Data protection

Access, correction, erasure: the rights look similar the world over. What differs is whether anyone enforces them.

Illustration: Data protection

One model, widely exported

Most recent data protection statutes share a blueprint: a lawful basis for every use, transparency obligations, data minimisation and purpose limitation, rights of access, correction, erasure, objection and portability, breach notification, and an independent regulator. That design spread outwards from Europe and has been adopted, sometimes almost word for word, across very different legal traditions.

The real difference is enforcement

On paper the rights are close to identical. In practice what counts is whether a regulator exists, whether it has staff and the power to fine, and whether it uses them. Some countries have a statute with no functioning authority behind it; others have an authority issuing substantial penalties. A third difference is routinely overlooked: whether government bodies are covered at all — several statutes exclude them expressly.

Compensation is the exception

Many statutes provide penalties payable to the state but no personal right to damages. Where such a right exists, courts generally require demonstrable harm; the breach alone is not enough. If you want compensation, start documenting the consequences for you from the first day — not the breach, the consequences.

The access request is the most effective tool

It is usually free, requires no reason, and forces the other side to disclose what it holds, where it came from and who it was shared with. Response deadlines are typically a month. The answer is also the foundation for anything that follows, which is why an access request belongs at the beginning of a dispute rather than at the end.

In writing, and dated

Send requests in writing with proof of delivery and keep that proof. Without a date you cannot later show that the deadline passed — and it is precisely that missed deadline that gives a regulator something to act on.

The law country by country

The legal framework, the procedure, the time limits and the costs differ from one country to another. Each country below has a detailed page: governing texts, key facts, the actual procedure, costs, where to go and the traps to avoid.

Select a country to open its detailed page.

European framework

European Union

The GDPR is a regulation: it applies directly in all twenty-seven member states without transposition, and it turned data protection into an enforceable individual right.

Britain and Ireland

United Kingdom

UK GDPR and the Data Protection Act 2018, enforced by the Information Commissioner, with a free complaints route.

Ireland

GDPR enforced by a Data Protection Commission that acts as lead regulator for much of the global tech industry.

North America

United States

No comprehensive federal privacy law: sectoral federal rules, an expanding patchwork of state statutes, and FTC enforcement.

Canada

PIPEDA federally, provincial statutes in three provinces, and Quebec's Law 25 as the strictest regime in North America.

Australia and New Zealand

Australia

The Privacy Act 1988 with thirteen Australian Privacy Principles, mandatory breach notification, and reforms introducing a privacy tort.

New Zealand

The Privacy Act 2020, with thirteen principles, mandatory breach notification and an unusually accessible complaints process.

South Asia

India

The DPDP Act 2023 became operational when its Rules were notified in November 2025, with obligations phased in to 2027.

Pakistan

No comprehensive data protection statute yet: protection rests on cybercrime legislation and sectoral rules.

South-East and East Asia

Singapore

The PDPA with consent, purpose limitation and a Do Not Call registry, plus mandatory breach notification since 2021.

Malaysia

The PDPA 2010, significantly amended in 2024 with breach notification, data protection officers and portability.

Philippines

The Data Privacy Act 2012, enforced by an active National Privacy Commission, with criminal penalties for unauthorised disclosure.

Hong Kong

The Personal Data (Privacy) Ordinance, with six data protection principles and a doxxing offence added in 2021.

Africa

South Africa

A national data protection statute with a dedicated regulator — enforcement capacity is the variable, not the rights.

Nigeria

A national data protection statute with a dedicated regulator — enforcement capacity is the variable, not the rights.

Kenya

A national data protection statute with a dedicated regulator — enforcement capacity is the variable, not the rights.

Ghana

A national data protection statute with a dedicated regulator — enforcement capacity is the variable, not the rights.

Uganda

A national data protection statute with a dedicated regulator — enforcement capacity is the variable, not the rights.

Zambia

A national data protection statute with a dedicated regulator — enforcement capacity is the variable, not the rights.

The Caribbean

Jamaica

A national data protection statute with a dedicated regulator — enforcement capacity is the variable, not the rights.

Trinidad and Tobago

A national data protection statute with a dedicated regulator — enforcement capacity is the variable, not the rights.

This topic is also covered for French-speaking countries · German-speaking countries · Spanish-speaking countries · Italy and Italian-speaking Switzerland · Portuguese-speaking countries · the Netherlands, Flanders and Suriname.

Further reading

Links to official or reference sources. They open in a new tab.

Page checked in September 2026. The instruments cited can change: if in doubt, confirm with the official source given.

Locate this page in the site map

A question, a correction, a suggestion? Write to us.