National and Regional Frameworks

4 slides · 2 min read · Domain 1

National and Regional Examples

At its heart, GDPR consists of rules, regulations and penalties that provide European citizens more control over their own personal data.

However, each member state within the European Union has their own set of legislation for privacy and data protection and in 2020 there were more than 50 areas where individual member states could use their own legislation instead of GDPR.

GDPR not only applies to any organization operating (based) within the EU but also to any and all organizations providing goods and services to individuals or organizations within the EU. This effectively means that every corporation globally will need to have a strategy in place that provides a GDPR compliance-like solution for data transfer to and from the EU.

The problem arises from the fact that many countries often don't have the same expectation of privacy. Within the U.S. the HIPAA protects healthcare records while the Gramm-Leach-Bliley Act protects financial records. However, more general data may not be protected to the same degree. The issue is further complicated because state and federal law may be different.

Here are 11 countries and one state that have GDPR-like legislation

Text on this slide

BRAZIL

Legislation: Lei Geral de Proteção de Dados (LCPD) (2018)

  • Compliance required within 18 months
  • Note: Based directly on GDPR.

CANADA

Legislation: Digital Charter Implementation Act (2020)

CHILE

Legislation: Constitutional change (2018)

  • Note: Chile amended its constitution to declare data privacy a human right.

JAPAN

Legislation: Protection of Personal Information Act (amended 2017)

  • Note: Applies to both domestic and foreign companies.

CHINA

Legislation: Personal Information Protection Law (2020)

NEW ZEALAND

Legislation: 1993 Privacy Act

  • Note: Misses some key GDPR elements.

THAILAND

Legislation: Personal Data Protection Act (PDPA) (2019)

  • AUSTRALIA

Legislation: Australia's Privacy Act (Notifiable Data Breaches) amendment (1988)

  • Note: Where there is a risk of harm, any organization turning over $3 million (Australia), must disclose data breaches within 30 days.

INDIA

Legislation: India's Personal Data Protection Bill (PDPB)

SOUTH KOREA

Legislation: Personal Information Protection Act (PIPA) (2011)

CALIFORNIA

Legislation: California Consumer Privacy Act (CCPA) (2018)

  • Note: While it doesn't quite align, but there are a lot of overlaps, this is the strongest protection within the U.S.

SOUTH AFRICA

Legislation: Protection of Personal Information Act (POPIA) (2020, enforcement to begin July 2021)

Test this domain