Direct answers first, nuance second. These are the questions practitioners ask most, including the ones whose answer depends on the channel.
Do I need consent to run targeted ads in the United States?
Generally no, for adults and non-sensitive data. US state laws run on opt-out: you can target until the consumer objects, but you must honor opt-outs (including the Global Privacy Control signal in states like California and Colorado), post the required disclosures, and get opt-in consent for sensitive categories such as health, precise geolocation and biometrics. Children are a different regime entirely: COPPA requires parental consent under 13, and several states now ban targeted advertising to anyone under 18.
Is the US really opt-out while the rest of the world is opt-in?
As a planning heuristic, yes. The EU, UK, Brazil, China, Korea, Canada and most other regulated markets require a legal basis or affirmative consent before tracking and targeted marketing. The US lets you proceed and obligates you to stop on request. The caveats: US calls and texts are opt-in under the TCPA, sensitive data is opt-in in most state laws, and Maryland's law bans some practices outright. Email is the reverse anomaly: CAN-SPAM is opt-out while Canada, the EU and Australia require opt-in.
Are marketing texts and calls opt-in or opt-out in the US?
Opt-in, emphatically. The TCPA requires prior express written consent for marketing calls and texts made with autodialers or prerecorded voice, and violations carry statutory damages of $500 to $1,500 per message with no cap. This is the most litigated consumer protection statute in the country. The US being 'opt-out' refers to targeted advertising and data sales, never to SMS.
How many US states have privacy laws in 2026?
Twenty-four states have enacted comprehensive consumer privacy laws and twenty are in effect: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and, since January 1, 2026, Indiana, Kentucky and Rhode Island. The four enacted in the 2026 sessions arrive on a published schedule: Louisiana and Oklahoma on January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028. There is still no federal comprehensive law.
What is the GDPR in one paragraph?
The General Data Protection Regulation is the EU's comprehensive privacy law, in force since May 2018 and binding on anyone processing EU residents' data for offering goods and services or monitoring behavior, wherever the company sits. Every use of personal data needs one of six legal bases; tracking and behavioral advertising effectively need consent; individuals hold rights to access, correct, delete and port their data; and violations carry fines up to EUR 20 million or 4 percent of global turnover. It is the template most of the world's newer laws copy.
Which countries have no data protection law at all?
About twenty, concentrated in conflict zones and small island states: Afghanistan, Iraq, Libya, Yemen, Sudan, Eritrea, Haiti, Venezuela, Bolivia, North Korea and much of the Pacific, including Papua New Guinea, Samoa and the Solomon Islands. Pakistan, Cambodia, Guatemala, Honduras, Suriname and South Sudan have only pending bills. The list keeps shrinking, with Bangladesh, Burundi, Cameroon, Djibouti, the Gambia, Liberia and Tonga all enacting or activating first laws in 2025 and 2026. Even in unregulated markets, sectoral rules and the extraterritorial reach of laws like the GDPR can still apply to campaigns.
Can I email a purchased list?
In the US, legally yes under CAN-SPAM if you honor unsubscribes and identification rules, though deliverability and brand risk argue against it. In Canada, no: CASL requires consent the list seller almost never validly holds, at up to CAD 10M in penalties. In the EU and UK, no for consumers: ePrivacy rules require opt-in consent, and the soft opt-in only covers your own customers. Australia's Spam Act likewise requires consent. Purchased-list email is effectively a US-only tactic.
What is a consent management platform and do I need one?
A CMP is the software layer that presents cookie and tracking choices, records the consent state, and signals it to your tags (usually through the IAB TCF or Google consent mode). If you run any pixels, analytics or adtech and can be seen from the EU, UK, Brazil or another opt-in market, you need one. In the US alone you can often run lighter: an opt-out mechanism, GPC honoring and disclosures, without a full consent wall.
What are SCCs and when do I need them?
Standard Contractual Clauses are regulator-approved contract terms that make an international data transfer lawful. You need them (or an alternative like adequacy or BCRs) whenever personal data moves from a restricted jurisdiction, the EU, UK, Brazil, Turkey, China among them, to a country without an adequacy finding. If your EU customer data lands in a US CRM and your vendor is not DPF-certified, SCCs plus a transfer impact assessment are the standard answer.
Is Google Analytics legal in Europe?
The current generation, deployed correctly, generally yes. The 2022-2023 decisions by Austrian, French, Italian and other regulators found the then-configuration of Universal Analytics unlawful because it moved identifiable data to the US without valid safeguards. The EU-US Data Privacy Framework (2023) restored a lawful transfer route for certified companies, and GA4 with consent mode, IP handling and EU data processing addresses much of the rest. You still need cookie consent to set the tags in the first place.
What changed in the UK after the Data (Use and Access) Act?
The DUAA, in force in stages from 2025 with the main data provisions live 5 February 2026, adjusted the UK GDPR without replacing it. The changes include recognised legitimate interests that skip the balancing test, statutory acknowledgment that direct marketing may qualify as a legitimate interest, relaxed automated decision-making rules, cookie exceptions for low-risk analytics, and PECR fines raised to UK GDPR levels. Cookies and consumer e-marketing remain opt-in, and the EU renewed UK adequacy through December 2031 after reviewing the Act.
When does India's DPDP Act start to bite?
In three phases from the 13 November 2025 notification of the DPDP Rules. Immediately, the provisions establishing the Data Protection Board took effect, and the government has been setting the Board up since. From 13 November 2026, consent managers can register. From 13 May 2027, everything else applies at once: notice, consent, rights, security, breach reporting and children's rules, along with the Board's enforcement powers and fines of up to INR 250 crore per breach category. Marketing to Indian consumers on unconsented lists has a hard expiry date of 13 May 2027.
Do privacy laws apply to B2B marketing?
Usually yes. The GDPR and its descendants protect any identifiable individual, and a work email with a name in it is personal data; the EU soft opt-in and corporate-subscriber nuances in PECR provide some room, but cold outreach to individuals in the EU needs a defensible basis. US state laws largely exempted B2B contacts at first, but California removed its exemption in 2023 and others cover employee and B2B data too. Canada's CASL applies regardless of whether the recipient is at work.
What is the safest global default if I can only build one playbook?
Build to the opt-in standard: collect affirmative consent for tracking and marketing, honor withdrawal instantly, minimize what you collect, and document transfers. That playbook is lawful nearly everywhere, and you can then loosen deliberately for the US (opt-out targeting, CAN-SPAM email) where the economics justify a second track. The reverse approach, building US-style and patching for everyone else, is how companies end up in EDPB decisions.