Explainer 21 min read 8 September 2026

Global Data Privacy Laws Compared: GDPR, DPDP, CCPA, LGPD, PIPL and the Rest

Every major privacy law side by side — GDPR, India’s DPDP, CCPA, LGPD, PIPL, APPI and more. Scope, consent, breach clocks, transfers and penalties.

If you sell software across borders, the question is never "which privacy law applies to us". It is "which seven, and where do they disagree?" This guide puts the major regimes side by side: what triggers each one, what lawful basis it expects, how fast it wants a breach reported, what it says about moving data across borders, and what it can fine you. The differences that matter are not in the principles, which are broadly similar everywhere. They are in the defaults, the deadlines, and the thresholds.

All commencement dates, framework versions and thresholds on this page are stated as of September 2026. These regimes are amended frequently; verify against the official texts linked at the bottom before relying on any figure.

The Short Version

Three things decide almost every question in this area.

The rules of thumb
  • Your users' location decides the law, not your office. Every major regime now reaches across borders. Incorporating in Delaware or Singapore changes nothing if people in Mumbai, Munich or São Paulo can sign up.
  • The principles agree; the defaults do not. Everyone wants notice, security, and rights over data. They disagree on whether silence means yes, how fast you must report a breach, and whether data may leave the country.
  • Build to the strictest, vary by region. One baseline that satisfies the toughest rule on each dimension, with per-region variations for the places that genuinely conflict. Running one programme per country does not scale past about three countries.

The two dimensions that break naive global designs are consent defaults and breach clocks. Get those wrong and no amount of policy documentation saves you.

The Master Comparison

Twelve regimes, the five things you need per regime. Detail on each follows.

RegimeWhat triggers itLawful basis modelBreach clockCross-border rulePenalty ceiling
EU GDPRUsers in the EEA; or monitoring their behaviourSix bases incl. legitimate interests72 hours to the DPAAdequacy, SCCs + TIA, or BCRs€20m or 4% of global turnover
UK GDPRUsers in the UKSix bases, as EU72 hours to the ICOUK adequacy, IDTA or UK Addendum£17.5m or 4% of global turnover
India DPDP 2023Users in India; offering goods or services to themConsent + narrow legitimate uses (s.7)Board: without delay, particulars in 72hNegative list — open unless restricted₹250 crore per violation category
India CERT-InAny ICT system in Indian/a — a security directive6 hoursLogs must be kept in IndiaUp to 1 year imprisonment or fine
California CCPA/CPRACalifornian consumers, above thresholdsNotice + opt-out of sale/sharingNo fixed statutory clockNo transfer restrictionPer-violation civil penalties
US HIPAAUS covered entities and their business associatesTreatment, payment, operations60 days to individualsNo geographic restriction; BAA governsTiered CMPs; criminal exposure
US COPPAServices directed to US under-13sVerifiable parental consentNo fixed statutory clockNo transfer restrictionPer-violation FTC penalties
Brazil LGPDUsers in Brazil; data collected in BrazilTen bases incl. credit protection3 business days to ANPDAdequacy, SCCs, BCRs2% of Brazil turnover, capped BRL 50m
China PIPLUsers in China; certain overseas processingSeparate consent per purposePrompt notification to the CACVolume-metered: assessment / SCC / exemptRMB 50m or 5% of turnover
Saudi PDPLResidents of the KingdomConsent + alternative bases72 hours to SDAIAAdequacy, SCCs, BCRs + risk assessmentSAR 5m; doubled for repeat
Canada PIPEDA / Quebec Law 25Commercial activity in Canada / QuebecMeaningful consentPIPEDA: as soon as feasible · Quebec: promptly, if serious injuryAccountability follows the dataQuebec: CAD 25m or 4% of turnover
Japan APPIHandling personal information of people in JapanNotified purpose of usePreliminary ~3–5 days; final 30 daysConsent, equivalence, or safeguardsUp to ¥100m for businesses

Two rows deserve a second look. CERT-In's six hours is the fastest clock anywhere on this page and catches every company running systems in India, whether or not it thinks of itself as a data business. And India's ₹250 crore is a fixed ceiling rather than a percentage, which makes it comparatively mild for a multinational and severe for a mid-sized company.

What Actually Decides Whether a Law Applies to You

Almost every regime on this page reaches beyond its own borders, and they nearly all use the same trigger: are you offering something to people here?

The test, regime by regime
  • GDPR: offering goods or services to people in the EEA, or monitoring their behaviour. The monitoring limb is the broadest trigger in the world; analytics on EEA visitors can be enough.
  • India DPDP: offering goods or services to people in India. Note there is no monitoring limb, so India is narrower than the GDPR here.
  • Brazil LGPD: offering to people in Brazil, or processing data collected in Brazil.
  • China PIPL: providing products or services to people in China, or analysing their behaviour.
  • California CCPA is the outlier: it applies only above revenue or data-volume thresholds, so a small company can serve Californians and stay outside it.
What this means for a SaaS product
  • A 12-person analytics startup in Bengaluru with a self-serve signup and no sales team is subject to the DPDP Act, the GDPR (if any EEA user signs up), and the LGPD (if any Brazilian does). Nobody had to sign a contract for those to attach.
  • The same startup is probably not subject to CCPA, because it will not cross California's thresholds for years. Building a "Do Not Sell" flow before then is wasted engineering.
  • A free tier counts. Under the GDPR the trigger is explicitly irrespective of payment, and the DPDP Act has no payment element in its test at all.

Consent: Three Incompatible Defaults

This is where a single global consent screen falls apart. The regimes do not merely differ in wording; they start from opposite defaults.

ModelWhereWhat it means in the product
Opt-in by defaultEU/UK, India, Brazil, Saudi ArabiaSilence means no. Nothing pre-ticked. You need an affirmative action before processing on a consent basis.
Opt-out for sale/sharingCalifornia and most US statesYou may proceed until told to stop, but you must offer a clear, working "Do Not Sell or Share" path.
Separate consent per purposeChinaOne consent does not cover several purposes. Cross-border transfer, sensitive data and third-party sharing each need their own.

The GDPR softens its own opt-in default with the legitimate-interests basis, which carries a great deal of ordinary marketing and analytics. India's DPDP Act has no equivalent: Section 7 lists a narrow set of legitimate uses and nothing resembling a general balancing test. This is the single most common failure when a European programme is copied into India: processing that was lawfully based on legitimate interests in Frankfurt needs actual consent in Chennai.

The mistake this causes
  • A European SaaS company launches in India and reuses its existing privacy notice. Its product-update emails ran on legitimate interests in the EU. In India those same emails need consent, and the notice never asked for it.
  • An Indian company expands to China and keeps its single "I agree to the privacy policy" checkbox. Under PIPL that one checkbox cannot carry transfer, sensitive data and third-party sharing at once.
  • The fix in both directions is the same: keep the lawful basis as a per-region setting attached to each processing purpose, not a global constant.

Breach Clocks: Six Hours to Sixty Days

This is the hardest dimension to run globally, because the spread is enormous and the clocks start at different moments.

DeadlineRegimeTo whom
6 hoursIndia CERT-In directionsCERT-In
72 hoursEU/UK GDPRSupervisory authority
72 hoursIndia DPDP (Rule 7 particulars)Data Protection Board
72 hoursSaudi PDPLSDAIA
3 business daysBrazil LGPDANPD and affected individuals
~3–5 days, then 30Japan APPIPPC — preliminary, then final report
30 days to assessAustralia NDB schemeOAIC, then notify as soon as practicable
60 daysUS HIPAAAffected individuals
“Promptly”Quebec Law 25CAI, where there is a risk of serious injury

Quebec is worth singling out because it is the one row with no number in it. The statute says “promptly” and sets no fixed deadline, and the obligation is triggered only where the incident presents a risk of serious injury — lesser incidents go in an internal register rather than to the regulator. You will see 72 hours quoted widely for Quebec; that is a planning benchmark practitioners borrowed from the GDPR, not the law. Building a runbook on it is safe. Telling your board it is the statutory deadline is not.

One incident, several clocks running at once
  • A SaaS company with users in India, Germany and Brazil, plus a US healthcare client, discovers a breach at 9pm on Friday. Four clocks start simultaneously: CERT-In at six hours, the German DPA and the Indian Board at 72, and Brazil's ANPD at three business days, while HIPAA's 60-day outer limit sits far behind them.
  • The instinct to wait for the forensics to finish and then notify everyone at once satisfies HIPAA and breaches everything above it.
  • The working design separates the two jobs: notify early with what is known, keep investigating afterwards. No regulator expects a complete forensic picture in six hours. They expect to have been told.

Cross-Border Transfers: Three Philosophies

How a regime treats data leaving the country tells you most of what you need to know about its politics.

Permission-based (EU, UK, Brazil, Saudi Arabia)

Transfer is allowed when a recognised safeguard is in place: an adequacy decision covering the destination, standard contractual clauses paired with a transfer impact assessment, or binding corporate rules within a group. The burden is on you to hold the paperwork.

Volume-metered (China)

China is the only major regime that meters exports by volume. Under the March 2024 CAC provisions, counted from 1 January each year: exporting sensitive personal information of 10,000 or more people, or non-sensitive data of 1,000,000 or more, requires a CAC security assessment; between 100,000 and 999,999 requires a filed standard contract or certification; below 100,000 is exempt. Critical Information Infrastructure Operators and exporters of "Important Data" always need the assessment.

Negative list (India)

India inverts the model. Under Section 16 of the DPDP Act, transfers are permitted by default and the government may restrict particular countries by notification. None has been notified. The practical caution is that sectoral rules survive this: Section 16(2) preserves stricter requirements elsewhere, most notably the Reserve Bank of India's rule that payment system data be stored in India.

Where teams get caught
  • A company assumes "no localisation law in India" means it can host everything in Singapore. True for ordinary customer data; false the moment payment system data is involved, because the RBI rule is untouched by the DPDP Act.
  • A company crosses China's 100,000-user line in October without noticing, because the count runs from 1 January and nobody was tracking it. The threshold is cumulative for the calendar year, so this needs metering in the product, not an annual legal review.
  • An EU-to-India transfer needs SCCs and a transfer impact assessment on the European side. India asks for nothing in return: the obligation is asymmetric, and only one side of it is yours to hold.

Children: Three Different Ages

One of the sharpest divergences, and a common source of product bugs for anyone with younger users.

RegimeAge of a childWhat is required
India DPDPUnder 18Verifiable parental consent; behavioural tracking and targeted advertising at children prohibited outright
EU GDPR16, member states may lower to 13Parental consent for information-society services; no blanket advertising ban
US COPPAUnder 13Verifiable parental consent before collection; internal-operations exception for persistent identifiers

India is the strictest on both counts: the highest age threshold and an outright prohibition rather than a consent requirement. Parental consent does not unlock behavioural advertising to an Indian minor — the ban is absolute.

The ed-tech problem
  • A learning app with students in India, Germany and the United States is running three age lines at once. A 15-year-old needs parental consent in Chennai, may not in Berlin depending on the member state, and does not in Chicago.
  • The same 15-year-old in India may not be shown targeted advertising at all, consent or no consent. That is a product constraint, not a consent-flow question, and it is the one most often missed.

Penalties: Design Matters More Than Size

Comparing headline numbers is misleading. What matters is how the ceiling is calculated, because that decides who actually feels it.

RegimeCeilingWho it hurts most
China PIPLRMB 50m or 5% of prior-year turnoverLarge companies — highest percentage anywhere
EU GDPR€20m or 4% of global turnoverLarge companies; global turnover, not EU turnover
Quebec Law 25CAD 25m or 4% of worldwide turnoverLarge companies
Brazil LGPD2% of Brazil turnover, capped BRL 50mModerate — capped and local-turnover based
India DPDP₹250 crore per violation categorySmall and mid-sized companies, in relative terms
Japan APPIUp to ¥100m for businessesComparatively modest

Note the structural difference. A turnover-based ceiling scales with the company, so a €20m fine is survivable for a large platform and fatal for a startup, though the startup would never face the maximum. India's fixed rupee ceiling does the opposite: it is a rounding error for a global platform and existential for a mid-sized Indian company. If you are a growing SaaS business, India's structure is the one that should worry you more, not less.

Building One Programme That Satisfies All of Them

The overlap is large enough that separate per-country programmes are wasted effort. What follows is the shared core, then the parts that genuinely cannot be unified.

Build once, use everywhere

Cannot be unified — put these in configuration

The reason to hold these in configuration rather than code is that they change. Thresholds move, countries get added to lists, commencement dates arrive. A regime change should be a settings update, not a release.

A realistic sequence for a growing SaaS company
  • Before you have foreign users: satisfy your home jurisdiction properly. For an Indian company that means the DPDP Act, the IT Act and SPDI Rules until May 2027, and a CERT-In reporting process with a named owner.
  • On your first EEA customer: add the GDPR layer: lawful basis records, a transfer mechanism, and the 72-hour process.
  • On your first enterprise deal: buy SOC 2 or ISO 27001, because procurement is now blocking revenue. Not before.
  • On entering China: treat it as a separate architecture problem, not a policy one. The export metering has to exist in the product.

If You Are Selling Into India

India is the newest of these regimes and the one most global teams have thought least about, so it is worth stating what is actually required.

The DPDP Act 2023 applies to you if people in India can sign up — there is no revenue floor, no user-count threshold, and no requirement that anyone pay. You do not need an Indian entity, and there is no DPDP equivalent of the GDPR's Article 27 local representative. You are not required to store Indian users' data in India. The core obligations commence on 13 May 2027.

What is genuinely new relative to a GDPR programme: consent replaces legitimate interests for most commercial processing; notices must be available in English or any of the 22 Eighth Schedule languages under Section 5(3); breach reporting has no risk threshold to filter out minor incidents; and everyone under 18 is a child, with tracking and targeted advertising at them prohibited outright.

Our guide for companies outside India works through Section 3(b) in detail, and DPDP compliance for global companies covers what an overseas team actually has to build. If your question is narrower, and you want to know which Indian frameworks apply to an Indian business, the companion piece comparing DPDP, GDPR, HIPAA, PCI DSS and the India stack is the better starting point.

Three Free Tools

All free, no signup.

Start here
  • DPDP checker — answer a few questions and get the list of Indian obligations that actually apply to your business. About two minutes.
  • 14-step compliance checklist — the work itself, in order, with a one-page PDF.
  • Consent notice generator — a DPDP consent notice in any of 23 languages, generated in your browser so nothing you type is sent to us.

References & Sources

  1. European Union — Regulation (EU) 2016/679 (General Data Protection Regulation), official text (Articles 3, 6, 8, 33, 44–49, 83).
  2. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text (Sections 3, 5, 7, 8, 9, 16, 44).
  3. Ministry of Electronics & IT — Data Protection Framework, including the DPDP Rules 2025 (G.S.R. 846(E), notified 13 November 2025; core obligations commence 13 May 2027).
  4. CERT-In — Directions under Section 70B(6) of the IT Act, 2000, dated 28 April 2022 (six-hour incident reporting, 180-day log retention in India).
  5. Reserve Bank of India — Storage of Payment System Data, 6 April 2018.
  6. UK Information Commissioner's Office — UK GDPR guidance and resources, including international transfer mechanisms.
  7. California Privacy Protection Agency — CCPA regulations, as amended by the CPRA.
  8. U.S. Department of Health & Human Services — HIPAA for Professionals (Privacy, Security and Breach Notification Rules).
  9. U.S. Federal Trade Commission — Children's Online Privacy Protection Rule (COPPA), 16 CFR Part 312.
  10. Brazil — Autoridade Nacional de Proteção de Dados (ANPD), Lei Geral de Proteção de Dados (Law No. 13,709/2018) and the security-incident notification regulation.
  11. Cyberspace Administration of China — Provisions on Promoting and Standardising Cross-Border Data Flows (March 2024) and the Personal Information Protection Law.
  12. Saudi Data & AI Authority — Personal Data Protection Law (PDPL) and implementing regulations.
  13. Office of the Privacy Commissioner of Canada — PIPEDA; Commission d'accès à l'information du Québec — Law 25.
  14. Personal Information Protection Commission, Japan — Act on the Protection of Personal Information (APPI) and enforcement rules.
  15. Office of the Australian Information Commissioner — Notifiable Data Breaches scheme and the Australian Privacy Principles.

This article is general information comparing data protection regimes across several jurisdictions. It is not legal advice and is not a substitute for advice on your own circumstances. These laws are amended frequently, several obligations commence on future dates, and thresholds change; verify against the current official texts and take qualified local advice before relying on any of it.

ComparisonGDPRDPDPCCPALGPDPIPLGlobalSaaS

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.

Related Articles

← All Blog Posts