← All cheat sheets

DATA PRIVACY LAWS COMPARISON

Plain-text reference · 9 KB. Read it, search it (Ctrl-F) or print it.

A side-by-side comparison of major global data privacy regulations.
Use this reference when assessing compliance obligations across jurisdictions.

OVERVIEW TABLE#

Law       | Jurisdiction     | Effective     | Scope
----------|------------------|---------------|-------------------------------
GDPR      | EU / EEA         | May 2018      | Any org processing EU resident data
CCPA/CPRA | California, USA  | Jan 2020/2023 | Businesses meeting CA thresholds
LGPD      | Brazil           | Sep 2020      | Any org processing Brazilian data
PDPA (SG) | Singapore        | Feb 2021      | Orgs collecting data in Singapore
PDPA (TH) | Thailand         | Jun 2022      | Orgs processing Thai resident data
POPIA     | South Africa     | Jul 2021      | Any org processing SA resident data

SCOPE AND APPLICABILITY#

GDPR:
  - Applies to controllers and processors in the EU
  - Extraterritorial: applies to non-EU orgs offering goods/services to EU
  - No revenue or size threshold
  - Covers all personal data of data subjects in the EU

CCPA/CPRA:
  - For-profit businesses doing business in California AND meeting one of:
    > Annual gross revenue > $25 million
    > Buy/sell/share personal info of 100,000+ consumers/households
    > Derive 50%+ revenue from selling/sharing personal info
  - CPRA created the California Privacy Protection Agency (CPPA)

LGPD:
  - Applies to any processing performed in Brazil
  - Or data collected in Brazil, or offering services to individuals in Brazil
  - No size threshold
  - Covers personal data and sensitive personal data

PDPA (Singapore):
  - All private sector organizations in Singapore
  - Excludes public agencies and organizations acting on their behalf
  - No size or revenue threshold
  - Covers personal data that can identify an individual

PDPA (Thailand):
  - All data controllers/processors handling Thai resident data
  - Extraterritorial reach for goods/services or monitoring behavior
  - Exemptions for personal/household use, public interest, media

POPIA:
  - Any responsible party processing personal info in South Africa
  - Or using processing means in South Africa
  - Covers juristic and natural persons
  - Exemptions for household, national security, journalism

KEY DEFINITIONS COMPARISON#

Concept          | GDPR              | CCPA/CPRA          | LGPD
-----------------|-------------------|--------------------|-----------------
Personal Data    | Personal Data     | Personal Info      | Personal Data
Sensitive Data   | Special Categories| Sensitive PI       | Sensitive PD
Data Owner       | Data Subject      | Consumer           | Data Subject
Controller       | Controller        | Business           | Controller
Processor        | Processor         | Service Provider   | Operator
Consent          | Explicit/Informed | Opt-out model      | Explicit/Informed
Legal Basis      | 6 legal bases     | No legal basis req | 10 legal bases
Regulator        | DPAs per state    | CPPA               | ANPD

DATA SUBJECT RIGHTS#

Right                   | GDPR | CCPA/CPRA | LGPD | PDPA(SG) | POPIA
------------------------|------|-----------|------|----------|------
Access                  |  Y   |     Y     |  Y   |    Y     |  Y
Rectification           |  Y   |     Y     |  Y   |    Y     |  Y
Deletion/Erasure        |  Y   |     Y     |  Y   |    N*    |  Y
Portability             |  Y   |     Y     |  Y   |    Y     |  Y
Opt-out of Sale         |  N/A |     Y     |  N/A |    N/A   |  N/A
Restrict Processing     |  Y   |     Y     |  Y   |    N     |  Y
Object to Processing    |  Y   |     N     |  Y   |    Y     |  Y
Automated Decision-Making| Y   |     Y     |  Y   |    N     |  Y
Non-Discrimination      |  Y   |     Y     |  Y   |    N     |  Y
Withdraw Consent        |  Y   |     Y     |  Y   |    Y     |  Y

* Singapore PDPA allows withdrawal of consent but not general erasure.
GDPR (6 Bases):
  1. Consent
  2. Contractual necessity
  3. Legal obligation
  4. Vital interests
  5. Public interest/official authority
  6. Legitimate interests (balancing test required)

CCPA/CPRA:
  - No legal basis requirement for collection
  - Purpose limitation: cannot use data beyond disclosed purposes
  - Opt-out mechanism for sale/sharing

LGPD (10 Bases):
  1. Consent
  2. Legal obligation
  3. Public administration policies
  4. Research (anonymized when possible)
  5. Contract execution
  6. Exercise of rights in judicial/arbitration
  7. Life/physical safety protection
  8. Health protection
  9. Legitimate interests
  10. Credit protection

BREACH NOTIFICATION REQUIREMENTS#

Law       | Notify Authority       | Notify Individuals       | Timeline
----------|------------------------|--------------------------|------------------
GDPR      | Yes (supervisory auth) | Yes (high risk)          | 72 hours to DPA
CCPA/CPRA | Yes (AG if 500+ CA)    | Yes                      | "Most expedient time"
LGPD      | Yes (ANPD)             | Yes (significant risk)   | Reasonable time (ANPD guidance)
PDPA (SG) | Yes (PDPC)             | Yes (significant harm)   | 3 calendar days to PDPC
PDPA (TH) | Yes (committee)        | Yes (high risk)          | 72 hours
POPIA     | Yes (Info Regulator)   | Yes                      | As soon as reasonably possible

PENALTIES AND ENFORCEMENT#

GDPR:
  - Up to EUR 20 million or 4% of annual global turnover (whichever higher)
  - Tier 1: EUR 10 million or 2% for lesser violations
  - DPAs can issue warnings, reprimands, orders, bans

CCPA/CPRA:
  - $2,500 per unintentional violation
  - $7,500 per intentional violation
  - Private right of action for data breaches: $100-$750 per consumer per incident
  - CPPA enforcement (administrative fines)

LGPD:
  - Warning with deadline for corrective measures
  - Simple fine up to 2% of revenue in Brazil, capped at BRL 50 million per violation
  - Daily fines, publicization, data blocking/deletion

PDPA (Singapore):
  - Up to SGD 1 million or 10% of annual turnover in Singapore
  - Directions to stop collection, destroy data, comply

PDPA (Thailand):
  - Criminal penalties up to THB 5 million and/or 1 year imprisonment
  - Administrative fines up to THB 5 million
  - Civil liability (punitive damages up to 2x actual damages)

POPIA:
  - Fines up to ZAR 10 million
  - Imprisonment up to 10 years for serious offenses
  - Administrative fines, enforcement notices

CROSS-BORDER DATA TRANSFERS#

GDPR:
  - Adequacy decisions (approved countries)
  - Standard Contractual Clauses (SCCs)
  - Binding Corporate Rules (BCRs)
  - Derogations (explicit consent, contract necessity)
  - Transfer Impact Assessments (TIAs) required post-Schrems II

CCPA/CPRA:
  - No specific cross-border transfer restrictions
  - Service provider contracts must include data protection obligations
  - Risk assessments for certain high-risk processing

LGPD:
  - Countries with adequate protection (ANPD list)
  - Standard contractual clauses
  - Binding corporate rules
  - Specific consent for transfer
  - International cooperation agreements

PDPA (Singapore):
  - Recipient country must have comparable protection
  - Contractual obligations on recipient
  - Consent of individual
  - Binding corporate rules

POPIA:
  - Adequate level of protection in recipient country
  - Binding corporate rules
  - Consent of data subject
  - Necessary for contract performance

DATA PROTECTION OFFICER (DPO)#

GDPR:
  - Mandatory for public authorities
  - Mandatory for large-scale systematic monitoring
  - Mandatory for large-scale processing of special categories
  - Must be independent, report to highest management level

CCPA/CPRA:
  - No DPO requirement
  - Must have processes for consumer requests

LGPD:
  - DPO (Encarregado) required for all controllers
  - ANPD may provide exceptions for small businesses

PDPA (Singapore):
  - Must designate at least one DPO
  - Business contact information must be available

POPIA:
  - Information Officer required
  - Must be registered with Information Regulator

COMPLIANCE QUICK CHECKLIST#

[ ] Identify which laws apply based on data subjects and business operations
[ ] Map all personal data flows (collection, processing, storage, sharing)
[ ] Establish lawful basis for each processing activity
[ ] Implement data subject rights request procedures
[ ] Create and maintain privacy notices/policies
[ ] Implement appropriate technical and organizational security measures
[ ] Establish breach notification procedures
[ ] Conduct Data Protection Impact Assessments where required
[ ] Implement cross-border transfer safeguards
[ ] Maintain records of processing activities
[ ] Appoint DPO where required
[ ] Train staff on data protection obligations
[ ] Review and update vendor/processor agreements
[ ] Implement data retention schedules
[ ] Conduct regular compliance audits

USEFUL RESOURCES#

- GDPR Full Text:        https://gdpr-info.eu/
- CCPA/CPRA Full Text:   https://oag.ca.gov/privacy/ccpa
- LGPD Full Text:        https://www.gov.br/anpd/
- PDPA Singapore:        https://www.pdpc.gov.sg/
- POPIA:                 https://popia.co.za/
- IAPP Privacy Tracker:  https://iapp.org/resources/

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.