International Data Privacy Laws
Global data protection regulations and privacy standards worldwide
Global Data Privacy Protection & Regulations
Data privacy is a fundamental human right recognized worldwide. From Europe's groundbreaking GDPR to comprehensive laws in Asia, Africa, and the Americas, countries around the globe are establishing strong protections for personal data. This page provides links to major international privacy laws and regulations.
Last updated: March 21, 2026
GDPR: General Data Protection Regulation
The world's strongest and most influential privacy law
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive privacy law that came into effect on May 25, 2018, across all EU member states. It sets the gold standard for data protection and has influenced privacy legislation worldwide.
Strong Consumer Rights
Access, rectification, erasure, portability, and right to object
Heavy Penalties
Up to โฌ20 million or 4% of global annual revenue, whichever is higher
Extraterritorial Reach
Applies to any organization processing EU residents' data
Accountability
Data Protection Impact Assessments (DPIAs) and mandatory breach notification
International Standards & Technical Implementation
Engineering clinical data pipelines for global interoperability and multi-jurisdictional compliance.
GDPR (EU/UK)
The Technical Challenge: Right to be Forgotten & Portability
GDPR is the gold standard for privacy. For health-tech, the biggest hurdle is ensuring "Special Category Data" (Health Data) is treated with enhanced protections.
- Art. 17 (Right to Erasure): Technical workflows for purging records across distributed systems.
- Art. 20 (Data Portability): Leveraging FHIR to meet machine-readable export requirements.
- Standard Contractual Clauses (SCCs): Managing technical controls for EU-to-US transfers.
Global Interoperability Frameworks
IPS (International Patient Summary)
The IPS is a specialized FHIR Implementation Guide designed for cross-border care. It is essential for apps serving international travelers or global workforces.
- Validating IPS terminology sets (SNOMED CT, LOINC).
- Mapping regional datasets to the IPS core library.
European Privacy Laws
Country-by-country data protection regulations across Europe
๐ช๐บ European Union Member States
All 27 EU member states are bound by GDPR, with additional national implementations:
๐ช๐บ All EU Member States (27 Countries)
GDPREffective: May 25, 2018
Applies to: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden
View GDPR Portal โ๐ฌ๐ง United Kingdom
UK GDPREffective: January 1, 2021 (Post-Brexit)
The UK's version of GDPR after Brexit, substantially similar to EU GDPR with some UK-specific modifications.
View ICO GDPR Guide โEffective: May 25, 2018
UK's implementation of GDPR, supplementing and tailoring UK GDPR provisions.
View DPA 2018 โ๐จ๐ญ Switzerland
EnactedEffective: September 1, 2023
Revised Swiss data protection law, aligned with GDPR standards while maintaining Swiss sovereignty.
View Swiss FADP โ๐ณ๐ด Norway
GDPR (EEA)Effective: May 25, 2018
Norway adopted GDPR through the European Economic Area (EEA) agreement, with national implementation.
View Norwegian DPA โ๐ฎ๐ธ Iceland
GDPR (EEA)Effective: May 25, 2018
Iceland implemented GDPR through the EEA agreement with national data protection authority.
View Icelandic DPA โ๐ฑ๐ฎ Liechtenstein
GDPR (EEA)Effective: May 25, 2018
Liechtenstein applies GDPR through its EEA membership.
View Liechtenstein DPA โ๐ Americas
๐จ๐ฆ Canada
EnactedEffective: January 1, 2001 (Amendments ongoing)
Federal law governing private sector organizations' collection, use, and disclosure of personal information.
View PIPEDA โEffective: September 22, 2023 (Phased)
Quebec's comprehensive privacy modernization, considered Canada's GDPR-equivalent.
View Quebec Law 25 โ๐ง๐ท Brazil
EnactedEffective: September 18, 2020
Comprehensive data protection law modeled after GDPR, covering all personal data processing in Brazil.
View ANPD (Brazilian DPA) โ LGPD English Guide โ๐ฆ๐ท Argentina
EnactedEffective: November 2, 2000
Recognized by EU as providing adequate protection for data transfers from Europe.
View Argentine DPA โ๐ฒ๐ฝ Mexico
EnactedEffective: July 6, 2010
Comprehensive privacy law for private sector data processing in Mexico.
View INAI (Mexican DPA) โ๐จ๐ฑ Chile
EnactedEffective: August 28, 1999 (Amendments ongoing)
Chilean data protection law with ongoing modernization efforts.
View Chilean Law โ๐จ๐ด Colombia
EnactedEffective: October 17, 2012
Comprehensive data protection law governing personal data processing in Colombia.
View Colombian Superintendence โ๐ Asia-Pacific
๐ฏ๐ต Japan
EnactedEffective: May 30, 2005 (Amended 2022)
Japan's comprehensive privacy law, recognized by EU for adequacy. 2022 amendments strengthen protection.
View PPC (Japanese DPA) โ๐ฐ๐ท South Korea
EnactedEffective: September 30, 2011 (Amended 2020)
Comprehensive data protection law with strong enforcement and data breach notification requirements.
View PIPC (Korean DPA) โ๐จ๐ณ China
EnactedEffective: November 1, 2021
China's comprehensive privacy law, modeled partially on GDPR with Chinese characteristics.
View CAC (Chinese Authority) โ๐ธ๐ฌ Singapore
EnactedEffective: July 2, 2014 (Amended 2021)
Comprehensive data protection law governing private sector, with mandatory breach notification.
View PDPC (Singapore) โ๐ฆ๐บ Australia
EnactedEffective: December 21, 1988 (Amended 2022)
Federal privacy law with 13 Australian Privacy Principles (APPs) and mandatory data breach notification.
View OAIC (Australian IC) โ๐ณ๐ฟ New Zealand
EnactedEffective: December 1, 2020
Modernized privacy law with 13 privacy principles and mandatory breach notification.
View NZ Privacy Commissioner โ๐ฎ๐ณ India
EnactedEnacted August 11, 2023; phased implementation through May 2027
India's comprehensive data protection law establishing rights and obligations for digital personal data.
View Indian DPDPA โ๐ต๐ญ Philippines
EnactedEffective: September 8, 2012
Comprehensive privacy law protecting personal data in government and private sector.
View NPC (Philippines) โ๐น๐ญ Thailand
EnactedEffective: June 1, 2022
GDPR-inspired comprehensive privacy law for Thailand.
View Thai PDPC โ๐ Middle East & Africa
๐ฟ๐ฆ South Africa
EnactedEffective: July 1, 2021
Comprehensive data protection law aligned with international standards including GDPR principles.
View IRSA (South African Regulator) โ๐ฎ๐ฑ Israel
EnactedEffective: 1981 (Amendments 2023)
Recognized by EU for adequacy, with ongoing modernization to align with GDPR.
View Israeli PPA โ๐ฆ๐ช UAE (Dubai)
EnactedEffective: January 2, 2022
Federal data protection law for UAE with GDPR-inspired provisions.
View UAE Data Office โEffective: 2016
Dubai International Financial Centre (DIFC) specific data protection law.
View DIFC โ๐ฐ๐ช Kenya
EnactedEffective: November 25, 2019
Comprehensive data protection law establishing data protection authority and consumer rights.
View ODPC (Kenya) โ๐ณ๐ฌ Nigeria
EnactedEffective: January 25, 2019
Comprehensive data protection regulation administered by NITDA.
View NITDA (Nigeria) โInternational Privacy Frameworks & Standards
Cross-border data transfer mechanisms and global privacy standards
APEC CBPR System
Asia-Pacific Economic Cooperation Cross-Border Privacy Rules
Voluntary framework for privacy protection across APEC economies, facilitating data flows.
Visit CBPR โOECD Privacy Guidelines
Organisation for Economic Co-operation and Development
International standards for privacy protection and transborder data flows since 1980.
Visit OECD Guidelines โEU-US Data Privacy Framework
Trans-Atlantic Data Transfers
Framework replacing Privacy Shield for EU-US data transfers (2023).
Visit Framework โISO 27701
Privacy Information Management
International standard for privacy information management systems.
Visit ISO โCouncil of Europe Convention 108+
European Convention for Data Protection
First legally binding international instrument on data protection, modernized in 2018.
Visit CoE โAfrican Union Data Protection Convention
Malabo Convention
Pan-African framework for data protection and privacy (2014).
Visit AU Convention โYour Data Health: Global Privacy Compliance
Your Data Health is committed to meeting the highest international privacy standards, wherever our members are located:
GDPR Compliant
Our platform meets all GDPR requirements including consent management, data portability, right to erasure, and breach notification.
International Standards
Your Data Health follows ISO 27701 for privacy management and implement privacy-by-design principles from GDPR and global best practices.
Cross-Border Transfers
Your Data Health uses approved mechanisms for international data transfers including Standard Contractual Clauses (SCCs) and adequacy decisions.
Local Compliance
Where members reside in countries with specific privacy laws, Your Data Health ensures compliance with local requirements.
Questions About International Privacy Compliance?
Your Data Health is here to help explain how Your Data Health protects your data under international law.
Ready to Take Control?
Enterprise compliance auditing for FHIR, MHMDA, and global privacy standards.
Audit My Pipelines