National and Regional Frameworks
4 slides · 2 min read · Domain 1
National and Regional Examples
At its heart, GDPR consists of rules, regulations and penalties that provide European citizens more control over their own personal data.
However, each member state within the European Union has their own set of legislation for privacy and data protection and in 2020 there were more than 50 areas where individual member states could use their own legislation instead of GDPR.
GDPR not only applies to any organization operating (based) within the EU but also to any and all organizations providing goods and services to individuals or organizations within the EU. This effectively means that every corporation globally will need to have a strategy in place that provides a GDPR compliance-like solution for data transfer to and from the EU.
The problem arises from the fact that many countries often don't have the same expectation of privacy. Within the U.S. the HIPAA protects healthcare records while the Gramm-Leach-Bliley Act protects financial records. However, more general data may not be protected to the same degree. The issue is further complicated because state and federal law may be different.
Here are 11 countries and one state that have GDPR-like legislation
Text on this slide
BRAZIL
Legislation: Lei Geral de Proteção de Dados (LCPD) (2018)
- Compliance required within 18 months
- Note: Based directly on GDPR.
CANADA
Legislation: Digital Charter Implementation Act (2020)
CHILE
Legislation: Constitutional change (2018)
- Note: Chile amended its constitution to declare data privacy a human right.
JAPAN
Legislation: Protection of Personal Information Act (amended 2017)
- Note: Applies to both domestic and foreign companies.
CHINA
Legislation: Personal Information Protection Law (2020)
NEW ZEALAND
Legislation: 1993 Privacy Act
- Note: Misses some key GDPR elements.
THAILAND
Legislation: Personal Data Protection Act (PDPA) (2019)
- AUSTRALIA
Legislation: Australia's Privacy Act (Notifiable Data Breaches) amendment (1988)
- Note: Where there is a risk of harm, any organization turning over $3 million (Australia), must disclose data breaches within 30 days.
INDIA
Legislation: India's Personal Data Protection Bill (PDPB)
SOUTH KOREA
Legislation: Personal Information Protection Act (PIPA) (2011)
CALIFORNIA
Legislation: California Consumer Privacy Act (CCPA) (2018)
- Note: While it doesn't quite align, but there are a lot of overlaps, this is the strongest protection within the U.S.
SOUTH AFRICA
Legislation: Protection of Personal Information Act (POPIA) (2020, enforcement to begin July 2021)
