CONNECTX Global Privacy & Data Protection Law Reference
Status: August 2026
A
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Afghanistan |
No reliably functioning comprehensive modern data-protection regime under the current de facto Taliban authorities; constitutional and pre-2021 frameworks have uncertain practical application. |
π΄ High uncertainty. De facto regime, very limited regulatory transparency and no independent democratic oversight comparable to EU systems. Project-specific legal review essential. |
| Albania |
Law No.Β 124/2024 on the Protection of Personal Data, modernized toward GDPR standards; Convention 108/108+ framework. |
π’ Established / modern framework. |
| Algeria |
Law No.Β 18-07 of 10 June 2018 relating to the Protection of Natural Persons in the Processing of Personal Data. |
π‘ Comprehensive law; regulatory and state-security exemptions require careful analysis. |
| Andorra |
Qualified Law 29/2021 on Personal Data Protection; closely aligned with GDPR; Convention 108+. |
π’ Established. |
| Angola |
Law No.Β 22/11 on Protection of Personal Data; Constitution also protects privacy. |
π‘ Comprehensive law, but enforcement maturity is more limited than EU jurisdictions. |
| Antigua and Barbuda |
Data Protection Act 2013. |
π‘ Comprehensive statutory framework; smaller regulatory environment. |
| Argentina |
Personal Data Protection Law No.Β 25,326 and implementing rules; constitutional habeas-data protection. Argentina has long held EU adequacy. |
π’ Established, although modernization legislation continues to evolve. |
| Armenia |
Law on Protection of Personal Data, 2015; Convention 108 framework. |
π’/π‘ Substantial framework. |
| Australia |
Privacy Act 1988, Australian Privacy Principles, Notifiable Data Breaches regime; extensive sectoral rules. Major privacy reform continues. |
π’ Established. |
| Austria |
EU GDPR + Austrian Data Protection Act (DSG). |
π’ Strict GDPR jurisdiction. |
| Azerbaijan |
Law on Personal Data (2010), Constitution and sectoral legislation. |
π‘ Law exists; government-access and independence questions require separate assessment. |
B
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Bahamas |
Data Protection (Privacy of Personal Information) Act 2003. |
π‘ Established statutory framework, older than GDPR. |
| Bahrain |
Personal Data Protection Law No.Β 30 of 2018 and implementing decisions. |
π’/π‘ Comprehensive modern framework. |
| Bangladesh |
Cyber Security Act and sectoral/constitutional privacy provisions; a comprehensive personal-data regime has been under legislative development. |
π Developing / changing framework. Verify current enactment and commencement before a project. |
| Barbados |
Data Protection Act 2019. |
π’/π‘ Comprehensive GDPR-influenced law. |
| Belarus |
Law No.Β 99-Z on Personal Data Protection, effective 2021. |
π΄ Formal law exists, but authoritarian political environment and independence/enforcement issues mean government-access and human-rights implications require heightened review. |
| Belgium |
EU GDPR + Belgian Data Protection Act of 30 July 2018. |
π’ Strict GDPR jurisdiction. |
| Belize |
Data Protection Act 2021. |
π’/π‘ Comprehensive framework. |
| Benin |
Digital Code, Law No.Β 2017-20, including personal-data protection rules; national data protection authority. |
π‘ Substantial framework. |
| Bhutan |
Information, Communications and Media Act 2018 and sectoral/constitutional privacy protections; no GDPR-equivalent standalone framework of comparable maturity. |
π Limited/developing. |
| Bolivia |
Constitution recognizes privacy and habeas data; sector-specific provisions exist, but no mature comprehensive GDPR-style national data-protection statute. |
π Limited/sectoral. |
| Bosnia and Herzegovina |
New Law on Protection of Personal Data adopted to align more closely with GDPR, replacing the older 2006 framework. |
π’/π‘ Modernizing framework. |
| Botswana |
Data Protection Act 2024, replacing/modernizing the prior framework. |
π‘ Modern comprehensive law; implementation still developing. |
| Brazil |
Lei Geral de ProteΓ§Γ£o de Dados β LGPD, Law 13.709/2018; ANPD regulator. |
π’ Major comprehensive regime. |
| Brunei Darussalam |
Personal Data Protection Order / developing comprehensive privacy framework alongside sectoral rules. |
π‘/π Verify operative provisions and implementing rules for specific processing. |
| Bulgaria |
EU GDPR + Bulgarian Personal Data Protection Act. |
π’ Strict GDPR jurisdiction. |
| Burkina Faso |
Law No.Β 001-2021/AN on protection of persons regarding processing of personal data, building on earlier legislation. |
π‘ Comprehensive framework; security situation and practical enforcement need project-specific assessment. |
| Burundi |
Privacy protections exist through constitutional/electronic-communications and other legislation, but comprehensive and independently enforced data protection remains limited. |
π /π΄ Limited regulatory clarity and enforcement capacity. |
Africa now has data-protection legislation in a large majority of countries, but a recent continent-wide assessment still found meaningful gaps between laws existing on paper and operational independent enforcement authorities.
C
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Cabo Verde |
Law No.Β 133/V/2001 and subsequent amendments concerning personal-data protection; strong Portuguese/EU influence. |
π’/π‘ Substantial framework. |
| Cambodia |
E-Commerce Law and sector-specific protections; comprehensive Personal Data Protection Law has been under development. |
π Draft/developing framework. |
| Cameroon |
Personal-data/cybersecurity and electronic-communications framework has recently been undergoing modernization; historically lacked a mature standalone GDPR-equivalent law. |
π Verify current implementing status before use. |
| Canada |
PIPEDA federally for commercial activities, Privacy Act for federal government, plus major provincial laws including Quebec Law 25; sector-specific legislation. |
π’ Established, sophisticated multi-layered regime. |
| Central African Republic |
No clearly established comprehensive and operational personal-data protection regime comparable to GDPR. |
π΄ Limited legislation/institutional capacity; political/security conditions and practical enforcement unclear. |
| Chad |
Law No.Β 007/PR/2015 on protection of personal data and electronic communications-related rules. |
π‘ Law exists; enforcement maturity limited. |
| Chile |
Law No.Β 19.628 currently applies. Major reform Law No.Β 21.719 introduces a GDPR-style regime and regulator, with full commencement scheduled after its transition period. |
π‘ Transition jurisdiction in 2026 β verify which provisions are in force on project date. |
| China |
Personal Information Protection Law (PIPL), Cybersecurity Law, Data Security Law plus extensive CAC regulations and data-transfer/security-assessment rules. |
π’ Very extensive law, but not an EU-style liberal privacy regime. Strong state-access powers, localization and national-security rules require separate analysis. |
| Colombia |
Law 1581 of 2012, Decree 1074/2015 and related habeas-data legislation. |
π’ Established. |
| Comoros |
No mature, clearly operational comprehensive data-protection regime identified. |
π΄ Limited framework and enforcement capacity. |
| Republic of the Congo |
Law No.Β 29-2019 concerning protection of personal data and related digital legislation. |
π‘ Framework exists; enforcement maturity limited. |
| Costa Rica |
Law No.Β 8968 on Protection of the Person regarding Processing of Personal Data and regulations. |
π’ Established. |
| CΓ΄te dβIvoire |
Law No.Β 2013-450 on Protection of Personal Data. |
π‘ Established statutory framework with ARTCI oversight. |
| Croatia |
EU GDPR + national GDPR Implementation Act. |
π’ Strict GDPR jurisdiction. |
| Cuba |
Constitution and Law No.Β 149/2022 on Protection of Personal Data, together with state information/security rules. |
π΄ Data law exists, but one-party state and limited independent judicial/regulatory oversight create significant human-rights and government-access considerations. |
| Cyprus |
EU GDPR + Law 125(I)/2018. |
π’ Strict GDPR jurisdiction. |
| Czechia |
EU GDPR + Act No.Β 110/2019 on Processing of Personal Data. |
π’ Strict GDPR jurisdiction. |
The GDPR applies directly throughout the EU and via the EEA framework in Norway, Iceland and Liechtenstein, supplemented by national legislation.
D
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Democratic Republic of the Congo |
Law No.Β 20/017 on telecommunications/ICT and Ordinance-Law No.Β 23/010 (Digital Code) contain personal-data protections. |
π‘ Developing framework and enforcement. |
| Denmark |
EU GDPR + Danish Data Protection Act 2018. |
π’ Strict GDPR jurisdiction. |
| Djibouti |
Constitutional, communications and digital rules provide some privacy protections; comprehensive independent data-protection framework remains limited. |
π Limited/developing. |
| Dominica |
Electronic Transactions Act and constitutional privacy protections; no mature comprehensive general Data Protection Act identified. |
π Limited/sectoral. |
| Dominican Republic |
Law No.Β 172-13 on Protection of Personal Data plus constitutional privacy protections. |
π’/π‘ Comprehensive legislation exists. |
E
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Ecuador |
Organic Law on Personal Data Protection (LOPDP), 2021, regulations and Data Protection Authority. |
π’ Modern GDPR-influenced regime. |
| Egypt |
Personal Data Protection Law No.Β 151 of 2020 and implementing framework. |
π‘ Comprehensive statute; national-security exclusions and regulator implementation are important. |
| El Salvador |
Constitution, consumer, telecom and digital legislation; recent privacy reform efforts should be checked for commencement. |
π Developing/fragmented framework. |
| Equatorial Guinea |
Limited sectoral/constitutional protections; no mature independently enforced comprehensive privacy regime. |
π΄ Authoritarian environment, limited legal transparency and independent oversight. |
| Eritrea |
No clearly operational comprehensive data-protection law or independent privacy regulator. |
π΄ Highly restrictive political system; very limited transparency and independent oversight. Legal position for advanced data processing is unclear. |
| Estonia |
EU GDPR + Personal Data Protection Act 2018. |
π’ Strict GDPR jurisdiction. |
| Eswatini |
Data Protection Act 2022 and related communications legislation. |
π‘ Modern framework; implementation/enforcement developing. |
| Ethiopia |
Personal-data provisions appear across the Constitution, Computer Crime Proclamation and newer digital legislation; comprehensive framework has been developing. |
π /π‘ Verify current comprehensive-law status and regulator before deployment. |
F
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Fiji |
Constitution protects privacy; Online Safety, telecommunications and sectoral rules apply; no mature GDPR-equivalent general privacy statute of comparable scope. |
π Sectoral/developing. |
| Finland |
EU GDPR + Data Protection Act 1050/2018. |
π’ Strict GDPR jurisdiction. |
| France |
EU GDPR + Loi Informatique et LibertΓ©s; CNIL regulation. |
π’ Strict and actively enforced privacy jurisdiction. |
G
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Gabon |
Law No.Β 001/2011 on Protection of Personal Data and related digital rules. |
π‘ Comprehensive framework. |
| Gambia |
Data-protection/privacy legislation has been developing alongside the 2009 Information and Communications Act and constitutional protections. |
π Verify current comprehensive-law commencement. |
| Georgia |
Law on Personal Data Protection, substantially modernized in 2023/2024. |
π’/π‘ Strong modern framework. |
| Germany |
EU GDPR + Federal Data Protection Act (BDSG), plus state laws. |
π’ Strict GDPR jurisdiction. |
| Ghana |
Data Protection Act 2012, Act 843. |
π’/π‘ Established law and regulator. |
| Greece |
EU GDPR + Law 4624/2019. |
π’ Strict GDPR jurisdiction. |
| Grenada |
Data Protection Act 2023. |
π‘ Modern law; implementation developing. |
| Guatemala |
Constitution and habeas-data / transparency / sectoral rules; no mature comprehensive GDPR-style private-sector data-protection statute. |
π Fragmented/limited. |
| Guinea |
Law L/2016/037/AN relating to cybersecurity and personal-data protection. |
π‘ Framework exists; enforcement capacity requires assessment. |
| Guinea-Bissau |
Limited comprehensive privacy framework and institutional enforcement. |
π /π΄ Limited regulatory clarity. |
| Guyana |
Data Protection Act 2023. |
π‘ Modern comprehensive legislation; implementation developing. |
Caribbean regimes vary considerably: for example Barbados, Belize, Guyana, Grenada and Jamaica have relatively recent statutes, whereas Dominica, Haiti and some other states still have significant gaps.
H
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Haiti |
Constitutional privacy protections but no established comprehensive general data-protection law and weak regulatory institutions. |
π΄ Severe institutional/political instability; practical legal enforcement and oversight unclear. |
| Honduras |
Constitution, Transparency and Access to Public Information Law and habeas-data principles; comprehensive data-protection legislation remains incomplete/developing. |
π Fragmented framework. |
| Hungary |
EU GDPR + Act CXII of 2011 on Informational Self-Determination and Freedom of Information. |
π’ Strict GDPR jurisdiction. |
I
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Iceland |
GDPR through EEA + Act No.Β 90/2018. |
π’ Strict GDPR/EEA jurisdiction. |
| India |
Digital Personal Data Protection Act 2023 + DPDP Rules 2025, with phased commencement; sectoral laws also apply. |
π‘ Major new regime; implementation is phased and some substantive obligations are not yet fully effective in August 2026. |
| Indonesia |
Personal Data Protection Law No.Β 27/2022; full transition concluded in 2024, plus electronic-systems rules. |
π’/π‘ Comprehensive modern regime; regulator/institutional implementation remains relevant. |
| Iran |
Constitution, Electronic Commerce Law and sectoral/cyber rules; comprehensive personal-data legislation remains fragmented. |
π΄ Authoritarian system, extensive state-security powers and limited independent oversight. Legal treatment of intelligence-related data is particularly sensitive and unclear. |
| Iraq |
Constitutional privacy rights plus telecom/electronic/cybercrime-related provisions; no mature comprehensive general data-protection law. |
π /π΄ Fragmented and uncertain. |
| Ireland |
EU GDPR + Data Protection Act 2018. |
π’ Strict GDPR jurisdiction; major technology regulator. |
| Israel |
Protection of Privacy Law 5741-1981, Privacy Protection Regulations and major Amendment 13 effective 2025. |
π’ Established, extensively modernized framework. |
| Italy |
EU GDPR + Legislative Decree 196/2003 as amended (Privacy Code). |
π’ Strict GDPR jurisdiction. |
Indiaβs 2023 DPDP Act and 2025 Rules are being brought into force on a phased basis, so a 2026 project needs to determine which provisions have actually commenced on the relevant date.
J
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Jamaica |
Data Protection Act 2020, with staged implementation and Office of the Information Commissioner. |
π‘ Comprehensive framework; confirm provisions currently in force. |
| Japan |
Act on Protection of Personal Information (APPI), extensively amended; Personal Information Protection Commission. |
π’ Mature comprehensive framework; EU adequacy. |
| Jordan |
Personal Data Protection Law No.Β 24 of 2023, effective 2024, plus implementing framework. |
π‘ Modern comprehensive law; implementation developing. |
K
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Kazakhstan |
Law on Personal Data and Their Protection (2013), with significant data-localization and information-security rules. |
π‘ Comprehensive statutory framework; state-access issues require separate review. |
| Kenya |
Data Protection Act 2019 + Data Protection Regulations 2021; Office of Data Protection Commissioner. |
π’/π‘ Modern and increasingly enforced regime. |
| Kiribati |
Constitutional and communications protections; no mature comprehensive general data-protection statute. |
π Limited framework. |
| Kuwait |
Communications and Information Technology Regulatory Authority Decision No.Β 42/2021 Data Privacy Protection Regulation, plus sectoral rules. |
π‘ Substantial but largely telecom/digital-services-based rather than one universal GDPR-equivalent statute. |
| Kyrgyzstan |
Law on Personal Information and newer Personal Data Protection framework; regulator-related reforms continue. |
π‘ Comprehensive principles exist; implementation/environment require verification. |
L
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Laos |
Law on Electronic Data Protection 2017, Electronic Transactions Law and cybersecurity rules. |
π‘ Framework exists. Government access and institutional independence need separate review. |
| Latvia |
EU GDPR + Personal Data Processing Law. |
π’ Strict GDPR jurisdiction. |
| Lebanon |
Law No.Β 81/2018 on Electronic Transactions and Personal Data, plus constitutional protections. |
π‘ Statutory protections exist; institutional/political circumstances affect enforcement. |
| Lesotho |
Data Protection Act 2011. |
π‘ Comprehensive law but enforcement capacity limited. |
| Liberia |
Constitution and sectoral/electronic-transaction rules; no mature operational comprehensive data-protection framework. |
π Limited/developing. |
| Libya |
Constitutional/declaration and telecom/cyber rules; no stable comprehensive independently enforced personal-data regime. |
π΄ Political fragmentation and limited regulatory certainty. Project-specific legal position unclear. |
| Liechtenstein |
GDPR through EEA + Data Protection Act 2018. |
π’ Strict GDPR/EEA jurisdiction. |
| Lithuania |
EU GDPR + Law on Legal Protection of Personal Data. |
π’ Strict GDPR jurisdiction. |
| Luxembourg |
EU GDPR + Law of 1 August 2018. |
π’ Strict GDPR jurisdiction. |
M
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Madagascar |
Law No.Β 2014-038 on Protection of Personal Data. |
π‘ Comprehensive law; enforcement maturity developing. |
| Malawi |
Data Protection Act 2024. |
π‘ Modern new framework; implementation developing. |
| Malaysia |
Personal Data Protection Act 2010, significantly amended by the Personal Data Protection (Amendment) Act 2024 and implementing rules. |
π’/π‘ Mature commercial privacy regime; notably different treatment of government processing. |
| Maldives |
Constitution and sectoral/electronic rules; comprehensive personal-data protection remains developing. |
π Limited/developing. |
| Mali |
Law No.Β 2013-015 on Protection of Personal Data; data-protection authority. |
π‘ Law exists. Political/military governance and security conditions require additional rule-of-law assessment. |
| Malta |
EU GDPR + Data Protection Act, Cap. 586. |
π’ Strict GDPR jurisdiction. |
| Marshall Islands |
Constitutional/sectoral privacy protections; no mature comprehensive national GDPR-style law. |
π Limited. |
| Mauritania |
Law No.Β 2017-020 on protection of personal data. |
π‘ Comprehensive statutory framework. |
| Mauritius |
Data Protection Act 2017, GDPR-influenced, with Data Protection Office. |
π’ Established. |
| Mexico |
Federal Law on Protection of Personal Data Held by Private Parties (modernized/reissued in 2025) plus separate public-sector data rules and state legislation. |
π’ Comprehensive but institutionally changed following 2024β25 reforms; verify competent authority. |
| Micronesia, Federated States of |
Constitutional privacy rights and sector-specific rules; no broad GDPR-equivalent statute. |
π Limited. |
| Moldova |
Law No.Β 133/2011 on Personal Data Protection; new GDPR-aligned legislation/reforms connected with EU accession. |
π‘/π’ Transitioning toward GDPR model. |
| Monaco |
Law No.Β 1.565 of 3 December 2024 on protection of personal data, replacing older framework and aligning more closely with GDPR/Convention 108+. |
π’ Modern framework. |
| Mongolia |
Law on Protection of Personal Information, effective 2022, plus cybersecurity/e-signature laws. |
π‘ Modern comprehensive framework. |
| Montenegro |
Law on Personal Data Protection; Convention 108 and EU-alignment reforms. |
π‘/π’ Substantial GDPR-oriented framework. |
| Morocco |
Law No.Β 09-08 on Protection of Individuals with regard to Processing of Personal Data; CNDP regulator. |
π’/π‘ Established. |
| Mozambique |
Constitution, Electronic Transactions Law, telecom and sectoral protections; no mature comprehensive standalone personal-data statute. |
π Fragmented/developing. |
| Myanmar |
Privacy and Electronic Transactions/cybersecurity legislation, but protections have been heavily altered/suspended following the military takeover. |
π΄ Military regime; weak independent oversight and substantial state-surveillance powers. Practical privacy protection highly uncertain. |
APAC contains mature frameworks such as Japanβs APPI, South Koreaβs PIPA, Singaporeβs PDPA and Australiaβs Privacy Act, alongside newer regimes in India, Indonesia and Vietnam and countries where comprehensive statutes remain under development.
N
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Namibia |
Constitution protects privacy; sectoral legislation applies; comprehensive Data Protection Bill has been under development. |
π No fully mature comprehensive statute yet; verify latest legislative status. |
| Nauru |
Constitutional and cybercrime/communications protections; no mature comprehensive privacy statute. |
π Limited framework. |
| Nepal |
Privacy Act 2018, Privacy Regulations and constitutional right to privacy. |
π‘ Comprehensive privacy law, though regulatory model differs from GDPR. |
| Netherlands |
EU GDPR + GDPR Implementation Act (UAVG). |
π’ Strict GDPR jurisdiction. |
| New Zealand |
Privacy Act 2020 and Privacy Principles; Privacy Commissioner. |
π’ Mature comprehensive regime; EU adequacy. |
| Nicaragua |
Law No.Β 787 on Protection of Personal Data (2012) plus constitutional habeas-data rights. |
π΄/π‘ Formal comprehensive law exists, but deterioration in democratic institutions and regulator/judicial independence creates elevated rule-of-law concerns. |
| Niger |
Law No.Β 2017-28 on Protection of Personal Data, as amended. |
π‘ Law exists. Current military-led political environment requires additional human-rights and oversight review. |
| Nigeria |
Nigeria Data Protection Act 2023, administered by Nigeria Data Protection Commission. |
π’/π‘ Major modern comprehensive regime. |
| North Korea |
Domestic information, cybersecurity and state-secrecy rules exist, but there is no transparent, independently enforceable personal-data protection regime comparable to international democratic privacy frameworks. |
π΄ Authoritarian one-party state; extremely limited transparency, no meaningful independent privacy oversight. Treat legal permissibility as fundamentally unclear. |
| North Macedonia |
Law on Personal Data Protection 2020, closely GDPR-aligned. |
π’/π‘ Strong modern framework. |
| Norway |
GDPR through EEA + Personal Data Act. |
π’ Strict GDPR/EEA jurisdiction. |
O
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Oman |
Personal Data Protection Law, Royal Decree 6/2022, plus Executive Regulations. |
π’/π‘ Modern comprehensive Gulf framework. |
P
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Pakistan |
Constitution, Prevention of Electronic Crimes Act and sectoral rules; Personal Data Protection Bill has undergone repeated revisions but comprehensive final framework has remained in development. |
π Verify current legislative enactment immediately before project. |
| Palau |
Constitutional privacy protections and sectoral rules; no mature comprehensive GDPR-style statute. |
π Limited. |
| Palestine |
Basic Law provides privacy protections; Electronic Transactions/Cybercrime and sectoral laws apply, but no mature independent comprehensive data-protection system comparable to GDPR. |
π Legal jurisdiction can also depend on territory and authority; practical enforcement complicated by conflict and divided governance. |
| Panama |
Law No.Β 81 of 2019 on Personal Data Protection + Executive Decree 285/2021. |
π’ Comprehensive modern framework. |
| Papua New Guinea |
Constitution and Cybercrime Code/sectoral legislation; comprehensive personal-data statute remains limited. |
π Limited/developing. |
| Paraguay |
Constitution, Law 1682/2001 and Law 6534/2020 regarding credit/personal data; comprehensive modern data-protection reforms have been under legislative development. |
π Sectoral/transition framework; verify recent enactments. |
| Peru |
Personal Data Protection Law No.Β 29733 and updated regulations. |
π’ Established comprehensive framework. |
| Philippines |
Data Privacy Act of 2012, RA 10173; National Privacy Commission. |
π’ Mature comprehensive regime. |
| Poland |
EU GDPR + Act of 10 May 2018 on Protection of Personal Data. |
π’ Strict GDPR jurisdiction. |
| Portugal |
EU GDPR + Law No.Β 58/2019. |
π’ Strict GDPR jurisdiction. |
Q
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Qatar |
Law No.Β 13 of 2016 concerning Personal Data Privacy Protection; separate QFC data-protection regime. |
π’/π‘ Comprehensive framework with jurisdiction-specific layers. |
R
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Romania |
EU GDPR + Law No.Β 190/2018. |
π’ Strict GDPR jurisdiction. |
| Russia |
Federal Law No.Β 152-FZ on Personal Data, data-localization requirements and extensive communications/security legislation. |
π΄ Extensive formal privacy law exists, but strong state-access/security powers, localization requirements and current rule-of-law/geopolitical conditions require heightened legal and ethical scrutiny. |
| Rwanda |
Law No.Β 058/2021 relating to Protection of Personal Data and Privacy. |
π’/π‘ Modern comprehensive framework. |
S
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Saint Kitts and Nevis |
Data Protection Act 2018. |
π‘ Comprehensive law; regulator/institutional implementation has historically lagged. |
| Saint Lucia |
Data Protection Act 2011. |
π‘ Comprehensive older framework. |
| Saint Vincent and the Grenadines |
Privacy Act 2003. |
π‘ Established but older statutory framework. |
| Samoa |
Constitutional privacy protections and sectoral/digital rules; no mature GDPR-equivalent comprehensive law. |
π Limited. |
| San Marino |
Law No.Β 171/2018 on protection of natural persons with regard to processing personal data, GDPR-oriented. |
π’ Modern framework. |
| SΓ£o TomΓ© and PrΓncipe |
Law No.Β 03/2016 on Protection of Personal Data. |
π‘ Comprehensive framework; smaller enforcement environment. |
| Saudi Arabia |
Personal Data Protection Law (PDPL), Royal Decree M/19, as amended, fully enforceable after transition; SDAIA regulations. |
π’/π‘ Strong modern statutory regime; government/national-security processing requires separate analysis. |
| Senegal |
Law No.Β 2008-12 on Protection of Personal Data; CDP regulator. |
π‘ Established comprehensive framework. |
| Serbia |
Law on Personal Data Protection 2018, substantially GDPR-aligned. |
π’/π‘ Strong framework. |
| Seychelles |
Data Protection Act 2023 / modernized framework replacing older legislation. |
π‘ Newer comprehensive regime; implementation developing. |
| Sierra Leone |
Constitution and cyber/communications rules; comprehensive data-protection legislation has been developing. |
π Limited/developing. |
| Singapore |
Personal Data Protection Act 2012, substantially amended; Personal Data Protection Commission. |
π’ Mature comprehensive commercial privacy framework. |
| Slovakia |
EU GDPR + Act No.Β 18/2018. |
π’ Strict GDPR jurisdiction. |
| Slovenia |
EU GDPR + Personal Data Protection Act ZVOP-2. |
π’ Strict GDPR jurisdiction. |
| Solomon Islands |
Constitutional and sectoral protections; no mature comprehensive general data-protection law. |
π Limited. |
| Somalia |
Constitution and communications/data legislation provide some protections; institutional and comprehensive privacy enforcement remains developing. |
π΄/π Weak/fragmented institutions and security conditions make practical legal position difficult to assess. |
| South Africa |
Protection of Personal Information Act 4 of 2013 (POPIA), fully effective 2021; Information Regulator. |
π’ Major comprehensive regime. |
| South Korea |
Personal Information Protection Act (PIPA), related network/credit laws and PIPC regulation. |
π’ One of the worldβs strongest comprehensive privacy frameworks; EU adequacy. |
| South Sudan |
Transitional Constitution and sectoral telecom/cyber rules; no mature comprehensive data-protection regime. |
π΄ Limited legal/institutional capacity and unstable political/security environment. |
| Spain |
EU GDPR + Organic Law 3/2018 (LOPDGDD). |
π’ Strict GDPR jurisdiction. |
| Sri Lanka |
Personal Data Protection Act No.Β 9 of 2022, amended and implemented in stages. |
π‘ Modern comprehensive framework; verify commencement of specific provisions. |
| Sudan |
Cybercrime/electronic transactions and constitutional/transitional protections; comprehensive independent privacy regime is not reliably operational. |
π΄ Ongoing conflict, competing authorities and institutional collapse make legal application highly uncertain. |
| Suriname |
Constitutional protections; draft Privacy and Personal Data Protection legislation has existed, but comprehensive enacted framework remains limited. |
π Draft/developing. |
| Sweden |
EU GDPR + Swedish Data Protection Act. |
π’ Strict GDPR jurisdiction. |
| Switzerland |
Revised Federal Act on Data Protection (nFADP), effective September 2023. |
π’ Mature comprehensive framework; EU adequacy. |
| Syria |
Cybercrime, communications and constitutional/state-security laws; comprehensive independently enforced personal-data protection remains unclear during continuing political transition. |
π΄ Political/legal transition and limited independent regulatory transparency. Project-specific law must be verified against the authority controlling the relevant territory. |
T
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Tajikistan |
Law on Personal Data Protection (2018) and information/security legislation. |
π‘ Formal framework exists; government-access and institutional independence require assessment. |
| Tanzania |
Personal Data Protection Act 2022 + 2023 regulations; Personal Data Protection Commission. |
π’/π‘ Modern comprehensive regime. |
| Thailand |
Personal Data Protection Act B.E. 2562 (2019), fully operational from 2022; PDPC. |
π’ Comprehensive GDPR-influenced regime. |
| Timor-Leste |
Constitution strongly protects privacy; sector-specific legislation exists, but no mature comprehensive GDPR-equivalent personal-data law. |
π Limited/developing. |
| Togo |
Law No.Β 2019-014 on Protection of Personal Data. |
π‘ Comprehensive framework. |
| Tonga |
Constitutional/common-law and communications protections; no mature comprehensive GDPR-style statute. |
π Limited. |
| Trinidad and Tobago |
Data Protection Act 2011, with only parts historically proclaimed/in force. |
π /π‘ Comprehensive statute exists but commencement status of individual provisions must be checked. |
| Tunisia |
Organic Law No.Β 2004-63 on Protection of Personal Data; constitutional protections and planned modernization. |
π‘ Established but older framework; political/institutional developments warrant careful review. |
| TΓΌrkiye |
Law No.Β 6698 on Protection of Personal Data (KVKK), substantially amended in 2024 particularly regarding processing and transfers. |
π’/π‘ Comprehensive established regime. |
| Turkmenistan |
Law on Information about Private Life and its Protection and other information laws provide formal protections. |
π΄ Highly authoritarian state, limited transparency and independent judicial/regulatory oversight; practical privacy-law constraints on state activity are unclear. |
| Tuvalu |
Constitutional privacy protections and sectoral communications laws; no mature comprehensive general data-protection statute. |
π Limited. |
U
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Uganda |
Data Protection and Privacy Act 2019 + Data Protection and Privacy Regulations 2021. |
π’/π‘ Comprehensive framework. |
| Ukraine |
Law No.Β 2297-VI on Protection of Personal Data; Convention 108; GDPR-alignment reforms connected to EU accession. Wartime measures can affect normal rights and state processing. |
π‘ Strong statutory basis but wartime/emergency rules require separate analysis. |
| United Arab Emirates |
Federal Decree-Law No.Β 45 of 2021 on Protection of Personal Data; separate DIFC and ADGM privacy regimes; sectoral health/telecom laws. |
π’/π‘ Sophisticated multi-layered regime. |
| United Kingdom |
UK GDPR + Data Protection Act 2018, as modified by the Data (Use and Access) Act 2025 and related regulations. |
π’ Mature, actively enforced comprehensive regime. |
| United States |
No single comprehensive federal GDPR equivalent. Federal sectoral laws include HIPAA, GLBA, COPPA, FCRA, ECPA/SCA, etc.; extensive state privacy laws including California CCPA/CPRA and laws in many other states. |
π’/π‘ Highly developed but fragmented. State, sector and government/intelligence rules must be assessed separately. |
| Uruguay |
Law No.Β 18.331 on Protection of Personal Data and Habeas Data, amended to align further with GDPR. |
π’ Mature comprehensive framework; EU adequacy. |
| Uzbekistan |
Law No.Β ZRU-547 on Personal Data (2019), with localization and related information-security rules. |
π‘ Comprehensive statutory framework; state-access and enforcement-independence questions require review. |
The United States remains unusual among large economies because it has no single federal GDPR-equivalent privacy statute; federal sectoral laws operate alongside a rapidly expanding collection of state comprehensive privacy statutes.
V
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Vanuatu |
Constitution and sectoral/cyber/communications provisions; no mature comprehensive general personal-data law. |
π Limited. |
| Vatican City / Holy See |
Internal Vatican legislation protects confidentiality and certain information, with GDPR-relevant arrangements affecting Vatican entities operating in Europe, but no general national GDPR-equivalent framework comparable to EU states. |
π Special sovereign/legal system; project-specific review essential. |
| Venezuela |
Constitution recognizes privacy, honor and habeas-data rights; sectoral banking, telecom, cyber and access-to-information rules apply, but no mature comprehensive GDPR-style personal-data statute. |
π΄/π Fragmented law plus serious institutional/rule-of-law concerns; government access and practical remedies require heightened assessment. |
| Vietnam |
Decree 13/2023 on Personal Data Protection, Data Law 2024 and newer comprehensive Personal Data Protection legislation/reforms, with cybersecurity/localization requirements. |
π’/π‘ Strong and rapidly evolving framework; substantial state-security and cross-border requirements. |
Vietnam, Indonesia, Thailand, Malaysia, Singapore and the Philippines all now have significant data-protection regimes, but their legal bases, transfer mechanisms and government exemptions differ materially.
Y
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Yemen |
Constitution and electronic/telecom/criminal protections exist, but no stable comprehensive operational data-protection framework across the fragmented authorities. |
π΄ Ongoing conflict and divided governance make applicable law and enforcement highly uncertain. |
Z
| Country |
Principal privacy / data framework |
CONNECTX practical status |
| Zambia |
Data Protection Act No.Β 3 of 2021; Office of Data Protection Commissioner. |
π’/π‘ Modern comprehensive regime. |
| Zimbabwe |
Cyber and Data Protection Act 2021, amending several statutes and establishing data-protection requirements. |
π‘ Comprehensive statutory rules exist; regulator independence/government-access questions require separate assessment. |