{
 "name": "Worldwide Register of Data Privacy Law",
 "publisher": "Digital Privacy Regulations",
 "url": "https://digitalprivacyregs.com",
 "updated": "2026-09-28",
 "jurisdictions": [
  {
   "name": "Austria",
   "slug": "austria",
   "url": "https://digitalprivacyregs.com/austria.html",
   "flag": "🇦🇹",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Datenschutzgesetz (DSG)",
   "year": 2018,
   "authority": "Datenschutzbehörde (DSB)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V (adequacy, SCCs, BCRs).",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Austria is home base for noyb, the NGO behind Schrems I and II, and the DSB issued one of the first decisions finding Google Analytics transfers unlawful in 2022. Expect complaint-driven enforcement with an emphasis on adtech and transfers.",
   "sources": [
    {
     "label": "Datenschutzbehörde",
     "url": "https://www.dsb.gv.at/"
    }
   ]
  },
  {
   "name": "Belgium",
   "slug": "belgium",
   "url": "https://digitalprivacyregs.com/belgium.html",
   "flag": "🇧🇪",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Data Protection Act of 30 July 2018",
   "year": 2018,
   "authority": "Autorité de protection des données / Gegevensbeschermingsautoriteit (APD/GBA)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "The Belgian authority is the lead regulator for IAB Europe and its Transparency and Consent Framework, the consent backbone of programmatic advertising in Europe. Its 2022 TCF decision, largely upheld through CJEU review in 2024, is required reading for anyone buying open-web inventory in the EU.",
   "sources": [
    {
     "label": "APD/GBA",
     "url": "https://www.dataprotectionauthority.be/"
    }
   ]
  },
  {
   "name": "Bulgaria",
   "slug": "bulgaria",
   "url": "https://digitalprivacyregs.com/bulgaria.html",
   "flag": "🇧🇬",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Personal Data Protection Act",
   "year": 2018,
   "authority": "Commission for Personal Data Protection (CPDP)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Enforcement is modest by EU standards but real; the CPDP's BGN 5.1M fine against the national revenue agency after its 2019 breach remains one of the larger public-sector penalties in the region.",
   "sources": [
    {
     "label": "CPDP",
     "url": "https://www.cpdp.bg/"
    }
   ]
  },
  {
   "name": "Croatia",
   "slug": "croatia",
   "url": "https://digitalprivacyregs.com/croatia.html",
   "flag": "🇭🇷",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Act on the Implementation of the GDPR",
   "year": 2018,
   "authority": "AZOP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "AZOP has stepped up fines since 2023, including multimillion-euro penalties against debt collection and retail companies, a sign that smaller member states are no longer soft jurisdictions.",
   "sources": [
    {
     "label": "AZOP",
     "url": "https://azop.hr/"
    }
   ]
  },
  {
   "name": "Cyprus",
   "slug": "cyprus",
   "url": "https://digitalprivacyregs.com/cyprus.html",
   "flag": "🇨🇾",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Law 125(I)/2018",
   "year": 2018,
   "authority": "Commissioner for Personal Data Protection",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "A small but fully aligned GDPR jurisdiction; the Commissioner handles a steady docket of marketing and CCTV complaints.",
   "sources": [
    {
     "label": "Commissioner",
     "url": "https://www.dataprotection.gov.cy/"
    }
   ]
  },
  {
   "name": "Czechia",
   "slug": "czechia",
   "url": "https://digitalprivacyregs.com/czechia.html",
   "flag": "🇨🇿",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Act No. 110/2019 on Personal Data Processing",
   "year": 2019,
   "authority": "UOOU",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; cookie opt-in mandatory since the 2022 Electronic Communications Act amendment.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Czechia ran an opt-out cookie regime until January 2022, when the amended Electronic Communications Act flipped it to opt-in. Legacy Czech sites still running without consent banners are now exposed.",
   "sources": [
    {
     "label": "UOOU",
     "url": "https://uoou.gov.cz/"
    }
   ]
  },
  {
   "name": "Denmark",
   "slug": "denmark",
   "url": "https://digitalprivacyregs.com/denmark.html",
   "flag": "🇩🇰",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Danish Data Protection Act",
   "year": 2018,
   "authority": "Datatilsynet",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "The DPA cannot fine directly; it refers cases to the police, and the courts set fines within GDPR maximums.",
   "summary": "Denmark is the odd one out procedurally: Datatilsynet cannot fine directly and must refer cases to the police and courts. It compensates with detailed guidance, including some of the EU's clearest cookie consent standards, and it forced Google Workspace out of schools over transfer concerns.",
   "sources": [
    {
     "label": "Datatilsynet",
     "url": "https://www.datatilsynet.dk/"
    }
   ]
  },
  {
   "name": "Estonia",
   "slug": "estonia",
   "url": "https://digitalprivacyregs.com/estonia.html",
   "flag": "🇪🇪",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Personal Data Protection Act",
   "year": 2019,
   "authority": "Andmekaitse Inspektsioon (AKI)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Digitally advanced and pragmatic; AKI focuses on guidance-first enforcement, with credential and breach cases dominating its docket.",
   "sources": [
    {
     "label": "AKI",
     "url": "https://www.aki.ee/"
    }
   ]
  },
  {
   "name": "Finland",
   "slug": "finland",
   "url": "https://digitalprivacyregs.com/finland.html",
   "flag": "🇫🇮",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Data Protection Act (1050/2018)",
   "year": 2018,
   "authority": "Office of the Data Protection Ombudsman",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "The Ombudsman's sanctions board has fined postal, psychotherapy and taxi-sector controllers; the Vastaamo psychotherapy breach also produced criminal convictions, a reminder that Nordic enforcement can reach individuals.",
   "sources": [
    {
     "label": "Data Protection Ombudsman",
     "url": "https://tietosuoja.fi/"
    }
   ]
  },
  {
   "name": "France",
   "slug": "france",
   "url": "https://digitalprivacyregs.com/france.html",
   "flag": "🇫🇷",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Loi Informatique et Libertés (1978, as amended)",
   "year": 2018,
   "authority": "CNIL",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis plus the CNIL's cookie doctrine, under which refusing must be as easy as accepting.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover; separate national cookie fines.",
   "summary": "The CNIL is the most consequential regulator in Europe for advertisers because it enforces cookies under national law, outside the one-stop-shop. That is how Google took EUR 150M and Meta EUR 60M in cookie fines, and how Criteo, an adtech company, took EUR 40M in 2023. If a French user can see your banner, assume the CNIL can reach you directly.",
   "sources": [
    {
     "label": "CNIL",
     "url": "https://www.cnil.fr/en"
    }
   ]
  },
  {
   "name": "Germany",
   "slug": "germany",
   "url": "https://digitalprivacyregs.com/germany.html",
   "flag": "🇩🇪",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + BDSG + TDDDG (cookies and terminal equipment)",
   "year": 2018,
   "authority": "BfDI plus 16 state DPAs",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis; TDDDG requires opt-in consent for cookies and device access.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Germany runs data protection through seventeen authorities: the federal BfDI plus one per state, each with its own enforcement temperament. The TDDDG (renamed from TTDSG in 2024) puts the cookie consent rule in statute, and German courts produced Planet49, the CJEU case that killed pre-ticked boxes across Europe.",
   "sources": [
    {
     "label": "BfDI",
     "url": "https://www.bfdi.bund.de/EN/Home/home_node.html"
    }
   ]
  },
  {
   "name": "Greece",
   "slug": "greece",
   "url": "https://digitalprivacyregs.com/greece.html",
   "flag": "🇬🇷",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Law 4624/2019",
   "year": 2019,
   "authority": "Hellenic DPA (HDPA)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "The HDPA has fined telecoms and delivery platforms into eight figures and issued a EUR 20M penalty against Clearview AI, one of several EU authorities to sanction scraped facial recognition.",
   "sources": [
    {
     "label": "HDPA",
     "url": "https://www.dpa.gr/en"
    }
   ]
  },
  {
   "name": "Hungary",
   "slug": "hungary",
   "url": "https://digitalprivacyregs.com/hungary.html",
   "flag": "🇭🇺",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Act CXII of 2011 (Info Act)",
   "year": 2018,
   "authority": "NAIH",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "NAIH is an active fining authority relative to market size and issued an early landmark on AI: a HUF 250M penalty over undisclosed emotion analysis of recorded customer calls.",
   "sources": [
    {
     "label": "NAIH",
     "url": "https://naih.hu/"
    }
   ]
  },
  {
   "name": "Ireland",
   "slug": "ireland",
   "url": "https://digitalprivacyregs.com/ireland.html",
   "flag": "🇮🇪",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Data Protection Act 2018",
   "year": 2018,
   "authority": "Data Protection Commission (DPC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Ireland is where Big Tech's European headquarters live, which makes the DPC the lead authority for Meta, TikTok, Google, LinkedIn and much of the ad-funded internet. It has issued the largest fines in GDPR history, often after EDPB pressure raised the number, including EUR 1.2B against Meta over US transfers and EUR 530M against TikTok over China transfers. On 21 September 2026 it fined Google EUR 403M over location data processed through Location History, Web & App Activity and Location Accuracy between 2018 and 2020.",
   "sources": [
    {
     "label": "DPC",
     "url": "https://www.dataprotection.ie/"
    },
    {
     "label": "DPC decision on Google location data, September 2026",
     "url": "https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-fines-google-eu403-million-following-inquiry-googles-processing-location"
    }
   ]
  },
  {
   "name": "Italy",
   "slug": "italy",
   "url": "https://digitalprivacyregs.com/italy.html",
   "flag": "🇮🇹",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Privacy Code (D.Lgs. 196/2003, as amended)",
   "year": 2018,
   "authority": "Garante",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "The Garante moves faster and more aggressively than most peers: it temporarily banned ChatGPT in 2023, fined OpenAI EUR 15M in 2024, sanctioned Replika, and polices pay-or-okay models and telemarketing chains with real energy. Italy also runs one of Europe's strictest telemarketing consent-and-registry regimes.",
   "sources": [
    {
     "label": "Garante",
     "url": "https://www.garanteprivacy.it/"
    }
   ]
  },
  {
   "name": "Latvia",
   "slug": "latvia",
   "url": "https://digitalprivacyregs.com/latvia.html",
   "flag": "🇱🇻",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Personal Data Processing Law",
   "year": 2018,
   "authority": "Data State Inspectorate (DVI)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "A quieter jurisdiction with guidance-led enforcement; standard GDPR rules apply in full.",
   "sources": [
    {
     "label": "DVI",
     "url": "https://www.dvi.gov.lv/"
    }
   ]
  },
  {
   "name": "Lithuania",
   "slug": "lithuania",
   "url": "https://digitalprivacyregs.com/lithuania.html",
   "flag": "🇱🇹",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Law on Legal Protection of Personal Data",
   "year": 2018,
   "authority": "VDAI",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "VDAI issued one of the first GDPR fines anywhere (against payment firm MisterTango in 2019) and later a EUR 2.4M penalty against Vinted over data subject rights handling.",
   "sources": [
    {
     "label": "VDAI",
     "url": "https://vdai.lrv.lt/en/"
    }
   ]
  },
  {
   "name": "Luxembourg",
   "slug": "luxembourg",
   "url": "https://digitalprivacyregs.com/luxembourg.html",
   "flag": "🇱🇺",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Law of 1 August 2018",
   "year": 2018,
   "authority": "CNPD",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Luxembourg is a small country with an enormous case. The CNPD's EUR 746M fine against Amazon over advertising-related processing remains the second largest GDPR penalty ever issued.",
   "sources": [
    {
     "label": "CNPD",
     "url": "https://cnpd.public.lu/en.html"
    }
   ]
  },
  {
   "name": "Malta",
   "slug": "malta",
   "url": "https://digitalprivacyregs.com/malta.html",
   "flag": "🇲🇹",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Data Protection Act (Cap. 586)",
   "year": 2018,
   "authority": "IDPC",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Fully aligned GDPR jurisdiction; the IDPC's docket skews toward gaming and financial services given the local industry mix.",
   "sources": [
    {
     "label": "IDPC",
     "url": "https://idpc.org.mt/"
    }
   ]
  },
  {
   "name": "Netherlands",
   "slug": "netherlands",
   "url": "https://digitalprivacyregs.com/netherlands.html",
   "flag": "🇳🇱",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + GDPR Implementation Act (UAVG)",
   "year": 2018,
   "authority": "Autoriteit Persoonsgegevens (AP)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "The AP has become one of the EU's heaviest hitters: EUR 290M against Uber over US transfers, EUR 30.5M against Clearview AI, and EUR 4.75M against Netflix over transparency. It also runs active cookie banner sweeps and has said it will fine sites with non-compliant banners.",
   "sources": [
    {
     "label": "Autoriteit Persoonsgegevens",
     "url": "https://www.autoriteitpersoonsgegevens.nl/en"
    }
   ]
  },
  {
   "name": "Poland",
   "slug": "poland",
   "url": "https://digitalprivacyregs.com/poland.html",
   "flag": "🇵🇱",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Personal Data Protection Act 2018",
   "year": 2018,
   "authority": "UODO",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "UODO fines steadily across sectors and pays particular attention to breach notification failures; Poland is also a large enough ad market that consent quality gets scrutinized.",
   "sources": [
    {
     "label": "UODO",
     "url": "https://uodo.gov.pl/en"
    }
   ]
  },
  {
   "name": "Portugal",
   "slug": "portugal",
   "url": "https://digitalprivacyregs.com/portugal.html",
   "flag": "🇵🇹",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Law 58/2019",
   "year": 2019,
   "authority": "CNPD",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "The CNPD fined the national statistics institute EUR 4.3M over census data sent through Cloudflare without transfer safeguards, an early signal on infrastructure-level transfer risk.",
   "sources": [
    {
     "label": "CNPD",
     "url": "https://www.cnpd.pt/"
    }
   ]
  },
  {
   "name": "Romania",
   "slug": "romania",
   "url": "https://digitalprivacyregs.com/romania.html",
   "flag": "🇷🇴",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Law 190/2018",
   "year": 2018,
   "authority": "ANSPDCP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "High volume of smaller fines, frequently for security failures and unlawful disclosure; standard GDPR rules apply in full.",
   "sources": [
    {
     "label": "ANSPDCP",
     "url": "https://www.dataprotection.ro/"
    }
   ]
  },
  {
   "name": "Slovakia",
   "slug": "slovakia",
   "url": "https://digitalprivacyregs.com/slovakia.html",
   "flag": "🇸🇰",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Act No. 18/2018",
   "year": 2018,
   "authority": "Office for Personal Data Protection",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Fully aligned GDPR jurisdiction with guidance-led enforcement.",
   "sources": [
    {
     "label": "UOOU SR",
     "url": "https://dataprotection.gov.sk/uoou/"
    }
   ]
  },
  {
   "name": "Slovenia",
   "slug": "slovenia",
   "url": "https://digitalprivacyregs.com/slovenia.html",
   "flag": "🇸🇮",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + ZVOP-2 (2023)",
   "year": 2023,
   "authority": "Information Commissioner (IP-RS)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Slovenia was the last member state to pass its GDPR implementation act; ZVOP-2 finally arrived in January 2023, and with it the Commissioner's full fining powers.",
   "sources": [
    {
     "label": "IP-RS",
     "url": "https://www.ip-rs.si/en/"
    }
   ]
  },
  {
   "name": "Spain",
   "slug": "spain",
   "url": "https://digitalprivacyregs.com/spain.html",
   "flag": "🇪🇸",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + LOPDGDD (Organic Law 3/2018) + LSSI",
   "year": 2018,
   "authority": "AEPD",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis; LSSI adds separate cookie and commercial email rules with their own fines.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover; LSSI fines on top.",
   "summary": "The AEPD issues more fines than any other EU authority by count, and Spain's LSSI gives it a second statute for cookies and unsolicited commercial email. Banks and telecoms have taken the biggest hits (CaixaBank EUR 6M, Vodafone EUR 8.15M), but small-business cookie fines are routine here too.",
   "sources": [
    {
     "label": "AEPD",
     "url": "https://www.aepd.es/"
    }
   ]
  },
  {
   "name": "Sweden",
   "slug": "sweden",
   "url": "https://digitalprivacyregs.com/sweden.html",
   "flag": "🇸🇪",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + Data Protection Act (2018:218)",
   "year": 2018,
   "authority": "IMY",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR legal basis required; ePrivacy consent for cookies and tracking.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "IMY fined Spotify SEK 58M over access-request handling and ordered several companies to stop using Google Analytics in 2023, part of the post-Schrems II wave that reshaped EU analytics stacks.",
   "sources": [
    {
     "label": "IMY",
     "url": "https://www.imy.se/en/"
    }
   ]
  },
  {
   "name": "United Kingdom",
   "slug": "united-kingdom",
   "url": "https://digitalprivacyregs.com/united-kingdom.html",
   "flag": "🇬🇧",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "UK GDPR + Data Protection Act 2018 + PECR, amended by the Data (Use and Access) Act 2025",
   "year": 2018,
   "authority": "Information Commissioner's Office (ICO), the Information Commission from September 30, 2026",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "UK GDPR legal basis; PECR opt-in for cookies and e-marketing, with a soft opt-in for existing customers.",
   "transfers": "UK adequacy regulations, IDTA and the UK Addendum to EU SCCs; EU adequacy for the UK renewed in July 2025.",
   "penalties": "Fines reach GBP 17.5M or 4% of global annual turnover, whichever is higher.",
   "summary": "The UK kept the GDPR after Brexit, then rewrote parts of it. The Data (Use and Access) Act 2025 is the biggest change since 2018, and most of its data protection provisions went live on 5 February 2026.",
   "sources": [
    {
     "label": "ICO",
     "url": "https://ico.org.uk/"
    },
    {
     "label": "DUAA 2025",
     "url": "https://www.legislation.gov.uk/ukpga/2025/18"
    }
   ]
  },
  {
   "name": "Switzerland",
   "slug": "switzerland",
   "url": "https://digitalprivacyregs.com/switzerland.html",
   "flag": "🇨🇭",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Federal Act on Data Protection (revFADP)",
   "year": 2023,
   "authority": "FDPIC",
   "consent_model": "hybrid",
   "consent_label": "Hybrid",
   "marketing_consent_note": "Processing is lawful without consent unless it breaches personality rights; consent needed for sensitive data, high-risk profiling and to justify breaches. Mass email marketing requires opt-in under unfair competition law.",
   "transfers": "Adequacy list maintained by the Federal Council, which covers certified US companies under the Swiss-US Data Privacy Framework since 15 September 2024; SCCs otherwise. Switzerland holds EU adequacy.",
   "penalties": "Criminal fines up to CHF 250,000, aimed primarily at responsible individuals; a business can be fined up to CHF 50,000 where identifying the individual would be disproportionate.",
   "summary": "Switzerland's fully revised FADP took effect 1 September 2023 with no transition period. Its architecture is unusual in two ways. Private-sector processing does not need a legal basis by default, and penalties are criminal fines aimed mainly at individual managers. The FDPIC is testing marketing practices directly, and in April 2026 it ordered Philipp Plein and another online seller to stop emailing and texting customers who had objected. Email marketing is still opt-in via the Unfair Competition Act.",
   "sources": [
    {
     "label": "FDPIC",
     "url": "https://www.edoeb.admin.ch/en"
    },
    {
     "label": "FDPIC ruling on marketing after objection",
     "url": "https://www.edoeb.admin.ch/en/ruling-against-cream-della-cream-and-philipp-plein"
    }
   ]
  },
  {
   "name": "Norway",
   "slug": "norway",
   "url": "https://digitalprivacyregs.com/norway.html",
   "flag": "🇳🇴",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR (via EEA) + Personal Data Act 2018",
   "year": 2018,
   "authority": "Datatilsynet",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR applies through the EEA Agreement; ePrivacy consent for cookies.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Norway applies the GDPR in full through the EEA and enforces hard: Datatilsynet's Grindr fine (NOK 65M) over sharing user data with adtech partners is a landmark for app monetization, and its 2023 order against Meta's behavioral advertising pushed the EU-wide consent requirement.",
   "sources": [
    {
     "label": "Datatilsynet",
     "url": "https://www.datatilsynet.no/en/"
    }
   ]
  },
  {
   "name": "Iceland",
   "slug": "iceland",
   "url": "https://digitalprivacyregs.com/iceland.html",
   "flag": "🇮🇸",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR (via EEA) + Act 90/2018",
   "year": 2018,
   "authority": "Personuvernd",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR applies through the EEA Agreement; ePrivacy consent for cookies.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Full GDPR jurisdiction through the EEA; enforcement is proportionate to the small market but the rules are identical to the EU's.",
   "sources": [
    {
     "label": "Personuvernd",
     "url": "https://www.personuvernd.is/"
    }
   ]
  },
  {
   "name": "Liechtenstein",
   "slug": "liechtenstein",
   "url": "https://digitalprivacyregs.com/liechtenstein.html",
   "flag": "🇱🇮",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR (via EEA) + Data Protection Act 2018",
   "year": 2018,
   "authority": "Datenschutzstelle",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR applies through the EEA Agreement; ePrivacy consent for cookies.",
   "transfers": "GDPR Chapter V.",
   "penalties": "Up to EUR 20M or 4% of global turnover.",
   "summary": "Applies the GDPR in full through the EEA.",
   "sources": [
    {
     "label": "Datenschutzstelle",
     "url": "https://www.datenschutzstelle.li/"
    }
   ]
  },
  {
   "name": "Andorra",
   "slug": "andorra",
   "url": "https://digitalprivacyregs.com/andorra.html",
   "flag": "🇦🇩",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Qualified Law 29/2021 on Personal Data Protection",
   "year": 2021,
   "authority": "APDA",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled consent and legal bases.",
   "transfers": "Andorra holds an EU adequacy decision, so data from the EEA flows in without extra safeguards.",
   "penalties": "Fines reach EUR 100,000 per infringement.",
   "summary": "Andorra rewrote its law in 2021 to mirror the GDPR and holds one of the EU's adequacy decisions, so data flows from the EU freely.",
   "sources": [
    {
     "label": "APDA",
     "url": "https://www.apda.ad/"
    }
   ]
  },
  {
   "name": "Monaco",
   "slug": "monaco",
   "url": "https://digitalprivacyregs.com/monaco.html",
   "flag": "🇲🇨",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 1.565 on Personal Data Protection",
   "year": 2024,
   "authority": "APDP (formerly CCIN)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-aligned framework adopted in late 2024.",
   "transfers": "GDPR-style transfer rules; Monaco has long sought EU adequacy.",
   "penalties": "The new law provides for administrative fines.",
   "summary": "Monaco replaced its aging 1993 regime with a GDPR-aligned law adopted in December 2024, upgrading its authority into the APDP and modernizing rights, obligations and transfers.",
   "sources": [
    {
     "label": "APDP Monaco",
     "url": "https://apdp.mc/"
    }
   ]
  },
  {
   "name": "San Marino",
   "slug": "san-marino",
   "url": "https://digitalprivacyregs.com/san-marino.html",
   "flag": "🇸🇲",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 171/2018 on Personal Data Protection",
   "year": 2018,
   "authority": "Data Protection Authority of San Marino",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled framework.",
   "transfers": "Transfer rules follow the GDPR model of adequacy, appropriate safeguards and narrow derogations.",
   "penalties": "Administrative fines follow the GDPR model.",
   "summary": "San Marino adopted a GDPR-equivalent statute in 2018; compliance built for the EU generally satisfies it.",
   "sources": []
  },
  {
   "name": "Ukraine",
   "slug": "ukraine",
   "url": "https://digitalprivacyregs.com/ukraine.html",
   "flag": "🇺🇦",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 2297-VI on Personal Data Protection",
   "year": 2010,
   "authority": "Parliament Commissioner for Human Rights (Ombudsman)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent is the primary basis under the 2010 law; a GDPR-aligned replacement (draft 8153) is pending.",
   "transfers": "Permitted to states with adequate protection; consent or contract otherwise.",
   "penalties": "Modest administrative fines; the pending bill would raise them sharply.",
   "summary": "Ukraine's 2010 law predates the GDPR but a full GDPR-aligned rewrite (draft law 8153) has been advancing as part of the EU accession agenda; expect the regime to converge with EU rules. Wartime data realities have also made Ukraine unusually attentive to data security.",
   "sources": []
  },
  {
   "name": "Moldova",
   "slug": "moldova",
   "url": "https://digitalprivacyregs.com/moldova.html",
   "flag": "🇲🇩",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 133/2011 on Personal Data Protection",
   "year": 2011,
   "authority": "NCPDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework modeled on the pre-GDPR EU directive; GDPR alignment advancing under the EU accession track.",
   "transfers": "Transfers abroad need an adequate destination or the authority's authorization.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "Moldova runs a directive-era law from 2011 and is upgrading toward the GDPR as an EU candidate; monitor for the replacement statute.",
   "sources": []
  },
  {
   "name": "Belarus",
   "slug": "belarus",
   "url": "https://digitalprivacyregs.com/belarus.html",
   "flag": "🇧🇾",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 99-Z on Personal Data Protection",
   "year": 2021,
   "authority": "National Personal Data Protection Center (NPDPC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent is the default basis, with listed exceptions.",
   "transfers": "Free to states with adequate protection per the NPDPC list; permits otherwise.",
   "penalties": "Violations carry administrative and criminal liability.",
   "summary": "Belarus's first standalone data protection law took effect in November 2021 with a consent-centric design and an active supervisory center; state access to data remains extensive.",
   "sources": []
  },
  {
   "name": "Russia",
   "slug": "russia",
   "url": "https://digitalprivacyregs.com/russia.html",
   "flag": "🇷🇺",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Federal Law No. 152-FZ on Personal Data",
   "year": 2006,
   "authority": "Roskomnadzor",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Written or clearly demonstrable consent is the default basis, and since 1 September 2025 it must be obtained as a separate document; separate consent for dissemination; strict formalities.",
   "transfers": "Prior notification to Roskomnadzor for cross-border transfers; since 26 July 2026 only countries on Roskomnadzor's list count as adequate, and Convention 108 membership no longer qualifies on its own. Since 1 July 2025, Russian citizens' data may not be processed in databases located abroad.",
   "penalties": "From May 30, 2025, leak-related fines reach turnover-based levels up to 3%, plus large fixed fines and criminal liability for illegal data trafficking.",
   "summary": "Russia pairs consent formalism with hard data localization. Databases of Russian citizens' personal data must sit in Russia (LinkedIn has been blocked since 2016 for refusing), and a 2025 overhaul added turnover-based fines for leaks, criminal exposure, a ban on using foreign databases for citizens' data from July 2025, and standalone consent documents from September 2025. A July 2026 law narrowed what counts as an adequate destination for transfers. Western platforms operate here under heavy restriction or not at all.",
   "sources": [
    {
     "label": "Roskomnadzor",
     "url": "https://rkn.gov.ru/"
    }
   ]
  },
  {
   "name": "Serbia",
   "slug": "serbia",
   "url": "https://digitalprivacyregs.com/serbia.html",
   "flag": "🇷🇸",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data Protection",
   "year": 2018,
   "authority": "Commissioner for Information of Public Importance and Personal Data Protection",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled bases and consent standard.",
   "transfers": "GDPR-style: adequacy list, SCCs adopted by the Commissioner.",
   "penalties": "Fines reach RSD 2M per violation, low by EU standards; a draft law published in July 2026 would overhaul the regime.",
   "summary": "Serbia copied the GDPR's structure into national law in 2018 as part of EU accession; the substance is familiar even if the fine ceilings are not. A draft replacement law published on 30 July 2026, grown from 102 to 175 articles with new AI and video-surveillance rules, finished public consultation in September.",
   "sources": [
    {
     "label": "IAPP on the 2026 draft",
     "url": "https://iapp.org/news/a/serbia-s-draft-personal-data-protection-law-what-changes-are-on-the-table"
    }
   ]
  },
  {
   "name": "Montenegro",
   "slug": "montenegro",
   "url": "https://digitalprivacyregs.com/montenegro.html",
   "flag": "🇲🇪",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data Protection (2008, as amended); GDPR-aligned replacement adopted on the EU accession track",
   "year": 2008,
   "authority": "AZLP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework; GDPR alignment phasing in.",
   "transfers": "Transfers abroad need an adequate destination or the authority's authorization.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "Montenegro has operated a directive-era law since 2008 and adopted a GDPR-aligned replacement as part of its EU accession work; expect EU-style obligations as the new framework applies.",
   "sources": []
  },
  {
   "name": "North Macedonia",
   "slug": "north-macedonia",
   "url": "https://digitalprivacyregs.com/north-macedonia.html",
   "flag": "🇲🇰",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data Protection",
   "year": 2020,
   "authority": "Agency for Personal Data Protection",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled bases and consent standard.",
   "transfers": "Transfer rules follow the GDPR model of adequacy, appropriate safeguards and narrow derogations.",
   "penalties": "Fines are set as a percentage of turnover, on the GDPR model.",
   "summary": "North Macedonia's 2020 law is a close GDPR transplant, with the transition period long expired; treat it as an EU-style jurisdiction.",
   "sources": []
  },
  {
   "name": "Albania",
   "slug": "albania",
   "url": "https://digitalprivacyregs.com/albania.html",
   "flag": "🇦🇱",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 124/2024 on Personal Data Protection",
   "year": 2024,
   "authority": "Information and Data Protection Commissioner (IDP)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-aligned bases and consent standard.",
   "transfers": "Transfer rules follow the GDPR model of adequacy, appropriate safeguards and narrow derogations.",
   "penalties": "The 2024 law substantially increased fines.",
   "summary": "Albania replaced its 2008 statute with a GDPR-aligned law adopted in December 2024, with obligations phasing in through 2025 and beyond; another accession-driven convergence with EU rules.",
   "sources": [
    {
     "label": "IDP Albania",
     "url": "https://www.idp.al/"
    }
   ]
  },
  {
   "name": "Bosnia and Herzegovina",
   "slug": "bosnia-and-herzegovina",
   "url": "https://digitalprivacyregs.com/bosnia-and-herzegovina.html",
   "flag": "🇧🇦",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Protection of Personal Data",
   "year": 2006,
   "authority": "Personal Data Protection Agency (AZLP)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework from the pre-GDPR era.",
   "transfers": "Transfers abroad require the authority's authorization.",
   "penalties": "Administrative fines are modest.",
   "summary": "Runs a 2006-era law; a GDPR-aligned draft has circulated for years without passage. Compliance built for the EU comfortably exceeds local requirements.",
   "sources": []
  },
  {
   "name": "Turkey",
   "slug": "turkey",
   "url": "https://digitalprivacyregs.com/turkey.html",
   "flag": "🇹🇷",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 6698 on Protection of Personal Data (KVKK), amended 2024",
   "year": 2016,
   "authority": "KVKK (Personal Data Protection Authority)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Explicit consent or a listed basis; electronic marketing needs opt-in consent recorded in the IYS registry. Since 1 August 2026, targeted ads must disclose the criteria behind them, and profiling-based targeting of known children is banned.",
   "transfers": "Rewritten June 2024: adequacy decisions, appropriate safeguards including standard contracts (which must be filed with the Authority within five business days), and limited derogations.",
   "penalties": "Administrative fines revalued each year; the 2026 range runs from TRY 85,437 to TRY 17,092,242 per violation.",
   "summary": "Turkey's KVKK borrows from the pre-GDPR directive but was substantially modernized in March 2024 (effective June 2024), expanding sensitive-data processing grounds and replacing the old consent-or-adequacy transfer rule with a GDPR-style toolkit, including standard contracts with a mandatory filing step many multinationals miss. Commercial email and SMS require opt-in consent registered through the national IYS system. An amended advertising regulation in force since 1 August 2026 adds ad-specific rules: targeted ads must tell consumers which criteria selected them and how to change them, profiling-based targeting of children is banned, and AI-generated endorsements must be labeled.",
   "sources": [
    {
     "label": "KVKK",
     "url": "https://www.kvkk.gov.tr/"
    },
    {
     "label": "Gün + Partners on the 2026 advertising amendments",
     "url": "https://gun.av.tr/insights/updates/amendments-to-the-regulation-on-commercial-advertisement-and-unfair-commercial-practices"
    }
   ]
  },
  {
   "name": "Georgia",
   "slug": "georgia",
   "url": "https://digitalprivacyregs.com/georgia.html",
   "flag": "🇬🇪",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data Protection (2023)",
   "year": 2023,
   "authority": "Personal Data Protection Service (PDPS)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-aligned bases; direct marketing requires consent with an easy withdrawal path.",
   "transfers": "Transfers abroad go to destinations on the adequacy list or rely on appropriate safeguards.",
   "penalties": "Administrative fines apply, rising for repeat violations.",
   "summary": "Georgia's 2023 law, in force from mid-2024, moved the country decisively toward the GDPR, adding DPO duties, breach notification and direct marketing rules under an assertive supervisory service.",
   "sources": [
    {
     "label": "PDPS",
     "url": "https://personaldata.ge/en"
    }
   ]
  },
  {
   "name": "Armenia",
   "slug": "armenia",
   "url": "https://digitalprivacyregs.com/armenia.html",
   "flag": "🇦🇲",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Protection of Personal Data",
   "year": 2015,
   "authority": "Personal Data Protection Agency (Ministry of Justice)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework.",
   "transfers": "Transfers abroad need an adequately protective destination or the individual's consent.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "A consent-centric 2015 law enforced by a Ministry of Justice agency; modernization proposals track the GDPR.",
   "sources": []
  },
  {
   "name": "Azerbaijan",
   "slug": "azerbaijan",
   "url": "https://digitalprivacyregs.com/azerbaijan.html",
   "flag": "🇦🇿",
   "region": "Europe",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data",
   "year": 2010,
   "authority": "Ministry of Digital Development and Transport (supervision)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework with registration duties.",
   "transfers": "Transfers are restricted to adequate destinations unless the individual consents.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "A 2010 consent-based law with registration requirements; enforcement is limited and the framework predates modern adtech questions.",
   "sources": []
  },
  {
   "name": "China",
   "slug": "china",
   "url": "https://digitalprivacyregs.com/china.html",
   "flag": "🇨🇳",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Information Protection Law (PIPL) + Data Security Law + Cybersecurity Law",
   "year": 2021,
   "authority": "Cyberspace Administration of China (CAC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent is the workhorse basis, and 'separate consent' is required for sensitive data, cross-border transfers, and sharing with other handlers. No legitimate-interest basis exists.",
   "transfers": "Three routes: CAC security assessment, Chinese standard contract filing, or certification, whose implementing measures took effect January 1, 2026. Thresholds were relaxed in March 2024, but important data and large-volume transfers still need assessment.",
   "penalties": "Up to RMB 50M or 5% of the prior year's turnover, plus personal liability for responsible individuals and business suspension.",
   "summary": "China's PIPL is stricter than the GDPR where it counts for marketers: there is no legitimate-interest basis, targeted advertising requires a non-personalized alternative, and cross-border transfers run through government-supervised channels.",
   "sources": [
    {
     "label": "CAC",
     "url": "https://www.cac.gov.cn/"
    },
    {
     "label": "Global Times on the Trip.com fine, June 2026",
     "url": "https://www.globaltimes.cn/page/202606/1363458.shtml"
    }
   ]
  },
  {
   "name": "India",
   "slug": "india",
   "url": "https://digitalprivacyregs.com/india.html",
   "flag": "🇮🇳",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Digital Personal Data Protection Act, 2023 + DPDP Rules, 2025",
   "year": 2023,
   "authority": "Data Protection Board of India (legally established November 2025; being set up)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or narrow 'legitimate uses' (which do not include marketing). Notice-backed, itemized consent is the default for commercial processing.",
   "transfers": "Permitted to all countries except those on a government blacklist (none yet notified); sectoral rules can be stricter.",
   "penalties": "Up to INR 250 crore (about USD 30M) per category of breach, stackable, enforceable from 13 May 2027.",
   "summary": "India's DPDP Act began its phased start on 13 November 2025, when the DPDP Rules were notified and the provisions establishing the Data Protection Board took effect. Consent-manager provisions follow on 13 November 2026, and the substantive duties, together with the Board's enforcement powers and penalties, apply from 13 May 2027.",
   "sources": [
    {
     "label": "MeitY",
     "url": "https://www.meity.gov.in/"
    },
    {
     "label": "DLA Piper, India",
     "url": "https://www.dlapiperdataprotection.com/index.html?t=law&c=IN"
    }
   ]
  },
  {
   "name": "Japan",
   "slug": "japan",
   "url": "https://digitalprivacyregs.com/japan.html",
   "flag": "🇯🇵",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Act on the Protection of Personal Information (APPI)",
   "year": 2003,
   "authority": "Personal Information Protection Commission (PPC)",
   "consent_model": "hybrid",
   "consent_label": "Hybrid",
   "marketing_consent_note": "Notice-based collection with purpose limitation; opt-in consent mainly for sensitive data and third-party provision (an opt-out filing route exists for non-sensitive data). The 2026 amendment adds consent exceptions for statistics and AI development and parental consent for under-16s.",
   "transfers": "Consent, or transfer to a country with equivalent standards (EU and UK are whitelisted), or safeguards with disclosure duties.",
   "penalties": "Orders first, then fines up to JPY 100M for corporate violations; the 2026 amendment adds tougher criminal penalties from January 2027 and administrative surcharges for violations affecting more than 1,000 people by July 2028.",
   "summary": "Japan runs a notice-and-purpose regime, which keeps first-party marketing workable, and it holds mutual adequacy with the EU. The Diet passed the triennial-review amendment on 10 July 2026, promulgated a week later as Act No. 56 of 2026. It relaxes consent for statistics and AI training, requires parental consent for under-16s, adds biometric rules and gives the PPC its first administrative surcharges, phasing in between January 2027 and July 2028.",
   "sources": [
    {
     "label": "PPC",
     "url": "https://www.ppc.go.jp/en/"
    },
    {
     "label": "A&O Shearman on the promulgated amendment",
     "url": "https://www.aoshearman.com/en/insights/ao-shearman-on-data/amendments-to-the-act-on-the-protection-of-personal-information-promulgated"
    }
   ]
  },
  {
   "name": "South Korea",
   "slug": "south-korea",
   "url": "https://digitalprivacyregs.com/south-korea.html",
   "flag": "🇰🇷",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Information Protection Act (PIPA), overhauled 2023",
   "year": 2011,
   "authority": "Personal Information Protection Commission (PIPC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-centric with tightly drawn alternatives; separate opt-in consent for marketing use and for sensitive data. The 2023 amendment eased contract-necessity processing but marketing still runs on consent.",
   "transfers": "Consent, contract necessity, certification, or destination adequacy recognized by the PIPC. Korea holds EU adequacy.",
   "penalties": "Up to 3% of total revenue, excluding revenue shown to be unrelated; from September 2026, up to 10% for repeat intentional violations, incidents affecting 10 million or more people, and breaches after an ignored corrective order.",
   "summary": "Korea's PIPA is one of Asia's strictest and most actively enforced regimes, and 2026 raised the stakes twice. In June the PIPC imposed a record KRW 624.7B on Coupang, including KRW 201.1B for collecting 11.17 million members' activity on third-party sites through its Coupang Partners affiliate program. In September an amendment took effect allowing fines of up to 10% of total revenue for the worst cases. Marketing consent must be separate, specific and unbundled from service consent, a line the PIPC drew with its 2022 fines on Google (KRW 69.2B) and Meta (KRW 30.8B).",
   "sources": [
    {
     "label": "PIPC",
     "url": "https://www.pipc.go.kr/eng/"
    },
    {
     "label": "Korea Herald on the Coupang penalty, June 2026",
     "url": "https://www.koreaherald.com/article/10769731"
    }
   ]
  },
  {
   "name": "Vietnam",
   "slug": "vietnam",
   "url": "https://digitalprivacyregs.com/vietnam.html",
   "flag": "🇻🇳",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data Protection (Law 91/2025/QH15) + Decree 356/2025",
   "year": 2025,
   "authority": "Ministry of Public Security (A05)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent is the anchor basis with limited exceptions; marketing use requires consent and data subjects must be able to refuse.",
   "transfers": "Transfer impact assessment dossiers filed with the Ministry of Public Security; the Data Law adds controls for core and important data.",
   "penalties": "Administrative penalties with turnover-based elements introduced through the new framework; criminal exposure for data trafficking.",
   "summary": "Vietnam graduated from decree to statute on 1 January 2026: the PDPL (passed 26 June 2025) plus implementing Decree 356 (31 December 2025) replaced Decree 13/2023. Sitting alongside it, the Data Law (in force 1 July 2025) governs core and important data, and a revamped Cybersecurity Law arrived 1 July 2026.",
   "sources": []
  },
  {
   "name": "Indonesia",
   "slug": "indonesia",
   "url": "https://digitalprivacyregs.com/indonesia.html",
   "flag": "🇮🇩",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Law (Law 27/2022)",
   "year": 2022,
   "authority": "PDP supervisory agency mandated by law, still not established; the Ministry of Communication and Digital Affairs (Komdigi) supervises in the interim",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-style bases including consent, contract and legitimate interests, but explicit consent dominates commercial practice; Indonesian-language consent requirements apply.",
   "transfers": "Adequacy first, then safeguards, then consent, the order the PDP Law and its 2026 implementing regulation set; sectoral localization persists for public-sector and some regulated data.",
   "penalties": "Administrative fines up to 2% of annual revenue plus corporate criminal liability for misuse.",
   "summary": "Indonesia's PDP Law became fully applicable in October 2024, and its long-awaited implementing regulation, Government Regulation 33 of 2026, was issued in mid-2026 to apply six months after promulgation, with detail on transfers, impact assessments and data protection officers. The dedicated supervisory agency still does not exist, so enforcement stays with the digital ministry for now.",
   "sources": [
    {
     "label": "Komdigi",
     "url": "https://www.komdigi.go.id/"
    },
    {
     "label": "CNBC Indonesia, September 2026",
     "url": "https://www.cnbcindonesia.com/tech/20260916115609-37-768328/lembaga-perlindungan-data-belum-ada-di-ri-padahal-aturannya-sudah-ada"
    }
   ]
  },
  {
   "name": "Thailand",
   "slug": "thailand",
   "url": "https://digitalprivacyregs.com/thailand.html",
   "flag": "🇹🇭",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Act (PDPA)",
   "year": 2019,
   "authority": "Personal Data Protection Committee (PDPC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled bases including legitimate interests, but consent must be explicit where relied on, and direct marketing practice leans on consent; cookie consent expected for tracking.",
   "transfers": "Adequacy, appropriate safeguards (SCC-style), BCRs or consent.",
   "penalties": "Administrative fines to THB 5M, criminal penalties for sensitive-data violations, and statutory damages with punitive multipliers.",
   "summary": "Thailand's PDPA, fully enforced since June 2022, is a close GDPR cousin with a working regulator. The PDPC issued its first fine, THB 7M, in August 2024 against an online retailer over failures that included a missing DPO, weak security and an unreported breach, followed by five more fines in 2025, and it keeps building out sub-regulations on security, transfers and breach reporting.",
   "sources": [
    {
     "label": "PDPC Thailand",
     "url": "https://www.pdpc.or.th/"
    }
   ]
  },
  {
   "name": "Singapore",
   "slug": "singapore",
   "url": "https://digitalprivacyregs.com/singapore.html",
   "flag": "🇸🇬",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Act (PDPA) 2012, amended 2020",
   "year": 2012,
   "authority": "Personal Data Protection Commission (PDPC)",
   "consent_model": "hybrid",
   "consent_label": "Hybrid",
   "marketing_consent_note": "Consent is the default but the 2020 amendments added deemed consent by notification and a legitimate interests exception; the Do Not Call registry governs phone and SMS marketing.",
   "transfers": "Comparable-protection standard via contracts, BCRs or certification (APEC CBPR recognized).",
   "penalties": "Up to 10% of annual Singapore turnover for large firms, or SGD 1M.",
   "summary": "Singapore runs the most business-calibrated regime in Asia: consent-based on paper, but with deemed consent and a legitimate-interests route that make first-party marketing manageable, plus a strict Do Not Call registry for calls and texts. The PDPC is a prolific, guidance-heavy enforcer.",
   "sources": [
    {
     "label": "PDPC Singapore",
     "url": "https://www.pdpc.gov.sg/"
    }
   ]
  },
  {
   "name": "Malaysia",
   "slug": "malaysia",
   "url": "https://digitalprivacyregs.com/malaysia.html",
   "flag": "🇲🇾",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Act 2010, amended 2024",
   "year": 2010,
   "authority": "Personal Data Protection Commissioner (JPDP)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based processing with a statutory right to stop direct marketing; the Act covers commercial transactions and excludes government.",
   "transfers": "2024 amendments scrapped the whitelist: transfers allowed where the destination has substantially similar law or adequate protection.",
   "penalties": "Raised in 2024 to RM 1M and imprisonment exposure per violation.",
   "summary": "Malaysia's 2024 amendment package modernized a 2010-era law in phases through 2025. Mandatory breach notification, DPO appointments and a data portability right arrived on 1 June 2025, biometric data joined the sensitive category, and processors took on direct security duties. Government processing remains outside the Act, a notable gap.",
   "sources": [
    {
     "label": "JPDP",
     "url": "https://www.pdp.gov.my/"
    }
   ]
  },
  {
   "name": "Philippines",
   "slug": "philippines",
   "url": "https://digitalprivacyregs.com/philippines.html",
   "flag": "🇵🇭",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Privacy Act of 2012 (RA 10173)",
   "year": 2012,
   "authority": "National Privacy Commission (NPC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or another lawful criterion; direct marketing and profiling effectively require consent, and the NPC polices deceptive consent design.",
   "transfers": "Accountability-based: the transferor remains responsible; contracts expected.",
   "penalties": "Criminal penalties under the Act plus NPC administrative fines of up to 3% of annual gross income, capped at PHP 5M per act (2022 circular).",
   "summary": "The Philippines was an early ASEAN adopter and has an unusually active regulator. The NPC issues compliance orders, runs breach investigations and added percentage-based administrative fines in 2022. On 22 September 2026 it issued show-cause orders to Meta, Roblox, Reddit and Discord over registration duties as part of a push on children's privacy. Amendment bills to modernize the 2012 Act recur each Congress.",
   "sources": [
    {
     "label": "NPC",
     "url": "https://privacy.gov.ph/"
    }
   ]
  },
  {
   "name": "Sri Lanka",
   "slug": "sri-lanka",
   "url": "https://digitalprivacyregs.com/sri-lanka.html",
   "flag": "🇱🇰",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Personal Data Protection Act No. 9 of 2022, amended by Act No. 22 of 2025",
   "year": 2022,
   "authority": "Data Protection Authority of Sri Lanka (operating)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled bases; consent must be demonstrable and withdrawable once the substantive provisions are brought into operation.",
   "transfers": "Transfers abroad will need an adequate destination or safeguards, with sectoral carve-outs, once the substantive provisions start.",
   "penalties": "Fines up to LKR 10M per violation, escalating for repeats, once the substantive provisions start.",
   "summary": "South Asia's first comprehensive law has a working regulator but no operative duties yet. Only the Data Protection Authority and interpretation provisions are in force; the 2025 amendment (Act No. 22 of 2025) left the start of the substantive obligations to a ministerial order, and none had been made as of early 2026. GDPR-trained compliance will travel well once it lands.",
   "sources": [
    {
     "label": "Data Protection Authority",
     "url": "https://www.dpa.gov.lk/"
    }
   ]
  },
  {
   "name": "Pakistan",
   "slug": "pakistan",
   "url": "https://digitalprivacyregs.com/pakistan.html",
   "flag": "🇵🇰",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Personal Data Protection Bill (pending); PECA 2016 covers cyber offenses",
   "year": null,
   "authority": "None yet (bill proposes a National Commission for Personal Data Protection)",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement today; sectoral rules (banking, telecom) impose confidentiality duties.",
   "transfers": "No general regime; the draft bill proposes localization for critical data.",
   "penalties": "No penalties apply under a general privacy law.",
   "summary": "Pakistan has circulated Personal Data Protection Bill drafts since 2018, with cabinet-approved versions in 2023 stalling short of enactment. Until a law passes, there is no general consent requirement for processing or marketing, only sectoral confidentiality rules.",
   "sources": []
  },
  {
   "name": "Bangladesh",
   "slug": "bangladesh",
   "url": "https://digitalprivacyregs.com/bangladesh.html",
   "flag": "🇧🇩",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Personal Data Protection Act, 2026 (Act No. 63 of 2026)",
   "year": 2026,
   "authority": "National Data Management Authority (created by the National Data Management Act, 2026; being set up)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based processing under the 2026 Act; the complaints, fines and compensation provisions start only when the government notifies them, no earlier than October 2027.",
   "transfers": "The Act regulates transfers abroad, with the National Data Management Authority as supervisor once it is operating.",
   "penalties": "Administrative fines and compensation provisions are deferred until the government notifies them, no earlier than October 2027.",
   "summary": "Bangladesh now has a data protection statute. Parliament passed the Personal Data Protection Act on 9 April 2026, replacing the interim government's 2025 ordinance, and most of it is treated as in force from 6 November 2025. The fines, complaints and chief data officer provisions wait for a government notice at least 18 months after enactment, and the new National Data Management Authority is still being built.",
   "sources": [
    {
     "label": "Personal Data Protection Act, 2026 (Laws of Bangladesh)",
     "url": "http://bdlaws.minlaw.gov.bd/act-details-1692.html"
    }
   ]
  },
  {
   "name": "Nepal",
   "slug": "nepal",
   "url": "https://digitalprivacyregs.com/nepal.html",
   "flag": "🇳🇵",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Individual Privacy Act, 2075 (2018)",
   "year": 2018,
   "authority": "No dedicated DPA; enforcement through courts and the National Information Commission for related matters",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent required for collection, use and publication of personal information, with broad government exceptions.",
   "transfers": "Transfers abroad rely on consent, and the law sets out no dedicated transfer mechanism.",
   "penalties": "Violations can bring fines and up to three years' imprisonment.",
   "summary": "Nepal legislated early for the region with the 2018 Privacy Act and 2020 regulations, but without a supervisory authority enforcement runs through criminal complaints, which keeps practical pressure low.",
   "sources": []
  },
  {
   "name": "Bhutan",
   "slug": "bhutan",
   "url": "https://digitalprivacyregs.com/bhutan.html",
   "flag": "🇧🇹",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "sectoral",
   "status_label": "Sectoral",
   "primary_law": "Information, Communications and Media Act 2018 (data provisions)",
   "year": 2018,
   "authority": "BICMA (media and ICT regulator)",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "Sectoral ICT provisions require care with personal information; no comprehensive consent regime.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "Only sector-specific penalties apply.",
   "summary": "Bhutan protects personal information through provisions of its 2018 ICM Act; a standalone privacy statute has been discussed but not enacted.",
   "sources": []
  },
  {
   "name": "Maldives",
   "slug": "maldives",
   "url": "https://digitalprivacyregs.com/maldives.html",
   "flag": "🇲🇻",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Data protection bill pending; constitutional privacy right",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "No penalties apply under a general privacy law.",
   "summary": "A data protection bill has been in development for several years; until enactment, only constitutional and sectoral protections apply.",
   "sources": []
  },
  {
   "name": "Afghanistan",
   "slug": "afghanistan",
   "url": "https://digitalprivacyregs.com/afghanistan.html",
   "flag": "🇦🇫",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection law.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No data protection framework exists, and none is in prospect under the current authorities.",
   "sources": []
  },
  {
   "name": "Mongolia",
   "slug": "mongolia",
   "url": "https://digitalprivacyregs.com/mongolia.html",
   "flag": "🇲🇳",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data Protection",
   "year": 2021,
   "authority": "National Human Rights Commission (oversight role)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based collection and processing with listed exceptions; sensitive data restricted.",
   "transfers": "Transfers abroad rely on the individual's consent or an international treaty.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "Mongolia's 2021 law, in force May 2022, replaced a 1990s-era statute with a modern consent-based framework, part of a broader digital-government package.",
   "sources": []
  },
  {
   "name": "Kazakhstan",
   "slug": "kazakhstan",
   "url": "https://digitalprivacyregs.com/kazakhstan.html",
   "flag": "🇰🇿",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data and its Protection",
   "year": 2013,
   "authority": "Ministry of Artificial Intelligence and Digital Development (successor to the Ministry of Digital Development since September 2025)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based with formal requirements; amendments have tightened biometric and digital-ID handling.",
   "transfers": "Restricted to states ensuring protection; consent otherwise. Domestic storage requirement for databases containing citizens' data.",
   "penalties": "Administrative fines; criminal exposure for unlawful dissemination.",
   "summary": "A consent-plus-localization regime in the Russian mold: personal data of Kazakh citizens must be stored on in-country servers, and cross-border transfers face adequacy-style limits.",
   "sources": []
  },
  {
   "name": "Kyrgyzstan",
   "slug": "kyrgyzstan",
   "url": "https://digitalprivacyregs.com/kyrgyzstan.html",
   "flag": "🇰🇬",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Information (2008, amended 2021)",
   "year": 2008,
   "authority": "State Personal Data Protection Agency",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based; 2021 amendments added localization and a supervisory agency.",
   "transfers": "Transfers are restricted, and a localization rule keeps certain data in the country.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "The 2021 amendments gave Kyrgyzstan a supervisory agency and Russian-style localization duties on top of its 2008 consent framework.",
   "sources": []
  },
  {
   "name": "Tajikistan",
   "slug": "tajikistan",
   "url": "https://digitalprivacyregs.com/tajikistan.html",
   "flag": "🇹🇯",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data Protection",
   "year": 2018,
   "authority": "Communications service under the Government",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based with listed exceptions.",
   "transfers": "Transfers are restricted to adequate destinations unless the individual consents.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "A 2018 consent-based law with limited visible enforcement.",
   "sources": []
  },
  {
   "name": "Turkmenistan",
   "slug": "turkmenistan",
   "url": "https://digitalprivacyregs.com/turkmenistan.html",
   "flag": "🇹🇲",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Information about Private Life and its Protection",
   "year": 2017,
   "authority": "State bodies; no independent DPA",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based on paper; state access is extensive.",
   "transfers": "Transfers abroad are restricted.",
   "penalties": "The law provides for administrative sanctions.",
   "summary": "A formal 2017 statute exists, but in one of the world's most closed information environments its practical meaning for private actors is limited.",
   "sources": []
  },
  {
   "name": "Uzbekistan",
   "slug": "uzbekistan",
   "url": "https://digitalprivacyregs.com/uzbekistan.html",
   "flag": "🇺🇿",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law on Personal Data (2019, amended 2021)",
   "year": 2019,
   "authority": "Personalization Agency under the Cabinet of Ministers (Uzkomnazorat oversight)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based; registration of databases required.",
   "transfers": "Localization: Uzbek citizens' personal data must be processed on servers physically located in Uzbekistan (2021 amendment); transfers restricted.",
   "penalties": "Administrative fines; blocking powers used against non-compliant platforms.",
   "summary": "Uzbekistan added a hard localization rule in 2021 and has blocked or throttled major platforms for non-compliance, making it one of Central Asia's most assertive regimes.",
   "sources": []
  },
  {
   "name": "Laos",
   "slug": "laos",
   "url": "https://digitalprivacyregs.com/laos.html",
   "flag": "🇱🇦",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "sectoral",
   "status_label": "Sectoral",
   "primary_law": "Law on Electronic Data Protection (2017)",
   "year": 2017,
   "authority": "Ministry of Technology and Communications",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-oriented rules for electronic data; scope and enforcement are narrow.",
   "transfers": "Some categories of data need government approval before leaving the country.",
   "penalties": "The law provides for administrative sanctions.",
   "summary": "The 2017 Electronic Data Protection Law covers electronic personal and organizational data with consent-style duties, but it falls short of a comprehensive privacy statute and sees little enforcement.",
   "sources": []
  },
  {
   "name": "Cambodia",
   "slug": "cambodia",
   "url": "https://digitalprivacyregs.com/cambodia.html",
   "flag": "🇰🇭",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Draft personal data protection law (pending); e-commerce and consumer protection laws carry data duties",
   "year": null,
   "authority": "None yet (Ministry of Post and Telecommunications drafting)",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement; e-commerce law imposes limited confidentiality duties.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "Only sector-specific penalties apply.",
   "summary": "A draft personal data protection law has been in preparation since 2021-2022; until it passes, only e-commerce and sectoral duties apply.",
   "sources": []
  },
  {
   "name": "Myanmar",
   "slug": "myanmar",
   "url": "https://digitalprivacyregs.com/myanmar.html",
   "flag": "🇲🇲",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "sectoral",
   "status_label": "Sectoral",
   "primary_law": "Cybersecurity Law (2025) data provisions; Law Protecting Privacy and Security of Citizens (2017, partly suspended)",
   "year": 2025,
   "authority": "Military-controlled ministries",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No functioning comprehensive consent regime; the 2025 Cybersecurity Law is built around state control.",
   "transfers": "The state controls cross-border data flows directly.",
   "penalties": "Criminal penalties apply under security laws.",
   "summary": "Post-coup Myanmar regulates data through a January 2025 Cybersecurity Law oriented to surveillance and VPN control; no rights-based privacy framework operates in practice.",
   "sources": []
  },
  {
   "name": "Brunei",
   "slug": "brunei",
   "url": "https://digitalprivacyregs.com/brunei.html",
   "flag": "🇧🇳",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Order, 2025",
   "year": 2025,
   "authority": "AITI (Authority for Info-communications Technology Industry)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Singapore-modeled consent framework for the private sector, with deemed consent concepts.",
   "transfers": "Transfers abroad need comparable protection at the destination.",
   "penalties": "Financial penalties up to 10% of local turnover or BND 1M for larger firms.",
   "summary": "Brunei's first private-sector data protection law, the Personal Data Protection Order 2025, was enacted in January 2025, and most of its substantive duties have applied since 1 January 2026. It is closely modeled on Singapore's PDPA and enforced by AITI; government processing sits outside it.",
   "sources": [
    {
     "label": "AITI: Personal Data Protection",
     "url": "https://www.aiti.gov.bn/regulatory/pdp/"
    }
   ]
  },
  {
   "name": "North Korea",
   "slug": "north-korea",
   "url": "https://digitalprivacyregs.com/north-korea.html",
   "flag": "🇰🇵",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "Not applicable.",
   "penalties": "Not applicable.",
   "summary": "No data protection framework exists, and with no commercial data economy to regulate, the question is academic.",
   "sources": []
  },
  {
   "name": "Timor-Leste",
   "slug": "timor-leste",
   "url": "https://digitalprivacyregs.com/timor-leste.html",
   "flag": "🇹🇱",
   "region": "Asia-Pacific",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None; constitutional privacy right",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force; constitutional privacy protections and general law apply.",
   "sources": []
  },
  {
   "name": "Israel",
   "slug": "israel",
   "url": "https://digitalprivacyregs.com/israel.html",
   "flag": "🇮🇱",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Protection of Privacy Law 1981, transformed by Amendment 13 (2024)",
   "year": 1981,
   "authority": "Privacy Protection Authority (PPA)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent (informed, and often implied by conduct for non-sensitive contexts) underpins processing; the Spam Law requires opt-in for commercial email, SMS and fax.",
   "transfers": "Regulated by the transfer regulations; Israel holds an EU adequacy decision, reaffirmed in the EU's 2024 review.",
   "penalties": "Amendment 13 armed the PPA with administrative fines that scale with database sensitivity and size; its first, in July 2026, was NIS 256,000 against the health fund Meuhedet for failing to report a breach.",
   "summary": "Amendment 13, in force 14 August 2025, is the biggest change to Israeli privacy law since 1981: modernized definitions, mandatory DPOs for major processors, real fining powers for the PPA, and a slimmed-down database registration duty. Israel's Spam Law has required opt-in for electronic marketing since 2008.",
   "sources": [
    {
     "label": "PPA",
     "url": "https://www.gov.il/en/departments/the_privacy_protection_authority"
    }
   ]
  },
  {
   "name": "Saudi Arabia",
   "slug": "saudi-arabia",
   "url": "https://digitalprivacyregs.com/saudi-arabia.html",
   "flag": "🇸🇦",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Law (PDPL), amended 2023",
   "year": 2021,
   "authority": "Saudi Data and AI Authority (SDAIA)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent is the default basis; the 2023 amendments added legitimate-interest room for non-sensitive data, but direct marketing effectively requires consent plus an opt-out in every message.",
   "transfers": "Transfer regulations (2024) allow adequacy-based transfers, safeguards (SCCs, BCRs, certification) and risk assessments; SDAIA has not published a list of adequate countries, so safeguards do most of the work.",
   "penalties": "Fines up to SAR 5M (doubled for repeats), criminal exposure for sensitive-data disclosure, plus SDAIA corrective powers.",
   "summary": "Saudi Arabia runs the Gulf's most consequential regime. The PDPL took full effect 14 September 2023, its enforcement grace period ended 14 September 2024, and SDAIA has since published registration, DPO and transfer rules. In January 2026 its violation committees announced their first 48 enforcement decisions, including penalties for marketing messages sent without consent. Marketing requires consent and a working opt-out, and sensitive-data marketing is prohibited outright.",
   "sources": [
    {
     "label": "SDAIA",
     "url": "https://sdaia.gov.sa/en/"
    },
    {
     "label": "Saudi Press Agency, January 2026",
     "url": "https://spa.gov.sa/en/N2489505"
    }
   ]
  },
  {
   "name": "United Arab Emirates",
   "slug": "united-arab-emirates",
   "url": "https://digitalprivacyregs.com/united-arab-emirates.html",
   "flag": "🇦🇪",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Federal Decree-Law No. 45/2021 (PDPL); DIFC and ADGM run separate GDPR-style regimes",
   "year": 2021,
   "authority": "UAE Data Office (federal); DIFC and ADGM Commissioners in the financial free zones",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-centric federal law on paper, but its executive regulations remain unissued, so operative obligations today come mainly from the DIFC and ADGM regimes and sectoral rules.",
   "transfers": "Federal law contemplates adequacy and safeguards pending regulations; DIFC and ADGM apply GDPR-style transfer tools with their own adequacy lists.",
   "penalties": "To be set by the pending executive regulations; DIFC fines have already reached six figures.",
   "summary": "The UAE's federal PDPL was issued in 2021 but its executive regulations have still not landed as of mid-2026, leaving enforcement effectively paused at the federal level. In practice the DIFC Data Protection Law 2020 and ADGM regulations, both GDPR-grade and actively enforced, plus sectoral health and telecom rules, are what companies actually comply with.",
   "sources": [
    {
     "label": "DIFC Commissioner",
     "url": "https://www.difc.ae/business/operating/data-protection/"
    }
   ]
  },
  {
   "name": "Qatar",
   "slug": "qatar",
   "url": "https://digitalprivacyregs.com/qatar.html",
   "flag": "🇶🇦",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 13 of 2016 on Personal Data Privacy Protection",
   "year": 2016,
   "authority": "National Cyber Governance and Assurance Affairs (NCGAA) under the NCSA; QFC has its own regime",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-based processing with direct marketing requiring prior consent and opt-out in each message.",
   "transfers": "Permitted with consent or where protection is not undermined; QFC applies GDPR-style rules.",
   "penalties": "Fines reach QAR 5M.",
   "summary": "The first Gulf state with a standalone privacy law (2016); guidelines issued from 2021 gave it operational teeth, and the Qatar Financial Centre runs a separate GDPR-style regime with its own DPO and transfer rules.",
   "sources": []
  },
  {
   "name": "Bahrain",
   "slug": "bahrain",
   "url": "https://digitalprivacyregs.com/bahrain.html",
   "flag": "🇧🇭",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Law (Law No. 30 of 2018)",
   "year": 2018,
   "authority": "Personal Data Protection Authority (under the Ministry of Justice)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or listed grounds; direct marketing requires prior consent.",
   "transfers": "Transfers go to adequacy-listed destinations or need authorization, with consent available as a derogation.",
   "penalties": "Criminal penalties including fines and imprisonment, plus administrative orders.",
   "summary": "In force since August 2019, Bahrain's law carries unusual criminal-law teeth, making certain violations, including unlawful sensitive-data processing and transfers, prosecutable offenses.",
   "sources": []
  },
  {
   "name": "Kuwait",
   "slug": "kuwait",
   "url": "https://digitalprivacyregs.com/kuwait.html",
   "flag": "🇰🇼",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "sectoral",
   "status_label": "Sectoral",
   "primary_law": "CITRA Data Privacy Protection Regulation (2021, updated 2024); no standalone statute",
   "year": 2021,
   "authority": "CITRA (Communication and Information Technology Regulatory Authority)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-oriented duties for telecom and ICT service providers, including apps and platforms, under a regulation that stops short of an economy-wide statute.",
   "transfers": "Regulated providers need CITRA approval for certain transfers abroad.",
   "penalties": "CITRA enforces through sanctions attached to its licensing powers.",
   "summary": "Kuwait has no comprehensive law and regulates privacy through a CITRA regulation binding telecom and ICT service providers, though the regulation's reach over apps and platforms makes it broader than it sounds. A full statute remains under discussion.",
   "sources": []
  },
  {
   "name": "Oman",
   "slug": "oman",
   "url": "https://digitalprivacyregs.com/oman.html",
   "flag": "🇴🇲",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Law (Royal Decree 6/2022)",
   "year": 2022,
   "authority": "Ministry of Transport, Communications and IT",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Express written-form consent is the default basis, one of the strictest consent standards anywhere; sensitive data needs ministry permits.",
   "transfers": "Permitted subject to conditions in the executive regulations (2024).",
   "penalties": "Fines reach OMR 500,000.",
   "summary": "In force since February 2023 with 2024 executive regulations, Oman's law is notable for demanding express consent as the default and permits for sensitive-data processing, a compliance posture stricter than the GDPR's on paper.",
   "sources": []
  },
  {
   "name": "Jordan",
   "slug": "jordan",
   "url": "https://digitalprivacyregs.com/jordan.html",
   "flag": "🇯🇴",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Law No. 24 of 2023",
   "year": 2023,
   "authority": "Personal Data Protection Council / unit within the Ministry of Digital Economy",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with listed exceptions; explicit rules for direct marketing consent.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "Administrative fines apply, and the authority can act against licences.",
   "summary": "Jordan's first comprehensive law took effect in March 2024 after a one-year transition, giving the region another GDPR-influenced consent regime; implementing regulations continue to roll out.",
   "sources": []
  },
  {
   "name": "Lebanon",
   "slug": "lebanon",
   "url": "https://digitalprivacyregs.com/lebanon.html",
   "flag": "🇱🇧",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 81/2018 on Electronic Transactions and Personal Data",
   "year": 2018,
   "authority": "Ministry of Economy and Trade (licensing role)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-oriented but with broad exemptions, in a regime built around licensing.",
   "transfers": "The law contemplates ministry authorization for transfers abroad.",
   "penalties": "Fines are limited.",
   "summary": "Law 81/2018 nominally covers personal data but its licensing-centric design, wide carve-outs and the absence of a real supervisory authority leave enforcement close to theoretical.",
   "sources": []
  },
  {
   "name": "Iraq",
   "slug": "iraq",
   "url": "https://digitalprivacyregs.com/iraq.html",
   "flag": "🇮🇶",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None; constitutional privacy right and sectoral rules",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No regime.",
   "penalties": "None under a general privacy law.",
   "summary": "No comprehensive data protection law is in force; draft digital-law initiatives have circulated without passage.",
   "sources": []
  },
  {
   "name": "Syria",
   "slug": "syria",
   "url": "https://digitalprivacyregs.com/syria.html",
   "flag": "🇸🇾",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law No. 12 of 2024 on the Protection of Electronic Personal Data",
   "year": 2024,
   "authority": "Personal Data Protection Authority provided by law; operating status unclear",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "The 2024 law exists on paper; whether and how it applies since the December 2024 change of government is unclear.",
   "transfers": "The 2024 law's transfer rules show no visible enforcement.",
   "penalties": "No enforcement has been observed under the 2024 law.",
   "summary": "Syria's previous government enacted Law No. 12 of 2024 on the protection of electronic personal data, with a dedicated authority. Since the December 2024 change of government there is no clear public record of the law being implemented or enforced.",
   "sources": [
    {
     "label": "Morrison Foerster privacy library",
     "url": "https://www.mofo.com/privacy-library/syria"
    }
   ]
  },
  {
   "name": "Yemen",
   "slug": "yemen",
   "url": "https://digitalprivacyregs.com/yemen.html",
   "flag": "🇾🇪",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No data protection framework exists.",
   "sources": []
  },
  {
   "name": "Iran",
   "slug": "iran",
   "url": "https://digitalprivacyregs.com/iran.html",
   "flag": "🇮🇷",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Personal Data Protection and Safeguarding Bill (pending); e-commerce law has limited data rules",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement; e-commerce law imposes narrow duties on online sellers.",
   "transfers": "Cross-border data flows run through a state-controlled network environment.",
   "penalties": "Only sector-specific penalties apply.",
   "summary": "A data protection bill has moved through drafting stages for years without enactment; state network control is the operative reality.",
   "sources": []
  },
  {
   "name": "Egypt",
   "slug": "egypt",
   "url": "https://digitalprivacyregs.com/egypt.html",
   "flag": "🇪🇬",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Personal Data Protection Law No. 151 of 2020",
   "year": 2020,
   "authority": "Personal Data Protection Center, which has begun licensing and issuing guidance",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first, with licences required under the Executive Regulation for processing, cross-border transfers, sensitive data and direct electronic marketing.",
   "transfers": "Cross-border transfers need a licence from the Center and an adequate level of protection at the destination.",
   "penalties": "Fines up to EGP 5M plus imprisonment for certain violations; the Executive Regulation's one-year grace period runs out in early November 2026.",
   "summary": "Egypt's Law 151 of 2020 finally gained its Executive Regulation in November 2025 (Ministerial Decision No. 816 of 2025), starting a one-year grace period that ends in early November 2026. The Personal Data Protection Center is licensing controllers and issuing guidance, and direct electronic marketing needs both consent and a licence. Build for enforcement from November.",
   "sources": [
    {
     "label": "Tech Hive Advisory review of the Executive Regulation",
     "url": "https://www.techhiveadvisory.africa/insights/review-of-egypts-executive-regulation-for-the-personal-data-protection-law"
    }
   ]
  },
  {
   "name": "Libya",
   "slug": "libya",
   "url": "https://digitalprivacyregs.com/libya.html",
   "flag": "🇱🇾",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No data protection framework exists.",
   "sources": []
  },
  {
   "name": "Tunisia",
   "slug": "tunisia",
   "url": "https://digitalprivacyregs.com/tunisia.html",
   "flag": "🇹🇳",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Organic Law 2004-63 on Personal Data Protection",
   "year": 2004,
   "authority": "INPDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with authorization and declaration duties; a GDPR-aligned replacement bill has been pending for years.",
   "transfers": "Transfers abroad require authorization from the INPDP.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "One of Africa's earliest laws (2004) with an active authority, the INPDP, but an aging framework; the long-pending GDPR-style replacement would modernize consent, rights and transfers.",
   "sources": []
  },
  {
   "name": "Algeria",
   "slug": "algeria",
   "url": "https://digitalprivacyregs.com/algeria.html",
   "flag": "🇩🇿",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 18-07 on Personal Data Protection",
   "year": 2018,
   "authority": "ANPDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with authorization duties for sensitive data and transfers.",
   "transfers": "Most transfers abroad require authorization from the ANPDP.",
   "penalties": "Violations can bring fines and imprisonment.",
   "summary": "Law 18-07 finally became operational when the ANPDP was installed in 2023, five years after adoption; registration and transfer-authorization duties now apply in earnest.",
   "sources": []
  },
  {
   "name": "Morocco",
   "slug": "morocco",
   "url": "https://digitalprivacyregs.com/morocco.html",
   "flag": "🇲🇦",
   "region": "Middle East & North Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 09-08 on Personal Data Protection",
   "year": 2009,
   "authority": "CNDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with prior declaration or authorization duties; direct marketing requires prior consent.",
   "transfers": "Transfers abroad require CNDP authorization, based on an adequacy-style assessment of the destination.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "Morocco's CNDP is one of Africa's most active authorities, running registration, audits and public campaigns under a 2009 law; a GDPR-alignment reform has been in preparation to match the EU adequacy ambition.",
   "sources": [
    {
     "label": "CNDP",
     "url": "https://www.cndp.ma/"
    }
   ]
  },
  {
   "name": "Nigeria",
   "slug": "nigeria",
   "url": "https://digitalprivacyregs.com/nigeria.html",
   "flag": "🇳🇬",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Nigeria Data Protection Act (NDPA) 2023 + GAID 2025",
   "year": 2023,
   "authority": "Nigeria Data Protection Commission (NDPC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or another lawful basis including legitimate interests, but direct marketing expects consent and a clear opt-out; the GAID details consent standards.",
   "transfers": "Adequacy, safeguards or derogations under the NDPA and GAID; the NDPC has not published a list of adequate destinations.",
   "penalties": "Up to NGN 10M or 2% of annual gross revenue for major data handlers, whichever is higher.",
   "summary": "Africa's largest market moved from regulation to statute with the NDPA in June 2023, then operationalized it with the General Application and Implementation Directive (GAID), issued March 2025 and effective September 2025. The NDPC registers major data handlers, audits actively and has sanctioned banks and fintechs, and in February 2026 it opened an investigation into Temu covering about 12.7 million Nigerian users. Treat Nigeria as a real enforcement jurisdiction.",
   "sources": [
    {
     "label": "NDPC",
     "url": "https://ndpc.gov.ng/"
    }
   ]
  },
  {
   "name": "South Africa",
   "slug": "south-africa",
   "url": "https://digitalprivacyregs.com/south-africa.html",
   "flag": "🇿🇦",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Protection of Personal Information Act (POPIA)",
   "year": 2013,
   "authority": "Information Regulator",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Eight processing conditions with justification grounds including legitimate interests, but section 69 makes electronic direct marketing opt-in, with a narrow existing-customer exception. Since April 2026, direct marketers must also register with the National Consumer Commission's opt-out registry and clean their lists against it monthly.",
   "transfers": "Adequate-law destinations, binding rules, consent or contract necessity.",
   "penalties": "Fines up to ZAR 10M and criminal penalties; enforcement notices are the workhorse.",
   "summary": "POPIA has been fully in force since July 2021, and the Information Regulator has used it, with enforcement notices against major institutions, a standing fight over direct marketing interpretation, and guidance confirming that unsolicited electronic marketing needs consent. Consumer Protection Act regulations gazetted in April 2026 add a second layer, requiring every direct marketer to register with the National Consumer Commission's opt-out registry before contacting anyone and to scrub lists monthly; the Regulator stresses that an opt-out registration never counts as consent. South Africa is opt-in for email and SMS marketing in practice.",
   "sources": [
    {
     "label": "Information Regulator",
     "url": "https://inforegulator.org.za/"
    },
    {
     "label": "Cliffe Dekker Hofmeyr on the 2026 direct marketing rules",
     "url": "https://www.cliffedekkerhofmeyr.com/en/news/publications/2026/South-Africa/Dispute-Resolution/dispute-resolution-14-july-still-getting-spam-calls-south-africa-tightens-direct-marketing-regulations"
    }
   ]
  },
  {
   "name": "Kenya",
   "slug": "kenya",
   "url": "https://digitalprivacyregs.com/kenya.html",
   "flag": "🇰🇪",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2019",
   "year": 2019,
   "authority": "Office of the Data Protection Commissioner (ODPC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled bases; direct marketing requires consent or an existing-customer relationship with opt-out, and the ODPC enforces this.",
   "transfers": "Adequacy, safeguards or consent; the Cabinet Secretary can require certain processing to run on servers in Kenya on grounds of strategic state interest or revenue protection.",
   "penalties": "Up to KES 5M or 1% of the preceding year's annual turnover, whichever is lower.",
   "summary": "Kenya's ODPC is East Africa's pacesetter: registration of controllers and processors, a steady stream of penalty notices (including against digital lenders and schools over marketing and children's images), and functioning complaint machinery. Compliance built for the GDPR maps over cleanly.",
   "sources": [
    {
     "label": "ODPC",
     "url": "https://www.odpc.go.ke/"
    }
   ]
  },
  {
   "name": "Ghana",
   "slug": "ghana",
   "url": "https://digitalprivacyregs.com/ghana.html",
   "flag": "🇬🇭",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2012 (Act 843)",
   "year": 2012,
   "authority": "Data Protection Commission",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with registration duties; direct marketing carries opt-out rights.",
   "transfers": "The controller stays accountable for personal data it sends overseas.",
   "penalties": "Fines and imprisonment for violations; registration enforcement is the practical lever.",
   "summary": "An early African adopter (2012) with an operating commission focused on controller registration and awareness; enforcement is steady and measured.",
   "sources": [
    {
     "label": "DPC Ghana",
     "url": "https://www.dataprotection.org.gh/"
    }
   ]
  },
  {
   "name": "Mauritius",
   "slug": "mauritius",
   "url": "https://digitalprivacyregs.com/mauritius.html",
   "flag": "🇲🇺",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2017",
   "year": 2017,
   "authority": "Data Protection Office",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-aligned consent and bases.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "Violations can bring fines up to MUR 200,000 and imprisonment.",
   "summary": "Mauritius aligned tightly with the GDPR in 2017 and ratified Convention 108+, positioning itself as the Indian Ocean's compliance-friendly hub; it has long pursued EU adequacy.",
   "sources": []
  },
  {
   "name": "Rwanda",
   "slug": "rwanda",
   "url": "https://digitalprivacyregs.com/rwanda.html",
   "flag": "🇷🇼",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law No. 058/2021 on Personal Data Protection and Privacy",
   "year": 2021,
   "authority": "National Cyber Security Authority (NCSA)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or listed bases; registration of controllers and processors required.",
   "transfers": "Data must be stored in Rwanda unless the NCSA authorizes transfer, a notable localization default.",
   "penalties": "Fines up to RWF 5M or 1% of turnover, plus criminal exposure.",
   "summary": "Rwanda's 2021 law came with a hard edge, including a store-in-Rwanda default absent NCSA authorization, active registration enforcement since the 2023 transition ended, and a security-agency regulator.",
   "sources": []
  },
  {
   "name": "Uganda",
   "slug": "uganda",
   "url": "https://digitalprivacyregs.com/uganda.html",
   "flag": "🇺🇬",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection and Privacy Act 2019",
   "year": 2019,
   "authority": "Personal Data Protection Office (PDPO)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with listed exceptions; registration required.",
   "transfers": "Transfers abroad need an adequate destination or the individual's consent.",
   "penalties": "Fines and imprisonment; corporate fines tied to turnover percentages for some offenses.",
   "summary": "Uganda's PDPO has moved from setup to enforcement, publishing decisions on breaches and unlawful disclosure; registration of collectors and processors is the entry-level duty.",
   "sources": []
  },
  {
   "name": "Tanzania",
   "slug": "tanzania",
   "url": "https://digitalprivacyregs.com/tanzania.html",
   "flag": "🇹🇿",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Act 2022",
   "year": 2022,
   "authority": "Personal Data Protection Commission (PDPC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with registration duties.",
   "transfers": "Transfers abroad need a Commission permit or an adequate destination.",
   "penalties": "Administrative fines set by the PDPC up to TZS 100M; criminal fines for companies reach TZS 5B.",
   "summary": "In force since mid-2023 with regulations and an operating commission; registration deadlines have passed, and the PDPC has begun compliance sweeps.",
   "sources": []
  },
  {
   "name": "Ethiopia",
   "slug": "ethiopia",
   "url": "https://digitalprivacyregs.com/ethiopia.html",
   "flag": "🇪🇹",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Proclamation No. 1321/2024",
   "year": 2024,
   "authority": "Ethiopian Communications Authority (ECA), which registers and licenses data handlers",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with GDPR-influenced bases and rights.",
   "transfers": "Adequacy or safeguard based, with localization options for sensitive categories.",
   "penalties": "The law provides for administrative fines and criminal penalties.",
   "summary": "Ethiopia adopted its first comprehensive law in 2024, a milestone for one of Africa's largest previously unregulated markets. The Ethiopian Communications Authority supervises it and requires data handlers to register and obtain licences, though implementing directives are still thin.",
   "sources": []
  },
  {
   "name": "Somalia",
   "slug": "somalia",
   "url": "https://digitalprivacyregs.com/somalia.html",
   "flag": "🇸🇴",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2023",
   "year": 2023,
   "authority": "Data Protection Authority",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework.",
   "transfers": "Transfers abroad sit under the data protection authority's supervision.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "Somalia surprised observers by enacting a comprehensive law in March 2023 and standing up an authority; capacity is now the constraint.",
   "sources": []
  },
  {
   "name": "Senegal",
   "slug": "senegal",
   "url": "https://digitalprivacyregs.com/senegal.html",
   "flag": "🇸🇳",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 2008-12 on Personal Data Protection",
   "year": 2008,
   "authority": "CDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with declaration and authorization duties.",
   "transfers": "Transfers abroad require authorization from the CDP.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "A pioneer of the Francophone African model (2008) with an active commission; a modernization bill to reach GDPR grade has been in preparation.",
   "sources": []
  },
  {
   "name": "Cote d'Ivoire",
   "slug": "cote-divoire",
   "url": "https://digitalprivacyregs.com/cote-divoire.html",
   "flag": "🇨🇮",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 2013-450 on Personal Data Protection",
   "year": 2013,
   "authority": "ARTCI",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with authorization duties.",
   "transfers": "Transfers abroad require authorization from ARTCI.",
   "penalties": "Fines apply, and the authority can act against licences.",
   "summary": "The telecom regulator ARTCI doubles as DPA under a 2013 law; registration and authorization are the operative duties.",
   "sources": []
  },
  {
   "name": "Benin",
   "slug": "benin",
   "url": "https://digitalprivacyregs.com/benin.html",
   "flag": "🇧🇯",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Digital Code (Law 2017-20), Book on Personal Data",
   "year": 2017,
   "authority": "APDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-influenced consent and bases inside the Digital Code.",
   "transfers": "The APDP supervises transfers abroad, which turn on the adequacy of the destination.",
   "penalties": "Fines up to substantial ceilings plus publication sanctions.",
   "summary": "Benin folded a full GDPR-style data protection book into its 2017 Digital Code, and the APDP is among Francophone Africa's more active enforcers, publishing decisions and fines.",
   "sources": []
  },
  {
   "name": "Burkina Faso",
   "slug": "burkina-faso",
   "url": "https://digitalprivacyregs.com/burkina-faso.html",
   "flag": "🇧🇫",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 001-2021 on Personal Data Protection",
   "year": 2021,
   "authority": "CIL",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first; the 2021 law replaced the 2004 pioneer statute with a modernized framework.",
   "transfers": "Transfers abroad require authorization from the CIL.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "Burkina Faso, one of Africa's first movers in 2004, refreshed its regime in 2021 with stronger rights and duties under the CIL.",
   "sources": []
  },
  {
   "name": "Togo",
   "slug": "togo",
   "url": "https://digitalprivacyregs.com/togo.html",
   "flag": "🇹🇬",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 2019-014 on Personal Data Protection",
   "year": 2019,
   "authority": "IPDCP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework.",
   "transfers": "Transfers abroad sit under the data protection authority's supervision.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "A 2019 law with its authority (IPDCP) installed in 2024; obligations are formal but enforcement is young.",
   "sources": []
  },
  {
   "name": "Mali",
   "slug": "mali",
   "url": "https://digitalprivacyregs.com/mali.html",
   "flag": "🇲🇱",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 2013-015 on Personal Data Protection",
   "year": 2013,
   "authority": "APDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with declaration duties.",
   "transfers": "Transfers abroad require authorization from the APDP.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "A 2013 Francophone-model law with a functioning authority that publishes deliberations; enforcement is modest.",
   "sources": []
  },
  {
   "name": "Niger",
   "slug": "niger",
   "url": "https://digitalprivacyregs.com/niger.html",
   "flag": "🇳🇪",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 2017-28 on Personal Data Protection (amended 2022)",
   "year": 2017,
   "authority": "HAPDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework.",
   "transfers": "Transfers abroad sit under the data protection authority's supervision.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "A 2017 law amended in 2022 with the HAPDP as authority; political instability has slowed institutional practice.",
   "sources": []
  },
  {
   "name": "Mauritania",
   "slug": "mauritania",
   "url": "https://digitalprivacyregs.com/mauritania.html",
   "flag": "🇲🇷",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 2017-020 on Personal Data Protection",
   "year": 2017,
   "authority": "Authority provided by law; operationalization limited",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first on paper.",
   "transfers": "The law ties transfers abroad to authorization by the data protection authority.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "A 2017 statute whose supervisory machinery has been slow to materialize; obligations are formal more than practical.",
   "sources": []
  },
  {
   "name": "Chad",
   "slug": "chad",
   "url": "https://digitalprivacyregs.com/chad.html",
   "flag": "🇹🇩",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 007/PR/2015 on Personal Data Protection",
   "year": 2015,
   "authority": "ANSICE",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework.",
   "transfers": "The law ties transfers abroad to authorization by the data protection authority.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "A 2015 law supervised by the cybersecurity agency ANSICE; enforcement remains limited.",
   "sources": []
  },
  {
   "name": "Cameroon",
   "slug": "cameroon",
   "url": "https://digitalprivacyregs.com/cameroon.html",
   "flag": "🇨🇲",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law No. 2024/017 of 23 December 2024 on Personal Data Protection",
   "year": 2024,
   "authority": "Personal Data Protection Authority (requires a presidential decree; not yet established)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework with data protection officer duties; its obligations have applied since the 18-month transition ended on 23 June 2026.",
   "transfers": "The law sets conditions for transfers abroad, but the authority meant to supervise them has not been set up.",
   "penalties": "The law provides for sanctions, but no authority is yet in place to impose them.",
   "summary": "Central Africa's largest economy has a comprehensive data protection law in force. Law No. 2024/017, enacted 23 December 2024, took full effect on 23 June 2026 when its 18-month transition ended. The supervisory authority still awaits the presidential decree that creates it, so the obligations apply without a regulator to police them.",
   "sources": [
    {
     "label": "Law No. 2024/017 (text)",
     "url": "https://dataprotection.africa/wp-content/uploads/Cameroon-data-protection-act.pdf"
    },
    {
     "label": "Ministry of Finance notice, July 2026",
     "url": "https://www.dgb.cm/la-loi-sur-la-protection-des-donnees-personnelles-entre-officiellement-en-vigueur/"
    }
   ]
  },
  {
   "name": "Central African Republic",
   "slug": "central-african-republic",
   "url": "https://digitalprivacyregs.com/central-african-republic.html",
   "flag": "🇨🇫",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law No. 24.001 on the Protection of Personal Data",
   "year": 2024,
   "authority": "Data protection agency provided by law, not yet created; the Ministry of Digital Economy supervises in the interim",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework on the francophone African model, in force since January 2024.",
   "transfers": "The law sets conditions for transfers abroad; with no agency in place, the ministry is the only supervisor.",
   "penalties": "The law provides for sanctions, but the agency meant to impose them does not yet exist.",
   "summary": "The Central African Republic promulgated Law No. 24.001 on 25 January 2024, in force the same day. The data protection agency it requires, due within a year, has not been created, and the digital economy ministry supervises in the meantime.",
   "sources": [
    {
     "label": "Law No. 24.001 (text)",
     "url": "https://blog.africadataprotection.org/wp-content/uploads/2025/07/Loi_24_001_portant_protection_des_donnes_a_caractere__personnel.pdf"
    }
   ]
  },
  {
   "name": "Republic of the Congo",
   "slug": "republic-of-the-congo",
   "url": "https://digitalprivacyregs.com/republic-of-the-congo.html",
   "flag": "🇨🇬",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 29-2019 on Personal Data Protection",
   "year": 2019,
   "authority": "Authority provided by law",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework.",
   "transfers": "The law ties transfers abroad to authorization by the data protection authority.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "A 2019 law on the Francophone model; institutional practice is still developing.",
   "sources": []
  },
  {
   "name": "Democratic Republic of the Congo",
   "slug": "democratic-republic-of-the-congo",
   "url": "https://digitalprivacyregs.com/democratic-republic-of-the-congo.html",
   "flag": "🇨🇩",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Digital Code (Ordonnance-loi 23/010 of 2023), personal data provisions",
   "year": 2023,
   "authority": "Data protection authority provided by the Digital Code (being established)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first, GDPR-influenced provisions inside the 2023 Digital Code.",
   "transfers": "Transfers abroad turn on authorization and the adequacy of the destination.",
   "penalties": "The Code provides for fines.",
   "summary": "The DRC's 2023 Digital Code brought its first real data protection regime, GDPR-influenced in structure; the supervisory institution is still being stood up.",
   "sources": []
  },
  {
   "name": "Gabon",
   "slug": "gabon",
   "url": "https://digitalprivacyregs.com/gabon.html",
   "flag": "🇬🇦",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 001/2011 on Personal Data Protection (amended 2023)",
   "year": 2011,
   "authority": "CNPDCP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first; the 2023 amendment modernized definitions and duties.",
   "transfers": "Transfers abroad require authorization from the CNPDCP.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "Gabon refreshed its 2011 law in 2023 and maintains an operating commission; declaration duties are the practical baseline.",
   "sources": []
  },
  {
   "name": "Equatorial Guinea",
   "slug": "equatorial-guinea",
   "url": "https://digitalprivacyregs.com/equatorial-guinea.html",
   "flag": "🇬🇶",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 1/2016 on Personal Data Protection",
   "year": 2016,
   "authority": "Authority provided by law; limited operation",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first on paper.",
   "transfers": "The law ties transfers abroad to authorization by the data protection authority.",
   "penalties": "The law provides for fines.",
   "summary": "A 2016 statute exists with minimal visible enforcement.",
   "sources": []
  },
  {
   "name": "Sao Tome and Principe",
   "slug": "sao-tome-and-principe",
   "url": "https://digitalprivacyregs.com/sao-tome-and-principe.html",
   "flag": "🇸🇹",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 3/2016 on Personal Data Protection",
   "year": 2016,
   "authority": "Authority provided by law",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework on the Lusophone model.",
   "transfers": "The law ties transfers abroad to authorization by the data protection authority.",
   "penalties": "The law provides for fines.",
   "summary": "A 2016 law modeled on Portuguese-influenced frameworks; enforcement capacity is minimal.",
   "sources": []
  },
  {
   "name": "Angola",
   "slug": "angola",
   "url": "https://digitalprivacyregs.com/angola.html",
   "flag": "🇦🇴",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 22/11 on Personal Data Protection",
   "year": 2011,
   "authority": "APD (operational since 2019)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with authorization duties; APD approval needed for sensitive processing and transfers.",
   "transfers": "Transfers abroad require APD authorization and turn on the adequacy of the destination.",
   "penalties": "Fines scale with the company's revenue band.",
   "summary": "Angola legislated in 2011 but only activated its authority in 2019; since then the APD has pushed registration and authorization compliance.",
   "sources": []
  },
  {
   "name": "Zambia",
   "slug": "zambia",
   "url": "https://digitalprivacyregs.com/zambia.html",
   "flag": "🇿🇲",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2021",
   "year": 2021,
   "authority": "Office of the Data Protection Commissioner",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or listed bases; registration required.",
   "transfers": "Sensitive personal data must be processed and stored on a server or data center in Zambia; other transfers need conditions met.",
   "penalties": "Some violations bring fines up to 2% of annual turnover.",
   "summary": "Zambia's 2021 Act pairs a GDPR-style rulebook with a localization rule for sensitive data; the Commissioner's office has been registering controllers since 2022-2023.",
   "sources": []
  },
  {
   "name": "Zimbabwe",
   "slug": "zimbabwe",
   "url": "https://digitalprivacyregs.com/zimbabwe.html",
   "flag": "🇿🇼",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2021 (Cyber and Data Protection Act)",
   "year": 2021,
   "authority": "POTRAZ (as Data Protection Authority)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or listed bases; DPO licensing rules issued 2024.",
   "transfers": "Transfers abroad need an adequate destination or the authority's authorization.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "Zimbabwe's 2021 Act designates telecom regulator POTRAZ as DPA; 2024 regulations added DPO licensing, an unusual requirement worth flagging for local operations.",
   "sources": []
  },
  {
   "name": "Malawi",
   "slug": "malawi",
   "url": "https://digitalprivacyregs.com/malawi.html",
   "flag": "🇲🇼",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2024",
   "year": 2024,
   "authority": "Malawi Communications Regulatory Authority (MACRA, interim)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first, GDPR-influenced framework.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "Malawi enacted its first comprehensive law in 2024 with MACRA supervising in the interim; implementation guidance is emerging.",
   "sources": []
  },
  {
   "name": "Mozambique",
   "slug": "mozambique",
   "url": "https://digitalprivacyregs.com/mozambique.html",
   "flag": "🇲🇿",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Draft data protection law (pending); constitutional and sectoral protections",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "Only sector-specific penalties apply.",
   "summary": "A draft law has advanced through government processes without final enactment; only constitutional and sectoral protections apply today.",
   "sources": []
  },
  {
   "name": "Namibia",
   "slug": "namibia",
   "url": "https://digitalprivacyregs.com/namibia.html",
   "flag": "🇳🇦",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Data Protection Bill (long pending)",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "No penalties apply under a general privacy law.",
   "summary": "Namibia's data protection bill has been in consultation for years; until it passes, no comprehensive obligations apply.",
   "sources": []
  },
  {
   "name": "Botswana",
   "slug": "botswana",
   "url": "https://digitalprivacyregs.com/botswana.html",
   "flag": "🇧🇼",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act (2018 regime, refreshed by the 2024 Act)",
   "year": 2018,
   "authority": "Information and Data Protection Commission",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or listed bases; registration duties apply.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "Violations can bring fines and imprisonment.",
   "summary": "Botswana's regime, in force since 2021 with full compliance expected from 2022, was refreshed through a 2024 Act updating the framework and its commission.",
   "sources": []
  },
  {
   "name": "Lesotho",
   "slug": "lesotho",
   "url": "https://digitalprivacyregs.com/lesotho.html",
   "flag": "🇱🇸",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Data Protection Act 2011",
   "year": 2011,
   "authority": "Commission provided by law; never fully operational",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first on paper.",
   "transfers": "The law ties transfers abroad to authorization by the data protection authority.",
   "penalties": "The law provides for fines.",
   "summary": "Lesotho passed a law in 2011 but the supervisory commission was never properly stood up, leaving the Act largely dormant.",
   "sources": []
  },
  {
   "name": "Eswatini",
   "slug": "eswatini",
   "url": "https://digitalprivacyregs.com/eswatini.html",
   "flag": "🇸🇿",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2022",
   "year": 2022,
   "authority": "Eswatini Communications Commission (data protection unit)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or listed bases, GDPR-influenced.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "A modern 2022 statute supervised through the communications regulator; obligations are GDPR-familiar.",
   "sources": []
  },
  {
   "name": "Madagascar",
   "slug": "madagascar",
   "url": "https://digitalprivacyregs.com/madagascar.html",
   "flag": "🇲🇬",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law 2014-038 on Personal Data Protection",
   "year": 2014,
   "authority": "Commission (CMIL) provided by law; operationalization has lagged",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first on paper.",
   "transfers": "The law ties transfers abroad to authorization by the data protection authority.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "The 2014 law's commission took nearly a decade to begin materializing, so practical enforcement remains thin.",
   "sources": []
  },
  {
   "name": "Seychelles",
   "slug": "seychelles",
   "url": "https://digitalprivacyregs.com/seychelles.html",
   "flag": "🇸🇨",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2023",
   "year": 2023,
   "authority": "Information Commission",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-influenced consent and bases.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "The authority can impose administrative fines.",
   "summary": "Seychelles replaced its never-commenced 2003 Act with a modern 2023 law, giving the offshore-services hub a real framework.",
   "sources": []
  },
  {
   "name": "Comoros",
   "slug": "comoros",
   "url": "https://digitalprivacyregs.com/comoros.html",
   "flag": "🇰🇲",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law on the Protection of Personal Data (adopted by the Assembly, June 2014)",
   "year": 2014,
   "authority": "National commission provided by law; never constituted",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first framework on paper; with no commission in place, nothing enforces it.",
   "transfers": "The law addresses transfers abroad, but no commission exists to apply it.",
   "penalties": "The law provides for sanctions that no operating body can impose.",
   "summary": "The Comoros Assembly adopted a personal data protection law in June 2014, and the Ministry of Justice publishes it among the country's laws, but the commission it creates has never been set up. In practice it remains a paper framework.",
   "sources": [
    {
     "label": "Ministry of Justice text",
     "url": "https://justice.gouv.km/texte/loi-du-26-juin-2014-portant-protection-des-donnees-a-caractere-personnel/"
    }
   ]
  },
  {
   "name": "Djibouti",
   "slug": "djibouti",
   "url": "https://digitalprivacyregs.com/djibouti.html",
   "flag": "🇩🇯",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Digital Code (Law No. 019/AN/23/9ème L), Book I on personal data protection",
   "year": 2025,
   "authority": "National Commission for the Protection of Personal Data (provided by the Code; not yet established)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first rules in Book I of the Digital Code; private-sector processing had one year to comply and the public sector two.",
   "transfers": "The Code sets conditions for transfers abroad, to be supervised by a commission that has not been set up.",
   "penalties": "The Code provides for sanctions, but no commission is yet in place to impose them.",
   "summary": "Djibouti adopted a Digital Code in July 2025 whose first book is a full data protection law, giving private-sector processing one year to comply and the public sector two. The national commission meant to supervise it has not been established.",
   "sources": [
    {
     "label": "Digital Code (Journal Officiel)",
     "url": "https://www.journalofficiel.dj/texte-juridique/loi-n019-an-23-9eme-l-portant-code-numerique/"
    }
   ]
  },
  {
   "name": "Eritrea",
   "slug": "eritrea",
   "url": "https://digitalprivacyregs.com/eritrea.html",
   "flag": "🇪🇷",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No data protection framework exists.",
   "sources": []
  },
  {
   "name": "Sudan",
   "slug": "sudan",
   "url": "https://digitalprivacyregs.com/sudan.html",
   "flag": "🇸🇩",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None; sectoral informatics offenses only",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No regime.",
   "penalties": "None under a general privacy law.",
   "summary": "No comprehensive law is in force, and the ongoing conflict has frozen legislative activity.",
   "sources": []
  },
  {
   "name": "South Sudan",
   "slug": "south-sudan",
   "url": "https://digitalprivacyregs.com/south-sudan.html",
   "flag": "🇸🇸",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Draft Data Protection Bill (validated at a 2026 workshop); no law in force",
   "year": null,
   "authority": "None yet (the National Communication Authority is leading the draft)",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework in force.",
   "transfers": "No rule restricts personal data leaving the country while the bill is pending.",
   "penalties": "No penalties apply until a law is passed.",
   "summary": "South Sudan has no data protection law, but the National Communication Authority has taken a draft Data Protection Bill through a validation workshop and calls enactment a national priority.",
   "sources": []
  },
  {
   "name": "Gambia",
   "slug": "gambia",
   "url": "https://digitalprivacyregs.com/gambia.html",
   "flag": "🇬🇲",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Personal Data Protection and Privacy Act, 2025 (Act No. 11 of 2025)",
   "year": 2025,
   "authority": "Information Commission (established under the Access to Information Act 2021), with its data protection role still being built",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "A modern framework built on consent and other lawful bases; guidance and enforcement practice are still taking shape.",
   "transfers": "The Act sets conditions for transfers abroad under the Information Commission's supervision.",
   "penalties": "The Act provides for fines and other sanctions; enforcement has yet to begin in earnest.",
   "summary": "The Gambia's Personal Data Protection and Privacy Act received presidential assent on 7 November 2025 and hands supervision to the existing Information Commission. Sources differ on whether it has formally commenced, and the Commission's data protection function is still being staffed.",
   "sources": [
    {
     "label": "Personal Data Protection and Privacy Act 2025 (text)",
     "url": "https://media2.mofo.com/v3/assets/blt5775cc69c999c255/blt7a10e6071e9d3fad/69d554b553df724b615c685d/personal-data-protection-and-privacy-act-2025.pdf"
    }
   ]
  },
  {
   "name": "Guinea",
   "slug": "guinea",
   "url": "https://digitalprivacyregs.com/guinea.html",
   "flag": "🇬🇳",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law L/2016/037 (cybersecurity and personal data provisions)",
   "year": 2016,
   "authority": "Authority provided by law; limited operation",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-oriented data provisions inside the 2016 cyber law.",
   "transfers": "The law ties transfers abroad to authorization by the data protection authority.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "Guinea's data protection rules live inside a 2016 cybersecurity statute; supervisory practice is minimal.",
   "sources": []
  },
  {
   "name": "Guinea-Bissau",
   "slug": "guinea-bissau",
   "url": "https://digitalprivacyregs.com/guinea-bissau.html",
   "flag": "🇬🇼",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force.",
   "sources": []
  },
  {
   "name": "Sierra Leone",
   "slug": "sierra-leone",
   "url": "https://digitalprivacyregs.com/sierra-leone.html",
   "flag": "🇸🇱",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Data Protection Bill (pending); cybersecurity law 2021",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "No penalties apply under a general privacy law.",
   "summary": "A data protection bill accompanies the 2021 cybersecurity law's rollout; enactment is still pending.",
   "sources": []
  },
  {
   "name": "Liberia",
   "slug": "liberia",
   "url": "https://digitalprivacyregs.com/liberia.html",
   "flag": "🇱🇷",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Data Protection Act (2026)",
   "year": 2026,
   "authority": "Supervision arrangements under the new Act; no regulator operating yet",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "The new Act sets consent and processing rules whose details await implementation.",
   "transfers": "The Act addresses transfers abroad; implementing rules and a working regulator are still to come.",
   "penalties": "The Act provides for sanctions, but no regulator is operating to impose them yet.",
   "summary": "Liberia enacted its first Data Protection Act in June 2026, signed by President Boakai alongside a Cybercrime Act. Commencement details and the regulator's set-up are still pending.",
   "sources": [
    {
     "label": "Liberia IGF statement, June 2026",
     "url": "https://liberiaigf.org/2026/06/25/official-statement-liberia-internet-governance-forum-liberia-igf-welcomes-the-enactment-of-liberias-first-data-protection-act/"
    }
   ]
  },
  {
   "name": "Burundi",
   "slug": "burundi",
   "url": "https://digitalprivacyregs.com/burundi.html",
   "flag": "🇧🇮",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law No. 1/03 of 10 March 2026 on the Protection of Personal Data",
   "year": 2026,
   "authority": "Personal Data Protection Agency (created by the law; implementing decree and appointments pending)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "A comprehensive law on the francophone African model, with consent as the main basis for processing; private-sector processing had six months to comply, a window that closed on 10 September 2026.",
   "transfers": "The law sets conditions for transfers abroad, but the agency meant to supervise them has not been set up.",
   "penalties": "The law provides for sanctions, but no agency is yet in place to impose them.",
   "summary": "Burundi enacted its first comprehensive data protection law on 10 March 2026, in force on promulgation, with six months for private-sector processing to comply and a year for the public sector. The Personal Data Protection Agency it creates still needs an implementing decree, so the law applies without a regulator to enforce it.",
   "sources": [
    {
     "label": "Law No. 1/03 of 10 March 2026 (National Assembly)",
     "url": "https://assemblee.bi/wp-content/uploads/2026/03/n%C2%B003-du-10-mars-2026.pdf"
    }
   ]
  },
  {
   "name": "Cabo Verde",
   "slug": "cabo-verde",
   "url": "https://digitalprivacyregs.com/cabo-verde.html",
   "flag": "🇨🇻",
   "region": "Sub-Saharan Africa",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 133/V/2001 as amended (2013, 2021)",
   "year": 2001,
   "authority": "CNPD",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first, Portuguese-model framework, updated repeatedly.",
   "transfers": "Transfers abroad require authorization from the CNPD.",
   "penalties": "The law provides for fines and criminal penalties.",
   "summary": "One of Africa's oldest frameworks (2001), kept current through amendments and an operating CNPD.",
   "sources": []
  },
  {
   "name": "Canada",
   "slug": "canada",
   "url": "https://digitalprivacyregs.com/canada.html",
   "flag": "🇨🇦",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "PIPEDA + CASL + Quebec Law 25 (provincial)",
   "year": 2000,
   "authority": "Office of the Privacy Commissioner (OPC); provincial commissioners in QC, BC, AB",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent is required for collection, use and disclosure; implied consent works for non-sensitive contexts, but CASL makes commercial email and SMS strictly opt-in with limited implied-consent windows.",
   "transfers": "Accountability-based: the transferring organization stays responsible; Quebec adds transfer impact assessments.",
   "penalties": "CASL penalties reach CAD 10M per violation; Quebec Law 25 fines reach CAD 25M or 4% of worldwide turnover. PIPEDA itself still lacks direct fining power after Bill C-27 died in January 2025.",
   "summary": "Canada is the strictest major market on earth for email: CASL requires express or narrowly implied consent before sending, with per-message penalties that have hit seven figures. Federally, PIPEDA soldiers on after the C-27 reform died with prorogation in January 2025, while Quebec's Law 25, fully phased in through September 2024, gives that province GDPR-grade rules, fines and portability.",
   "sources": [
    {
     "label": "OPC",
     "url": "https://www.priv.gc.ca/en/"
    }
   ]
  },
  {
   "name": "Brazil",
   "slug": "brazil",
   "url": "https://digitalprivacyregs.com/brazil.html",
   "flag": "🇧🇷",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Lei Geral de Proteção de Dados (LGPD)",
   "year": 2018,
   "authority": "ANPD (Agência Nacional de Proteção de Dados), a regulatory agency since Law 15.352/2026",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Ten legal bases including legitimate interests, but consent is expected for cookies and most adtech, and the ANPD's guidance pushes granular banners.",
   "transfers": "ANPD's 2024 transfer regulation created Brazilian SCCs (adaptation deadline passed August 2025), adequacy decisions and BCR-style mechanisms.",
   "penalties": "Up to 2% of Brazil revenue, capped at R$50M per violation; daily fines and processing bans available.",
   "summary": "The LGPD is the GDPR's closest large-market cousin, fully enforceable since August 2021 with sanctions live since 2023. The ANPD has moved from guidance to action with its dosimetry regulation, cookie guidance that expects real consent, a 2024 international transfer framework with Brazilian standard clauses, and high-profile measures against Meta's AI training and X, though it has imposed only one fine. In 2026 it became a full regulatory agency and took on the ECA Digital, the children's online statute in force since 17 March 2026, which bars profiling-based ad targeting of minors and carries fines up to 10% of Brazilian group revenue, capped at R$50M per infraction.",
   "sources": [
    {
     "label": "ANPD",
     "url": "https://www.gov.br/anpd/pt-br"
    },
    {
     "label": "LGPD text",
     "url": "https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm"
    },
    {
     "label": "Law 15.352/2026 (Câmara)",
     "url": "https://www2.camara.leg.br/legin/fed/lei/2026/lei-15352-25-fevereiro-2026-798731-publicacaooriginal-178208-pl.html"
    },
    {
     "label": "Senado Notícias on ECA Digital timing",
     "url": "https://www12.senado.leg.br/noticias/materias/2025/09/18/medida-provisoria-da-seis-meses-para-plataformas-cumprirem-eca-digital"
    }
   ]
  },
  {
   "name": "Mexico",
   "slug": "mexico",
   "url": "https://digitalprivacyregs.com/mexico.html",
   "flag": "🇲🇽",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP 2025)",
   "year": 2025,
   "authority": "Secretariat of Anti-Corruption and Good Governance (SABG), replacing the dissolved INAI",
   "consent_model": "hybrid",
   "consent_label": "Hybrid",
   "marketing_consent_note": "Tacit consent works for non-sensitive data, so a business can provide the privacy notice and proceed unless the person objects. Express consent for financial data, express and written for sensitive data.",
   "transfers": "Notice-based for many transfers with consent triggers for others; group transfers and processor transfers eased.",
   "penalties": "Fines from 100 to 320,000 UMA (into the millions of dollars), doubled for sensitive data, plus criminal exposure; in July 2026 the SABG fined the Mexican Football Federation MXN 42.8M over biometric data in its FAN ID program.",
   "summary": "Mexico rebuilt its framework in 2025. A new LFPDPPP took effect 21 March 2025 and the constitutional reform dissolved INAI, moving enforcement to the executive-branch SABG. The tacit-consent model survived, which keeps Mexico friendlier to marketers than most of Latin America. The SABG's first major fine landed in July 2026, MXN 42.8M against the Mexican Football Federation for collecting fans' biometric data without telling them it was sensitive, while implementing regulations for the 2025 law remain unpublished. The loss of an independent regulator is the story to watch.",
   "sources": [
    {
     "label": "Mexican federal laws library",
     "url": "https://www.diputados.gob.mx/LeyesBiblio/"
    },
    {
     "label": "Infobae on the FMF fine, July 2026",
     "url": "https://www.infobae.com/mexico/2026/07/12/la-secretaria-anticorrupcion-impone-multa-de-428-mdp-a-la-federacion-mexicana-de-futbol-por-fallas-de-privacidad/"
    }
   ]
  },
  {
   "name": "Chile",
   "slug": "chile",
   "url": "https://digitalprivacyregs.com/chile.html",
   "flag": "🇨🇱",
   "region": "Americas",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law 21.719 (2024), replacing Law 19.628 (1999)",
   "year": 2024,
   "authority": "Agencia de Protección de Datos Personales (board not yet appointed)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled: consent or another legal basis including legitimate interests, with sensitive-data and children's rules; the outgoing 1999 law was consent-based but toothless.",
   "transfers": "Adequacy decisions, safeguards and derogations on the GDPR pattern.",
   "penalties": "Up to UTM-denominated fines reaching roughly USD 1.5M, and up to 4% of annual revenue for repeated grave violations.",
   "summary": "Chile's new law has a legal start date of 1 December 2026, and it may slip. Law 21.719, published December 2024, replaces a 1999 law that had no regulator and no real fines, bringing a data protection agency, turnover-linked penalties and EU-style legal bases. The agency's board has not been appointed after the Senate rejected the nominees, and on 1 September 2026 the government filed an urgent bill to move the start to 1 December 2027 and enlarge the board to five members. Plan for December 2026 until Congress decides.",
   "sources": [
    {
     "label": "Ley Chile",
     "url": "https://www.bcn.cl/leychile"
    },
    {
     "label": "Diario Financiero, 1 September 2026",
     "url": "https://www.df.cl/economia-y-politica/congreso/gobierno-ingresa-al-congreso-proyecto-que-posterga-por-un-ano-la-entrada-en"
    },
    {
     "label": "IAPP, August 2026",
     "url": "https://iapp.org/news/a/protecci-n-de-datos-personales-puntos-pendientes-antes-de-la-entrada-en-vigor-de-la-reforma-en-chile"
    }
   ]
  },
  {
   "name": "Argentina",
   "slug": "argentina",
   "url": "https://digitalprivacyregs.com/argentina.html",
   "flag": "🇦🇷",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Law 25.326",
   "year": 2000,
   "authority": "AAIP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with listed exceptions; the do-not-call registry and marketing opt-outs are enforced.",
   "transfers": "Adequacy-based; Argentina itself holds an EU adequacy decision, reaffirmed in the EU's 2024 review.",
   "penalties": "Administrative fines updated by the AAIP; modest by global standards.",
   "summary": "Latin America's original comprehensive law (2000) and one of only two in the region with EU adequacy. A GDPR-grade replacement bill has been introduced repeatedly, most recently in 2023, without passage; the AAIP compensates with active resolutions and guidance.",
   "sources": [
    {
     "label": "AAIP",
     "url": "https://www.argentina.gob.ar/aaip"
    }
   ]
  },
  {
   "name": "Uruguay",
   "slug": "uruguay",
   "url": "https://digitalprivacyregs.com/uruguay.html",
   "flag": "🇺🇾",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 18.331 on Personal Data Protection",
   "year": 2008,
   "authority": "URCDP",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first with GDPR-style updates layered in since 2018 (breach notification, DPOs, impact assessments).",
   "transfers": "Transfers abroad require an adequate destination, and Uruguay itself holds an EU adequacy decision.",
   "penalties": "Administrative fines apply, alongside registry sanctions.",
   "summary": "The region's quiet overachiever: EU adequacy since 2012, Convention 108+ membership, and steady GDPR-style upgrades bolted onto its 2008 law.",
   "sources": [
    {
     "label": "URCDP",
     "url": "https://www.gub.uy/unidad-reguladora-control-datos-personales/"
    }
   ]
  },
  {
   "name": "Colombia",
   "slug": "colombia",
   "url": "https://digitalprivacyregs.com/colombia.html",
   "flag": "🇨🇴",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 1581 of 2012 (habeas data)",
   "year": 2012,
   "authority": "Superintendence of Industry and Commerce (SIC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Prior, express and informed consent is the general rule, with a national database registry (RNBD) for larger companies.",
   "transfers": "Adequate-protection standard per SIC circulars; declarations of conformity available.",
   "penalties": "Fines up to about 2,000 monthly minimum wages per violation; the SIC fines frequently.",
   "summary": "Colombia pairs a strict express-consent standard with one of Latin America's most active enforcers: the SIC issues a constant stream of fines, including for unsolicited marketing, and runs the mandatory database registry.",
   "sources": [
    {
     "label": "SIC",
     "url": "https://www.sic.gov.co/"
    }
   ]
  },
  {
   "name": "Peru",
   "slug": "peru",
   "url": "https://digitalprivacyregs.com/peru.html",
   "flag": "🇵🇪",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 29733 on Personal Data Protection + 2024 Regulation",
   "year": 2011,
   "authority": "ANPD (National Authority, within the Ministry of Justice)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Prior, express, unequivocal consent is the default, one of the region's strictest standards; the 2024 regulation (effective 30 March 2025) modernized notices, cookies and children's rules.",
   "transfers": "Transfers abroad must be registered with the authority and turn on the adequacy of the destination.",
   "penalties": "Fines up to 100 UIT (S/550,000, about USD 160,000) for very serious infractions, actively imposed.",
   "summary": "Peru enforces more than its size suggests, with express-consent formalism, a database registration regime, and a fully rewritten regulation in force since March 2025 that reaches cookies, biometric data and digital services directly. Its duty to appoint data protection officers phases in by company size from November 2026.",
   "sources": [
    {
     "label": "DLA Piper, Peru",
     "url": "https://www.dlapiperdataprotection.com/?t=law&c=PE"
    }
   ]
  },
  {
   "name": "Ecuador",
   "slug": "ecuador",
   "url": "https://digitalprivacyregs.com/ecuador.html",
   "flag": "🇪🇨",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Organic Law on Personal Data Protection (LOPDP)",
   "year": 2021,
   "authority": "Superintendence of Personal Data Protection (SPDP), the authority since April 2024",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled bases with consent prominent; sanctions became applicable in 2023.",
   "transfers": "Transfers abroad need an adequate destination, appropriate safeguards or the individual's consent.",
   "penalties": "Serious violations bring fines up to 1% of prior-year revenue.",
   "summary": "Ecuador's 2021 law is a faithful GDPR adaptation. Its Superintendence became the operating authority in April 2024 and has since issued rules on DPOs, sanction methodology, transfers, large-scale processing, biometrics and breach notification, backed by turnover-linked fine ceilings.",
   "sources": [
    {
     "label": "SPDP resolutions",
     "url": "https://spdp.gob.ec/resoluciones2/"
    }
   ]
  },
  {
   "name": "Bolivia",
   "slug": "bolivia",
   "url": "https://digitalprivacyregs.com/bolivia.html",
   "flag": "🇧🇴",
   "region": "Americas",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None; constitutional habeas data only",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No regime.",
   "penalties": "None under a general privacy law.",
   "summary": "Bolivia remains one of South America's last holdouts, with constitutional habeas data actions but no comprehensive statute or authority.",
   "sources": []
  },
  {
   "name": "Paraguay",
   "slug": "paraguay",
   "url": "https://digitalprivacyregs.com/paraguay.html",
   "flag": "🇵🇾",
   "region": "Americas",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law No. 7593/2025 on Personal Data Protection",
   "year": 2025,
   "authority": "National Personal Data Protection Agency, a unit under the ICT ministry (MITIC), not yet operating",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-influenced consent and legal bases under the new law; until it applies, only the 2020 credit-data law (Law 6534/2020) is operative.",
   "transfers": "The new law brings adequacy and safeguard mechanisms for transfers abroad when it applies in late 2027.",
   "penalties": "The new law provides for administrative fines once it applies in late 2027.",
   "summary": "Paraguay promulgated its first comprehensive data protection law, Law No. 7593/2025, on 27 November 2025. It enters into force 24 months after publication, in late November 2027, and creates a national agency under the ICT ministry; until then the operative rules remain the 2020 credit-data law.",
   "sources": [
    {
     "label": "Altra Legal, December 2025",
     "url": "https://altra.com.py/se-promulgo-la-ley-no-7-593-2025-de-proteccion-de-datos-personales/"
    }
   ]
  },
  {
   "name": "Venezuela",
   "slug": "venezuela",
   "url": "https://digitalprivacyregs.com/venezuela.html",
   "flag": "🇻🇪",
   "region": "Americas",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None; constitutional habeas data and case law only",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No regime.",
   "penalties": "None under a general privacy law.",
   "summary": "No comprehensive statute exists; protection rests on constitutional habeas data and scattered sectoral rules.",
   "sources": []
  },
  {
   "name": "Guyana",
   "slug": "guyana",
   "url": "https://digitalprivacyregs.com/guyana.html",
   "flag": "🇬🇾",
   "region": "Americas",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Data Protection Act 2023",
   "year": 2023,
   "authority": "Data Protection Commissioner (appointed February 2026); commencement order pending",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-influenced consent and bases.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "The Act provides for fines.",
   "summary": "Guyana enacted a modern law in 2023 as oil wealth accelerates digitization and appointed its first Data Protection Commissioner in February 2026, but the Act still awaits the commencement order that switches its duties on.",
   "sources": []
  },
  {
   "name": "Suriname",
   "slug": "suriname",
   "url": "https://digitalprivacyregs.com/suriname.html",
   "flag": "🇸🇷",
   "region": "Americas",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Draft Privacy and Personal Data Protection Act (pending in the National Assembly)",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No rule restricts personal data leaving the country while the bill is pending.",
   "penalties": "No penalties apply until a law is passed.",
   "summary": "Suriname has no data protection law, but a draft privacy and personal data law has been before the National Assembly since about 2021.",
   "sources": [
    {
     "label": "National Assembly bill page",
     "url": "https://www.dna.sr/wetgeving/ontwerpwetten-bij-dna/in-behandeling/ontwerpwet-bescherming-privacy-en-persoonsgegevens/"
    }
   ]
  },
  {
   "name": "Panama",
   "slug": "panama",
   "url": "https://digitalprivacyregs.com/panama.html",
   "flag": "🇵🇦",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 81 of 2019 on Personal Data Protection",
   "year": 2019,
   "authority": "ANTAI",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or listed bases; in force since 2021 with a 2021 executive decree.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "Fines reach USD 10,000 plus other sanctions, a modest ceiling.",
   "summary": "Panama's Law 81 took effect in 2021 with ANTAI supervising; a workable GDPR-lite framework for a services-heavy economy.",
   "sources": []
  },
  {
   "name": "Costa Rica",
   "slug": "costa-rica",
   "url": "https://digitalprivacyregs.com/costa-rica.html",
   "flag": "🇨🇷",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 8968 on Protection of the Person Regarding Processing of Personal Data",
   "year": 2011,
   "authority": "PRODHAB",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Express consent is the general rule, with database registration duties.",
   "transfers": "Transfers abroad rest mainly on the individual's consent.",
   "penalties": "Fines reach about USD 20,000, plus registry sanctions.",
   "summary": "A 2011 express-consent law with an operating agency (PRODHAB); a modernization bill has circulated for years without passage.",
   "sources": []
  },
  {
   "name": "Nicaragua",
   "slug": "nicaragua",
   "url": "https://digitalprivacyregs.com/nicaragua.html",
   "flag": "🇳🇮",
   "region": "Americas",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Law 787 on Personal Data Protection",
   "year": 2012,
   "authority": "DIPRODAP (provided by law, never operational)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first on paper.",
   "transfers": "Transfers abroad rest mainly on the individual's consent.",
   "penalties": "Penalties are nominal.",
   "summary": "Law 787 exists on paper but its authority was never stood up, so the framework is effectively dormant.",
   "sources": []
  },
  {
   "name": "Honduras",
   "slug": "honduras",
   "url": "https://digitalprivacyregs.com/honduras.html",
   "flag": "🇭🇳",
   "region": "Americas",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Data protection bill (pending); constitutional habeas data",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "No penalties apply under a general privacy law.",
   "summary": "Bills have circulated for a decade without enactment; only constitutional habeas data applies.",
   "sources": []
  },
  {
   "name": "El Salvador",
   "slug": "el-salvador",
   "url": "https://digitalprivacyregs.com/el-salvador.html",
   "flag": "🇸🇻",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Law (2024)",
   "year": 2024,
   "authority": "State Cybersecurity Agency (ACE)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first, GDPR-influenced framework.",
   "transfers": "Transfers abroad turn on adequacy or appropriate safeguards.",
   "penalties": "The law scales fines by severity.",
   "summary": "El Salvador enacted its first comprehensive law in late 2024, paired with a cybersecurity law and supervised by the new ACE; a fast-moving digital-state agenda finally acquired a privacy layer.",
   "sources": []
  },
  {
   "name": "Guatemala",
   "slug": "guatemala",
   "url": "https://digitalprivacyregs.com/guatemala.html",
   "flag": "🇬🇹",
   "region": "Americas",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Data protection bills (pending); access-to-information law covers state data",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement for the private sector.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "No penalties apply under a general privacy law.",
   "summary": "Multiple bills have stalled in Congress; the private sector faces no comprehensive obligations.",
   "sources": []
  },
  {
   "name": "Belize",
   "slug": "belize",
   "url": "https://digitalprivacyregs.com/belize.html",
   "flag": "🇧🇿",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2021",
   "year": 2021,
   "authority": "Data Protection Officer / Commissioner under the Act",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-influenced consent and bases.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "The Act provides for fines.",
   "summary": "A modern 2021 statute on the Commonwealth Caribbean model, in force since 2022.",
   "sources": []
  },
  {
   "name": "Cuba",
   "slug": "cuba",
   "url": "https://digitalprivacyregs.com/cuba.html",
   "flag": "🇨🇺",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 149 of 2022 on Personal Data Protection",
   "year": 2022,
   "authority": "State supervision; no independent DPA",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-oriented rules within a state-controlled information system.",
   "transfers": "The state controls cross-border data flows directly.",
   "penalties": "Enforcement runs through administrative measures.",
   "summary": "Cuba adopted a personal data law in 2022; it grants formal rights while preserving expansive state access, and there is no independent regulator.",
   "sources": []
  },
  {
   "name": "Dominican Republic",
   "slug": "dominican-republic",
   "url": "https://digitalprivacyregs.com/dominican-republic.html",
   "flag": "🇩🇴",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Law 172-13 on Personal Data Protection",
   "year": 2013,
   "authority": "Superintendence of Banks (credit data); no general DPA",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first on paper, credit-data enforcement in practice.",
   "transfers": "Transfers abroad rest mainly on the individual's consent.",
   "penalties": "Fines apply, mostly in the credit-reporting context.",
   "summary": "Law 172-13 is comprehensive in text but its supervision is anchored in credit reporting; a modern replacement bill with a real DPA has been under discussion for years.",
   "sources": []
  },
  {
   "name": "Haiti",
   "slug": "haiti",
   "url": "https://digitalprivacyregs.com/haiti.html",
   "flag": "🇭🇹",
   "region": "Americas",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force.",
   "sources": []
  },
  {
   "name": "Jamaica",
   "slug": "jamaica",
   "url": "https://digitalprivacyregs.com/jamaica.html",
   "flag": "🇯🇲",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2020",
   "year": 2020,
   "authority": "Office of the Information Commissioner (OIC)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled standards; registration of controllers required.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "Certain offenses bring fines up to 4% of annual gross income.",
   "summary": "Fully in force since December 2023 with GDPR-style registration and breach duties; the OIC has been processing registrations at scale.",
   "sources": []
  },
  {
   "name": "Bahamas",
   "slug": "bahamas",
   "url": "https://digitalprivacyregs.com/bahamas.html",
   "flag": "🇧🇸",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection (Privacy of Personal Information) Act 2003",
   "year": 2003,
   "authority": "Data Protection Commissioner",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Directive-era consent-oriented rules.",
   "transfers": "The Act places transfers abroad under the Commissioner's supervision.",
   "penalties": "Fines are modest.",
   "summary": "An early Caribbean adopter (2003) whose framework now trails the modern Commonwealth Caribbean laws; modernization has been recommended repeatedly.",
   "sources": []
  },
  {
   "name": "Barbados",
   "slug": "barbados",
   "url": "https://digitalprivacyregs.com/barbados.html",
   "flag": "🇧🇧",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2019",
   "year": 2019,
   "authority": "Data Protection Commissioner",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "GDPR-modeled consent and bases.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "The Act provides for fines and imprisonment.",
   "summary": "A close GDPR adaptation in force since 2021; registration and DPO duties apply to larger processors.",
   "sources": []
  },
  {
   "name": "Trinidad and Tobago",
   "slug": "trinidad-and-tobago",
   "url": "https://digitalprivacyregs.com/trinidad-and-tobago.html",
   "flag": "🇹🇹",
   "region": "Americas",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Data Protection Act 2011 (partially proclaimed)",
   "year": 2011,
   "authority": "Office of the Information Commissioner (partially constituted)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-first in the unproclaimed parts; only general provisions are in force.",
   "transfers": "The Act's transfer provisions are not yet operative.",
   "penalties": "Penalties for the core duties are not yet operative.",
   "summary": "The 2011 Act has sat partially proclaimed for over a decade, with its administrative provisions live and its substantive obligations still waiting. Full proclamation is perennially promised.",
   "sources": []
  },
  {
   "name": "Antigua and Barbuda",
   "slug": "antigua-and-barbuda",
   "url": "https://digitalprivacyregs.com/antigua-and-barbuda.html",
   "flag": "🇦🇬",
   "region": "Americas",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Data Protection Act 2013",
   "year": 2013,
   "authority": "Information Commissioner (limited operation)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent-oriented framework; commencement and supervision have been incomplete.",
   "transfers": "The Act places transfers abroad under the Commissioner's supervision.",
   "penalties": "The Act provides for fines.",
   "summary": "A 2013 Act whose supervisory practice never fully materialized; treat obligations as formal.",
   "sources": []
  },
  {
   "name": "Saint Kitts and Nevis",
   "slug": "saint-kitts-and-nevis",
   "url": "https://digitalprivacyregs.com/saint-kitts-and-nevis.html",
   "flag": "🇰🇳",
   "region": "Americas",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Data Protection Act 2018",
   "year": 2018,
   "authority": "Information Commissioner (being operationalized)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Commonwealth-model consent framework.",
   "transfers": "The Act places transfers abroad under the Commissioner's supervision.",
   "penalties": "The Act provides for fines.",
   "summary": "A 2018 Commonwealth-model Act; supervisory machinery remains thin.",
   "sources": []
  },
  {
   "name": "Saint Lucia",
   "slug": "saint-lucia",
   "url": "https://digitalprivacyregs.com/saint-lucia.html",
   "flag": "🇱🇨",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Data Protection Act 2011",
   "year": 2011,
   "authority": "Data Protection Commissioner",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Commonwealth-model consent framework, in force since 2015.",
   "transfers": "The Act places transfers abroad under the Commissioner's supervision.",
   "penalties": "The Act provides for fines.",
   "summary": "In force since 2015 on the Commonwealth model; enforcement is light but the obligations are real.",
   "sources": []
  },
  {
   "name": "Saint Vincent and the Grenadines",
   "slug": "saint-vincent-and-the-grenadines",
   "url": "https://digitalprivacyregs.com/saint-vincent-and-the-grenadines.html",
   "flag": "🇻🇨",
   "region": "Americas",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None in force; the Privacy Act 2003 was passed but never brought into force",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework in force.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "Saint Vincent and the Grenadines passed a Privacy Act in 2003, but no commencement order was ever issued, so no data protection law is in force.",
   "sources": [
    {
     "label": "UWI Data Protection Office",
     "url": "https://www.uwi.edu/data-protection/resources-external-svg"
    }
   ]
  },
  {
   "name": "Grenada",
   "slug": "grenada",
   "url": "https://digitalprivacyregs.com/grenada.html",
   "flag": "🇬🇩",
   "region": "Americas",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Data Protection Act 2023",
   "year": 2023,
   "authority": "Information Commission (a three-member body under the Act; commencement order pending)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Modern Commonwealth-model framework that applies once commenced by ministerial order.",
   "transfers": "Transfers abroad need an adequate destination or appropriate safeguards such as contractual clauses.",
   "penalties": "The Act provides for fines.",
   "summary": "Grenada enacted a modern Data Protection Act in 2023 that creates a three-member Information Commission. The Act starts on a date set by ministerial order, and no order has been reported.",
   "sources": []
  },
  {
   "name": "Dominica",
   "slug": "dominica",
   "url": "https://digitalprivacyregs.com/dominica.html",
   "flag": "🇩🇲",
   "region": "Americas",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None in force",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force; regional model legislation has informed drafts.",
   "sources": []
  },
  {
   "name": "United States",
   "slug": "united-states",
   "url": "https://digitalprivacyregs.com/united-states.html",
   "flag": "🇺🇸",
   "region": "Americas",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "No federal comprehensive law; 24 state comprehensive laws (20 in effect) + sectoral statutes (COPPA, HIPAA, GLBA, FCRA, TCPA, CAN-SPAM)",
   "year": 2020,
   "authority": "FTC (Section 5) + state Attorneys General + California Privacy Protection Agency",
   "consent_model": "optout",
   "consent_label": "Opt-out",
   "marketing_consent_note": "Targeted advertising and data sales run on opt-out for adults and non-sensitive data. Opt-in is required for sensitive data in most state laws, for children's data, and for calls and texts under the TCPA.",
   "transfers": "No general restrictions on data leaving the US; the EU-US Data Privacy Framework governs inbound EU data.",
   "penalties": "State AG actions typically $7,500 per violation ($2,500-$7,500 under CCPA); FTC consent decrees; TCPA statutory damages of $500-$1,500 per call or text.",
   "summary": "The United States is the world's great opt-out exception. With no federal comprehensive law, advertisers can generally target adults using personal data without prior consent, subject to a growing patchwork of state opt-out rights. That summary holds for global media planning, and its exceptions are where US enforcement now lives.",
   "sources": [
    {
     "label": "California Privacy Protection Agency",
     "url": "https://cppa.ca.gov/"
    },
    {
     "label": "FTC",
     "url": "https://www.ftc.gov/"
    },
    {
     "label": "IAPP US state tracker",
     "url": "https://iapp.org/resources/article/us-state-privacy-legislation-tracker/"
    }
   ]
  },
  {
   "name": "Australia",
   "slug": "australia",
   "url": "https://digitalprivacyregs.com/australia.html",
   "flag": "🇦🇺",
   "region": "Oceania",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Privacy Act 1988 + Australian Privacy Principles, amended 2024",
   "year": 1988,
   "authority": "Office of the Australian Information Commissioner (OAIC)",
   "consent_model": "hybrid",
   "consent_label": "Hybrid",
   "marketing_consent_note": "Collection runs on notice and fair-collection rules, with consent required for sensitive information. APP 7 lets direct marketing proceed with an opt-out where data came from the individual, opt-in otherwise. The Spam Act makes email and SMS opt-in.",
   "transfers": "APP 8 accountability: the discloser remains liable for overseas recipients unless an exception applies.",
   "penalties": "For serious interferences: the greater of AUD 50M, three times the benefit, or 30% of adjusted turnover; a mid-2020s penalty overhaul with tiers for lesser breaches.",
   "summary": "Australia's Privacy Act is old but newly dangerous. The 2022 penalty overhaul raised ceilings to AUD 50M or 30% of turnover, and the December 2024 amendment package added a statutory tort for serious invasions of privacy (live since June 2025), criminal doxxing offenses, and two duties landing on 10 December 2026: privacy policies must disclose automated decisions that significantly affect individuals, and the OAIC must register a Children's Online Privacy Code, released in exposure draft this year. The bigger 'tranche 2' rewrite, including a fair-and-reasonable test and the fate of the small-business exemption, remains pending.",
   "sources": [
    {
     "label": "OAIC",
     "url": "https://www.oaic.gov.au/"
    },
    {
     "label": "OAIC: Children's Online Privacy Code",
     "url": "https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code"
    }
   ]
  },
  {
   "name": "New Zealand",
   "slug": "new-zealand",
   "url": "https://digitalprivacyregs.com/new-zealand.html",
   "flag": "🇳🇿",
   "region": "Oceania",
   "un_member": true,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Privacy Act 2020",
   "year": 2020,
   "authority": "Office of the Privacy Commissioner (OPC)",
   "consent_model": "hybrid",
   "consent_label": "Hybrid",
   "marketing_consent_note": "Purpose-and-notice model built on thirteen Information Privacy Principles; IPP3A, in force since 1 May 2026, requires notice when personal information is collected indirectly. The Unsolicited Electronic Messages Act makes email and SMS opt-in.",
   "transfers": "IPP12: disclosure abroad requires comparable safeguards, consent or a prescribed country. New Zealand holds EU adequacy.",
   "penalties": "Compliance notices and modest fines (to NZD 10,000), plus Human Rights Review Tribunal damages; light by global standards.",
   "summary": "New Zealand modernized in 2020 with mandatory breach notification and extraterritorial reach while keeping a principles-based, consent-light design, and EU adequacy makes it a comfortable node in global data architecture. 2026 brought IPP3A's notice duty for indirectly collected data on 1 May and, on 3 August, the end of the grace period for existing biometric processing under the Biometric Processing Privacy Code. Marketing email and SMS remain opt-in under the 2007 anti-spam law.",
   "sources": [
    {
     "label": "OPC NZ",
     "url": "https://www.privacy.org.nz/"
    }
   ]
  },
  {
   "name": "Papua New Guinea",
   "slug": "papua-new-guinea",
   "url": "https://digitalprivacyregs.com/papua-new-guinea.html",
   "flag": "🇵🇬",
   "region": "Oceania",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None; Digital Government Act touches public-sector data",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No regime.",
   "penalties": "None under a general privacy law.",
   "summary": "No comprehensive law is in force; a national data protection policy has been under development.",
   "sources": []
  },
  {
   "name": "Fiji",
   "slug": "fiji",
   "url": "https://digitalprivacyregs.com/fiji.html",
   "flag": "🇫🇯",
   "region": "Oceania",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Personal data protection bill (in development); constitutional privacy right",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No comprehensive consent requirement.",
   "transfers": "No general rule restricts personal data leaving the country.",
   "penalties": "No penalties apply under a general privacy law.",
   "summary": "Fiji has been drafting a data protection framework as part of its digital economy program; nothing comprehensive is yet in force.",
   "sources": []
  },
  {
   "name": "Solomon Islands",
   "slug": "solomon-islands",
   "url": "https://digitalprivacyregs.com/solomon-islands.html",
   "flag": "🇸🇧",
   "region": "Oceania",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force.",
   "sources": []
  },
  {
   "name": "Vanuatu",
   "slug": "vanuatu",
   "url": "https://digitalprivacyregs.com/vanuatu.html",
   "flag": "🇻🇺",
   "region": "Oceania",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Data Protection and Privacy Act No. 13 of 2024",
   "year": 2024,
   "authority": "Deputy Commissioner of Data Protection and Privacy under the Digital Safety Authority (not yet operational)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "A comprehensive framework covering public and private sectors; practical enforcement awaits the Digital Safety Authority.",
   "transfers": "The Act regulates transfers abroad, pending an operational regulator.",
   "penalties": "The Act provides for penalties that no operating regulator yet enforces.",
   "summary": "Vanuatu passed a Data Protection and Privacy Act in 2024 covering both public and private sectors, reported to be in effect from February 2025. The Digital Safety Authority that houses its commissioner is not yet operating.",
   "sources": [
    {
     "label": "Morrison Foerster privacy library",
     "url": "https://www.mofo.com/privacy-library/vanuatu"
    }
   ]
  },
  {
   "name": "Samoa",
   "slug": "samoa",
   "url": "https://digitalprivacyregs.com/samoa.html",
   "flag": "🇼🇸",
   "region": "Oceania",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force.",
   "sources": []
  },
  {
   "name": "Kiribati",
   "slug": "kiribati",
   "url": "https://digitalprivacyregs.com/kiribati.html",
   "flag": "🇰🇮",
   "region": "Oceania",
   "un_member": true,
   "status": "bill",
   "status_label": "Bill pending",
   "primary_law": "Data Protection Bill 2025 (first reading April 2025); no law confirmed in force",
   "year": null,
   "authority": "None yet",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework in force.",
   "transfers": "No rule restricts personal data leaving the country while the bill is pending.",
   "penalties": "No penalties apply until a law is passed.",
   "summary": "Kiribati's first Data Protection Bill passed its first reading in April 2025, covering both public and private sectors. Final passage has not been confirmed.",
   "sources": [
    {
     "label": "RNZ, April 2025",
     "url": "https://www.rnz.co.nz/news/pacific/556942/kiribati-s-first-of-its-kind-data-protection-bill-passes-first-reading"
    }
   ]
  },
  {
   "name": "Tonga",
   "slug": "tonga",
   "url": "https://digitalprivacyregs.com/tonga.html",
   "flag": "🇹🇴",
   "region": "Oceania",
   "un_member": true,
   "status": "adopted",
   "status_label": "Adopted",
   "primary_law": "Privacy Act 2025 (Act 34 of 2025)",
   "year": 2025,
   "authority": "Privacy Commissioner (provided by the Act; appointment not yet announced)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Comprehensive framework for controllers and processors based in Tonga or targeting people there; commencement is by Cabinet proclamation.",
   "transfers": "The Act regulates transfers abroad once it commences.",
   "penalties": "The Act provides for penalties; breach notification duties apply only two years after commencement.",
   "summary": "Tonga's Privacy Act 2025 received royal assent on 16 December 2025, a comprehensive law that also reaches organizations outside Tonga that target people there. It starts on a date proclaimed by Cabinet, reports conflict on whether that has happened, and no Privacy Commissioner has been announced.",
   "sources": [
    {
     "label": "Privacy Act 2025 (Attorney General's Office)",
     "url": "https://ago.gov.to/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0052/PrivacyAct2025_1.pdf"
    }
   ]
  },
  {
   "name": "Tuvalu",
   "slug": "tuvalu",
   "url": "https://digitalprivacyregs.com/tuvalu.html",
   "flag": "🇹🇻",
   "region": "Oceania",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force.",
   "sources": []
  },
  {
   "name": "Nauru",
   "slug": "nauru",
   "url": "https://digitalprivacyregs.com/nauru.html",
   "flag": "🇳🇷",
   "region": "Oceania",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force.",
   "sources": []
  },
  {
   "name": "Palau",
   "slug": "palau",
   "url": "https://digitalprivacyregs.com/palau.html",
   "flag": "🇵🇼",
   "region": "Oceania",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force.",
   "sources": []
  },
  {
   "name": "Marshall Islands",
   "slug": "marshall-islands",
   "url": "https://digitalprivacyregs.com/marshall-islands.html",
   "flag": "🇲🇭",
   "region": "Oceania",
   "un_member": true,
   "status": "sectoral",
   "status_label": "Sectoral",
   "primary_law": "Personal Data Protection Act 2025 (P.L. 2025-43), public sector only",
   "year": 2025,
   "authority": "Economic Policy, Planning and Statistics Office (for government bodies)",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "The 2025 Act covers government ministries and agencies only; private businesses have no general consent rule.",
   "transfers": "No general rule restricts private-sector data leaving the country.",
   "penalties": "No penalties apply to private businesses under a general privacy law.",
   "summary": "The Marshall Islands passed a Personal Data Protection Act in 2025, but it binds government ministries and agencies only and takes effect twelve months after certification. Private-sector data remains unregulated.",
   "sources": [
    {
     "label": "P.L. 2025-43 (Nitijela)",
     "url": "https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0043/2025-0043_1.pdf"
    }
   ]
  },
  {
   "name": "Micronesia",
   "slug": "micronesia",
   "url": "https://digitalprivacyregs.com/micronesia.html",
   "flag": "🇫🇲",
   "region": "Oceania",
   "un_member": true,
   "status": "none",
   "status_label": "No law",
   "primary_law": "None",
   "year": null,
   "authority": "None",
   "consent_model": "none",
   "consent_label": "None",
   "marketing_consent_note": "No data protection framework.",
   "transfers": "No regime.",
   "penalties": "None.",
   "summary": "No comprehensive data protection law is in force.",
   "sources": []
  },
  {
   "name": "European Union",
   "slug": "european-union",
   "url": "https://digitalprivacyregs.com/european-union.html",
   "flag": "🇪🇺",
   "region": "Special",
   "un_member": false,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "GDPR + ePrivacy Directive",
   "year": 2018,
   "authority": "EDPB coordination + national DPAs; European Commission for adequacy",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "A lawful basis under Article 6 for all processing; freely given, specific, informed, unambiguous consent for cookies, tracking and most adtech via the ePrivacy Directive.",
   "transfers": "Chapter V: adequacy decisions, SCCs, BCRs, derogations; the EU-US Data Privacy Framework covers certified US companies.",
   "penalties": "Up to EUR 20M or 4% of global annual turnover, whichever is higher.",
   "summary": "The GDPR is the world's reference privacy law: one regulation binding 27 member states plus the EEA, exported globally through adequacy, contract clauses and imitation. For advertisers the operative pair is GDPR plus the ePrivacy Directive, which together make consent the price of tracking in Europe.",
   "sources": [
    {
     "label": "GDPR text",
     "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
     "label": "EDPB",
     "url": "https://www.edpb.europa.eu/"
    },
    {
     "label": "European Commission adequacy",
     "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en"
    }
   ]
  },
  {
   "name": "Hong Kong",
   "slug": "hong-kong",
   "url": "https://digitalprivacyregs.com/hong-kong.html",
   "flag": "🇭🇰",
   "region": "Special",
   "un_member": false,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data (Privacy) Ordinance (PDPO)",
   "year": 1996,
   "authority": "Privacy Commissioner for Personal Data (PCPD)",
   "consent_model": "hybrid",
   "consent_label": "Hybrid",
   "marketing_consent_note": "Notice-and-purpose model in which collection needs only notice, while Part 6A requires explicit consent-style agreement before using personal data in direct marketing, with criminal penalties for violations.",
   "transfers": "Section 33 transfer restrictions were enacted in 1995 but never brought into force; the PCPD publishes recommended model clauses instead.",
   "penalties": "Enforcement notices, then criminal prosecution; direct marketing offenses carry fines to HKD 1M and imprisonment.",
   "summary": "Asia's oldest privacy law (1996) runs on notice, with one sharp exception in direct marketing. Part 6A, added after the 2010 Octopus scandal, makes using personal data for marketing without the individual's agreement a criminal offense, and the PCPD prosecutes. The 2021 amendment added anti-doxxing offenses with extraterritorial reach.",
   "sources": [
    {
     "label": "PCPD",
     "url": "https://www.pcpd.org.hk/"
    }
   ]
  },
  {
   "name": "Macau",
   "slug": "macau",
   "url": "https://digitalprivacyregs.com/macau.html",
   "flag": "🇲🇴",
   "region": "Special",
   "un_member": false,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Act (Law 8/2005)",
   "year": 2005,
   "authority": "Office for Personal Data Protection (GPDP)",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "EU-directive-modeled: consent or another legitimacy ground; notification duties to the GPDP for many processing operations.",
   "transfers": "Transfers abroad need an adequacy-style assessment of the destination or GPDP authorization.",
   "penalties": "Administrative fines and criminal penalties for serious violations.",
   "summary": "Macau transplanted the pre-GDPR EU directive into local law in 2005 and enforces it through the GPDP, with notification duties that surprise operators used to the GDPR's accountability model. The casino economy keeps CCTV, marketing and cross-border questions on the regulator's desk.",
   "sources": [
    {
     "label": "GPDP",
     "url": "https://www.dsedt.gov.mo/"
    }
   ]
  },
  {
   "name": "Taiwan",
   "slug": "taiwan",
   "url": "https://digitalprivacyregs.com/taiwan.html",
   "flag": "🇹🇼",
   "region": "Special",
   "un_member": false,
   "status": "inforce",
   "status_label": "In force",
   "primary_law": "Personal Data Protection Act (PDPA)",
   "year": 2010,
   "authority": "Personal Data Protection Commission (preparatory office; a November 2025 amendment makes it the sole authority from a date not yet set), with sectoral ministries in the meantime",
   "consent_model": "optin",
   "consent_label": "Opt-in",
   "marketing_consent_note": "Consent or a listed statutory basis; notification duties at collection; opt-out must be honored for marketing, and first-use marketing requires a free opt-out channel.",
   "transfers": "Permitted unless restricted by ministries (restrictions exist for some destinations); sectoral rules add localization pockets.",
   "penalties": "2023 amendments raised fines (to NTD 15M for serious security failures) after the iRent breach; criminal exposure for unlawful use.",
   "summary": "Taiwan's PDPA dates to 2010 (roots in 1995) and is mid-transformation. 2023 amendments raised penalties and mandated an independent Personal Data Protection Commission, and a further amendment promulgated in November 2025 makes the Commission the sole supervisory authority once a start date is set. Until then the preparatory office works alongside ministry-by-ministry enforcement.",
   "sources": []
  }
 ]
}