Framework hub

Global privacy

Non-EU privacy, personal information, electronic marketing, cross-border transfer, and child-data rules for EU-incorporated software teams serving global users.

Focus 1

Outbound trigger

Look beyond incorporation when you target users, sell locally, collect local personal information, run campaigns, or host regulated sector workflows outside Europe.

Open related page

Focus 2

Data rights

Access, correction, deletion, portability, opt-out, consent, and breach notification duties vary by country and often require operational request handling.

Focus 3

Marketing and cookies

Email, SMS, push messages, tracking, children, and advertising can trigger separate laws even before a user becomes a paying customer.

Focus 4

Transfers and processors

Cross-border transfer notices, onward transfer contracts, processor terms, localization questions, and security measures are the main early design checks.

Source updates

MEDIUMFederal Register2026-08-26

Telemarketing Sales Rule Fees

The Federal Trade Commission ("Commission") is amending its Telemarketing Sales Rule ("TSR") by updating the fees charged to entities accessing the National Do Not Call Registry...

US federal regulationDORAPDPA
MEDIUMFederal Register2026-10-01

Rule on Impersonation of Government and Businesses

The Federal Trade Commission ("FTC" or "Commission") proposes to commence a rulemaking proceeding to prevent certain unfair or deceptive acts or practices by search engine, social media,...

US federal regulationFTC privacy
HIGHFederal Register2026-09-24

Rules of Practice

The Federal Trade Commission ("Commission" or "FTC") is amending its rules of practice to revise the description of the FTC's EEO Office and Regional Offices and to update the list of...

US federal regulationDORAFTC privacy
MEDIUMFederal Register2026-09-24

Rules of Practice

The Federal Trade Commission ("Commission" or "FTC") is amending its rules of practice in order to eliminate the agency's post- employment clearance rule.

US federal regulationDORAFTC privacy

Country framework map

CA

PIPEDA

Commercial activity involving Canadian personal information.

OPC PIPEDA
CA

CASL

Commercial electronic messages, unsubscribe flows, or software installation touching Canada.

Canada CASL
BR

LGPD

Offering goods or services in Brazil, processing data in Brazil, or using data collected in Brazil.

ANPD
AU

Privacy Act

Carrying on business in Australia or handling Australian personal information.

OAIC Privacy Act
IN

DPDP Act

Digital personal data connected to people in India or services offered to them.

MeitY
SG

PDPA

Collecting, using, disclosing, or transferring personal data in Singapore.

PDPC
JP

APPI

Handling personal information of people in Japan or cross-border transfers involving Japan.

PPC Japan
CN

PIPL

Providing products or services to individuals in China or analyzing their behavior.

NPC PIPL
KR

PIPA

Personal information processing tied to Korean users, local services, AI privacy, or Korean business operations.

PIPC Korea
NZ

Privacy Act 2020

New Zealand users, privacy breach handling, access/correction requests, or overseas disclosure.

NZ Privacy Act
ZA

POPIA

South African personal information, direct marketing, operator relationships, or local customer operations.

Information Regulator
MX

LFPDPPP

Mexican personal data, privacy notices, ARCO rights requests, consent, sensitive data, or transfers.

INAI Mexico