Global Privacy Law and DPA Directory
Data protection laws exist across the globe. This tool has an interactive map identifying those countries with data protection laws. Within each country’s listing, if available, you can link to a resource containing the data protection law, the data protection authority, and relevant IAPP resources. The IAPP Resource Center also hosts a "Global Comprehensive Privacy Law Mapping Chart," which maps the differences between comprehensive privacy laws globally.
The Westin Research Center will periodically update these tools. As always, we appreciate input from our members. If you have comments about the information or believe additional material should be included, please share it with us at research@iapp.org.
Note: This tool is for informational purposes and is not legal advice. The status of a country's data protection legislation should always be verified via official sources.
-
Afghanistan
The IAPP is unaware of data protection legislation in Afghanistan.
Last Updated: December 2021
-
Åland Islands
Privacy Legislation:
- DPA Legislation Page
- It appears the Aland Islands are subject to the EU General Data Protection Regulation.
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Albania
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Algeria
Privacy Legislation:
- Law No. 18-07 on the protection of natural persons with respect to the processing of data (In-Language)
Authority:
- National Authority for Protection of Personal Data (not yet established)
Last Updated: December 2021
-
Andorra
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Angola
Comprehensive Data Protection Law:
Authority:
Last Updated: December 2021
-
Anguilla
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Anguilla.
Last Updated: December 2021
-
Antigua and Barbuda
Privacy Legislation:
Authority:
- The IAPP is unaware of a website for the Information Commissioner.
Last Updated: December 2021
-
Argentina
Privacy Legislation:
Authority:
Additional Resources:
- Argentina is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Armenia
Privacy Legislation:
- Law On Personal Data Protection, and RA Government Decision N 1175-N dated 15 October 2015 "On Defining Requirements for Material Carriers of Biometric Personal Data and Technologies for Storage of Such Data outside of Information Systems"
- Law on the Protection of Personal Data (2015) (English, sourced from Freedom of Information Center of Armenia)
Authority:
Last Updated: December 2021
-
Aruba
Privacy Legislation:
Authority:
- Ministry of Justice (Unofficial)
Last Updated: December 2021
-
Australia
Privacy Legislation:
Authority:
- Office of the Australian Information Commissioner
- Information and Privacy Commission (New South Wales)
- Information Commissioner (Northern Territory)
- Office of the Information Commissioner (Queensland)
- Office of the Victorian Information Commissioner (Victoria)
Additional Resources:
- The IAPP Resource Center hosts an "Australia and New Zealand" topic page.
- Australia is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Austria
Privacy Legislation:
- As a European Union Member-State, Austria is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Azerbaijan
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Bahamas, The
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Bahrain
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Bangladesh
Privacy Legislation:
- Bangladesh is reportedly considering a personal data protection law like GDPR.
Additional Resources:
In 2020, Bangladesh passed the Digital Security Act.
Bangladesh e-Government Computer Incident Response Team (BGD e-GOV CIRT)
Last Updated: December 2021
-
Barbados
Privacy Legislation:
Authority:
- Barbados appointed its first Data Protection Commissioner in 2021. IAPP is unaware of an established data protection office.
Last Updated: December 2021
-
Belarus
Privacy Legislation:
Authority:
- National Center for Data Protection (Link not available)
Last Updated: December 2021
-
Belgium
Privacy Legislation:
- As a European Union Member-State, Belgium is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Belize
Privacy Legislation/Authority:
- The IAPP is unaware of a data protection authority or data protection legislation for Belize.
Last Updated: December 2021
-
Benin
Privacy Legislation:
Authority:
Additional Resources:
- Benin is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Bermuda
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Bhutan
Privacy Legislation:
- Bhutan enacted the Information, Communications and Media Act in 2018. It applies to ICT and Media Sectors.
- Information, Communications and Media Act, 2018
Authority:
Last Updated: December 2021
-
Bolivia
Privacy Legislation/Authority:
- The IAPP is unaware of a data protection authority or data protection legislation for Bolivia.
Last Updated: December 2021
-
Bonair, Saint Eustatius and Saba
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Bosnia and Herzegovina
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Botswana
Privacy Legislation:
Authority:
- Information and Data Protection Commission (not yet established).
Last Updated: December 2021
-
Brazil
Privacy Legislation:
Authority:
Additional Resources:
- The IAPP Resource Center hosts a "Brazil" topic page.
- Brazil is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
British Virgin Islands
Privacy Legislation/Authority:
Authority:
- The IAPP is unaware of an established data protection authority for the British Virgin Islands.
Last Updated: December 2021
-
Brunei
Privacy Legislation/Authority:
- The Authority for Infocommunications Technology Industry (AITI) is the interim data office to develop a new data protection law. The draft law can be found here.
Last Updated: December 2021
-
Bulgaria
Privacy Legislation:
- As a European Union Member-State, Bulgaria is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Burkina Faso
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Burundi
Privacy Legislation/Authority
- The IAPP is unaware of a data protection authority or data protection legislation for Burundi.
Last Updated: December 2021
-
Cambodia
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Cambodia.
Last Updated: December 2021
-
Cameroon
Privacy Legislation/Authority:
- The IAPP is unaware of a data protection authority or data protection legislation for Cameroon.
Last Updated: December 2021
-
Canada
Privacy Legislation:
Authority:
Additional Resources:
- The IAPP Resource Center hosts a "Canada" topic page.
- Canada is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Cape Verde
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Cayman Islands
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Central African Republic
Privacy Legislation/Authority:
- The IAPP is unaware of data protection legislation in Central African Republic.
Last Updated: December 2021
-
Chad
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Chile
Privacy Legislation:
Authority:
- The IAPP is unaware of a data protection authority for Chile.
Last Updated: December 2021
-
China
Privacy Legislation:
- Personal Information Protection Law of the People's Republic of China (English, In-Language)
Authority:
- Cyberspace Administration of China (CAC)
- The Ministry of Public Security
- Ministry of Industry and Information Technology
Additional Resources:
- The IAPP Resource Center hosts a "China" topic page.
- China is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Colombia
Privacy Legislation:
- Law 1581/2012 and Law 1266/2008
- In addition to the data protection laws, there are decrees and other documents with relevant data protection provisions, including Decree 1377/2013 and Decree 2591/1991.
Authority:
Additional Resources:
- Colombia is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Costa Rica
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Croatia
Privacy Legislation:
- As a European Union Member-State, Croatia is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Cuba
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Cuba.
Last Updated: December 2021
-
Curaçao
Privacy Legislation/Authority:
Authority:
- The IAPP is unaware of a data protection authority for Curaçao.
Last Updated: December 2021
-
Cyprus
Privacy Legislation:
- As a European Union Member-State, Cyprus is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Czech Republic
Privacy Legislation:
- As a European Union Member-State, the Czech Republic is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Democratic Republic of the Congo
Privacy Legislation:
- The IAPP is unaware of data protection legislation in the Democratic Republic of the Congo.
Last Updated: December 2021
-
Denmark
Privacy Legislation:
- As a European Union Member-State, Denmark is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Djibouti
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Djibouti.
Last Updated: December 2021
-
Dominica
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Dominica.
Last Updated: December 2021
-
Dominican Republic
Privacy Legislation:
Authority:
- The IAPP is unaware of a data protection authority for the Dominican Republic.
Last Updated: December 2021
-
Ecuador
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority for Ecuador.
Last Updated: December 2021
-
Egypt
Privacy Legislation:
- View Data Protection Law (English, In-Language)
Authority:
- Personal Data Protection Centre (Not yet established)
Last Updated: December 2021
-
El Salvador
Privacy Legislation:
Last Updated: December 2021
-
Equatorial Guinea
Privacy Legislation:
Authority:
- The IAPP is currently unaware of an established data protection authority for Equatorial Guinea.
Last Updated: December 2021
-
Eritrea
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Eritrea.
Last Updated: December 2021
-
Estonia
Privacy Legislation:
- As a European Union Member-State, Estonia is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Eswatini
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Eswatani.
Last Updated: December 2021
-
Ethiopia
Privacy Legislation:
- The IAPP is unaware of specific data protection legislation in Ethiopia.
Last Updated: December 2021
-
Faroe Islands
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Fiji
Privacy Legislation:
- The IAPP is unaware of specific data protection legislation in Fiji.
Last Updated: December 2021
-
Finland
Privacy Legislation:
- As a European Union Member-State, Finland is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
France
Privacy Legislation:
- As a European Union Member-State, France is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
French Guiana
Privacy Legislation:
- French Guiana is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
French Polynesia
Privacy Legislation:
- French Polynesia is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Gabon
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Gambia
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Gambia.
Last Updated: December 2021
-
Georgia
Privacy Legislation:
Authority:
- State Inspector's Service
Note: Parliament approved a bill abolishing the agency on Dec. 31, 2021. It is unknown whether the bill will become enforceable.
Last Updated: December 2021
- State Inspector's Service
-
Germany
Privacy Legislation:
- As a European Union Member-State, Germany is subject to the EU General Data Protection Regulation.
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Ghana
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Gibraltar
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Greece
Privacy Legislation:
- As a European Union Member-State, Greece is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Greenland
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Guadeloupe
Privacy Legislation:
- Guadeloupe is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Guatemala
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Guatemala.
Last Updated: December 2021
-
Guernsey
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Guinea
Privacy Legislation:
Authority:
- Regulatory Authority for Posts and Telecommunications (not confirmed)
Last Updated: December 2021
-
Guinea-Bissau
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Guinea-Bissau.
Last Updated: December 2021
-
Guyana
Privacy Legislation/Authority:
- The IAPP is unaware of a data protection authority or data protection legislation for Guyana.
Last Updated: December 2021
-
Haiti
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Haiti.
Last Updated: December 2021
-
Honduras
Privacy Legislation:
- The IAPP is unaware of data protection legislation for Honduras.
Authority:
Last Updated: December 2021
-
Hong Kong
Privacy Legislation:
Authority:
Additional Resources:
- Hong Kong is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Hungary
Privacy Legislation:
- As a European Union Member-State, Hungary is subject to the EU General Data Protection Regulation.
- Act CXII of 2011 ("Privacy Act")
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Iceland
Privacy Legislation:
- Iceland is a European Economic Area country that is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
India
Privacy Legislation:
- India is considering draft personal data protection legislation. (Personal Data Protection Bill, 2019)
Additional Resources:
- The IAPP Resource Center hosts an "India" topic page.
Last Updated: December 2021
-
Indonesia
Privacy Legislation:
Last Updated: December 2021
-
Iran
Privacy Legislation:
- The IAPP is unaware of specific data protection legislation in Iran.
Last Updated: December 2021
-
Iraq
Privacy Legislation:
- The IAPP is unaware of specific data protection legislation in Iraq.
Last Updated: December 2021
-
Ireland
Privacy Legislation:
- As a European Union Member-State, Ireland is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Isle of Man
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Israel
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Italy
Privacy Legislation:
- As a European Union Member-State, Italy is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Ivory Coast
Privacy Legislation:
- Law No. 2013-450 (In-Language, English)
- DPA Legislation Page
Authority:
Last Updated: December 2021
-
Jamaica
Privacy Legislation:
Authority:
- The Information Commissioner, Celia Barclay, assumed her role on December 1, 2021. The Office of the Information Commissioner is in the process of being staffed.
Last Updated: December 2021
-
Japan
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Jersey
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Jordan
Privacy Legislation/Authority:
- Jordan is considering draft personal data protection legislation. (Draft law proposed in 2021)
Last Updated: December 2021
-
Kazakhstan
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Kenya
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Kosovo
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Kuwait
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Kyrgyzstan
Privacy Legislation:
Authority:
- The State agency for protection of personal data was established in 2021 (link unavailable)
Last Updated: December 2021
-
Lao People’s Democratic Republic
Privacy Legislation:
- The IAPP is unaware of specific data protection legislation in Lao People's Democratic Republic.
Last Updated: December 2021
-
Latvia
Privacy Legislation:
- As a European Union Member-State, Latvia is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Lebanon
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority.
Last Updated: December 2021
-
Lesotho
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority.
Last Updated: December 2021
-
Liberia
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Liberia.
Last Updated: December 2021
-
Libya
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Libya.
Last Updated: December 2021
-
Liechtenstein
Privacy Legislation:
- Liechtenstein is a European Economic Area country that is subject to the EU General Data Protection Regulation.
- DPA Legal Bases Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Lithuania
Privacy Legislation:
- As a European Union Member-State, Lithuania is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Luxembourg
Privacy Legislation:
- As a European Union Member-State, Luxembourg is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Macau
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Madagascar
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority.
Last Updated: December 2021
-
Malawi
Privacy Legislation:
Last Updated: December 2021
-
Malaysia
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Mali
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Malta
Privacy Legislation:
- As a European Union Member-State, Malta is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Martinique
Privacy Legislation:
- Martinique is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Mauritania
Privacy Legislation:
- Law No. 2017-020 on Personal Data Protection (not yet in effect)
Authority:
- The IAPP is unaware of an established data protection authority for Mauritania.
Last Updated: December 2021
-
Mauritius
Privacy Legislation/Authority:
Last Updated: December 2021
-
Mayotte
Privacy Legislation:
- Mayotte is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Mexico
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Moldova
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Monaco
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Mongolia
Privacy Legislation:
- A draft law on the protection of personal data was submitted to Mongolia’s Parliament.
- It appears the law was passed in December 2021.
Last Updated: February 2022
-
Montenegro
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Morocco
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Mozambique
Privacy Legislation:
- The IAPP is unaware of specific data protection legislation in Mozambique.
Last Updated: December 2021
-
Myanmar
Privacy Legislation:
- The IAPP is unaware of specific data protection legislation in Myanmar.
Last Updated: December 2021
-
Namibia
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Namibia.
Last Updated: December 2021
-
Nepal
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority.
Last Updated: December 2021
-
Netherlands, The
Privacy Legislation:
- As a European Union Member-State, The Netherlands is subject to the EU General Data Protection Regulation.
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
New Caledonia
Privacy Legislation:
- New Caledonia is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
New Zealand
Privacy Legislation:
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "Australia and New Zealand" topic page.
- New Zealand is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Nicaragua
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection agency.
Last Updated: December 2021
-
Niger
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Nigeria
Privacy Legislation:
Authority:
- The National Information Technology Development Agency (NITDA)
- In February 2022, Nigeria's president approved the Nigeria Data Protection Bureau and appointed Dr. Olatunji as National Commissioner.
Additional Resources:
- Nigeria is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: February 2022
-
North Korea
Privacy Legislation:
- The IAPP is unaware of data protection legislation in North Korea.
Last Updated: December 2021
-
Norway
Privacy Legislation:
- Norway is a European Economic Area country that is subject to the EU General Data Protection Regulation.
- DPA Regulations Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Oman
Privacy Legislation:
- Oman adopted the Law on the Protection of Personal Data in February 2022. The law will come into force in February 2023.
Last Updated: February 2022
-
Pakistan
Privacy Legislation:
Last Updated: December 2021
-
Palestinian Territories
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Palestine.
Last Updated: December 2021
-
Panama
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Papua New Guinea
Privacy Legislation:
- The IAPP is unaware of specific data protection legislation in Papua New Guinea.
Last Updated: December 2021
-
Paraguay
Privacy Legislation:
Authority:
- The law designates the Central Bank of Paraguay and the Secretariat for the Defense of the Consumer and the User as enforcement authorities.
Last Updated: December 2021
-
Peru
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Philippines
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Poland
Privacy Legislation:
- As a European Union Member-State, Poland is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Portugal
Privacy Legislation:
- As a European Union Member-State, Portugal is subject to the EU General Data Protection Regulation.
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Qatar
Privacy Legislation:
Authority:
- Compliance and Data Protection (CDP)
- Qatar Financial Center (QFC) Regulatory Authority (Data Protection Regulations, Data Protection Rules)
Last Updated: December 2021
-
Republic of North Macedonia
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Republic of Serbia
Privacy Legislation:
- Law on Protection of Personal Data, 2018 (English, In-Language)
Authority:
Last Updated: December 2021
-
Republic of the Congo
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority for the Republic of the Congo.
Last Updated: December 2021
-
Reunion
Privacy Legislation:
- Reunion is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Romania
Privacy Legislation:
- As a European Union Member-State, Romania is subject to the EU General Data Protection Regulation.
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Russia
Privacy Legislation:
Authority:
Additional Resources:
- The IAPP Resource Center hosts a "Russia" topic page.
Last Updated: December 2021
-
Rwanda
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority for Rwanda.
Last Updated: December 2021
-
Saint Barthelemy
Privacy Legislation:
- Saint Barthelemy is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Saint Kitts and Nevis
Privacy Legislation:
- Data Protection Act, 2018 (does not appear to be in force)
Authority:
- The IAPP is unaware of an established data protection authority for Saint Kitts and Nevis.
Last Updated: December 2021
-
Saint Lucia
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority for Saint Lucia.
Last Updated: December 2021
-
Saint Martin
Privacy Legislation:
- Saint Martin is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Saint Pierre and Miquelon
Privacy Legislation:
- Saint Pierre and Miquelon is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Saint Vincent and the Grenadines
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority for Saint Vincent and the Grenadines.
Last Updated: December 2021
-
San Marino
Privacy Legislation:
Authority:
Last Updated: December 2021
-
São Tomé and Príncipe
Privacy Legislation/Authority:
Last Updated: December 2021
-
Saudi Arabia
Privacy Legislation:
- Personal Data Protection Law (Delayed to March 2023)
Authority:
Last Updated: March 2022
-
Senegal
Privacy Legislation/Authority:
Last Updated: December 2021
-
Seychelles
Privacy Legislation:
- Data Protection Act (not yet in force)
Authority:
- The IAPP is unaware of an established data protection authority for Seychelles.
Last Updated: December 2021
-
Sierra Leone
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Sierra Leone.
Last Updated: December 2021
-
Singapore
Privacy Legislation:
Authority:
Additional Resources:
- Singapore is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Sint Maarten
Privacy Legislation:
Authority:
- The IAPP is unaware of a data protection authority in Sint Maarten.
Last Updated: December 2021
-
Slovakia
Privacy Legislation:
- As a European Union Member-State, Slovakia is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Slovenia
Privacy Legislation:
- As a European Union Member-State, Slovenia is subject to the EU General Data Protection Regulation.
- DPA Legislation Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Solomon Islands
Privacy Legislation:
- The IAPP is unaware of data protection legislation in the Solomon Islands.
Last Updated: December 2021
-
Somalia
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Somalia.
Last Updated: December 2021
-
South Africa
Privacy Legislation:
Authority:
Additional Resources:
- South Africa is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
South Georgia and the South Sandwich Islands
Privacy Legislation:
- The IAPP is unaware of data protection legislation in South Georgia and the South Sandwich Islands.
Last Updated: December 2021
-
South Korea
Privacy Legislation:
Authority:
Additional Resources:
- South Korea is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
South Sudan
Privacy Legislation:
- The IAPP is unaware of data protection legislation in South Sudan.
Last Updated: December 2021
-
Spain
Privacy Legislation:
- As a European Union Member-State, Spain is subject to the EU General Data Protection Regulation.
- DPA Regulations Page
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Sri Lanka
Privacy Legislation:
Last Updated: December 2021
-
Sudan
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Sudan.
Last Updated: December 2021
-
Suriname
Privacy Legislation:
Last Updated: December 2021
-
Sweden
Privacy Legislation:
- As a European Union Member-State, Sweden is subject to the EU General Data Protection Regulation.
Authority:
Additional Resources:
- The IAPP Resource Center hosts an "EU General Data Protection Regulation" topic page.
- The EU General Data Protection Regulation is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Switzerland
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Syria
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Syria.
Last Updated: December 2021
-
Taiwan
Privacy Legislation/Authority:
Last Updated: December 2021
-
Tajikistan
Privacy Legislation:
Authority:
- It appears the Main Department for the Protection of State Secrets under the Government of the Republic of Tajikistan is the regulator.
Last Updated: December 2021
-
Tanzania
Privacy Legislation:
Last Updated: December 2021
-
Thailand
Privacy Legislation:
Authority:
Last Updated: June 2022
-
Togo
Privacy Legislation:
Authority:
- The IAPP is unaware of an established data protection authority for Togo.
Last Updated: December 2021
-
Trinidad and Tobago
Privacy Legislation:
- Data Protection Act, 2011 (partially in force)
Authority:
- It does not appear the Office of the Information Commissioner is established.
Last Updated: December 2021
-
Tunisia
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Turkey
Privacy Legislation:
Authority:
Additional Resources:
- Turkey is included in the IAPP's "Global Comprehensive Privacy Law Mapping Chart."
Last Updated: December 2021
-
Turkmenistan
Privacy Legislation:
Authority:
- The IAPP is unaware of a data protection authority for Turkmenistan.
Last Updated: December 2021
-
Turks and Caicos Islands
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Turks and Caicos.
Last Updated: December 2021
-
Uganda
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Ukraine
Privacy Legislation:
Authority:
Last Updated: December 2021
-
United Arab Emirates
Privacy Legislation/Authority:
- Federal Decree Law No. 45/2021 (Link not available)
- The UAE Data Office is not yet established.
- Abu Dhabi Global Market (ADGM) – Office of Data Protection, Regulations
- Dubai International Finance Centre (DIFC) – Data Protection Law
Last Updated: December 2021
-
United Kingdom
Privacy Legislation:
Authority:
Additional Resources:
- The IAPP Resource Center hosts a "United Kingdom" topic page.
Last Updated: December 2021
-
United States of America
Federal Privacy Legislation:
- The U.S. does not have a comprehensive federal data protection law. It takes a sectoral approach, with national laws and regulations addressing privacy in several areas, including personal health information, financial institutions, credit report information, and children’s information. The Federal Trade Commission is the most prominent enforcement body, but there are sector-specific enforcement bodies too.
- The IAPP Resource Center hosts a US Federal Privacy Legislation tracker.
State Privacy Legislation:
- Each state also may have its own sectoral privacy laws and regulations. California, Virginia and Colorado have adopted comprehensive data protection laws. State attorney generals typically are the primary enforcement authorities for state privacy laws. California has established the California Privacy Protection Agency. The CPPA and the California attorney general will share enforcement authority.
- The IAPP Resource Center hosts a US State Privacy Legislation tracker.
Additional Resources:
- Federal Trade Commission – Protecting Consumer Privacy and Security Resources
- The IAPP Resource Center hosts United States, US Federal Privacy and US State Privacy topic pages.
Last Updated: December 2021
-
Uruguay
Privacy Legislation:
Authority:
Last Updated: December 2021
-
Uzbekistan
Privacy Legislation:
- Law No. ZRU-547 on Personal Data, 2019 (The law was amended in January 2021.)
Authority:
Last Updated: December 2021
-
Venezuela
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Venezuela.
Last Updated: December 2021
-
Vietnam
Privacy Legislation/Authority:
- A draft decree on personal data protection was proposed in 2021.
- Draft Decree on Personal Data Protection, 2021 (Link not available)
Last Updated: December 2021
-
Wallis and Futuna
Privacy Legislation:
- Wallis and Futuna is a French overseas territory. The CNIL has guidance regarding the applicability of the GDPR and the French data protection act, Informatique et Libertés.
Last Updated: December 2021
-
Western Sahara
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Western Sahara.
Last Updated: December 2021
-
Yemen
Privacy Legislation:
- The IAPP is unaware of data protection legislation in Yemen.
Last Updated: December 2021
-
Zambia
Privacy Legislation:
Authority:
- The Office of the Data Protection Commissioner is not yet established.
Last Updated: December 2021
-
Zimbabwe
Privacy Legislation:
Authority:
Last Updated: December 2021