If you sell software across borders, the question is never "which privacy law applies to us". It is "which seven, and where do they disagree?" This guide puts the major regimes side by side: what triggers each one, what lawful basis it expects, how fast it wants a breach reported, what it says about moving data across borders, and what it can fine you. The differences that matter are not in the principles, which are broadly similar everywhere. They are in the defaults, the deadlines, and the thresholds.
All commencement dates, framework versions and thresholds on this page are stated as of September 2026. These regimes are amended frequently; verify against the official texts linked at the bottom before relying on any figure.
The Short Version
Three things decide almost every question in this area.
- Your users' location decides the law, not your office. Every major regime now reaches across borders. Incorporating in Delaware or Singapore changes nothing if people in Mumbai, Munich or São Paulo can sign up.
- The principles agree; the defaults do not. Everyone wants notice, security, and rights over data. They disagree on whether silence means yes, how fast you must report a breach, and whether data may leave the country.
- Build to the strictest, vary by region. One baseline that satisfies the toughest rule on each dimension, with per-region variations for the places that genuinely conflict. Running one programme per country does not scale past about three countries.
The two dimensions that break naive global designs are consent defaults and breach clocks. Get those wrong and no amount of policy documentation saves you.
The Master Comparison
Twelve regimes, the five things you need per regime. Detail on each follows.
| Regime | What triggers it | Lawful basis model | Breach clock | Cross-border rule | Penalty ceiling |
|---|---|---|---|---|---|
| EU GDPR | Users in the EEA; or monitoring their behaviour | Six bases incl. legitimate interests | 72 hours to the DPA | Adequacy, SCCs + TIA, or BCRs | €20m or 4% of global turnover |
| UK GDPR | Users in the UK | Six bases, as EU | 72 hours to the ICO | UK adequacy, IDTA or UK Addendum | £17.5m or 4% of global turnover |
| India DPDP 2023 | Users in India; offering goods or services to them | Consent + narrow legitimate uses (s.7) | Board: without delay, particulars in 72h | Negative list — open unless restricted | ₹250 crore per violation category |
| India CERT-In | Any ICT system in India | n/a — a security directive | 6 hours | Logs must be kept in India | Up to 1 year imprisonment or fine |
| California CCPA/CPRA | Californian consumers, above thresholds | Notice + opt-out of sale/sharing | No fixed statutory clock | No transfer restriction | Per-violation civil penalties |
| US HIPAA | US covered entities and their business associates | Treatment, payment, operations | 60 days to individuals | No geographic restriction; BAA governs | Tiered CMPs; criminal exposure |
| US COPPA | Services directed to US under-13s | Verifiable parental consent | No fixed statutory clock | No transfer restriction | Per-violation FTC penalties |
| Brazil LGPD | Users in Brazil; data collected in Brazil | Ten bases incl. credit protection | 3 business days to ANPD | Adequacy, SCCs, BCRs | 2% of Brazil turnover, capped BRL 50m |
| China PIPL | Users in China; certain overseas processing | Separate consent per purpose | Prompt notification to the CAC | Volume-metered: assessment / SCC / exempt | RMB 50m or 5% of turnover |
| Saudi PDPL | Residents of the Kingdom | Consent + alternative bases | 72 hours to SDAIA | Adequacy, SCCs, BCRs + risk assessment | SAR 5m; doubled for repeat |
| Canada PIPEDA / Quebec Law 25 | Commercial activity in Canada / Quebec | Meaningful consent | PIPEDA: as soon as feasible · Quebec: promptly, if serious injury | Accountability follows the data | Quebec: CAD 25m or 4% of turnover |
| Japan APPI | Handling personal information of people in Japan | Notified purpose of use | Preliminary ~3–5 days; final 30 days | Consent, equivalence, or safeguards | Up to ¥100m for businesses |
Two rows deserve a second look. CERT-In's six hours is the fastest clock anywhere on this page and catches every company running systems in India, whether or not it thinks of itself as a data business. And India's ₹250 crore is a fixed ceiling rather than a percentage, which makes it comparatively mild for a multinational and severe for a mid-sized company.
What Actually Decides Whether a Law Applies to You
Almost every regime on this page reaches beyond its own borders, and they nearly all use the same trigger: are you offering something to people here?
- GDPR: offering goods or services to people in the EEA, or monitoring their behaviour. The monitoring limb is the broadest trigger in the world; analytics on EEA visitors can be enough.
- India DPDP: offering goods or services to people in India. Note there is no monitoring limb, so India is narrower than the GDPR here.
- Brazil LGPD: offering to people in Brazil, or processing data collected in Brazil.
- China PIPL: providing products or services to people in China, or analysing their behaviour.
- California CCPA is the outlier: it applies only above revenue or data-volume thresholds, so a small company can serve Californians and stay outside it.
- A 12-person analytics startup in Bengaluru with a self-serve signup and no sales team is subject to the DPDP Act, the GDPR (if any EEA user signs up), and the LGPD (if any Brazilian does). Nobody had to sign a contract for those to attach.
- The same startup is probably not subject to CCPA, because it will not cross California's thresholds for years. Building a "Do Not Sell" flow before then is wasted engineering.
- A free tier counts. Under the GDPR the trigger is explicitly irrespective of payment, and the DPDP Act has no payment element in its test at all.
Consent: Three Incompatible Defaults
This is where a single global consent screen falls apart. The regimes do not merely differ in wording; they start from opposite defaults.
| Model | Where | What it means in the product |
|---|---|---|
| Opt-in by default | EU/UK, India, Brazil, Saudi Arabia | Silence means no. Nothing pre-ticked. You need an affirmative action before processing on a consent basis. |
| Opt-out for sale/sharing | California and most US states | You may proceed until told to stop, but you must offer a clear, working "Do Not Sell or Share" path. |
| Separate consent per purpose | China | One consent does not cover several purposes. Cross-border transfer, sensitive data and third-party sharing each need their own. |
The GDPR softens its own opt-in default with the legitimate-interests basis, which carries a great deal of ordinary marketing and analytics. India's DPDP Act has no equivalent: Section 7 lists a narrow set of legitimate uses and nothing resembling a general balancing test. This is the single most common failure when a European programme is copied into India: processing that was lawfully based on legitimate interests in Frankfurt needs actual consent in Chennai.
- A European SaaS company launches in India and reuses its existing privacy notice. Its product-update emails ran on legitimate interests in the EU. In India those same emails need consent, and the notice never asked for it.
- An Indian company expands to China and keeps its single "I agree to the privacy policy" checkbox. Under PIPL that one checkbox cannot carry transfer, sensitive data and third-party sharing at once.
- The fix in both directions is the same: keep the lawful basis as a per-region setting attached to each processing purpose, not a global constant.
Breach Clocks: Six Hours to Sixty Days
This is the hardest dimension to run globally, because the spread is enormous and the clocks start at different moments.
| Deadline | Regime | To whom |
|---|---|---|
| 6 hours | India CERT-In directions | CERT-In |
| 72 hours | EU/UK GDPR | Supervisory authority |
| 72 hours | India DPDP (Rule 7 particulars) | Data Protection Board |
| 72 hours | Saudi PDPL | SDAIA |
| 3 business days | Brazil LGPD | ANPD and affected individuals |
| ~3–5 days, then 30 | Japan APPI | PPC — preliminary, then final report |
| 30 days to assess | Australia NDB scheme | OAIC, then notify as soon as practicable |
| 60 days | US HIPAA | Affected individuals |
| “Promptly” | Quebec Law 25 | CAI, where there is a risk of serious injury |
Quebec is worth singling out because it is the one row with no number in it. The statute says “promptly” and sets no fixed deadline, and the obligation is triggered only where the incident presents a risk of serious injury — lesser incidents go in an internal register rather than to the regulator. You will see 72 hours quoted widely for Quebec; that is a planning benchmark practitioners borrowed from the GDPR, not the law. Building a runbook on it is safe. Telling your board it is the statutory deadline is not.
- A SaaS company with users in India, Germany and Brazil, plus a US healthcare client, discovers a breach at 9pm on Friday. Four clocks start simultaneously: CERT-In at six hours, the German DPA and the Indian Board at 72, and Brazil's ANPD at three business days, while HIPAA's 60-day outer limit sits far behind them.
- The instinct to wait for the forensics to finish and then notify everyone at once satisfies HIPAA and breaches everything above it.
- The working design separates the two jobs: notify early with what is known, keep investigating afterwards. No regulator expects a complete forensic picture in six hours. They expect to have been told.
Cross-Border Transfers: Three Philosophies
How a regime treats data leaving the country tells you most of what you need to know about its politics.
Permission-based (EU, UK, Brazil, Saudi Arabia)
Transfer is allowed when a recognised safeguard is in place: an adequacy decision covering the destination, standard contractual clauses paired with a transfer impact assessment, or binding corporate rules within a group. The burden is on you to hold the paperwork.
Volume-metered (China)
China is the only major regime that meters exports by volume. Under the March 2024 CAC provisions, counted from 1 January each year: exporting sensitive personal information of 10,000 or more people, or non-sensitive data of 1,000,000 or more, requires a CAC security assessment; between 100,000 and 999,999 requires a filed standard contract or certification; below 100,000 is exempt. Critical Information Infrastructure Operators and exporters of "Important Data" always need the assessment.
Negative list (India)
India inverts the model. Under Section 16 of the DPDP Act, transfers are permitted by default and the government may restrict particular countries by notification. None has been notified. The practical caution is that sectoral rules survive this: Section 16(2) preserves stricter requirements elsewhere, most notably the Reserve Bank of India's rule that payment system data be stored in India.
- A company assumes "no localisation law in India" means it can host everything in Singapore. True for ordinary customer data; false the moment payment system data is involved, because the RBI rule is untouched by the DPDP Act.
- A company crosses China's 100,000-user line in October without noticing, because the count runs from 1 January and nobody was tracking it. The threshold is cumulative for the calendar year, so this needs metering in the product, not an annual legal review.
- An EU-to-India transfer needs SCCs and a transfer impact assessment on the European side. India asks for nothing in return: the obligation is asymmetric, and only one side of it is yours to hold.
Children: Three Different Ages
One of the sharpest divergences, and a common source of product bugs for anyone with younger users.
| Regime | Age of a child | What is required |
|---|---|---|
| India DPDP | Under 18 | Verifiable parental consent; behavioural tracking and targeted advertising at children prohibited outright |
| EU GDPR | 16, member states may lower to 13 | Parental consent for information-society services; no blanket advertising ban |
| US COPPA | Under 13 | Verifiable parental consent before collection; internal-operations exception for persistent identifiers |
India is the strictest on both counts: the highest age threshold and an outright prohibition rather than a consent requirement. Parental consent does not unlock behavioural advertising to an Indian minor — the ban is absolute.
- A learning app with students in India, Germany and the United States is running three age lines at once. A 15-year-old needs parental consent in Chennai, may not in Berlin depending on the member state, and does not in Chicago.
- The same 15-year-old in India may not be shown targeted advertising at all, consent or no consent. That is a product constraint, not a consent-flow question, and it is the one most often missed.
Penalties: Design Matters More Than Size
Comparing headline numbers is misleading. What matters is how the ceiling is calculated, because that decides who actually feels it.
| Regime | Ceiling | Who it hurts most |
|---|---|---|
| China PIPL | RMB 50m or 5% of prior-year turnover | Large companies — highest percentage anywhere |
| EU GDPR | €20m or 4% of global turnover | Large companies; global turnover, not EU turnover |
| Quebec Law 25 | CAD 25m or 4% of worldwide turnover | Large companies |
| Brazil LGPD | 2% of Brazil turnover, capped BRL 50m | Moderate — capped and local-turnover based |
| India DPDP | ₹250 crore per violation category | Small and mid-sized companies, in relative terms |
| Japan APPI | Up to ¥100m for businesses | Comparatively modest |
Note the structural difference. A turnover-based ceiling scales with the company, so a €20m fine is survivable for a large platform and fatal for a startup, though the startup would never face the maximum. India's fixed rupee ceiling does the opposite: it is a rounding error for a global platform and existential for a mid-sized Indian company. If you are a growing SaaS business, India's structure is the one that should worry you more, not less.
Building One Programme That Satisfies All of Them
The overlap is large enough that separate per-country programmes are wasted effort. What follows is the shared core, then the parts that genuinely cannot be unified.
Build once, use everywhere
- A data inventory. What you collect, why, where it lives, who you share it with, how long you keep it. Every regime on this page starts here.
- Access and deletion workflows. The rights differ in detail but the machinery is the same. Build to the shortest deadline you face and the rest are satisfied automatically.
- Vendor contracts. Processor terms under the GDPR, Section 8(2) contracts under the DPDP Act, BAAs under HIPAA: one well-drafted template with regional annexes covers all of it.
- Encryption, access control, logging, and a rehearsed incident-response plan. Universal.
Cannot be unified — put these in configuration
- Consent defaults: opt-in, opt-out or per-purpose, keyed to the user's region.
- Breach clocks: a per-jurisdiction table your incident process reads, not a number in a runbook.
- Export thresholds: China's volume counters especially, which need live metering.
- Age thresholds: 13, 16 or 18, plus India's advertising prohibition as a hard product constraint.
The reason to hold these in configuration rather than code is that they change. Thresholds move, countries get added to lists, commencement dates arrive. A regime change should be a settings update, not a release.
- Before you have foreign users: satisfy your home jurisdiction properly. For an Indian company that means the DPDP Act, the IT Act and SPDI Rules until May 2027, and a CERT-In reporting process with a named owner.
- On your first EEA customer: add the GDPR layer: lawful basis records, a transfer mechanism, and the 72-hour process.
- On your first enterprise deal: buy SOC 2 or ISO 27001, because procurement is now blocking revenue. Not before.
- On entering China: treat it as a separate architecture problem, not a policy one. The export metering has to exist in the product.
If You Are Selling Into India
India is the newest of these regimes and the one most global teams have thought least about, so it is worth stating what is actually required.
The DPDP Act 2023 applies to you if people in India can sign up — there is no revenue floor, no user-count threshold, and no requirement that anyone pay. You do not need an Indian entity, and there is no DPDP equivalent of the GDPR's Article 27 local representative. You are not required to store Indian users' data in India. The core obligations commence on 13 May 2027.
What is genuinely new relative to a GDPR programme: consent replaces legitimate interests for most commercial processing; notices must be available in English or any of the 22 Eighth Schedule languages under Section 5(3); breach reporting has no risk threshold to filter out minor incidents; and everyone under 18 is a child, with tracking and targeted advertising at them prohibited outright.
Our guide for companies outside India works through Section 3(b) in detail, and DPDP compliance for global companies covers what an overseas team actually has to build. If your question is narrower, and you want to know which Indian frameworks apply to an Indian business, the companion piece comparing DPDP, GDPR, HIPAA, PCI DSS and the India stack is the better starting point.
Three Free Tools
All free, no signup.
- DPDP checker — answer a few questions and get the list of Indian obligations that actually apply to your business. About two minutes.
- 14-step compliance checklist — the work itself, in order, with a one-page PDF.
- Consent notice generator — a DPDP consent notice in any of 23 languages, generated in your browser so nothing you type is sent to us.
References & Sources
- European Union — Regulation (EU) 2016/679 (General Data Protection Regulation), official text (Articles 3, 6, 8, 33, 44–49, 83).
- India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text (Sections 3, 5, 7, 8, 9, 16, 44).
- Ministry of Electronics & IT — Data Protection Framework, including the DPDP Rules 2025 (G.S.R. 846(E), notified 13 November 2025; core obligations commence 13 May 2027).
- CERT-In — Directions under Section 70B(6) of the IT Act, 2000, dated 28 April 2022 (six-hour incident reporting, 180-day log retention in India).
- Reserve Bank of India — Storage of Payment System Data, 6 April 2018.
- UK Information Commissioner's Office — UK GDPR guidance and resources, including international transfer mechanisms.
- California Privacy Protection Agency — CCPA regulations, as amended by the CPRA.
- U.S. Department of Health & Human Services — HIPAA for Professionals (Privacy, Security and Breach Notification Rules).
- U.S. Federal Trade Commission — Children's Online Privacy Protection Rule (COPPA), 16 CFR Part 312.
- Brazil — Autoridade Nacional de Proteção de Dados (ANPD), Lei Geral de Proteção de Dados (Law No. 13,709/2018) and the security-incident notification regulation.
- Cyberspace Administration of China — Provisions on Promoting and Standardising Cross-Border Data Flows (March 2024) and the Personal Information Protection Law.
- Saudi Data & AI Authority — Personal Data Protection Law (PDPL) and implementing regulations.
- Office of the Privacy Commissioner of Canada — PIPEDA; Commission d'accès à l'information du Québec — Law 25.
- Personal Information Protection Commission, Japan — Act on the Protection of Personal Information (APPI) and enforcement rules.
- Office of the Australian Information Commissioner — Notifiable Data Breaches scheme and the Australian Privacy Principles.
This article is general information comparing data protection regimes across several jurisdictions. It is not legal advice and is not a substitute for advice on your own circumstances. These laws are amended frequently, several obligations commence on future dates, and thresholds change; verify against the current official texts and take qualified local advice before relying on any of it.