DATA PRIVACY LAWS COMPARISON
A side-by-side comparison of major global data privacy regulations. Use this reference when assessing compliance obligations across jurisdictions.
OVERVIEW TABLE#
Law | Jurisdiction | Effective | Scope ----------|------------------|---------------|------------------------------- GDPR | EU / EEA | May 2018 | Any org processing EU resident data CCPA/CPRA | California, USA | Jan 2020/2023 | Businesses meeting CA thresholds LGPD | Brazil | Sep 2020 | Any org processing Brazilian data PDPA (SG) | Singapore | Feb 2021 | Orgs collecting data in Singapore PDPA (TH) | Thailand | Jun 2022 | Orgs processing Thai resident data POPIA | South Africa | Jul 2021 | Any org processing SA resident data
SCOPE AND APPLICABILITY#
GDPR:
- Applies to controllers and processors in the EU
- Extraterritorial: applies to non-EU orgs offering goods/services to EU
- No revenue or size threshold
- Covers all personal data of data subjects in the EU
CCPA/CPRA:
- For-profit businesses doing business in California AND meeting one of:
> Annual gross revenue > $25 million
> Buy/sell/share personal info of 100,000+ consumers/households
> Derive 50%+ revenue from selling/sharing personal info
- CPRA created the California Privacy Protection Agency (CPPA)
LGPD:
- Applies to any processing performed in Brazil
- Or data collected in Brazil, or offering services to individuals in Brazil
- No size threshold
- Covers personal data and sensitive personal data
PDPA (Singapore):
- All private sector organizations in Singapore
- Excludes public agencies and organizations acting on their behalf
- No size or revenue threshold
- Covers personal data that can identify an individual
PDPA (Thailand):
- All data controllers/processors handling Thai resident data
- Extraterritorial reach for goods/services or monitoring behavior
- Exemptions for personal/household use, public interest, media
POPIA:
- Any responsible party processing personal info in South Africa
- Or using processing means in South Africa
- Covers juristic and natural persons
- Exemptions for household, national security, journalism
KEY DEFINITIONS COMPARISON#
Concept | GDPR | CCPA/CPRA | LGPD -----------------|-------------------|--------------------|----------------- Personal Data | Personal Data | Personal Info | Personal Data Sensitive Data | Special Categories| Sensitive PI | Sensitive PD Data Owner | Data Subject | Consumer | Data Subject Controller | Controller | Business | Controller Processor | Processor | Service Provider | Operator Consent | Explicit/Informed | Opt-out model | Explicit/Informed Legal Basis | 6 legal bases | No legal basis req | 10 legal bases Regulator | DPAs per state | CPPA | ANPD
DATA SUBJECT RIGHTS#
Right | GDPR | CCPA/CPRA | LGPD | PDPA(SG) | POPIA ------------------------|------|-----------|------|----------|------ Access | Y | Y | Y | Y | Y Rectification | Y | Y | Y | Y | Y Deletion/Erasure | Y | Y | Y | N* | Y Portability | Y | Y | Y | Y | Y Opt-out of Sale | N/A | Y | N/A | N/A | N/A Restrict Processing | Y | Y | Y | N | Y Object to Processing | Y | N | Y | Y | Y Automated Decision-Making| Y | Y | Y | N | Y Non-Discrimination | Y | Y | Y | N | Y Withdraw Consent | Y | Y | Y | Y | Y * Singapore PDPA allows withdrawal of consent but not general erasure.
LEGAL BASES FOR PROCESSING#
GDPR (6 Bases): 1. Consent 2. Contractual necessity 3. Legal obligation 4. Vital interests 5. Public interest/official authority 6. Legitimate interests (balancing test required) CCPA/CPRA: - No legal basis requirement for collection - Purpose limitation: cannot use data beyond disclosed purposes - Opt-out mechanism for sale/sharing LGPD (10 Bases): 1. Consent 2. Legal obligation 3. Public administration policies 4. Research (anonymized when possible) 5. Contract execution 6. Exercise of rights in judicial/arbitration 7. Life/physical safety protection 8. Health protection 9. Legitimate interests 10. Credit protection
BREACH NOTIFICATION REQUIREMENTS#
Law | Notify Authority | Notify Individuals | Timeline ----------|------------------------|--------------------------|------------------ GDPR | Yes (supervisory auth) | Yes (high risk) | 72 hours to DPA CCPA/CPRA | Yes (AG if 500+ CA) | Yes | "Most expedient time" LGPD | Yes (ANPD) | Yes (significant risk) | Reasonable time (ANPD guidance) PDPA (SG) | Yes (PDPC) | Yes (significant harm) | 3 calendar days to PDPC PDPA (TH) | Yes (committee) | Yes (high risk) | 72 hours POPIA | Yes (Info Regulator) | Yes | As soon as reasonably possible
PENALTIES AND ENFORCEMENT#
GDPR: - Up to EUR 20 million or 4% of annual global turnover (whichever higher) - Tier 1: EUR 10 million or 2% for lesser violations - DPAs can issue warnings, reprimands, orders, bans CCPA/CPRA: - $2,500 per unintentional violation - $7,500 per intentional violation - Private right of action for data breaches: $100-$750 per consumer per incident - CPPA enforcement (administrative fines) LGPD: - Warning with deadline for corrective measures - Simple fine up to 2% of revenue in Brazil, capped at BRL 50 million per violation - Daily fines, publicization, data blocking/deletion PDPA (Singapore): - Up to SGD 1 million or 10% of annual turnover in Singapore - Directions to stop collection, destroy data, comply PDPA (Thailand): - Criminal penalties up to THB 5 million and/or 1 year imprisonment - Administrative fines up to THB 5 million - Civil liability (punitive damages up to 2x actual damages) POPIA: - Fines up to ZAR 10 million - Imprisonment up to 10 years for serious offenses - Administrative fines, enforcement notices
CROSS-BORDER DATA TRANSFERS#
GDPR: - Adequacy decisions (approved countries) - Standard Contractual Clauses (SCCs) - Binding Corporate Rules (BCRs) - Derogations (explicit consent, contract necessity) - Transfer Impact Assessments (TIAs) required post-Schrems II CCPA/CPRA: - No specific cross-border transfer restrictions - Service provider contracts must include data protection obligations - Risk assessments for certain high-risk processing LGPD: - Countries with adequate protection (ANPD list) - Standard contractual clauses - Binding corporate rules - Specific consent for transfer - International cooperation agreements PDPA (Singapore): - Recipient country must have comparable protection - Contractual obligations on recipient - Consent of individual - Binding corporate rules POPIA: - Adequate level of protection in recipient country - Binding corporate rules - Consent of data subject - Necessary for contract performance
DATA PROTECTION OFFICER (DPO)#
GDPR: - Mandatory for public authorities - Mandatory for large-scale systematic monitoring - Mandatory for large-scale processing of special categories - Must be independent, report to highest management level CCPA/CPRA: - No DPO requirement - Must have processes for consumer requests LGPD: - DPO (Encarregado) required for all controllers - ANPD may provide exceptions for small businesses PDPA (Singapore): - Must designate at least one DPO - Business contact information must be available POPIA: - Information Officer required - Must be registered with Information Regulator
COMPLIANCE QUICK CHECKLIST#
[ ] Identify which laws apply based on data subjects and business operations [ ] Map all personal data flows (collection, processing, storage, sharing) [ ] Establish lawful basis for each processing activity [ ] Implement data subject rights request procedures [ ] Create and maintain privacy notices/policies [ ] Implement appropriate technical and organizational security measures [ ] Establish breach notification procedures [ ] Conduct Data Protection Impact Assessments where required [ ] Implement cross-border transfer safeguards [ ] Maintain records of processing activities [ ] Appoint DPO where required [ ] Train staff on data protection obligations [ ] Review and update vendor/processor agreements [ ] Implement data retention schedules [ ] Conduct regular compliance audits
USEFUL RESOURCES#
- GDPR Full Text: https://gdpr-info.eu/ - CCPA/CPRA Full Text: https://oag.ca.gov/privacy/ccpa - LGPD Full Text: https://www.gov.br/anpd/ - PDPA Singapore: https://www.pdpc.gov.sg/ - POPIA: https://popia.co.za/ - IAPP Privacy Tracker: https://iapp.org/resources/
DATA PRIVACY LAWS COMPARISON
=============================
Source: https://cheatsheet.johlem.net
A side-by-side comparison of major global data privacy regulations.
Use this reference when assessing compliance obligations across jurisdictions.
OVERVIEW TABLE
--------------
Law | Jurisdiction | Effective | Scope
----------|------------------|---------------|-------------------------------
GDPR | EU / EEA | May 2018 | Any org processing EU resident data
CCPA/CPRA | California, USA | Jan 2020/2023 | Businesses meeting CA thresholds
LGPD | Brazil | Sep 2020 | Any org processing Brazilian data
PDPA (SG) | Singapore | Feb 2021 | Orgs collecting data in Singapore
PDPA (TH) | Thailand | Jun 2022 | Orgs processing Thai resident data
POPIA | South Africa | Jul 2021 | Any org processing SA resident data
SCOPE AND APPLICABILITY
-----------------------
GDPR:
- Applies to controllers and processors in the EU
- Extraterritorial: applies to non-EU orgs offering goods/services to EU
- No revenue or size threshold
- Covers all personal data of data subjects in the EU
CCPA/CPRA:
- For-profit businesses doing business in California AND meeting one of:
> Annual gross revenue > $25 million
> Buy/sell/share personal info of 100,000+ consumers/households
> Derive 50%+ revenue from selling/sharing personal info
- CPRA created the California Privacy Protection Agency (CPPA)
LGPD:
- Applies to any processing performed in Brazil
- Or data collected in Brazil, or offering services to individuals in Brazil
- No size threshold
- Covers personal data and sensitive personal data
PDPA (Singapore):
- All private sector organizations in Singapore
- Excludes public agencies and organizations acting on their behalf
- No size or revenue threshold
- Covers personal data that can identify an individual
PDPA (Thailand):
- All data controllers/processors handling Thai resident data
- Extraterritorial reach for goods/services or monitoring behavior
- Exemptions for personal/household use, public interest, media
POPIA:
- Any responsible party processing personal info in South Africa
- Or using processing means in South Africa
- Covers juristic and natural persons
- Exemptions for household, national security, journalism
KEY DEFINITIONS COMPARISON
--------------------------
Concept | GDPR | CCPA/CPRA | LGPD
-----------------|-------------------|--------------------|-----------------
Personal Data | Personal Data | Personal Info | Personal Data
Sensitive Data | Special Categories| Sensitive PI | Sensitive PD
Data Owner | Data Subject | Consumer | Data Subject
Controller | Controller | Business | Controller
Processor | Processor | Service Provider | Operator
Consent | Explicit/Informed | Opt-out model | Explicit/Informed
Legal Basis | 6 legal bases | No legal basis req | 10 legal bases
Regulator | DPAs per state | CPPA | ANPD
DATA SUBJECT RIGHTS
--------------------
Right | GDPR | CCPA/CPRA | LGPD | PDPA(SG) | POPIA
------------------------|------|-----------|------|----------|------
Access | Y | Y | Y | Y | Y
Rectification | Y | Y | Y | Y | Y
Deletion/Erasure | Y | Y | Y | N* | Y
Portability | Y | Y | Y | Y | Y
Opt-out of Sale | N/A | Y | N/A | N/A | N/A
Restrict Processing | Y | Y | Y | N | Y
Object to Processing | Y | N | Y | Y | Y
Automated Decision-Making| Y | Y | Y | N | Y
Non-Discrimination | Y | Y | Y | N | Y
Withdraw Consent | Y | Y | Y | Y | Y
* Singapore PDPA allows withdrawal of consent but not general erasure.
LEGAL BASES FOR PROCESSING
---------------------------
GDPR (6 Bases):
1. Consent
2. Contractual necessity
3. Legal obligation
4. Vital interests
5. Public interest/official authority
6. Legitimate interests (balancing test required)
CCPA/CPRA:
- No legal basis requirement for collection
- Purpose limitation: cannot use data beyond disclosed purposes
- Opt-out mechanism for sale/sharing
LGPD (10 Bases):
1. Consent
2. Legal obligation
3. Public administration policies
4. Research (anonymized when possible)
5. Contract execution
6. Exercise of rights in judicial/arbitration
7. Life/physical safety protection
8. Health protection
9. Legitimate interests
10. Credit protection
BREACH NOTIFICATION REQUIREMENTS
---------------------------------
Law | Notify Authority | Notify Individuals | Timeline
----------|------------------------|--------------------------|------------------
GDPR | Yes (supervisory auth) | Yes (high risk) | 72 hours to DPA
CCPA/CPRA | Yes (AG if 500+ CA) | Yes | "Most expedient time"
LGPD | Yes (ANPD) | Yes (significant risk) | Reasonable time (ANPD guidance)
PDPA (SG) | Yes (PDPC) | Yes (significant harm) | 3 calendar days to PDPC
PDPA (TH) | Yes (committee) | Yes (high risk) | 72 hours
POPIA | Yes (Info Regulator) | Yes | As soon as reasonably possible
PENALTIES AND ENFORCEMENT
--------------------------
GDPR:
- Up to EUR 20 million or 4% of annual global turnover (whichever higher)
- Tier 1: EUR 10 million or 2% for lesser violations
- DPAs can issue warnings, reprimands, orders, bans
CCPA/CPRA:
- $2,500 per unintentional violation
- $7,500 per intentional violation
- Private right of action for data breaches: $100-$750 per consumer per incident
- CPPA enforcement (administrative fines)
LGPD:
- Warning with deadline for corrective measures
- Simple fine up to 2% of revenue in Brazil, capped at BRL 50 million per violation
- Daily fines, publicization, data blocking/deletion
PDPA (Singapore):
- Up to SGD 1 million or 10% of annual turnover in Singapore
- Directions to stop collection, destroy data, comply
PDPA (Thailand):
- Criminal penalties up to THB 5 million and/or 1 year imprisonment
- Administrative fines up to THB 5 million
- Civil liability (punitive damages up to 2x actual damages)
POPIA:
- Fines up to ZAR 10 million
- Imprisonment up to 10 years for serious offenses
- Administrative fines, enforcement notices
CROSS-BORDER DATA TRANSFERS
-----------------------------
GDPR:
- Adequacy decisions (approved countries)
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs)
- Derogations (explicit consent, contract necessity)
- Transfer Impact Assessments (TIAs) required post-Schrems II
CCPA/CPRA:
- No specific cross-border transfer restrictions
- Service provider contracts must include data protection obligations
- Risk assessments for certain high-risk processing
LGPD:
- Countries with adequate protection (ANPD list)
- Standard contractual clauses
- Binding corporate rules
- Specific consent for transfer
- International cooperation agreements
PDPA (Singapore):
- Recipient country must have comparable protection
- Contractual obligations on recipient
- Consent of individual
- Binding corporate rules
POPIA:
- Adequate level of protection in recipient country
- Binding corporate rules
- Consent of data subject
- Necessary for contract performance
DATA PROTECTION OFFICER (DPO)
------------------------------
GDPR:
- Mandatory for public authorities
- Mandatory for large-scale systematic monitoring
- Mandatory for large-scale processing of special categories
- Must be independent, report to highest management level
CCPA/CPRA:
- No DPO requirement
- Must have processes for consumer requests
LGPD:
- DPO (Encarregado) required for all controllers
- ANPD may provide exceptions for small businesses
PDPA (Singapore):
- Must designate at least one DPO
- Business contact information must be available
POPIA:
- Information Officer required
- Must be registered with Information Regulator
COMPLIANCE QUICK CHECKLIST
---------------------------
[ ] Identify which laws apply based on data subjects and business operations
[ ] Map all personal data flows (collection, processing, storage, sharing)
[ ] Establish lawful basis for each processing activity
[ ] Implement data subject rights request procedures
[ ] Create and maintain privacy notices/policies
[ ] Implement appropriate technical and organizational security measures
[ ] Establish breach notification procedures
[ ] Conduct Data Protection Impact Assessments where required
[ ] Implement cross-border transfer safeguards
[ ] Maintain records of processing activities
[ ] Appoint DPO where required
[ ] Train staff on data protection obligations
[ ] Review and update vendor/processor agreements
[ ] Implement data retention schedules
[ ] Conduct regular compliance audits
USEFUL RESOURCES
-----------------
- GDPR Full Text: https://gdpr-info.eu/
- CCPA/CPRA Full Text: https://oag.ca.gov/privacy/ccpa
- LGPD Full Text: https://www.gov.br/anpd/
- PDPA Singapore: https://www.pdpc.gov.sg/
- POPIA: https://popia.co.za/
- IAPP Privacy Tracker: https://iapp.org/resources/
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.