DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Reference · The signature question

Opt-in vs opt-out: the world consent map

The regulated world requires permission before targeting. The United States requires a working off switch. This page sorts every jurisdiction by which side of that line it sits on.

Updated September 28, 2026 · digitalprivacyregs.com

Every media plan on earth reduces to one question per market, whether personal data can drive targeting before people say yes. This page sorts all 197 jurisdictions by the answer, and the pattern is stark. The regulated world runs on opt-in. One superpower runs on opt-out. A pragmatic middle runs on notice.

151Opt-in jurisdictions
1Opt-out (the US)
7Hybrid / notice-based
38No consent rule (no law)

Opt-in: permission first (151 jurisdictions)

The GDPR family and its cousins. Tracking, profiling and most marketing need affirmative consent or another tightly drawn legal basis before processing starts. This bloc covers the EU and EEA, the UK, Brazil, China, Korea, Canada, most of Africa and Latin America, and the Gulf. If your campaign can be seen from these markets, permission is the price of entry.

JurisdictionRegionStatusWhat consent means here
๐Ÿ‡ฆ๐Ÿ‡ฑ AlbaniaEuropeIn forceGDPR-aligned bases and consent standard.
๐Ÿ‡ฉ๐Ÿ‡ฟ AlgeriaMiddle East & North AfricaIn forceConsent-first with authorization duties for sensitive data and transfers.
๐Ÿ‡ฆ๐Ÿ‡ฉ AndorraEuropeIn forceGDPR-modeled consent and legal bases.
๐Ÿ‡ฆ๐Ÿ‡ด AngolaSub-Saharan AfricaIn forceConsent-first with authorization duties; APD approval needed for sensitive processing and transfers.
๐Ÿ‡ฆ๐Ÿ‡ฌ Antigua and BarbudaAmericasAdoptedConsent-oriented framework; commencement and supervision have been incomplete.
๐Ÿ‡ฆ๐Ÿ‡ท ArgentinaAmericasIn forceConsent-first with listed exceptions; the do-not-call registry and marketing opt-outs are enforced.
๐Ÿ‡ฆ๐Ÿ‡ฒ ArmeniaEuropeIn forceConsent-first framework.
๐Ÿ‡ฆ๐Ÿ‡น AustriaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฆ๐Ÿ‡ฟ AzerbaijanEuropeIn forceConsent-first framework with registration duties.
๐Ÿ‡ง๐Ÿ‡ธ BahamasAmericasIn forceDirective-era consent-oriented rules.
๐Ÿ‡ง๐Ÿ‡ญ BahrainMiddle East & North AfricaIn forceConsent or listed grounds; direct marketing requires prior consent.
๐Ÿ‡ง๐Ÿ‡ฉ BangladeshAsia-PacificAdoptedConsent-based processing under the 2026 Act; the complaints, fines and compensation provisions start only when the government notifies them, no earlier than October 2027.
๐Ÿ‡ง๐Ÿ‡ง BarbadosAmericasIn forceGDPR-modeled consent and bases.
๐Ÿ‡ง๐Ÿ‡พ BelarusEuropeIn forceConsent is the default basis, with listed exceptions.
๐Ÿ‡ง๐Ÿ‡ช BelgiumEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ง๐Ÿ‡ฟ BelizeAmericasIn forceGDPR-influenced consent and bases.
๐Ÿ‡ง๐Ÿ‡ฏ BeninSub-Saharan AfricaIn forceGDPR-influenced consent and bases inside the Digital Code.
๐Ÿ‡ง๐Ÿ‡ฆ Bosnia and HerzegovinaEuropeIn forceConsent-first framework from the pre-GDPR era.
๐Ÿ‡ง๐Ÿ‡ผ BotswanaSub-Saharan AfricaIn forceConsent or listed bases; registration duties apply.
๐Ÿ‡ง๐Ÿ‡ท BrazilAmericasIn forceTen legal bases including legitimate interests, but consent is expected for cookies and most adtech, and the ANPD's guidance pushes granular banners.
๐Ÿ‡ง๐Ÿ‡ณ BruneiAsia-PacificIn forceSingapore-modeled consent framework for the private sector, with deemed consent concepts.
๐Ÿ‡ง๐Ÿ‡ฌ BulgariaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ง๐Ÿ‡ซ Burkina FasoSub-Saharan AfricaIn forceConsent-first; the 2021 law replaced the 2004 pioneer statute with a modernized framework.
๐Ÿ‡ง๐Ÿ‡ฎ BurundiSub-Saharan AfricaAdoptedA comprehensive law on the francophone African model, with consent as the main basis for processing; private-sector processing had six months to comply, a window that closed on 10 September 2026.
๐Ÿ‡จ๐Ÿ‡ป Cabo VerdeSub-Saharan AfricaIn forceConsent-first, Portuguese-model framework, updated repeatedly.
๐Ÿ‡จ๐Ÿ‡ฒ CameroonSub-Saharan AfricaAdoptedConsent-first framework with data protection officer duties; its obligations have applied since the 18-month transition ended on 23 June 2026.
๐Ÿ‡จ๐Ÿ‡ฆ CanadaAmericasIn forceConsent is required for collection, use and disclosure; implied consent works for non-sensitive contexts, but CASL makes commercial email and SMS strictly opt-in with limited implied-consent windows.
๐Ÿ‡จ๐Ÿ‡ซ Central African RepublicSub-Saharan AfricaAdoptedConsent-first framework on the francophone African model, in force since January 2024.
๐Ÿ‡น๐Ÿ‡ฉ ChadSub-Saharan AfricaIn forceConsent-first framework.
๐Ÿ‡จ๐Ÿ‡ฑ ChileAmericasAdoptedGDPR-modeled: consent or another legal basis including legitimate interests, with sensitive-data and children's rules; the outgoing 1999 law was consent-based but toothless.
๐Ÿ‡จ๐Ÿ‡ณ ChinaAsia-PacificIn forceConsent is the workhorse basis, and 'separate consent' is required for sensitive data, cross-border transfers, and sharing with other handlers. No legitimate-interest basis exists.
๐Ÿ‡จ๐Ÿ‡ด ColombiaAmericasIn forcePrior, express and informed consent is the general rule, with a national database registry (RNBD) for larger companies.
๐Ÿ‡ฐ๐Ÿ‡ฒ ComorosSub-Saharan AfricaAdoptedConsent-first framework on paper; with no commission in place, nothing enforces it.
๐Ÿ‡จ๐Ÿ‡ท Costa RicaAmericasIn forceExpress consent is the general rule, with database registration duties.
๐Ÿ‡จ๐Ÿ‡ฎ Cote d'IvoireSub-Saharan AfricaIn forceConsent-first with authorization duties.
๐Ÿ‡ญ๐Ÿ‡ท CroatiaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡จ๐Ÿ‡บ CubaAmericasIn forceConsent-oriented rules within a state-controlled information system.
๐Ÿ‡จ๐Ÿ‡พ CyprusEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡จ๐Ÿ‡ฟ CzechiaEuropeIn forceGDPR legal basis required; cookie opt-in mandatory since the 2022 Electronic Communications Act amendment.
๐Ÿ‡จ๐Ÿ‡ฉ Democratic Republic of the CongoSub-Saharan AfricaIn forceConsent-first, GDPR-influenced provisions inside the 2023 Digital Code.
๐Ÿ‡ฉ๐Ÿ‡ฐ DenmarkEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฉ๐Ÿ‡ฏ DjiboutiSub-Saharan AfricaAdoptedConsent-first rules in Book I of the Digital Code; private-sector processing had one year to comply and the public sector two.
๐Ÿ‡ฉ๐Ÿ‡ด Dominican RepublicAmericasIn forceConsent-first on paper, credit-data enforcement in practice.
๐Ÿ‡ช๐Ÿ‡จ EcuadorAmericasIn forceGDPR-modeled bases with consent prominent; sanctions became applicable in 2023.
๐Ÿ‡ช๐Ÿ‡ฌ EgyptMiddle East & North AfricaAdoptedConsent-first, with licences required under the Executive Regulation for processing, cross-border transfers, sensitive data and direct electronic marketing.
๐Ÿ‡ธ๐Ÿ‡ป El SalvadorAmericasIn forceConsent-first, GDPR-influenced framework.
๐Ÿ‡ฌ๐Ÿ‡ถ Equatorial GuineaSub-Saharan AfricaIn forceConsent-first on paper.
๐Ÿ‡ช๐Ÿ‡ช EstoniaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ธ๐Ÿ‡ฟ EswatiniSub-Saharan AfricaIn forceConsent or listed bases, GDPR-influenced.
๐Ÿ‡ช๐Ÿ‡น EthiopiaSub-Saharan AfricaIn forceConsent-first with GDPR-influenced bases and rights.
๐Ÿ‡ช๐Ÿ‡บ European UnionSpecialIn forceA lawful basis under Article 6 for all processing; freely given, specific, informed, unambiguous consent for cookies, tracking and most adtech via the ePrivacy Directive.
๐Ÿ‡ซ๐Ÿ‡ฎ FinlandEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ซ๐Ÿ‡ท FranceEuropeIn forceGDPR legal basis plus the CNIL's cookie doctrine, under which refusing must be as easy as accepting.
๐Ÿ‡ฌ๐Ÿ‡ฆ GabonSub-Saharan AfricaIn forceConsent-first; the 2023 amendment modernized definitions and duties.
๐Ÿ‡ฌ๐Ÿ‡ฒ GambiaSub-Saharan AfricaAdoptedA modern framework built on consent and other lawful bases; guidance and enforcement practice are still taking shape.
๐Ÿ‡ฌ๐Ÿ‡ช GeorgiaEuropeIn forceGDPR-aligned bases; direct marketing requires consent with an easy withdrawal path.
๐Ÿ‡ฉ๐Ÿ‡ช GermanyEuropeIn forceGDPR legal basis; TDDDG requires opt-in consent for cookies and device access.
๐Ÿ‡ฌ๐Ÿ‡ญ GhanaSub-Saharan AfricaIn forceConsent-first with registration duties; direct marketing carries opt-out rights.
๐Ÿ‡ฌ๐Ÿ‡ท GreeceEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฌ๐Ÿ‡ฉ GrenadaAmericasAdoptedModern Commonwealth-model framework that applies once commenced by ministerial order.
๐Ÿ‡ฌ๐Ÿ‡ณ GuineaSub-Saharan AfricaIn forceConsent-oriented data provisions inside the 2016 cyber law.
๐Ÿ‡ฌ๐Ÿ‡พ GuyanaAmericasAdoptedGDPR-influenced consent and bases.
๐Ÿ‡ญ๐Ÿ‡บ HungaryEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฎ๐Ÿ‡ธ IcelandEuropeIn forceGDPR applies through the EEA Agreement; ePrivacy consent for cookies.
๐Ÿ‡ฎ๐Ÿ‡ณ IndiaAsia-PacificAdoptedConsent or narrow 'legitimate uses' (which do not include marketing). Notice-backed, itemized consent is the default for commercial processing.
๐Ÿ‡ฎ๐Ÿ‡ฉ IndonesiaAsia-PacificIn forceGDPR-style bases including consent, contract and legitimate interests, but explicit consent dominates commercial practice; Indonesian-language consent requirements apply.
๐Ÿ‡ฎ๐Ÿ‡ช IrelandEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฎ๐Ÿ‡ฑ IsraelMiddle East & North AfricaIn forceConsent (informed, and often implied by conduct for non-sensitive contexts) underpins processing; the Spam Law requires opt-in for commercial email, SMS and fax.
๐Ÿ‡ฎ๐Ÿ‡น ItalyEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฏ๐Ÿ‡ฒ JamaicaAmericasIn forceGDPR-modeled standards; registration of controllers required.
๐Ÿ‡ฏ๐Ÿ‡ด JordanMiddle East & North AfricaIn forceConsent-first with listed exceptions; explicit rules for direct marketing consent.
๐Ÿ‡ฐ๐Ÿ‡ฟ KazakhstanAsia-PacificIn forceConsent-based with formal requirements; amendments have tightened biometric and digital-ID handling.
๐Ÿ‡ฐ๐Ÿ‡ช KenyaSub-Saharan AfricaIn forceGDPR-modeled bases; direct marketing requires consent or an existing-customer relationship with opt-out, and the ODPC enforces this.
๐Ÿ‡ฐ๐Ÿ‡ผ KuwaitMiddle East & North AfricaSectoralConsent-oriented duties for telecom and ICT service providers, including apps and platforms, under a regulation that stops short of an economy-wide statute.
๐Ÿ‡ฐ๐Ÿ‡ฌ KyrgyzstanAsia-PacificIn forceConsent-based; 2021 amendments added localization and a supervisory agency.
๐Ÿ‡ฑ๐Ÿ‡ฆ LaosAsia-PacificSectoralConsent-oriented rules for electronic data; scope and enforcement are narrow.
๐Ÿ‡ฑ๐Ÿ‡ป LatviaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฑ๐Ÿ‡ง LebanonMiddle East & North AfricaIn forceConsent-oriented but with broad exemptions, in a regime built around licensing.
๐Ÿ‡ฑ๐Ÿ‡ธ LesothoSub-Saharan AfricaAdoptedConsent-first on paper.
๐Ÿ‡ฑ๐Ÿ‡ท LiberiaSub-Saharan AfricaAdoptedThe new Act sets consent and processing rules whose details await implementation.
๐Ÿ‡ฑ๐Ÿ‡ฎ LiechtensteinEuropeIn forceGDPR applies through the EEA Agreement; ePrivacy consent for cookies.
๐Ÿ‡ฑ๐Ÿ‡น LithuaniaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฑ๐Ÿ‡บ LuxembourgEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฒ๐Ÿ‡ด MacauSpecialIn forceEU-directive-modeled: consent or another legitimacy ground; notification duties to the GPDP for many processing operations.
๐Ÿ‡ฒ๐Ÿ‡ฌ MadagascarSub-Saharan AfricaAdoptedConsent-first on paper.
๐Ÿ‡ฒ๐Ÿ‡ผ MalawiSub-Saharan AfricaIn forceConsent-first, GDPR-influenced framework.
๐Ÿ‡ฒ๐Ÿ‡พ MalaysiaAsia-PacificIn forceConsent-based processing with a statutory right to stop direct marketing; the Act covers commercial transactions and excludes government.
๐Ÿ‡ฒ๐Ÿ‡ฑ MaliSub-Saharan AfricaIn forceConsent-first with declaration duties.
๐Ÿ‡ฒ๐Ÿ‡น MaltaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ฒ๐Ÿ‡ท MauritaniaSub-Saharan AfricaIn forceConsent-first on paper.
๐Ÿ‡ฒ๐Ÿ‡บ MauritiusSub-Saharan AfricaIn forceGDPR-aligned consent and bases.
๐Ÿ‡ฒ๐Ÿ‡ฉ MoldovaEuropeIn forceConsent-first framework modeled on the pre-GDPR EU directive; GDPR alignment advancing under the EU accession track.
๐Ÿ‡ฒ๐Ÿ‡จ MonacoEuropeIn forceGDPR-aligned framework adopted in late 2024.
๐Ÿ‡ฒ๐Ÿ‡ณ MongoliaAsia-PacificIn forceConsent-based collection and processing with listed exceptions; sensitive data restricted.
๐Ÿ‡ฒ๐Ÿ‡ช MontenegroEuropeIn forceConsent-first framework; GDPR alignment phasing in.
๐Ÿ‡ฒ๐Ÿ‡ฆ MoroccoMiddle East & North AfricaIn forceConsent-first with prior declaration or authorization duties; direct marketing requires prior consent.
๐Ÿ‡ณ๐Ÿ‡ต NepalAsia-PacificIn forceConsent required for collection, use and publication of personal information, with broad government exceptions.
๐Ÿ‡ณ๐Ÿ‡ฑ NetherlandsEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ณ๐Ÿ‡ฎ NicaraguaAmericasAdoptedConsent-first on paper.
๐Ÿ‡ณ๐Ÿ‡ช NigerSub-Saharan AfricaIn forceConsent-first framework.
๐Ÿ‡ณ๐Ÿ‡ฌ NigeriaSub-Saharan AfricaIn forceConsent or another lawful basis including legitimate interests, but direct marketing expects consent and a clear opt-out; the GAID details consent standards.
๐Ÿ‡ฒ๐Ÿ‡ฐ North MacedoniaEuropeIn forceGDPR-modeled bases and consent standard.
๐Ÿ‡ณ๐Ÿ‡ด NorwayEuropeIn forceGDPR applies through the EEA Agreement; ePrivacy consent for cookies.
๐Ÿ‡ด๐Ÿ‡ฒ OmanMiddle East & North AfricaIn forceExpress written-form consent is the default basis, one of the strictest consent standards anywhere; sensitive data needs ministry permits.
๐Ÿ‡ต๐Ÿ‡ฆ PanamaAmericasIn forceConsent or listed bases; in force since 2021 with a 2021 executive decree.
๐Ÿ‡ต๐Ÿ‡พ ParaguayAmericasAdoptedGDPR-influenced consent and legal bases under the new law; until it applies, only the 2020 credit-data law (Law 6534/2020) is operative.
๐Ÿ‡ต๐Ÿ‡ช PeruAmericasIn forcePrior, express, unequivocal consent is the default, one of the region's strictest standards; the 2024 regulation (effective 30 March 2025) modernized notices, cookies and children's rules.
๐Ÿ‡ต๐Ÿ‡ญ PhilippinesAsia-PacificIn forceConsent or another lawful criterion; direct marketing and profiling effectively require consent, and the NPC polices deceptive consent design.
๐Ÿ‡ต๐Ÿ‡ฑ PolandEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ต๐Ÿ‡น PortugalEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ถ๐Ÿ‡ฆ QatarMiddle East & North AfricaIn forceConsent-based processing with direct marketing requiring prior consent and opt-out in each message.
๐Ÿ‡จ๐Ÿ‡ฌ Republic of the CongoSub-Saharan AfricaIn forceConsent-first framework.
๐Ÿ‡ท๐Ÿ‡ด RomaniaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ท๐Ÿ‡บ RussiaEuropeIn forceWritten or clearly demonstrable consent is the default basis, and since 1 September 2025 it must be obtained as a separate document; separate consent for dissemination; strict formalities.
๐Ÿ‡ท๐Ÿ‡ผ RwandaSub-Saharan AfricaIn forceConsent or listed bases; registration of controllers and processors required.
๐Ÿ‡ฐ๐Ÿ‡ณ Saint Kitts and NevisAmericasAdoptedCommonwealth-model consent framework.
๐Ÿ‡ฑ๐Ÿ‡จ Saint LuciaAmericasIn forceCommonwealth-model consent framework, in force since 2015.
๐Ÿ‡ธ๐Ÿ‡ฒ San MarinoEuropeIn forceGDPR-modeled framework.
๐Ÿ‡ธ๐Ÿ‡น Sao Tome and PrincipeSub-Saharan AfricaIn forceConsent-first framework on the Lusophone model.
๐Ÿ‡ธ๐Ÿ‡ฆ Saudi ArabiaMiddle East & North AfricaIn forceConsent is the default basis; the 2023 amendments added legitimate-interest room for non-sensitive data, but direct marketing effectively requires consent plus an opt-out in every message.
๐Ÿ‡ธ๐Ÿ‡ณ SenegalSub-Saharan AfricaIn forceConsent-first with declaration and authorization duties.
๐Ÿ‡ท๐Ÿ‡ธ SerbiaEuropeIn forceGDPR-modeled bases and consent standard.
๐Ÿ‡ธ๐Ÿ‡จ SeychellesSub-Saharan AfricaIn forceGDPR-influenced consent and bases.
๐Ÿ‡ธ๐Ÿ‡ฐ SlovakiaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ธ๐Ÿ‡ฎ SloveniaEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡ธ๐Ÿ‡ด SomaliaSub-Saharan AfricaIn forceConsent-first framework.
๐Ÿ‡ฟ๐Ÿ‡ฆ South AfricaSub-Saharan AfricaIn forceEight processing conditions with justification grounds including legitimate interests, but section 69 makes electronic direct marketing opt-in, with a narrow existing-customer exception. Since April 2026, direct marketers must also register with the National Consumer Commission's opt-out registry and clean their lists against it monthly.
๐Ÿ‡ฐ๐Ÿ‡ท South KoreaAsia-PacificIn forceConsent-centric with tightly drawn alternatives; separate opt-in consent for marketing use and for sensitive data. The 2023 amendment eased contract-necessity processing but marketing still runs on consent.
๐Ÿ‡ช๐Ÿ‡ธ SpainEuropeIn forceGDPR legal basis; LSSI adds separate cookie and commercial email rules with their own fines.
๐Ÿ‡ฑ๐Ÿ‡ฐ Sri LankaAsia-PacificAdoptedGDPR-modeled bases; consent must be demonstrable and withdrawable once the substantive provisions are brought into operation.
๐Ÿ‡ธ๐Ÿ‡ช SwedenEuropeIn forceGDPR legal basis required; ePrivacy consent for cookies and tracking.
๐Ÿ‡น๐Ÿ‡ผ TaiwanSpecialIn forceConsent or a listed statutory basis; notification duties at collection; opt-out must be honored for marketing, and first-use marketing requires a free opt-out channel.
๐Ÿ‡น๐Ÿ‡ฏ TajikistanAsia-PacificIn forceConsent-based with listed exceptions.
๐Ÿ‡น๐Ÿ‡ฟ TanzaniaSub-Saharan AfricaIn forceConsent-first with registration duties.
๐Ÿ‡น๐Ÿ‡ญ ThailandAsia-PacificIn forceGDPR-modeled bases including legitimate interests, but consent must be explicit where relied on, and direct marketing practice leans on consent; cookie consent expected for tracking.
๐Ÿ‡น๐Ÿ‡ฌ TogoSub-Saharan AfricaIn forceConsent-first framework.
๐Ÿ‡น๐Ÿ‡ด TongaOceaniaAdoptedComprehensive framework for controllers and processors based in Tonga or targeting people there; commencement is by Cabinet proclamation.
๐Ÿ‡น๐Ÿ‡น Trinidad and TobagoAmericasAdoptedConsent-first in the unproclaimed parts; only general provisions are in force.
๐Ÿ‡น๐Ÿ‡ณ TunisiaMiddle East & North AfricaIn forceConsent-first with authorization and declaration duties; a GDPR-aligned replacement bill has been pending for years.
๐Ÿ‡น๐Ÿ‡ท TurkeyEuropeIn forceExplicit consent or a listed basis; electronic marketing needs opt-in consent recorded in the IYS registry. Since 1 August 2026, targeted ads must disclose the criteria behind them, and profiling-based targeting of known children is banned.
๐Ÿ‡น๐Ÿ‡ฒ TurkmenistanAsia-PacificIn forceConsent-based on paper; state access is extensive.
๐Ÿ‡บ๐Ÿ‡ฌ UgandaSub-Saharan AfricaIn forceConsent-first with listed exceptions; registration required.
๐Ÿ‡บ๐Ÿ‡ฆ UkraineEuropeIn forceConsent is the primary basis under the 2010 law; a GDPR-aligned replacement (draft 8153) is pending.
๐Ÿ‡ฆ๐Ÿ‡ช United Arab EmiratesMiddle East & North AfricaAdoptedConsent-centric federal law on paper, but its executive regulations remain unissued, so operative obligations today come mainly from the DIFC and ADGM regimes and sectoral rules.
๐Ÿ‡ฌ๐Ÿ‡ง United KingdomEuropeIn forceUK GDPR legal basis; PECR opt-in for cookies and e-marketing, with a soft opt-in for existing customers.
๐Ÿ‡บ๐Ÿ‡พ UruguayAmericasIn forceConsent-first with GDPR-style updates layered in since 2018 (breach notification, DPOs, impact assessments).
๐Ÿ‡บ๐Ÿ‡ฟ UzbekistanAsia-PacificIn forceConsent-based; registration of databases required.
๐Ÿ‡ป๐Ÿ‡บ VanuatuOceaniaAdoptedA comprehensive framework covering public and private sectors; practical enforcement awaits the Digital Safety Authority.
๐Ÿ‡ป๐Ÿ‡ณ VietnamAsia-PacificIn forceConsent is the anchor basis with limited exceptions; marketing use requires consent and data subjects must be able to refuse.
๐Ÿ‡ฟ๐Ÿ‡ฒ ZambiaSub-Saharan AfricaIn forceConsent or listed bases; registration required.
๐Ÿ‡ฟ๐Ÿ‡ผ ZimbabweSub-Saharan AfricaIn forceConsent or listed bases; DPO licensing rules issued 2024.

Opt-out: the American exception (1 jurisdiction)

The United States lets advertisers use personal data to target adults without prior consent, then obligates them to stop on request. No other major economy works this way. The exceptions carry the enforcement risk: sensitive data is opt-in under most state laws, calls and texts are opt-in under the TCPA, and children are off-limits. The full anatomy is on the United States page and the state law tracker.

JurisdictionRegionStatusWhat consent means here
๐Ÿ‡บ๐Ÿ‡ธ United StatesAmericasIn forceTargeted advertising and data sales run on opt-out for adults and non-sensitive data. Opt-in is required for sensitive data in most state laws, for children's data, and for calls and texts under the TCPA.

Hybrid: notice-based regimes (7 jurisdictions)

Japan, Singapore, Australia, New Zealand, Hong Kong, Mexico and Switzerland run a third model. Collection rests on notice and purpose limitation, and consent is reserved for sensitive data, marketing or disclosure. These are the most workable major markets for first-party marketing, though each layers channel rules on top, and email and SMS marketing need consent in Australia, New Zealand, Japan and Switzerland.

JurisdictionRegionStatusWhat consent means here
๐Ÿ‡ฆ๐Ÿ‡บ AustraliaOceaniaIn forceCollection runs on notice and fair-collection rules, with consent required for sensitive information. APP 7 lets direct marketing proceed with an opt-out where data came from the individual, opt-in otherwise. The Spam Act makes email and SMS opt-in.
๐Ÿ‡ญ๐Ÿ‡ฐ Hong KongSpecialIn forceNotice-and-purpose model in which collection needs only notice, while Part 6A requires explicit consent-style agreement before using personal data in direct marketing, with criminal penalties for violations.
๐Ÿ‡ฏ๐Ÿ‡ต JapanAsia-PacificIn forceNotice-based collection with purpose limitation; opt-in consent mainly for sensitive data and third-party provision (an opt-out filing route exists for non-sensitive data). The 2026 amendment adds consent exceptions for statistics and AI development and parental consent for under-16s.
๐Ÿ‡ฒ๐Ÿ‡ฝ MexicoAmericasIn forceTacit consent works for non-sensitive data, so a business can provide the privacy notice and proceed unless the person objects. Express consent for financial data, express and written for sensitive data.
๐Ÿ‡ณ๐Ÿ‡ฟ New ZealandOceaniaIn forcePurpose-and-notice model built on thirteen Information Privacy Principles; IPP3A, in force since 1 May 2026, requires notice when personal information is collected indirectly. The Unsolicited Electronic Messages Act makes email and SMS opt-in.
๐Ÿ‡ธ๐Ÿ‡ฌ SingaporeAsia-PacificIn forceConsent is the default but the 2020 amendments added deemed consent by notification and a legitimate interests exception; the Do Not Call registry governs phone and SMS marketing.
๐Ÿ‡จ๐Ÿ‡ญ SwitzerlandEuropeIn forceProcessing is lawful without consent unless it breaches personality rights; consent needed for sensitive data, high-risk profiling and to justify breaches. Mass email marketing requires opt-in under unfair competition law.

No rule: the unregulated map (38 jurisdictions)

Mostly conflict states, holdout economies and Pacific micro-states. No local consent rule exists, but platform policies and the extraterritorial reach of laws like the GDPR still apply to campaigns run from or into these markets.

JurisdictionRegionStatusWhat consent means here
๐Ÿ‡ฆ๐Ÿ‡ซ AfghanistanAsia-PacificNo lawNo data protection law.
๐Ÿ‡ง๐Ÿ‡น BhutanAsia-PacificSectoralSectoral ICT provisions require care with personal information; no comprehensive consent regime.
๐Ÿ‡ง๐Ÿ‡ด BoliviaAmericasNo lawNo comprehensive consent requirement.
๐Ÿ‡ฐ๐Ÿ‡ญ CambodiaAsia-PacificBill pendingNo comprehensive consent requirement; e-commerce law imposes limited confidentiality duties.
๐Ÿ‡ฉ๐Ÿ‡ฒ DominicaAmericasNo lawNo comprehensive consent requirement.
๐Ÿ‡ช๐Ÿ‡ท EritreaSub-Saharan AfricaNo lawNo data protection framework.
๐Ÿ‡ซ๐Ÿ‡ฏ FijiOceaniaBill pendingNo comprehensive consent requirement.
๐Ÿ‡ฌ๐Ÿ‡น GuatemalaAmericasBill pendingNo comprehensive consent requirement for the private sector.
๐Ÿ‡ฌ๐Ÿ‡ผ Guinea-BissauSub-Saharan AfricaNo lawNo data protection framework.
๐Ÿ‡ญ๐Ÿ‡น HaitiAmericasNo lawNo data protection framework.
๐Ÿ‡ญ๐Ÿ‡ณ HondurasAmericasBill pendingNo comprehensive consent requirement.
๐Ÿ‡ฎ๐Ÿ‡ท IranMiddle East & North AfricaBill pendingNo comprehensive consent requirement; e-commerce law imposes narrow duties on online sellers.
๐Ÿ‡ฎ๐Ÿ‡ถ IraqMiddle East & North AfricaNo lawNo comprehensive consent requirement.
๐Ÿ‡ฐ๐Ÿ‡ฎ KiribatiOceaniaBill pendingNo data protection framework in force.
๐Ÿ‡ฑ๐Ÿ‡พ LibyaMiddle East & North AfricaNo lawNo data protection framework.
๐Ÿ‡ฒ๐Ÿ‡ป MaldivesAsia-PacificBill pendingNo comprehensive consent requirement.
๐Ÿ‡ฒ๐Ÿ‡ญ Marshall IslandsOceaniaSectoralThe 2025 Act covers government ministries and agencies only; private businesses have no general consent rule.
๐Ÿ‡ซ๐Ÿ‡ฒ MicronesiaOceaniaNo lawNo data protection framework.
๐Ÿ‡ฒ๐Ÿ‡ฟ MozambiqueSub-Saharan AfricaBill pendingNo comprehensive consent requirement.
๐Ÿ‡ฒ๐Ÿ‡ฒ MyanmarAsia-PacificSectoralNo functioning comprehensive consent regime; the 2025 Cybersecurity Law is built around state control.
๐Ÿ‡ณ๐Ÿ‡ฆ NamibiaSub-Saharan AfricaBill pendingNo comprehensive consent requirement.
๐Ÿ‡ณ๐Ÿ‡ท NauruOceaniaNo lawNo data protection framework.
๐Ÿ‡ฐ๐Ÿ‡ต North KoreaAsia-PacificNo lawNo data protection framework.
๐Ÿ‡ต๐Ÿ‡ฐ PakistanAsia-PacificBill pendingNo comprehensive consent requirement today; sectoral rules (banking, telecom) impose confidentiality duties.
๐Ÿ‡ต๐Ÿ‡ผ PalauOceaniaNo lawNo data protection framework.
๐Ÿ‡ต๐Ÿ‡ฌ Papua New GuineaOceaniaNo lawNo comprehensive consent requirement.
๐Ÿ‡ป๐Ÿ‡จ Saint Vincent and the GrenadinesAmericasNo lawNo data protection framework in force.
๐Ÿ‡ผ๐Ÿ‡ธ SamoaOceaniaNo lawNo data protection framework.
๐Ÿ‡ธ๐Ÿ‡ฑ Sierra LeoneSub-Saharan AfricaBill pendingNo comprehensive consent requirement.
๐Ÿ‡ธ๐Ÿ‡ง Solomon IslandsOceaniaNo lawNo data protection framework.
๐Ÿ‡ธ๐Ÿ‡ธ South SudanSub-Saharan AfricaBill pendingNo data protection framework in force.
๐Ÿ‡ธ๐Ÿ‡ฉ SudanSub-Saharan AfricaNo lawNo comprehensive consent requirement.
๐Ÿ‡ธ๐Ÿ‡ท SurinameAmericasBill pendingNo comprehensive consent requirement.
๐Ÿ‡ธ๐Ÿ‡พ SyriaMiddle East & North AfricaAdoptedThe 2024 law exists on paper; whether and how it applies since the December 2024 change of government is unclear.
๐Ÿ‡น๐Ÿ‡ฑ Timor-LesteAsia-PacificNo lawNo comprehensive consent requirement.
๐Ÿ‡น๐Ÿ‡ป TuvaluOceaniaNo lawNo data protection framework.
๐Ÿ‡ป๐Ÿ‡ช VenezuelaAmericasNo lawNo comprehensive consent requirement.
๐Ÿ‡พ๐Ÿ‡ช YemenMiddle East & North AfricaNo lawNo data protection framework.

The channel matrix

Consent models are channel-specific, and the US flips depending on which channel you touch.

ChannelEU / UKUnited StatesCanadaAustralia
Targeted display and socialOpt-in (consent)Opt-out (state laws)Consent (implied possible)Notice + opt-out (APP 7)
Cookies and trackersOpt-in (ePrivacy)No general rule; opt-out of sale/shareConsent principlesNotice-based
Email marketingOpt-in + soft opt-inOpt-out (CAN-SPAM)Opt-in (CASL)Opt-in (Spam Act)
SMS and callsOpt-inOpt-in (TCPA)Opt-in (CASL + telemarketing rules)Opt-in
Sensitive-data targetingExplicit consent or prohibitedOpt-in; banned from sale in MarylandExpress consentConsent (sensitive information)

The planning rule that follows is to build the opt-in playbook once, run it everywhere, and loosen deliberately for the US where the economics justify a second track. The GDPR vs US comparison works through the differences line by line.

Cite this page: "Consent Models Worldwide: Opt-In vs Opt-Out." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/consent-models.html. Accessed [date].