Every media plan on earth reduces to one question per market, whether personal data can drive targeting before people say yes. This page sorts all 197 jurisdictions by the answer, and the pattern is stark. The regulated world runs on opt-in. One superpower runs on opt-out. A pragmatic middle runs on notice.
Opt-in: permission first (151 jurisdictions)
The GDPR family and its cousins. Tracking, profiling and most marketing need affirmative consent or another tightly drawn legal basis before processing starts. This bloc covers the EU and EEA, the UK, Brazil, China, Korea, Canada, most of Africa and Latin America, and the Gulf. If your campaign can be seen from these markets, permission is the price of entry.
| Jurisdiction | Region | Status | What consent means here |
|---|---|---|---|
| ๐ฆ๐ฑ Albania | Europe | In force | GDPR-aligned bases and consent standard. |
| ๐ฉ๐ฟ Algeria | Middle East & North Africa | In force | Consent-first with authorization duties for sensitive data and transfers. |
| ๐ฆ๐ฉ Andorra | Europe | In force | GDPR-modeled consent and legal bases. |
| ๐ฆ๐ด Angola | Sub-Saharan Africa | In force | Consent-first with authorization duties; APD approval needed for sensitive processing and transfers. |
| ๐ฆ๐ฌ Antigua and Barbuda | Americas | Adopted | Consent-oriented framework; commencement and supervision have been incomplete. |
| ๐ฆ๐ท Argentina | Americas | In force | Consent-first with listed exceptions; the do-not-call registry and marketing opt-outs are enforced. |
| ๐ฆ๐ฒ Armenia | Europe | In force | Consent-first framework. |
| ๐ฆ๐น Austria | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฆ๐ฟ Azerbaijan | Europe | In force | Consent-first framework with registration duties. |
| ๐ง๐ธ Bahamas | Americas | In force | Directive-era consent-oriented rules. |
| ๐ง๐ญ Bahrain | Middle East & North Africa | In force | Consent or listed grounds; direct marketing requires prior consent. |
| ๐ง๐ฉ Bangladesh | Asia-Pacific | Adopted | Consent-based processing under the 2026 Act; the complaints, fines and compensation provisions start only when the government notifies them, no earlier than October 2027. |
| ๐ง๐ง Barbados | Americas | In force | GDPR-modeled consent and bases. |
| ๐ง๐พ Belarus | Europe | In force | Consent is the default basis, with listed exceptions. |
| ๐ง๐ช Belgium | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ง๐ฟ Belize | Americas | In force | GDPR-influenced consent and bases. |
| ๐ง๐ฏ Benin | Sub-Saharan Africa | In force | GDPR-influenced consent and bases inside the Digital Code. |
| ๐ง๐ฆ Bosnia and Herzegovina | Europe | In force | Consent-first framework from the pre-GDPR era. |
| ๐ง๐ผ Botswana | Sub-Saharan Africa | In force | Consent or listed bases; registration duties apply. |
| ๐ง๐ท Brazil | Americas | In force | Ten legal bases including legitimate interests, but consent is expected for cookies and most adtech, and the ANPD's guidance pushes granular banners. |
| ๐ง๐ณ Brunei | Asia-Pacific | In force | Singapore-modeled consent framework for the private sector, with deemed consent concepts. |
| ๐ง๐ฌ Bulgaria | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ง๐ซ Burkina Faso | Sub-Saharan Africa | In force | Consent-first; the 2021 law replaced the 2004 pioneer statute with a modernized framework. |
| ๐ง๐ฎ Burundi | Sub-Saharan Africa | Adopted | A comprehensive law on the francophone African model, with consent as the main basis for processing; private-sector processing had six months to comply, a window that closed on 10 September 2026. |
| ๐จ๐ป Cabo Verde | Sub-Saharan Africa | In force | Consent-first, Portuguese-model framework, updated repeatedly. |
| ๐จ๐ฒ Cameroon | Sub-Saharan Africa | Adopted | Consent-first framework with data protection officer duties; its obligations have applied since the 18-month transition ended on 23 June 2026. |
| ๐จ๐ฆ Canada | Americas | In force | Consent is required for collection, use and disclosure; implied consent works for non-sensitive contexts, but CASL makes commercial email and SMS strictly opt-in with limited implied-consent windows. |
| ๐จ๐ซ Central African Republic | Sub-Saharan Africa | Adopted | Consent-first framework on the francophone African model, in force since January 2024. |
| ๐น๐ฉ Chad | Sub-Saharan Africa | In force | Consent-first framework. |
| ๐จ๐ฑ Chile | Americas | Adopted | GDPR-modeled: consent or another legal basis including legitimate interests, with sensitive-data and children's rules; the outgoing 1999 law was consent-based but toothless. |
| ๐จ๐ณ China | Asia-Pacific | In force | Consent is the workhorse basis, and 'separate consent' is required for sensitive data, cross-border transfers, and sharing with other handlers. No legitimate-interest basis exists. |
| ๐จ๐ด Colombia | Americas | In force | Prior, express and informed consent is the general rule, with a national database registry (RNBD) for larger companies. |
| ๐ฐ๐ฒ Comoros | Sub-Saharan Africa | Adopted | Consent-first framework on paper; with no commission in place, nothing enforces it. |
| ๐จ๐ท Costa Rica | Americas | In force | Express consent is the general rule, with database registration duties. |
| ๐จ๐ฎ Cote d'Ivoire | Sub-Saharan Africa | In force | Consent-first with authorization duties. |
| ๐ญ๐ท Croatia | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐จ๐บ Cuba | Americas | In force | Consent-oriented rules within a state-controlled information system. |
| ๐จ๐พ Cyprus | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐จ๐ฟ Czechia | Europe | In force | GDPR legal basis required; cookie opt-in mandatory since the 2022 Electronic Communications Act amendment. |
| ๐จ๐ฉ Democratic Republic of the Congo | Sub-Saharan Africa | In force | Consent-first, GDPR-influenced provisions inside the 2023 Digital Code. |
| ๐ฉ๐ฐ Denmark | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฉ๐ฏ Djibouti | Sub-Saharan Africa | Adopted | Consent-first rules in Book I of the Digital Code; private-sector processing had one year to comply and the public sector two. |
| ๐ฉ๐ด Dominican Republic | Americas | In force | Consent-first on paper, credit-data enforcement in practice. |
| ๐ช๐จ Ecuador | Americas | In force | GDPR-modeled bases with consent prominent; sanctions became applicable in 2023. |
| ๐ช๐ฌ Egypt | Middle East & North Africa | Adopted | Consent-first, with licences required under the Executive Regulation for processing, cross-border transfers, sensitive data and direct electronic marketing. |
| ๐ธ๐ป El Salvador | Americas | In force | Consent-first, GDPR-influenced framework. |
| ๐ฌ๐ถ Equatorial Guinea | Sub-Saharan Africa | In force | Consent-first on paper. |
| ๐ช๐ช Estonia | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ธ๐ฟ Eswatini | Sub-Saharan Africa | In force | Consent or listed bases, GDPR-influenced. |
| ๐ช๐น Ethiopia | Sub-Saharan Africa | In force | Consent-first with GDPR-influenced bases and rights. |
| ๐ช๐บ European Union | Special | In force | A lawful basis under Article 6 for all processing; freely given, specific, informed, unambiguous consent for cookies, tracking and most adtech via the ePrivacy Directive. |
| ๐ซ๐ฎ Finland | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ซ๐ท France | Europe | In force | GDPR legal basis plus the CNIL's cookie doctrine, under which refusing must be as easy as accepting. |
| ๐ฌ๐ฆ Gabon | Sub-Saharan Africa | In force | Consent-first; the 2023 amendment modernized definitions and duties. |
| ๐ฌ๐ฒ Gambia | Sub-Saharan Africa | Adopted | A modern framework built on consent and other lawful bases; guidance and enforcement practice are still taking shape. |
| ๐ฌ๐ช Georgia | Europe | In force | GDPR-aligned bases; direct marketing requires consent with an easy withdrawal path. |
| ๐ฉ๐ช Germany | Europe | In force | GDPR legal basis; TDDDG requires opt-in consent for cookies and device access. |
| ๐ฌ๐ญ Ghana | Sub-Saharan Africa | In force | Consent-first with registration duties; direct marketing carries opt-out rights. |
| ๐ฌ๐ท Greece | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฌ๐ฉ Grenada | Americas | Adopted | Modern Commonwealth-model framework that applies once commenced by ministerial order. |
| ๐ฌ๐ณ Guinea | Sub-Saharan Africa | In force | Consent-oriented data provisions inside the 2016 cyber law. |
| ๐ฌ๐พ Guyana | Americas | Adopted | GDPR-influenced consent and bases. |
| ๐ญ๐บ Hungary | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฎ๐ธ Iceland | Europe | In force | GDPR applies through the EEA Agreement; ePrivacy consent for cookies. |
| ๐ฎ๐ณ India | Asia-Pacific | Adopted | Consent or narrow 'legitimate uses' (which do not include marketing). Notice-backed, itemized consent is the default for commercial processing. |
| ๐ฎ๐ฉ Indonesia | Asia-Pacific | In force | GDPR-style bases including consent, contract and legitimate interests, but explicit consent dominates commercial practice; Indonesian-language consent requirements apply. |
| ๐ฎ๐ช Ireland | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฎ๐ฑ Israel | Middle East & North Africa | In force | Consent (informed, and often implied by conduct for non-sensitive contexts) underpins processing; the Spam Law requires opt-in for commercial email, SMS and fax. |
| ๐ฎ๐น Italy | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฏ๐ฒ Jamaica | Americas | In force | GDPR-modeled standards; registration of controllers required. |
| ๐ฏ๐ด Jordan | Middle East & North Africa | In force | Consent-first with listed exceptions; explicit rules for direct marketing consent. |
| ๐ฐ๐ฟ Kazakhstan | Asia-Pacific | In force | Consent-based with formal requirements; amendments have tightened biometric and digital-ID handling. |
| ๐ฐ๐ช Kenya | Sub-Saharan Africa | In force | GDPR-modeled bases; direct marketing requires consent or an existing-customer relationship with opt-out, and the ODPC enforces this. |
| ๐ฐ๐ผ Kuwait | Middle East & North Africa | Sectoral | Consent-oriented duties for telecom and ICT service providers, including apps and platforms, under a regulation that stops short of an economy-wide statute. |
| ๐ฐ๐ฌ Kyrgyzstan | Asia-Pacific | In force | Consent-based; 2021 amendments added localization and a supervisory agency. |
| ๐ฑ๐ฆ Laos | Asia-Pacific | Sectoral | Consent-oriented rules for electronic data; scope and enforcement are narrow. |
| ๐ฑ๐ป Latvia | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฑ๐ง Lebanon | Middle East & North Africa | In force | Consent-oriented but with broad exemptions, in a regime built around licensing. |
| ๐ฑ๐ธ Lesotho | Sub-Saharan Africa | Adopted | Consent-first on paper. |
| ๐ฑ๐ท Liberia | Sub-Saharan Africa | Adopted | The new Act sets consent and processing rules whose details await implementation. |
| ๐ฑ๐ฎ Liechtenstein | Europe | In force | GDPR applies through the EEA Agreement; ePrivacy consent for cookies. |
| ๐ฑ๐น Lithuania | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฑ๐บ Luxembourg | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฒ๐ด Macau | Special | In force | EU-directive-modeled: consent or another legitimacy ground; notification duties to the GPDP for many processing operations. |
| ๐ฒ๐ฌ Madagascar | Sub-Saharan Africa | Adopted | Consent-first on paper. |
| ๐ฒ๐ผ Malawi | Sub-Saharan Africa | In force | Consent-first, GDPR-influenced framework. |
| ๐ฒ๐พ Malaysia | Asia-Pacific | In force | Consent-based processing with a statutory right to stop direct marketing; the Act covers commercial transactions and excludes government. |
| ๐ฒ๐ฑ Mali | Sub-Saharan Africa | In force | Consent-first with declaration duties. |
| ๐ฒ๐น Malta | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ฒ๐ท Mauritania | Sub-Saharan Africa | In force | Consent-first on paper. |
| ๐ฒ๐บ Mauritius | Sub-Saharan Africa | In force | GDPR-aligned consent and bases. |
| ๐ฒ๐ฉ Moldova | Europe | In force | Consent-first framework modeled on the pre-GDPR EU directive; GDPR alignment advancing under the EU accession track. |
| ๐ฒ๐จ Monaco | Europe | In force | GDPR-aligned framework adopted in late 2024. |
| ๐ฒ๐ณ Mongolia | Asia-Pacific | In force | Consent-based collection and processing with listed exceptions; sensitive data restricted. |
| ๐ฒ๐ช Montenegro | Europe | In force | Consent-first framework; GDPR alignment phasing in. |
| ๐ฒ๐ฆ Morocco | Middle East & North Africa | In force | Consent-first with prior declaration or authorization duties; direct marketing requires prior consent. |
| ๐ณ๐ต Nepal | Asia-Pacific | In force | Consent required for collection, use and publication of personal information, with broad government exceptions. |
| ๐ณ๐ฑ Netherlands | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ณ๐ฎ Nicaragua | Americas | Adopted | Consent-first on paper. |
| ๐ณ๐ช Niger | Sub-Saharan Africa | In force | Consent-first framework. |
| ๐ณ๐ฌ Nigeria | Sub-Saharan Africa | In force | Consent or another lawful basis including legitimate interests, but direct marketing expects consent and a clear opt-out; the GAID details consent standards. |
| ๐ฒ๐ฐ North Macedonia | Europe | In force | GDPR-modeled bases and consent standard. |
| ๐ณ๐ด Norway | Europe | In force | GDPR applies through the EEA Agreement; ePrivacy consent for cookies. |
| ๐ด๐ฒ Oman | Middle East & North Africa | In force | Express written-form consent is the default basis, one of the strictest consent standards anywhere; sensitive data needs ministry permits. |
| ๐ต๐ฆ Panama | Americas | In force | Consent or listed bases; in force since 2021 with a 2021 executive decree. |
| ๐ต๐พ Paraguay | Americas | Adopted | GDPR-influenced consent and legal bases under the new law; until it applies, only the 2020 credit-data law (Law 6534/2020) is operative. |
| ๐ต๐ช Peru | Americas | In force | Prior, express, unequivocal consent is the default, one of the region's strictest standards; the 2024 regulation (effective 30 March 2025) modernized notices, cookies and children's rules. |
| ๐ต๐ญ Philippines | Asia-Pacific | In force | Consent or another lawful criterion; direct marketing and profiling effectively require consent, and the NPC polices deceptive consent design. |
| ๐ต๐ฑ Poland | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ต๐น Portugal | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ถ๐ฆ Qatar | Middle East & North Africa | In force | Consent-based processing with direct marketing requiring prior consent and opt-out in each message. |
| ๐จ๐ฌ Republic of the Congo | Sub-Saharan Africa | In force | Consent-first framework. |
| ๐ท๐ด Romania | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ท๐บ Russia | Europe | In force | Written or clearly demonstrable consent is the default basis, and since 1 September 2025 it must be obtained as a separate document; separate consent for dissemination; strict formalities. |
| ๐ท๐ผ Rwanda | Sub-Saharan Africa | In force | Consent or listed bases; registration of controllers and processors required. |
| ๐ฐ๐ณ Saint Kitts and Nevis | Americas | Adopted | Commonwealth-model consent framework. |
| ๐ฑ๐จ Saint Lucia | Americas | In force | Commonwealth-model consent framework, in force since 2015. |
| ๐ธ๐ฒ San Marino | Europe | In force | GDPR-modeled framework. |
| ๐ธ๐น Sao Tome and Principe | Sub-Saharan Africa | In force | Consent-first framework on the Lusophone model. |
| ๐ธ๐ฆ Saudi Arabia | Middle East & North Africa | In force | Consent is the default basis; the 2023 amendments added legitimate-interest room for non-sensitive data, but direct marketing effectively requires consent plus an opt-out in every message. |
| ๐ธ๐ณ Senegal | Sub-Saharan Africa | In force | Consent-first with declaration and authorization duties. |
| ๐ท๐ธ Serbia | Europe | In force | GDPR-modeled bases and consent standard. |
| ๐ธ๐จ Seychelles | Sub-Saharan Africa | In force | GDPR-influenced consent and bases. |
| ๐ธ๐ฐ Slovakia | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ธ๐ฎ Slovenia | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐ธ๐ด Somalia | Sub-Saharan Africa | In force | Consent-first framework. |
| ๐ฟ๐ฆ South Africa | Sub-Saharan Africa | In force | Eight processing conditions with justification grounds including legitimate interests, but section 69 makes electronic direct marketing opt-in, with a narrow existing-customer exception. Since April 2026, direct marketers must also register with the National Consumer Commission's opt-out registry and clean their lists against it monthly. |
| ๐ฐ๐ท South Korea | Asia-Pacific | In force | Consent-centric with tightly drawn alternatives; separate opt-in consent for marketing use and for sensitive data. The 2023 amendment eased contract-necessity processing but marketing still runs on consent. |
| ๐ช๐ธ Spain | Europe | In force | GDPR legal basis; LSSI adds separate cookie and commercial email rules with their own fines. |
| ๐ฑ๐ฐ Sri Lanka | Asia-Pacific | Adopted | GDPR-modeled bases; consent must be demonstrable and withdrawable once the substantive provisions are brought into operation. |
| ๐ธ๐ช Sweden | Europe | In force | GDPR legal basis required; ePrivacy consent for cookies and tracking. |
| ๐น๐ผ Taiwan | Special | In force | Consent or a listed statutory basis; notification duties at collection; opt-out must be honored for marketing, and first-use marketing requires a free opt-out channel. |
| ๐น๐ฏ Tajikistan | Asia-Pacific | In force | Consent-based with listed exceptions. |
| ๐น๐ฟ Tanzania | Sub-Saharan Africa | In force | Consent-first with registration duties. |
| ๐น๐ญ Thailand | Asia-Pacific | In force | GDPR-modeled bases including legitimate interests, but consent must be explicit where relied on, and direct marketing practice leans on consent; cookie consent expected for tracking. |
| ๐น๐ฌ Togo | Sub-Saharan Africa | In force | Consent-first framework. |
| ๐น๐ด Tonga | Oceania | Adopted | Comprehensive framework for controllers and processors based in Tonga or targeting people there; commencement is by Cabinet proclamation. |
| ๐น๐น Trinidad and Tobago | Americas | Adopted | Consent-first in the unproclaimed parts; only general provisions are in force. |
| ๐น๐ณ Tunisia | Middle East & North Africa | In force | Consent-first with authorization and declaration duties; a GDPR-aligned replacement bill has been pending for years. |
| ๐น๐ท Turkey | Europe | In force | Explicit consent or a listed basis; electronic marketing needs opt-in consent recorded in the IYS registry. Since 1 August 2026, targeted ads must disclose the criteria behind them, and profiling-based targeting of known children is banned. |
| ๐น๐ฒ Turkmenistan | Asia-Pacific | In force | Consent-based on paper; state access is extensive. |
| ๐บ๐ฌ Uganda | Sub-Saharan Africa | In force | Consent-first with listed exceptions; registration required. |
| ๐บ๐ฆ Ukraine | Europe | In force | Consent is the primary basis under the 2010 law; a GDPR-aligned replacement (draft 8153) is pending. |
| ๐ฆ๐ช United Arab Emirates | Middle East & North Africa | Adopted | Consent-centric federal law on paper, but its executive regulations remain unissued, so operative obligations today come mainly from the DIFC and ADGM regimes and sectoral rules. |
| ๐ฌ๐ง United Kingdom | Europe | In force | UK GDPR legal basis; PECR opt-in for cookies and e-marketing, with a soft opt-in for existing customers. |
| ๐บ๐พ Uruguay | Americas | In force | Consent-first with GDPR-style updates layered in since 2018 (breach notification, DPOs, impact assessments). |
| ๐บ๐ฟ Uzbekistan | Asia-Pacific | In force | Consent-based; registration of databases required. |
| ๐ป๐บ Vanuatu | Oceania | Adopted | A comprehensive framework covering public and private sectors; practical enforcement awaits the Digital Safety Authority. |
| ๐ป๐ณ Vietnam | Asia-Pacific | In force | Consent is the anchor basis with limited exceptions; marketing use requires consent and data subjects must be able to refuse. |
| ๐ฟ๐ฒ Zambia | Sub-Saharan Africa | In force | Consent or listed bases; registration required. |
| ๐ฟ๐ผ Zimbabwe | Sub-Saharan Africa | In force | Consent or listed bases; DPO licensing rules issued 2024. |
Opt-out: the American exception (1 jurisdiction)
The United States lets advertisers use personal data to target adults without prior consent, then obligates them to stop on request. No other major economy works this way. The exceptions carry the enforcement risk: sensitive data is opt-in under most state laws, calls and texts are opt-in under the TCPA, and children are off-limits. The full anatomy is on the United States page and the state law tracker.
| Jurisdiction | Region | Status | What consent means here |
|---|---|---|---|
| ๐บ๐ธ United States | Americas | In force | Targeted advertising and data sales run on opt-out for adults and non-sensitive data. Opt-in is required for sensitive data in most state laws, for children's data, and for calls and texts under the TCPA. |
Hybrid: notice-based regimes (7 jurisdictions)
Japan, Singapore, Australia, New Zealand, Hong Kong, Mexico and Switzerland run a third model. Collection rests on notice and purpose limitation, and consent is reserved for sensitive data, marketing or disclosure. These are the most workable major markets for first-party marketing, though each layers channel rules on top, and email and SMS marketing need consent in Australia, New Zealand, Japan and Switzerland.
| Jurisdiction | Region | Status | What consent means here |
|---|---|---|---|
| ๐ฆ๐บ Australia | Oceania | In force | Collection runs on notice and fair-collection rules, with consent required for sensitive information. APP 7 lets direct marketing proceed with an opt-out where data came from the individual, opt-in otherwise. The Spam Act makes email and SMS opt-in. |
| ๐ญ๐ฐ Hong Kong | Special | In force | Notice-and-purpose model in which collection needs only notice, while Part 6A requires explicit consent-style agreement before using personal data in direct marketing, with criminal penalties for violations. |
| ๐ฏ๐ต Japan | Asia-Pacific | In force | Notice-based collection with purpose limitation; opt-in consent mainly for sensitive data and third-party provision (an opt-out filing route exists for non-sensitive data). The 2026 amendment adds consent exceptions for statistics and AI development and parental consent for under-16s. |
| ๐ฒ๐ฝ Mexico | Americas | In force | Tacit consent works for non-sensitive data, so a business can provide the privacy notice and proceed unless the person objects. Express consent for financial data, express and written for sensitive data. |
| ๐ณ๐ฟ New Zealand | Oceania | In force | Purpose-and-notice model built on thirteen Information Privacy Principles; IPP3A, in force since 1 May 2026, requires notice when personal information is collected indirectly. The Unsolicited Electronic Messages Act makes email and SMS opt-in. |
| ๐ธ๐ฌ Singapore | Asia-Pacific | In force | Consent is the default but the 2020 amendments added deemed consent by notification and a legitimate interests exception; the Do Not Call registry governs phone and SMS marketing. |
| ๐จ๐ญ Switzerland | Europe | In force | Processing is lawful without consent unless it breaches personality rights; consent needed for sensitive data, high-risk profiling and to justify breaches. Mass email marketing requires opt-in under unfair competition law. |
No rule: the unregulated map (38 jurisdictions)
Mostly conflict states, holdout economies and Pacific micro-states. No local consent rule exists, but platform policies and the extraterritorial reach of laws like the GDPR still apply to campaigns run from or into these markets.
| Jurisdiction | Region | Status | What consent means here |
|---|---|---|---|
| ๐ฆ๐ซ Afghanistan | Asia-Pacific | No law | No data protection law. |
| ๐ง๐น Bhutan | Asia-Pacific | Sectoral | Sectoral ICT provisions require care with personal information; no comprehensive consent regime. |
| ๐ง๐ด Bolivia | Americas | No law | No comprehensive consent requirement. |
| ๐ฐ๐ญ Cambodia | Asia-Pacific | Bill pending | No comprehensive consent requirement; e-commerce law imposes limited confidentiality duties. |
| ๐ฉ๐ฒ Dominica | Americas | No law | No comprehensive consent requirement. |
| ๐ช๐ท Eritrea | Sub-Saharan Africa | No law | No data protection framework. |
| ๐ซ๐ฏ Fiji | Oceania | Bill pending | No comprehensive consent requirement. |
| ๐ฌ๐น Guatemala | Americas | Bill pending | No comprehensive consent requirement for the private sector. |
| ๐ฌ๐ผ Guinea-Bissau | Sub-Saharan Africa | No law | No data protection framework. |
| ๐ญ๐น Haiti | Americas | No law | No data protection framework. |
| ๐ญ๐ณ Honduras | Americas | Bill pending | No comprehensive consent requirement. |
| ๐ฎ๐ท Iran | Middle East & North Africa | Bill pending | No comprehensive consent requirement; e-commerce law imposes narrow duties on online sellers. |
| ๐ฎ๐ถ Iraq | Middle East & North Africa | No law | No comprehensive consent requirement. |
| ๐ฐ๐ฎ Kiribati | Oceania | Bill pending | No data protection framework in force. |
| ๐ฑ๐พ Libya | Middle East & North Africa | No law | No data protection framework. |
| ๐ฒ๐ป Maldives | Asia-Pacific | Bill pending | No comprehensive consent requirement. |
| ๐ฒ๐ญ Marshall Islands | Oceania | Sectoral | The 2025 Act covers government ministries and agencies only; private businesses have no general consent rule. |
| ๐ซ๐ฒ Micronesia | Oceania | No law | No data protection framework. |
| ๐ฒ๐ฟ Mozambique | Sub-Saharan Africa | Bill pending | No comprehensive consent requirement. |
| ๐ฒ๐ฒ Myanmar | Asia-Pacific | Sectoral | No functioning comprehensive consent regime; the 2025 Cybersecurity Law is built around state control. |
| ๐ณ๐ฆ Namibia | Sub-Saharan Africa | Bill pending | No comprehensive consent requirement. |
| ๐ณ๐ท Nauru | Oceania | No law | No data protection framework. |
| ๐ฐ๐ต North Korea | Asia-Pacific | No law | No data protection framework. |
| ๐ต๐ฐ Pakistan | Asia-Pacific | Bill pending | No comprehensive consent requirement today; sectoral rules (banking, telecom) impose confidentiality duties. |
| ๐ต๐ผ Palau | Oceania | No law | No data protection framework. |
| ๐ต๐ฌ Papua New Guinea | Oceania | No law | No comprehensive consent requirement. |
| ๐ป๐จ Saint Vincent and the Grenadines | Americas | No law | No data protection framework in force. |
| ๐ผ๐ธ Samoa | Oceania | No law | No data protection framework. |
| ๐ธ๐ฑ Sierra Leone | Sub-Saharan Africa | Bill pending | No comprehensive consent requirement. |
| ๐ธ๐ง Solomon Islands | Oceania | No law | No data protection framework. |
| ๐ธ๐ธ South Sudan | Sub-Saharan Africa | Bill pending | No data protection framework in force. |
| ๐ธ๐ฉ Sudan | Sub-Saharan Africa | No law | No comprehensive consent requirement. |
| ๐ธ๐ท Suriname | Americas | Bill pending | No comprehensive consent requirement. |
| ๐ธ๐พ Syria | Middle East & North Africa | Adopted | The 2024 law exists on paper; whether and how it applies since the December 2024 change of government is unclear. |
| ๐น๐ฑ Timor-Leste | Asia-Pacific | No law | No comprehensive consent requirement. |
| ๐น๐ป Tuvalu | Oceania | No law | No data protection framework. |
| ๐ป๐ช Venezuela | Americas | No law | No comprehensive consent requirement. |
| ๐พ๐ช Yemen | Middle East & North Africa | No law | No data protection framework. |
The channel matrix
Consent models are channel-specific, and the US flips depending on which channel you touch.
| Channel | EU / UK | United States | Canada | Australia |
|---|---|---|---|---|
| Targeted display and social | Opt-in (consent) | Opt-out (state laws) | Consent (implied possible) | Notice + opt-out (APP 7) |
| Cookies and trackers | Opt-in (ePrivacy) | No general rule; opt-out of sale/share | Consent principles | Notice-based |
| Email marketing | Opt-in + soft opt-in | Opt-out (CAN-SPAM) | Opt-in (CASL) | Opt-in (Spam Act) |
| SMS and calls | Opt-in | Opt-in (TCPA) | Opt-in (CASL + telemarketing rules) | Opt-in |
| Sensitive-data targeting | Explicit consent or prohibited | Opt-in; banned from sale in Maryland | Express consent | Consent (sensitive information) |
The planning rule that follows is to build the opt-in playbook once, run it everywhere, and loosen deliberately for the US where the economics justify a second track. The GDPR vs US comparison works through the differences line by line.