a political agreement on the NIS 2 Directive. The Directive was published in the Official Journal of the European Union in December 2022, and EU member states must have adopted and published measures necessary to comply by 17 October 2024, and applied those measures beginning on 18 October 2024. The NIS 2 Directive broadens the scope of the original NIS Directive and imposes cybersecurity requirements relating to incident response, supply chain security, encryption and vulnerability disclosure on organisations operating in ‘important sectors’ (such as waste management, postal services, chemicals, food, medical device manufacturers, digital providers and producers of electronics), in addition to ‘essential sectors’.

For entities operating in the financial sector, the Digital Operational Resilience Act (DORA) entered into force in January 2023 and became applicable in January 2025. DORA aims to ensure that the EU financial sector is able to stay resilient in the event of severe operational disruption by imposing strengthened requirements on financial entities with respect to cybersecurity risk management, third-party risk management, incident management and reporting, and cyber resilience testing.

In the 2016 referendum, the UK voted to leave the EU. In March 2017, the UK’s government formally notified the EU of the UK’s referendum decision, triggering article 50 of the EU’s Lisbon Treaty. This signalled the beginning of the process of leaving the EU. The UK left the EU on 31 January 2020 and entered a Brexit transition period that ended on 31 December 2020. Following the end of the transition period, the GDPR no longer applies directly in the UK. In its place, the UK government enacted the Data Protection, Privacy and Electronic Communications (Amendments, etc) Regulations 2019 (EU Exit), which amends the UK Data Protection Act 2018 and merges it with the requirements of the GDPR to form a data protection regime that will work in a UK context after Brexit. This new regime is known as the UK GDPR.

In February 2021, the European Commission published a draft data protection adequacy decision relating to the UK. The draft decision was adopted in June 2021, enabling organisations in the EU to continue to transfer personal data to organisations in the UK without restrictions. In reaching the decision, the European Commission analysed the data protection legal framework in the UK and concluded that the UK’s data protection regime meets EU data protection adequacy requirements. On 19 December 2025, the European Commission announced its decision to renew the two UK adequacy decisions originally adopted in 2021, stating that the UK’s legal framework continues to provide data protection standards essentially equivalent to those provided in the EU. The UK has, likewise, recognised the EU as providing an adequate level of protection for personal data. In 2022, the UK government announced its intention to review and modernise the UK’s data protection regime, including by diverging from the GDPR in a number of ways to reduce regulatory burdens on business, particularly small businesses. Despite several attempts by the UK government to enact its proposed data protection reform package, the Data Protection and Digital Information (No. 2) Bill, introduced to the UK Parliament in March 2023, failed when the UK government announced its intention to call a general election on 4 July 2024.

In October 2024, the UK Government introduced the draft Data (Use and Access) Act. Following a series of amendments in both Houses of the UK Parliament, it received Royal Assent on 19 June 2025. Its provisions are being commenced in phases, with the earliest taking effect on 19 June 2025. The Data (Use and Access) Act includes some features that resemble earlier reform proposals, but it makes more limited changes to the UK’s existing data protection framework. One notable reform is the introduction of ‘recognised legitimate interests’ as a new lawful basis for processing personal data. This allows organisations to process data for specified purposes without carrying out a legitimate interests assessment. Those purposes include national security, defence, emergency response, and safeguarding vulnerable individuals. The Data (Use and Access) Act also confirms that certain activities may still rely on the ordinary legitimate interests basis, subject to a legitimate interests assessment. These include direct marketing, intra-group data sharing for internal administrative purposes, and network and information security. Other reforms include increased maximum fines under the UK Privacy and Electronic Communications Regulations to align with the UK GDPR, reforms to the structure of the UK data protection authority (the Information Commissioner’s Office), and a revised framework for international transfers of personal data. Under the latter framework, the Secretary of State may approve transfers by regulations if the relevant third country meets the statutory ‘data protection test’, namely that its protections are not materially lower than those in the UK. Although the Data (Use and Access) Act changes some terminology and procedures, it is not expected to significantly affect the practical operation of international data transfers from the UK.

Global perspective

United States and the EU

Moving outside Europe, the picture is more varied. From an EU perspective, the United States is considered by many to have less regard for the importance of personal information protection. However, the United States has had a Privacy Act regulating government departments and agencies since 1974, and there are hundreds of privacy laws at the federal and state level governing various types of information and data processing activities (eg, surveillance laws, biometric data laws and laws requiring online privacy policies).

Contrary to the EU’s omnibus law approach, the United States has historically adopted a sectoral approach to privacy and data protection. For instance, it has implemented specific privacy legislation aimed at protecting children online, the Children’s Online Privacy Protection Act 1998 (COPPA). It has also adopted specific privacy rules for health-related data, the Health Insurance Portability and Accountability Act (HIPAA), and for financial institutions, the Gramm-Leach-Bliley Act (GLBA). This approach has changed in the more recent past, with the enactment in California of the nation’s first comprehensive privacy law, known as the California Consumer Privacy Act of 2018 (CCPA). The CCPA imposes obligations on a range of businesses to provide privacy notices, creates privacy rights of access, deletion and the opportunity to opt out of the sale of personal information, and imposes obligations on businesses to include specified language in their service provider agreements. In November 2020, California voters approved Proposition 24, a ballot referendum to amend the CCPA. Proposition 24, titled the California Privacy Rights Act of 2020 (CPRA), expands certain of the CCPA’s compliance obligations and consumer rights. The CPRA took effect on 1 January 2023. Inspired by California, 20 other US states have enacted similar comprehensive privacy legislation. As a result of this state legislative activity, and absent a comprehensive federal privacy and data security law, US businesses are having to contend with a patchwork of different state requirements. There have been significant efforts to enact privacy legislation at the federal level, but no bills have been finalised at the time of writing.

From a cybersecurity perspective, in October 2015, the US Senate passed the Cybersecurity Information Sharing Act (CISA), which aims to facilitate the sharing of information on cyber threats between private companies and US intelligence agencies. A few months later, the US Department of Homeland Security (DHS) issued guidelines and procedures for sharing information under the CISA. The Judicial Redress Act was enacted in February 2016 as a gesture to the EU that the United States is taking privacy seriously. The Judicial Redress Act is designed to ensure that all EU citizens have the right to enforce data protection rights in US courts. In May 2017, then-President Trump signed an executive order aimed at strengthening the cybersecurity of federal networks and critical infrastructure. In March 2022, President Biden signed into law the Cyber Incident Reporting for Critical Infrastructure Act of 2022, which creates legal protections and provides cybersecurity guidance to companies that operate in critical infrastructure sectors.

The United States also used to be in a privileged position on account of the EU-US Safe Harbor scheme, which had been recognised by the European Commission as providing adequate protection for the purposes of data transfers from the EU to the United States. This formal finding of adequacy for companies that joined and complied with the Safe Harbor was heavily criticised in the EU following the Edward Snowden revelations. On 6 October 2015, in a landmark decision, the Court of Justice of the European Union (CJEU) declared the Safe Harbor invalid. This decision forced thousands of businesses that had relied directly or indirectly on the Safe Harbor to look for alternative ways of transferring personal information from the EU to the US. To address the legal vacuum that was created following the invalidation of the Safe Harbor, the European Commission and the US agreed in February 2016 on a new framework for transatlantic data transfers: the EU-US Privacy Shield.

In accordance with the EU-US Privacy Shield adequacy decision that was adopted in July 2016, the first joint annual review of the Privacy Shield and how it functions in practice took place in September 2017. In its report concluding the first review, the European Commission reiterated its support for the Privacy Shield while outlining certain areas in need of improvement, including the need for ongoing monitoring of compliance with the Privacy Shield Principles by the Department of Commerce and strengthening of the privacy protections contained in the US Foreign Intelligence Surveillance Act (FISA). The Privacy Shield has also been subject to two further joint annual reviews in 2018 and 2019. In the European Commission’s report following the latest review, the Commission welcomed further information provided by US authorities in relation to the Foreign Intelligence Surveillance Act and highlighted a number of steps that should be taken to better ensure the effective functioning of the Privacy Shield (eg, by reducing the grace period that applies when organisations are required to recertify annually to a maximum period of 30 days).

Four years after the EU-US Privacy Shield was adopted, the CJEU invalidated the Privacy Shield on 16 July 2020. In a case now known as Schrems II brought by Max Schrems – the privacy activist who is credited with initiating the downfall of Safe Harbor – the CJEU ruled that the EU-US Privacy Shield was not a valid mechanism to lawfully transfer EU personal data to the United States. In the decision, the CJEU held that:

the limitations on the protection of personal data arising from [US domestic law] on the access and use [of the transferred data] by US public authorities […] are not circumscribed in a way that satisfies requirements that are essentially equivalent to those required under EU law, by the principle of proportionality, in so far as the surveillance programmes based on those provisions are not limited to what is strictly necessary.

Further, the CJEU found that the EU-US Privacy Shield framework does not grant EU individuals actionable rights before a body offering guarantees that are substantially equivalent to those required under EU law. On those grounds, the CJEU declared the EU-US Privacy Shield invalid. Since the Schrems II decision, the United States and EU authorities have successfully negotiated a revised data transfer framework, known as the EU-US Data Privacy Framework, in 2023 to replace the Privacy Shield.

In 2021, the European Commission adopted new standard contractual clauses (SCCs) in replacement of the existing controller-to-controller and controller-to-processor standard contractual clauses, adopted in 2004 and 2010, respectively. The new SCCs may be used by entities subject to the GDPR to ensure an adequate level of protection for personal data transferred to recipients located in jurisdictions not deemed by the EU to provide an adequate level of protection for personal data transferred, which includes the United States. The new SCCs adopt a modular approach and include provisions that may be used for controller-controller, controller-processor, processor-processor and processor-controller data transfers. The primary purpose of the new SCCs is to provide a data transfer mechanism that operates seamlessly with the legal framework of the GDPR. In addition, following the Schrems II decision, the CJEU held that organisations relying on the standard contractual clauses are required to carry out a case-by-case assessment of whether the standard contractual clauses, in fact, provide an adequate level of protection and require organisations to adduce additional contractual, technical and organisational safeguards where that is not the case.

On 2 February 2022, the UK Information Commissioner’s Office published an international data transfer agreement (IDTA) and an international data transfer addendum to the European Commission’s standard contractual clauses (the Addendum) for use by UK exporters. The IDTA and the Addendum came into force on 21 March 2022.

Asia-Pacific

In the Asia-Pacific region, the early adopters of privacy and data protection laws – Australia, New Zealand and Hong Kong – have been joined by most of the other major jurisdictions. In early 2017, Australia amended its privacy act to introduce data breach notification requirements, replacing the previous voluntary regime and, in 2022, to significantly enhance the enforcement powers of the Australian regulator, including the maximum fine it may issue. In December 2024, Australia enacted the Privacy and Other Legislation Amendment Act 2024 (the first tranche of a broader, multi-stage reform programme), which received Royal Assent on 10 December 2024. The reforms introduce enhanced regulator powers (including new search and seizure authority), a tiered civil penalty and infringement notice regime, a statutory tort for serious invasions of privacy, new criminal offences for doxing, transparency requirements for automated decision-making, and code-making powers beginning with a new Children’s Online Privacy Code. Additional reforms are expected in a second tranche, the timing of which remains pending. Beginning 1 July 2026, a further amendment will bring more small businesses within the scope of the Privacy Act. New Zealand also amended its privacy law to enact mandatory data breach notification, effective December 2020. China adopted a comprehensive Cybersecurity Law that came into effect on 1 June 2017. In 2021, China passed two further landmark laws on cybersecurity and data protection. In June 2021, China enacted the Data Security Law, which focuses on data categorisation and classification as well as the protection of certain ‘important data’. In August 2021, China passed the Personal Information Protection Law (PIPL), the first national privacy law in China. Together with China’s Cybersecurity Law, these three laws comprise a comprehensive system of data protection in China. The PIPL includes a set of data processing principles, obligations for data controllers (known as ‘personal information processors’ or ‘data handlers’ under PIPL), a set of rights for individuals, and restrictions on cross-border data transfers, as well as data localisation rules. The Cyberspace Administration of China (CAC) has passed several implementing guidelines with respect to these three laws, including clarifying the regime related to cross-border data transfers. Companies that wish to transfer data outside of China must, subject to certain exemptions for particular categories of data transfers, rely on one of three available transfer mechanisms under PIPL to engage in cross-border transfers. These mechanisms include:

  • undergoing a data transfer security assessment administered by the CAC;
  • signing a model contract that sets out responsibilities for the data exporter and importer and filing a copy of the contract with the CAC; or
  • obtaining a special data protection certification from a designated institution in China.

In October 2025, China passed significant amendments to its Cybersecurity Law, which took effect on 1 January 2026. The amendments introduce dedicated provisions on AI governance and impose new supply chain cybersecurity obligations on both purchasers and suppliers of key network equipment and specialised cybersecurity products. The amendments also increase penalties for non-compliance. In April 2018, the Hong Kong Privacy Commissioner for Personal Data announced plans to review and update the 1996 data protection law in light of the GDPR and recent large-scale data breaches affecting Hong Kong citizens’ personal data. In February 2023, the Privacy Commissioner published a report that included its strategic focus for 2023, and which set out the proposed amendments to the data protection law. These include:

  • establishing a mandatory data breach notification mechanism;
  • requiring creation of a data retention policy, empowering the Privacy Commissioner to impose administrative fines; and
  • introducing direct regulation of data processors.

These proposed amendments remain pending as of 2026. In the interim, the Privacy Commissioner has continued to pursue active enforcement, conducting over 130 investigations between 2024 and 2025, including more than 80 criminal cases, with focus areas including AI governance, data security, doxxing prevention, and cross-border data transfers.

India enacted the Digital Personal Data Protection Act (DPDPA) in August 2023, following a process spanning multiple draft bills over several years. The comprehensive law establishes a consent-driven, rights-based framework governing how organisations process and protect personal data, and creates a Data Protection Board of India as the enforcement authority. The Ministry of Electronics and Information Technology notified implementing rules – the Digital Personal Data Protection Rules 2025 – on 14 November 2025, giving full operational effect to the Act. The Rules introduce a phased compliance timeline of 12-18 months, with immediate obligations around data breach notification and establishment of the Data Protection Board.

In December 2016, Indonesia adopted its first data protection law, which focuses on the processing of personal information through electronic media. In October 2022, the Personal Data Protection Law (PDPL) came into force. The PDPL, which is partly modelled on the EU’s GDPR, includes obligations for data controllers and processors, rights for data subjects, and concepts such as lawful bases for processing and sensitive data.

Japan amended its Personal Information Protection Act in September 2015, creating an independent data protection authority and imposing restrictions on cross-border data transfers (which took effect in September 2017). On 17 July 2018, the EU and Japan successfully concluded negotiations on a reciprocal finding of an adequate level of data protection, thereby agreeing to recognise each other’s data protection systems as equivalent. This will allow personal data to flow legally between the EU (and the UK) and Japan, without being subject to any further safeguards or authorisations. In April 2022, amendments to the Japanese law took effect, which extend the law’s extraterritorial application, impose stricter data breach reporting requirements, and enhance the rights of data subjects. The Personal Data Protection Standard in Malaysia came into force in December 2015 and complements the existing data protection law. In July 2024, the Malaysian Parliament introduced amendments (effective in 2025) revising the definition of personal data and sensitive personal data, and requiring data breach notifications and the appointment of a data protection officer. Additionally, the amendments allow for cross-border data transfers if the importing country has a law substantially similar to, or an adequate level of protection that is consistent with, the Personal Data Protection Standard. In the Philippines, the implementing rules for the Data Privacy Act of 2012 have introduced GDPR-inspired concepts, such as a data protection officer designation and 72-hour breach notification requirements.

Having one of the most advanced data protection regimes in the region (underpinned by the Personal Data Protection Act 2012), Singapore passed its Cybersecurity Act in February 2018, which provides a national framework for the prevention and management of cyber incidents. In February 2021, Singapore enacted significant amendments to the Personal Data Protection Act, including a mandatory data breach notification law to replace previous non-binding breach notification guidance, enhanced data subject rights, and additional grounds for processing personal data, including a ‘legitimate interests’ exception.

South Korea has lived up to its reputation as having one of the strictest data protection regimes in the Asia-Pacific region. The European Commission and the UK government have now both recognised South Korean data protection law as adequate, hence allowing unrestricted transfers of personal information to South Korea. In Taiwan, amendments to the Personal Information Protection Act came into effect in March 2016. The amendments introduced, among other things, rules for processing sensitive personal information. Thailand adopted the Personal Data Protection Act in May 2019, which entered into force on 1 June 2022.

In December 2019, the Vietnamese Ministry of Public Security published a six-part draft Decree on Personal Data Protection, which was released for public comments in February 2021. In April 2023, the final Decree on Personal Data Protection was issued, and the law came into effect on 1 July 2023. In September 2024, Vietnam issued a new draft of its Personal Data Protection Law, which is meant to strengthen data privacy measures. The law was passed by the National Assembly in mid-2025, and implementing rules (Decree 356/2025) took effect on 1 January 2026, replacing the earlier Decree 13/2023.

Central and South America

Latin America has seen a noticeable increase in legislative initiatives in recent years. Only a handful of Latin American countries currently do not have specific privacy and data protection laws. Argentina and Uruguay have modelled their data protection laws on the EU’s approach under the EU Data Protection Directive, which explains why they are the only Latin American countries considered by the European Commission to provide an adequate level of data protection. The process for comprehensively reforming Argentina’s data protection law has been ongoing since 2022 and has not yet resulted in enacted legislation. The original 2023 executive reform bill expired without passage. As of 2025, multiple competing bills have been introduced but a final law has not been adopted. Costa Rica, Panama and Peru have launched similar initiatives to Argentina’s, while in January 2017, Mexico expanded the scope of its data protection law to cover data processing by private and public persons or entities. Nicaragua passed its data protection law in 2012, but it does not have a fully functioning data protection authority at this point. Other countries in Latin America have some degree of constitutional protection for privacy, including a right to habeas data, for example, Brazil and Paraguay. On 10 July 2018, Brazil’s Federal Senate approved a comprehensive data protection bill, known as the Brazilian General Data Protection Law (LGPD) that was inspired by the GDPR. The LGPD has been in force since August 2021, and a national data protection authority was established in August 2020. In 2024, the LGPD was amended to include standard contractual clauses for international data transfers, stricter penalties for non-compliance and greater control for data subjects exercising their own rights. In December 2024, Chile published its Personal Data Protection Law, which becomes effective in December 2026.

Africa

The global gaps in coverage lie in Africa and the Middle East. However, the number of countries with laws impacting personal information is steadily rising in both regions.

As noted earlier, the African Union adopted a Convention on Cyber Security and Personal Data Protection in June 2014. Initially, there were concerns that the Convention was too vague and insufficiently focused on privacy rights. In May 2017, the Commission of the African Union and the Internet Society issued guidelines and recommendations to address these concerns.

An increasing number of African countries are implementing data protection laws as well as cybersecurity regulations, irrespective of the Convention. Angola, for example, introduced its data protection law in 2011 and approved a law in 2016 to create a data protection authority, which started to operate fully in 2020. Equatorial Guinea’s new data protection law entered into force in August 2016 and is clearly inspired by EU data protection standards. Mauritania adopted data protection rules in June 2017, while South Africa passed a data protection law based on the (former) EU model in 2013, which became enforceable on 1 July 2021. In October 2015, the South African government created a virtual national cybersecurity hub to foster cooperation between the government and private companies. It also introduced the Cybercrimes Act, which became enforceable in December 2021. Tanzania passed its Cyber Crime Act in September 2015 and its Personal Data Protection Act in 2022 and, in 2018, Benin updated its earlier 2009 legal framework on data protection. Uganda passed its Data Protection and Privacy Act in 2019 and Data Protection and Privacy Regulations in 2021. Four African countries joined Convention 108 between 2016 and 2017: Cape Verde, Mauritius, Senegal and Tunisia. They were joined by Morocco in 2019. Mauritius also amended its data protection law in light of the EU GDPR, while Morocco published a Q&A in June 2017 and held a seminar in July 2018 on the impact of the GDPR on Moroccan companies. In November 2019, Kenya’s comprehensive Data Protection Act entered into force. In 2020, Egypt adopted its comprehensive Personal Data Protection Law. In 2021, Rwanda, Zambia and Zimbabwe all approved comprehensive data protection laws; in 2022, Eswatini followed suit, and the trend continued with the Democratic Republic of Congo, Somalia and Nigeria in 2023, and Ethiopia, Cameroon and Malawi in 2024. Additionally, in October 2024, Botswana passed the 2024 Data Protection Act, which repealed its 2018 Data Protection Act. Attempts to introduce comprehensive data protection laws in Namibia are also underway.

The Middle East

In the Middle East, there are several laws that cover specific industry sectors but, apart from Israel, few countries have comprehensive data protection laws. Israel updated its data protection law in March 2017 by adding data security-related obligations, including data breach notification requirements. The European Commission recognises Israel as a jurisdiction that provides an adequate level of protection of personal data. Qatar passed its first data protection law in November 2016, followed by Bahrain in 2018, both of which are largely inspired by the EU’s data protection principles. In January 2018, the Dubai International Financial Centre Authority of the UAE amended its existing data protection law to bring it in line with the GDPR. The UAE’s Abu Dhabi Global Market enacted similar amendments to its data protection regulations in 2021, more closely aligning the existing law with the GDPR. In July 2020, the Dubai International Financial Centre (DIFC) enacted a replacement for the previous data protection law in that jurisdiction. The new DIFC data protection law took effect on 1 October 2020. The new data protection law was, in part, an effort to help ensure that DIFC, a financial hub for the Middle East, Africa and South Asia, meets the standard of data protection required to receive an ‘adequacy’ finding from the European Commission and the UK to facilitate cross-border transfers of EU and UK personal data to the DIFC without a separate data transfer mechanism. On 2 January 2022, the UAE’s first federal Data Protection Law came into force.

Conclusion

Now, more than ever, global businesses face the challenge of complying with a myriad of laws and regulations on privacy, data protection and cybersecurity. This can make it difficult to roll out new programmes, technologies and policies with a single, harmonised approach. In some countries, restrictions on cross-border data transfers will apply, while in others, localisation requirements may require data to be kept in the country. In some jurisdictions, processing personal information generally requires individuals’ consent, while in others, consent should be used only in exceptional situations. Some countries have special rules on, for example, employee monitoring. Other countries rely on vague constitutional language to govern data protection.

This publication can hopefully continue to serve as a compass to those doing business globally and help them navigate the (increasingly) murky waters of privacy and data protection.

This article first appeared on Lexology | Source