Law / Frameworks / NIST Privacy Framework / Control-P

NIST Privacy Framework, Control-PCT.PO-P1

Policies, processes, and procedures for authorizing data processing (e.g., organizational decisions, individual consent), revoking authorizations, and maintaining authorizations are established and in place.NIST Privacy Framework, version 1.0, January 2020, CT.PO-P1

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

515
laws
210
places
4
with court rulings behind them
39
not yet in force
9
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Alabama
  • Albania
  • Algeria
  • Andorra
  • Angola
  • Antigua and Barbuda
  • Argentina
  • Armenia
  • Australia
  • Austria
  • Azerbaijan
  • Bahamas
  • Bahrain
  • Bangladesh
  • Barbados
  • Belarus
  • Belgium
  • Belize
  • Benin
  • Bermuda
  • Bhutan
  • Bolivia
  • Bosnia and Herzegovina
  • Botswana
  • Brazil
  • Brunei Darussalam
  • Bulgaria
  • Burkina Faso
  • Cabo Verde
  • California
  • Cambodia
  • Cameroon
  • Canada
  • Cayman Islands
  • Central African Republic
  • Chad
  • Chile
  • China
  • Colombia
  • Colorado
  • Comoros
  • Connecticut
  • Costa Rica
  • Croatia
  • Cuba
  • Cyprus
  • Czech Republic
  • Côte d'Ivoire
  • Delaware
  • Democratic Republic of the Congo
  • Denmark
  • Djibouti
  • Dominican Republic
  • Ecuador
  • Egypt
  • El Salvador
  • Equatorial Guinea
  • Eritrea
  • Estonia
  • Eswatini
  • Ethiopia
  • European Union
  • Finland
  • Florida
  • France
  • Gabon
  • Gambia
  • Georgia
  • Germany
  • Ghana
  • Greece
  • Grenada
  • Guam
  • Guatemala
  • Honduras
  • Hungary
  • Iceland
  • Idaho
  • Illinois
  • India
  • Indiana
  • Indonesia
  • Iran
  • Ireland
  • Italy
  • Jamaica
  • Japan
  • Jordan
  • Kansas
  • Kazakhstan
  • Kentucky
  • Kenya
  • Kiribati
  • Kosovo
  • Kuwait
  • Kyrgyzstan
  • Latvia
  • Lebanon
  • Lesotho
  • Liberia
  • Libya
  • Liechtenstein
  • Lithuania
  • Louisiana
  • Luxembourg
  • Madagascar
  • Maine
  • Malawi
  • Malaysia
  • Maldives
  • Mali
  • Malta
  • Marshall Islands
  • Maryland
  • Massachusetts
  • Mauritania
  • Mauritius
  • Mexico
  • Michigan
  • Minnesota
  • Missouri
  • Moldova
  • Monaco
  • Mongolia
  • Montana
  • Montenegro
  • Morocco
  • Nauru
  • Nepal
  • Netherlands
  • Nevada
  • New Hampshire
  • New Jersey
  • New Mexico
  • New Zealand
  • Nicaragua
  • Niger
  • Nigeria
  • North Macedonia
  • Norway
  • Oklahoma
  • Oregon
  • Panama
  • Paraguay
  • Pennsylvania
  • Peru
  • Philippines
  • Poland
  • Portugal
  • Puerto Rico
  • Qatar
  • Republic of the Congo
  • Rhode Island
  • Romania
  • Russia
  • Rwanda
  • Saint Kitts and Nevis
  • Saint Lucia
  • Samoa
  • San Marino
  • Sao Tome and Principe
  • Saudi Arabia
  • Senegal
  • Serbia
  • Seychelles
  • Singapore
  • Slovakia
  • Slovenia
  • Solomon Islands
  • Somalia
  • South Africa
  • South Dakota
  • South Korea
  • Spain
  • Sri Lanka
  • Suriname
  • Sweden
  • Switzerland
  • Syria
  • Taiwan
  • Tajikistan
  • Tanzania
  • Tennessee
  • Texas
  • Thailand
  • Timor-Leste
  • Togo
  • Tonga
  • Trinidad and Tobago
  • Tunisia
  • Turkey
  • Turkmenistan
  • Uganda
  • Ukraine
  • United Arab Emirates
  • United Kingdom
  • United States
  • Uruguay
  • Utah
  • Uzbekistan
  • Vanuatu
  • Venezuela
  • Vermont
  • Virginia
  • Washington
  • Zambia
  • Zimbabwe

Comprehensive regime

169 laws, 160 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

Establish one of the lawful bases Article 7 lists, such as the data subject's consent, contractual necessity, a legal obligation, vital interests, a public task, or a legitimate interest that does not override the data subject's rights, before processing personal data of a person in Albania.

Demonstrate that consent was given, present a request for consent separately from other matters in clear and plain language, and let the data subject withdraw consent at any time as easily as it was given.

+1 more
Algeria Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Obtain a lawful basis before processing the personal data of a person in Algeria, whether the processing is automated or manual: express consent, or a legal obligation, a vital interest, a contract with the data subject, a public-interest task, or a legitimate interest.

Process a child's personal data only with the consent of their legal representative or the authorisation of the competent judge.

Andorra LQPD, Llei 29/2021 del 28 d'octubre

Establish a lawful basis under Article 6 before processing personal data of a person in Andorra, and apply the Article 5 principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and security throughout.

Angola Law on the Protection of Personal Data

Obtain the data subject's unequivocal, express consent before processing their personal data, or notify the Agência de Protecção de Dados, unless a contract-performance, legal-obligation, vital-interest, public-interest, or legitimate-interest ground applies.

Obtain the data subject's consent or the APD's authorisation before processing personal data on their creditworthiness or solvency, unless the information comes from a publicly accessible source, and notify the data subject within sixty days of entering their data in a debtor file.

+1 more
Antigua and Barbuda Data Protection Act, 2013

Obtain a data subject's consent before processing their personal data, other than sensitive personal data, arising from a commercial transaction, unless a listed alternative ground such as contract performance, a legal obligation, protecting vital interests or the administration of justice applies.

Argentina Ley 25.326, Ley de Protección de los Datos Personales

Obtain the data subject's free, express, and informed consent before processing their personal data, unless it comes from an unrestricted public-access source, is needed for a State function or legal obligation, is limited to a short listing of name and identifying numbers, arises from a contractual, scientific, or professional relationship, or is financial-entity customer data covered by Ley 21.526.

Keep personal data confidential during and after your involvement in processing it, and disclose it to a third party only for a purpose tied to both parties' legitimate interest and with the data subject's prior, revocable, informed consent naming the purpose and the recipient, unless a listed exception applies.

+3 more
Armenia Law on Protection of Personal Data, comprehensive regime

An app that collects, uses, or discloses the personal data of an individual in Armenia must have a lawful basis for processing under Arts. 4-8 of the Law on Protection of Personal Data.

Austria Datenschutzgesetz (DSG), Data Protection Act

Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Austria.

Azerbaijan Law on Personal Data, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Azerbaijan, including a facial image or voiceprint, must have a lawful basis under Art. 9.6, most commonly consent for data in an open category or a legislative basis defining the purpose and method of processing, since Azerbaijan's law reaches biometric data under these same ordinary conditions rather than exempting it.

Bahrain Personal Data Protection Law, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Bahrain must obtain the Data Subject's consent or rely on a listed alternative lawful basis under the Personal Data Protection Law.

Show the other 159 laws
Bangladesh Personal Data Protection Act, 2026, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Bangladesh, including a voiceprint, faceprint, or other biometric identifier, must have a lawful basis before processing, ordinarily the data principal's voluntary, specific, and revocable consent or one of the Act's enumerated legitimate-interest grounds, and must not retain the data beyond what its stated purpose requires.

Barbados Data Protection Act, 2019

Before processing personal data, establish a lawful basis and confine processing to the stated purpose.

Belarus Law of the Republic of Belarus On Personal Data Protection

Establish a lawful basis, generally the personal data subject's consent unless another basis in this Law applies, before processing personal data of a person in Belarus, and limit processing to explicit, pre declared, legitimate purposes, under Article 4.

Take consent that is freely given, unambiguous and informed, obtainable in writing, as an electronic document, or in another electronic form, and be ready to prove that it was obtained, under Article 5.

Belgium Act of 30 July 2018 on the Protection of Natural Persons with regard to Personal Data

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Belgium, and treat 13 as the digital-consent age under Act Article 7 for information-society services offered directly to a child.

Belize Data Protection Act 2021, comprehensive regime from a date not yet set

Before processing personal data of a person in Belize, establish a lawful basis such as consent, a contract with the data subject, or a legal obligation, and process it fairly, transparently, and only for the specified purpose.

Do not process sensitive personal data, including biometric data such as a voiceprint or faceprint, unless a listed condition applies, such as the data subject's consent or a deliberate act by the data subject making the information public.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Obtain a lawful basis, ordinarily the data subject's consent, before collecting, processing, transmitting, storing, or using their personal data, unless a specific legal exception applies.

Bermuda Personal Information Protection Act 2016, application and general principles

Obtain verifiable consent from a parent or guardian before relying on consent to use a child's personal information in a service targeted at children or known to be used by a child.

Bhutan Information, Communications and Media Act of Bhutan 2018, data protection and privacy duties

An app that collects, uses, or discloses the personal data of an individual in Bhutan, including a voiceprint, faceprint, or other biometric identifier, must obtain the subject's express written permission before collecting it and must not disclose it to a third party without authorization. An ICT or media service provider or vendor must additionally publish a privacy policy, limit collection and use to what is reasonably appropriate, store and use data only for its intended purpose, and remain responsible for data it transfers to a third party.

Bolivia Reglamento para el Desarrollo de TIC, Tratamiento de los Datos Personales

Obtain a person's prior knowledge and express consent before collecting, processing, blocking, cancelling, transferring, consulting, or interconnecting their personal data.

Do not use, communicate, or transfer personal data to a third party without the data subject's consent or a competent court's written order.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina

Establish a lawful basis under Article 8 before processing personal data of a person in Bosnia and Herzegovina, and appoint a Data Protection Officer under Articles 39 to 41 wherever the processing meets the threshold the Act sets, such as processing carried out by a public authority or large-scale monitoring or special-category processing.

Botswana Data Protection Act, 2024 (Act No. 18 of 2024)

Obtain a lawful basis before processing personal data of a person in Botswana, or of a person elsewhere if the processing is by a controller or processor established in Botswana.

Be able to demonstrate that a data subject has consented to processing based on consent, and let the data subject withdraw that consent at any time.

Brazil Lei Geral de Proteção de Dados Pessoais (LGPD)

Establish a lawful basis under article 7 before processing personal data, including data the person has made public.

Take consent only when it is provided in writing or by another means demonstrating the data subject's free will, in a clause set apart from the other contract terms, and be ready to prove it meets these requirements.

Brunei Darussalam Personal Data Protection Order 2025, comprehensive regime

Brunei's Personal Data Protection Order 2025 has been in effect since for Parts 3 to 9, section 42, and Schedules 1 to 5, the commencement date Government Gazette No. S 11/2025 directly confirms. An app that collects, uses, or discloses the personal data of a person in Brunei, including a voiceprint, faceprint, or other biometric identifier, since the Order draws no sensitive-category distinction, must obtain the individual's consent or rely on a Schedule 1, 2, or 3 consent-free basis before processing.

Bulgaria Personal Data Protection Act (Zakon za zashtita na lichnite danni, ZZLD)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Bulgaria; the Act's own text is not confirmed, and any Bulgarian-specific addition to that basis is unverified.

Burkina Faso Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel

Obtain the data subject's prior consent before processing their personal data, unless a specific legal exception applies, such as performing a contract, complying with a legal obligation, protecting a vital interest, or a public interest ground.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data

Process personal data only where the data subject has unambiguously consented or where processing is necessary for a contract, a legal obligation, the data subject's vital interests, a public interest task, or your or a third party's legitimate interest that does not override the data subject's rights.

Cambodia Draft Law on Personal Data Protection, final draft proposed

If enacted as drafted, a data controller or processor would need one of six legal bases, including the data subject's consent, before processing personal data, and would need a parent or guardian's verified consent before processing the personal data of a data subject under the age of 16.

Cameroon Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set

Rely on a lawful basis, consent, a legal obligation, a public-interest mission, or health protection, before processing personal data, and where consent is the basis, make it free, informed, specific, unequivocal, and express.

Obtain parental or legal-representative consent before processing the personal data of a person under 18.

+1 more
Canada Bill C-36, Protecting Privacy and Consumer Data Act proposed

Not yet in force. If enacted as proposed, would require organizations to be transparent about their use of automated decision making for significant decisions about individuals, set higher standards for handling children's information, and obtain meaningful consent supported by plain-language explanations.

Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

Obtain knowing, meaningful consent before collecting, using or disclosing personal information, and limit collection to what a reasonable person would consider appropriate for the stated purpose.

Cayman Islands Data Protection Act 2021 Revision, application, principles and data subject rights

Have a lawful basis for collecting and processing personal data, and hold it only for specified purposes.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel

Have a lawful basis, such as a contract's performance, a legal obligation, a legitimate interest that does not override the data subject's rights, the data subject's freely given and revocable consent, a vital interest, or a public interest mission, before processing someone's personal data.

Chad Loi n°007/PR/2015, principes directeurs du traitement des données (consentement, licéité, finalité, conservation)

Process personal data only with the data subject's consent, or, absent consent, only when indispensable to a legal obligation, a public-interest mission, a contract with the data subject, or the data subject's vital interest.

Chile Ley 19.628, sobre Protección de la Vida Privada

Obtain a lawful basis before processing personal data of a person in Chile through a registry or data bank, whether the processor is a public body or a private party, per Ley 19.628 Article 1.

Chile Ley 21.719, Regula la Protección y el Tratamiento de los Datos Personales from , in 2 months

From , obtain a lawful basis before processing personal data of a person in Chile; this obligation does not yet bind as of this writing.

China Personal Information Protection Law of the PRC, General Processing Rules and Lawful Bases

Establish one of PIPL's enumerated lawful bases, most commonly informed consent, before collecting or processing personal information of a person in China.

Colombia Ley 1581 de 2012, General Personal Data Protection

Obtain the data subject's prior, explicit and informed authorization before collecting or processing their personal data, unless a statutory exception applies.

Keep proof of the data subject's authorization, tell them at authorization the purpose of the processing, keep their personal data updated and accurate, secure it against unauthorized alteration, loss, consultation, use or access, and correct it once it is shown to be incorrect.

Colombia Superintendencia Circular on AI and Personal Data

Before collecting personal data from the internet to develop, train, test or deploy an artificial intelligence system, obtain the data subject's prior, express and informed authorization; a datum being accessible online does not make it a public datum exempt from that requirement.

Colorado SB 21-190, Colorado Privacy Act (CPA)

Obtain the consumer's affirmative opt-in consent before processing sensitive data, including biometric data used for identification, or before resuming processing for targeted advertising or sale after a consumer opts out.

Costa Rica Protección de la Persona frente al Tratamiento de sus Datos Personales

Before collecting a person's personal data, inform them of the purpose of collection and obtain their express, written consent, unless the data are publicly accessible or a law or judicial order compels disclosure.

Do not process data revealing racial or ethnic origin, political opinions, religious convictions, health, or sexual orientation without the data subject's consent or another narrow statutory ground.

Croatia Act on the Implementation of the General Data Protection Regulation

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Croatia, following the Act's institutional and procedural rules.

Cuba Ley 149/2022, De Protección de Datos Personales, general regime

Obtain the data subject's express, unambiguous, free and informed consent before collecting or processing sensitive data (sex, gender identity, sexual orientation, ethnic origin, health, disability, genetic information, religious belief, political affiliation, or criminal record), absent a statutory exception.

Cyprus Law 125(I)/2018, Cyprus GDPR Supplement

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Cyprus, including data collected by crawling.

Czech Republic Act on Personal Data Processing

Establish a GDPR Article 6 lawful basis before processing personal data of a person in the Czech Republic; Act 110/2019 supplies the UOOU's procedural powers rather than a substantive addition to that basis.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data

Have a lawful basis, such as the person's express consent, before collecting, transmitting, storing or using anyone's personal data, whether the processing is automated or not.

Do not send unsolicited electronic direct-marketing messages using a person's personal data without their consent.

+1 more
Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Obtain the data subject's consent before processing their personal data, unless the processing is necessary to perform a legal obligation.

Denmark Danish Data Protection Act (Databeskyttelsesloven)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Denmark, including data collected by crawling.

Djibouti Digital Code, Book I: Personal Data Protection and CNDP

Obtain a lawful basis, most often the data subject's express, unambiguous, free, specific and informed consent, before processing their personal data.

Dominican Republic Ley No. 172-13 sobre Protección Integral de los Datos Personales

Obtain the data subject's free, express, and conscious consent before processing or transferring their personal data, unless the law lists an exception.

Ecuador LOPDP, comprehensive personal-data protection regime

Do not process personal data without a lawful basis under the Act, and obtain explicit consent before processing a sensitive category of data unless another enumerated ground applies.

Egypt Law No. 151 of 2020 Promulgating the Personal Data Protection Law

Obtain the data subject's explicit consent before processing their personal data unless another lawful ground applies, such as performing a contract, complying with a legal obligation, or acting under a judicial order.

El Salvador Ley para la Protección de Datos Personales

Obtain a person's express, informed, free, specific and individualized consent, or another lawful basis this Law recognizes such as contractual necessity, a legal obligation, vital interests, or a legitimate interest that does not override the data subject's rights, before processing their personal data, unless this Law excuses consent for the specific processing.

Let a data subject revoke their consent at any time without retroactive effect, and act on a revocation within five business days of the request.

+1 more
Equatorial Guinea Ley de Protección de Datos Personales

Obtain clear, unequivocal consent before processing a person's personal data, and express written consent before processing a sensitive category (race, tribe or ethnicity, health, sexual life, religious, political or union creed).

Eritrea Civil Code of the State of Eritrea, Personality Rights (Image and Correspondence) from a date not yet set

Do not exhibit, reproduce, or offer for sale a person's photograph or image without that person's consent, unless the image concerns a fact, event, or ceremony of public interest or one that took place in public, or the person's notoriety, public office, or the requirements of justice, police, or a scientific, cultural, or didactic interest justifies the use.

Do not divulge the contents of a confidential letter, electronic message, or other private communication addressed to another person without the consent of its author.

Estonia Personal Data Protection Act (Isikuandmete kaitse seadus)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Estonia, including data collected by crawling.

Eswatini Data Protection Act, 2022 (Act No. 5 of 2022)

Obtain a lawful basis, such as the data subject's explicit consent, contractual necessity, compliance with a legal obligation, or another listed ground, before processing personal information of an identifiable individual, whether by automated or non-automated means.

Ethiopia Personal Data Protection Proclamation

Have a lawful basis for processing personal data before collecting, storing, or otherwise processing it, whether by automated means or in a filing system.

Take consent only where it is free, informed, specific and clear and requires an active action from the data subject, request it separately from other terms rather than bundled with them, let the data subject withdraw it at any time, and be able to prove it was given.

European Union General Data Protection Regulation (GDPR), Comprehensive Regime

Establish and document a lawful basis under Article 6 before processing any personal data of a person in the EU.

Finland Data Protection Act (Tietosuojalaki)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Finland, including data collected by crawling.

France Loi Informatique et Libertés, GDPR-Aligned Comprehensive Regime (Data Processing, Data Files and Individual Liberties Act)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in France, and follow Loi 78-17 Article 6's cross-reference to GDPR Article 9 for any special-category data.

Gabon Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023

Have a lawful basis for processing, such as the data subject's consent, a legal obligation, a public-service mission, contract performance, or a legitimate interest that does not override the data subject's own rights and freedoms.

Where you rely on consent, be able to demonstrate it was given and present the request clearly and separately from other terms; never treat acceptance of general terms of use or a pre-checked box as consent, and in an electronic transaction take it through an unambiguous act such as a checkbox.

+1 more
Gambia Personal Data Protection and Privacy Act, 2025 from a date not yet set

Establish one of the Act's seven lawful bases before processing personal data, whether you are established in The Gambia or process the data of individuals in the country from outside it.

Georgia Law on Personal Data Protection, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Georgia must establish a lawful basis for the processing under Art. 5 of the Law on Personal Data Protection.

Germany Bundesdatenschutzgesetz (BDSG), Federal Data Protection Act

Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Germany.

Where you process employee data, including biometric data for workplace access or time and attendance, satisfy BDSG Section 26(3)'s stricter conditions rather than relying on employee consent alone.

Ghana Data Protection Act

Have a lawful basis for processing personal data, and register with the Data Protection Commission before processing begins.

Do not require a person to supply or produce a particular record, including a health record, as a condition of providing them goods, facilities, or services, unless the requirement is authorised by law or is in the public interest.

Greece Law 4624/2019, Greek GDPR Implementation Law (Nomos 4624/2019, N. 4624/2019)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Greece, including data collected by crawling.

Ground employee consent to data processing in Greece on more than the ordinary GDPR consent standard, since Law 4624/2019 narrows employee consent to exceptional cases given the dependence inherent in an employment relationship, per secondary commentary.

Grenada Data Protection Act, No. 1 of 2023 from a date not yet set

Establish a lawful basis, ordinarily the data subject's consent, before processing personal data about them, or rely on one of the Act's specific alternative grounds such as contractual necessity, a legal obligation, or a statutory or government function.

Do not disclose personal data for a new purpose or to a new class of recipient without the data subject's consent, unless the disclosure prevents or detects crime, is authorised by an enactment or court order, or the Minister deems it justified as being in the public interest.

Guatemala Ley de Acceso a la Información Pública, Decreto 57-2008 (personal-data provisions)

Do not disseminate, distribute, or commercialize personal data held in an information system without the data subject's express written consent.

Never commercialize sensitive personal data (racial or ethnic origin, political ideology, religious belief, health, sexual life, or similarly intimate data) by any means.

+1 more
Hungary Infotörvény (Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Hungary; the Infotorveny supplements the GDPR with mainly procedural rules rather than a substantive addition to that basis.

Iceland Act No. 90/2018 on Data Protection and the Processing of Personal Data

Establish a lawful basis under Act No. 90/2018 Article 8 (mirroring GDPR Article 6) before processing personal data of a person in Iceland, including data collected by crawling.

India Digital Personal Data Protection Act, 2023, comprehensive regime and lawful basis from , in 7 months

India's Digital Personal Data Protection Act has not yet begun to bind app developers as of the date shown; its lawful-basis and consent duties are scheduled to commence . Once in force, an app that collects, uses, or discloses the personal data of an individual in India, including a voiceprint, faceprint, or other biometric identifier, which the Act treats as ordinary personal data since it has no separate sensitive-category tier, will need a lawful basis under section 4, ordinarily the data principal's free, specific, informed, and unambiguous consent under section 6, or one of section 7's enumerated legitimate uses.

Indonesia Law on Personal Data Protection, comprehensive regime

An app that collects, uses, or discloses the personal data of an individual in Indonesia must establish a lawful basis under Article 20, most commonly consent, though the procedural detail for several related duties awaits implementing regulations that had not yet issued as of the date shown.

Ireland Data Protection Act 2018

Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Ireland.

Ireland DPC Guidance: AI, Large Language Models and Data Protection

Establish a lawful basis before collecting or otherwise using personal data, including publicly accessible personal data, to train an AI model on people in Ireland, and account for the purpose the person originally made that data public for, not only whether it was public.

Italy Codice Privacy (Personal Data Protection Code), as Amended for GDPR Alignment

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Italy, following the Codice Privacy's institutional and procedural rules.

Jamaica Data Protection Act, 2020, registration, lawful basis and standards for processing

Have at least one condition under section 23 for every processing operation, such as the data subject's consent, the performance of a contract, a legal obligation, or a legitimate interest that is not outweighed by the data subject's rights and freedoms.

Jordan Personal Data Protection Law, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Jordan must obtain consent or rely on one of the Law's enumerated alternative bases, must confine retention to the processing purpose unless legislation specifies otherwise, and must appoint a data-protection lead if it processes Sensitive Personal Data or transfers personal data to a database outside Jordan.

Kazakhstan Law on Personal Data and Their Protection, comprehensive regime and lawful bases

An app that collects, uses, or discloses the personal data of individuals in Kazakhstan must obtain the subject's consent, or rely on one of the Law's limited consent-free grounds, before processing, and must confine that processing to the stated purpose of collection.

Kenya Data Protection Act, 2019

Obtain consent from a child's parent or guardian, verified through an age-verification mechanism, before processing that child's personal data.

Kiribati Data Protection Act 2025 from a date not yet set

On commencement, process personal data only on one of the Act's lawful bases, such as consent, contract necessity, legal obligation, or legitimate interests, and only for a purpose that is explicit and not prohibited by law.

Kosovo Law No. 06/L-082 on Protection of Personal Data

Establish a lawful basis under Article 5 before processing personal data of a person in Kosovo, and apply the Article 4 principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability throughout.

Use personal data collected from public sources for direct marketing only as Article 73 allows, limited to name, address, telephone number and email address unless the data subject has separately consented, and obtain written consent before using sensitive personal data for marketing.

Kuwait CITRA Data Privacy Protection Regulation from a date not yet set

An app that is a CITRA-licensed telecommunications or information-technology service provider in Kuwait must, per secondary legal-commentary sources not yet confirmed at primary source, obtain a customer's explicit consent (or a guardian's, for a minor under 18) before collecting or processing personal data, a duty that reaches a voiceprint or faceprint like any other identifying data, since the reported consent requirement carries no category-specific qualification; this is an inference from secondary commentary, not an independently confirmed reading of the regulation's own biometric-data treatment. Kuwait has no general cross-sector personal-data statute, so an app outside CITRA's licensed scope is not currently bound by a dedicated privacy law of this kind.

Latvia Personal Data Processing Law (Fizisko personu datu apstrādes likums)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Latvia, including data collected by crawling.

Lesotho Data Protection Act, 2011 (Act No. 5 of 2012)

Obtain a lawful basis, such as the data subject's explicit consent, contractual necessity, compliance with a legal obligation, or another listed ground, before processing personal information of an identifiable individual, whether by automated or non-automated means.

Liberia Telecommunications Act of 2007, Protection of Personal Information (§§ 51-52)

Collect, use, maintain, or disclose a telecommunications customer's information or communications only as permitted or required by law, or with that customer's consent.

Libya Law No. 6 of 2022, protection of personal data collected in electronic transactions

Before collecting personal data for issuing, maintaining, or facilitating an authentication certificate, obtain the person's explicit consent, and do not use it for a different purpose without a further explicit consent.

Do not collect, disclose, provide, or process personal data without the data subject's consent unless it is necessary to prevent or detect a crime under an official request from investigative bodies, required or permitted by law or a court decision, needed for a tax assessment or collection, or needed to protect the person's vital urgent interest.

+1 more
Liechtenstein Datenschutzgesetz (DSG)

Establish a lawful basis under the DSG, mirroring GDPR Article 6, before processing personal data of a person in Liechtenstein, including data collected by crawling.

Lithuania Law on Legal Protection of Personal Data

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Lithuania, including data collected by crawling.

Luxembourg Act of 1 August 2018 on the Organisation of the CNPD and the General Data Protection Framework

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Luxembourg, including data collected by crawling.

Madagascar Law No. 2014-038, protection of personal data

Have the data subject's consent, or another of the five lawful grounds in article 17, before processing personal data.

Process data on a subcontractor's behalf only on the controller's instructions, and use only a subcontractor that offers sufficient guarantees to implement the required security measures.

Maine Broadband internet access service, customer personal information privacy from a date not yet set

Obtain a Maine broadband customer's express, affirmative, opt-in consent before using, disclosing, selling, or permitting access to their customer personal information, and let them revoke that consent at any time.

Do not refuse service, or charge a penalty or offer a discount, based on a customer's consent decision under this statute.

Malawi Electronic Transactions and Cyber Security Act, 2016, personal data processing and security duties (Part VII)

Have a lawful basis before processing personal data: the data subject's unambiguous consent, contractual necessity, compliance with a legal obligation, protecting the data subject's vital interests, a public interest or official task, or your own legitimate interests where they do not override the data subject's rights and freedoms.

Malaysia Personal Data Protection Act, comprehensive regime and lawful bases

An app that collects, uses, or discloses the personal data of an individual in Malaysia must obtain consent, subject to the contract, legal-obligation, or vital-interest exceptions, and processing sensitive personal data needs the data subject's explicit consent under the Act's stricter standard.

Maldives Personal Data Protection Bill, pending before the People's Majlis proposed

If enacted as drafted, a Controller or Processor would need a lawful basis before processing personal data, would have to collect it only for specific, explicit and legitimate purposes declared before collection, and would not be able to process it further in a way incompatible with those purposes.

Malta Data Protection Act, Chapter 586 of the Laws of Malta

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Malta, including data collected by crawling.

Mauritius Data Protection Act 2017, establishment and lawful processing

Process personal data lawfully, fairly and transparently, only for an explicit and legitimate purpose that fits one of the Act's listed lawful-processing grounds.

Obtain the consent of a child's parent or guardian, verified with reasonable effort, before processing the personal data of a child below 16.

Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)

Obtain the data subject's consent, express or tacit, before processing their personal data, unless a listed statutory exception applies, and treat consent for financial or patrimonial data as requiring express consent.

Moldova Law No. 195/2024 on Personal Data Protection

Establish a lawful basis and allocate controller and processor duties before processing personal data of a person in Moldova.

Take consent only on the conditions article 7 sets, and be able to demonstrate the data subject gave it.

Monaco Loi sur la Protection des Données Personnelles

Establish one of the lawful bases Article 5 lists, such as consent, contract necessity, a legal obligation, vital interests, an important public interest ground, or legitimate interest, before processing personal data of a person in Monaco.

Take consent only as a free, specific, informed and unambiguous act, present a bundled consent request separately from other terms, and do not make consent a condition of a good or service unless the processing is indispensable to providing it.

Montenegro Law on Personal Data Protection from a date not yet set

Establish a lawful basis, such as the data subject's prior consent or one of the grounds listed in Article 10, before processing personal data of a person in Montenegro.

Morocco Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data

Obtain the data subject's unambiguous consent before processing their personal data, unless a legal obligation, contract performance, vital interest, public interest mission, or legitimate interest ground applies.

Nauru Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications

As a licensed communications service provider, do not disclose information concerning a subscriber without the subscriber's written consent, unless the Act or another written law requires or authorises the disclosure.

Take reasonable steps to maintain the confidentiality of a subscriber's communications, and do not intercept, monitor, alter, or modify their content except as permitted or required by law.

+2 more
Nepal Privacy Act, 2075, general privacy and collection regime

An app that collects, uses, or discloses the personal information of an individual in Nepal, including a voiceprint, faceprint, or other biometric identifier, must have the person's consent or fall within a statutory exception before collecting it, and a body corporate must limit use to its stated purpose and obtain consent before using the information for another purpose.

Netherlands Uitvoeringswet Algemene verordening gegevensbescherming (UAVG), GDPR Implementation Act

Establish a GDPR Article 6 lawful basis before processing personal data of a person in the Netherlands, following the UAVG's institutional and procedural rules and Chapter 3-4 national derogations.

New Zealand Privacy Act 2020, Information Privacy Principles and Extraterritorial Reach

Do not collect personal information unless it is for a lawful purpose connected with a function or activity of your organisation and the collection is necessary for that purpose.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales

Before processing personal data, obtain the data subject's consent, unless a listed exception applies.

Assign or transfer personal data domestically only for a purpose directly related to your legitimate interest and that of the recipient, and only with the data subject's prior, informed, and revocable consent, unless a listed exception applies.

Niger Loi n° 2022-59, protection des données à caractère personnel

Obtain the data subject's express prior consent before processing their personal data, unless the processing is necessary for a legal obligation, a public-interest or official mission, performance of a contract, or safeguarding the data subject's own vital interests or fundamental rights.

Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Process personal data on one of the lawful bases section 25 recognises, and hold to the section 24 principles of fairness, lawfulness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, confidentiality, integrity and availability.

Take consent for cookies and other tracking tools freely, informed and specific, display a conspicuous cookie banner at the first part of the page, and let a data subject reject every cookie other than the necessary ones that carry security, network stability and accessibility.

North Macedonia Law on Personal Data Protection (LPDP)

Get the Agency's prior approval before any systematic and extensive processing of a citizen's national identification number, and otherwise process it only with the data subject's prior consent or another case a law states.

Process personal data for direct marketing, including related profiling, only after the data subject has given explicit consent.

North Macedonia Law on Personal Data Protection (LPDP), video surveillance

Obtain the written consent of at least 70% of the owners or tenants of a single-unit or multi-unit residential building before introducing video surveillance there, and never transmit its recordings over cable television, the internet or another electronic means, or record the entrances to other individual apartments.

Norway Personal Data Act (personopplysningsloven)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Norway, including data collected by crawling.

Ground the processing of a Norwegian national identity number (fodselsnummer) or other unique identifier on a legitimate need for secure identification, under Personal Data Act Section 12.

Oregon Oregon Consumer Privacy Act (OCPA), general applicability and controller duties

Do not sell precise geolocation data or process a known Oregon minor's (under-16) data for targeted advertising, sale, or profiling; both are prohibited outright as of .

Panama Ley 81 de 2019, Sobre Protección de Datos Personales

Have a lawful basis, such as consent, contractual necessity or a legal obligation, before processing a person's personal data, and use it only for the purpose for which it was collected.

Paraguay Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months

Establish a valid legal basis, such as the data subject's consent or a contract, before processing any personal data, and make sure any consent obtained is prior, free, informed and unambiguous.

Obtain the consent of a child or adolescent only on the terms article 7 sets, and rely on legitimate interest only where article 8 allows.

Peru Ley 29733, Ley de Protección de Datos Personales

Obtain a person's prior, informed, express, and unequivocal consent before processing their personal data, unless a law authorizes the processing without it, and let them revoke that consent at any time under the same requirements that applied when they gave it.

Philippines Data Privacy Act of 2012, comprehensive regime and lawful processing criteria

An app that processes the personal information of an individual in the Philippines must satisfy one of the Act's lawful-processing criteria, with a stricter, separate standard for sensitive personal information, even though the Act's own sensitive-category list does not name biometric data specifically; a faceprint or voiceprint is still personal information subject to the Act's general processing criteria.

Poland Act on the Protection of Personal Data of 10 May 2018

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Poland; the Act adds no Polish derogation to the Article 6 list.

Portugal Lei n.o 58/2019, Portuguese GDPR Implementation Law (Lei de Execução do RGPD)

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Portugal, including data collected by crawling.

Qatar Personal Data Privacy Protection Law, comprehensive regime

An app that collects, uses, or discloses the personal data of an individual in Qatar, including a voiceprint, faceprint, or other biometric identifier, must have a lawful, consent-and-purpose-based basis for processing under the PDPPL; Qatar's special-nature-data list does not name biometric data as its own heightened category, but ordinary personal data duties still apply to it.

Québec Act respecting the protection of personal information in the private sector, comprehensive regime

Obtain clear, free and informed consent requested for each specific purpose before using or communicating personal information for a purpose other than the one for which it was collected, and obtain express consent where the information is sensitive.

Republic of the Congo Law No. 29-2019 on the Protection of Personal Data

Obtain the data subject's consent before processing their personal data, unless a legal obligation, public-interest mission, vital-interest, or another statutory ground applies.

Romania Law No. 190/2018 on Measures for the Implementation of Regulation (EU) 2016/679

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Romania; the Act's own text is not confirmed, and any Romanian-specific addition to that basis is unverified.

Russia Federal Law No. 152-FZ "On Personal Data"

Establish one of the six Article 6 lawful bases, consent, contract performance, legal obligation, vital interests, legitimate interests, or the journalism/science/literature/art exception, before processing personal data of a person in Russia.

Rwanda Law relating to the Protection of Personal Data and Privacy

Have a lawful basis under this Law, such as the data subject's consent or one of the other seven grounds article 46 lists, before processing personal data.

Where consent is the basis for processing, obtain it only after the data subject is informed of the consequences of consenting, and let the data subject withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

Saint Kitts and Nevis Data Protection Act, 2018 from a date not yet set

Obtain a data subject's consent before processing their personal data other than sensitive personal data, unless a listed exception applies.

Do not disclose personal data for a new purpose without the data subject's consent, except where crime prevention or detection, legal authorisation, a reasonable belief in a right or in the data subject's consent, or the public interest applies.

Saint Lucia Data Protection Act

Obtain a person's express consent before processing their personal data, unless a specific ground applies such as performing a contract with them, complying with a legal obligation, or a legitimate interest that does not override their privacy rights, and let them object to processing done on public interest or legitimate interest grounds and revoke consent at any time.

Samoa Telecommunications Act 2005, confidentiality and protection of customer personal information

Do not disclose information concerning a telecommunications customer without the customer's written consent, unless disclosure is required or permitted by the Regulator or by law.

Take all reasonable steps to keep customer communications confidential, and do not intercept, monitor, alter, or modify their content except as the Act permits.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Establish a lawful basis before processing personal data of a person in San Marino under Law 171/2018.

Take consent only where you can demonstrate the data subject gave it, and for an information society service offered to a child, only on the terms article 7 sets.

Sao Tome and Principe Lei n.º 03/2016, Protecção de Dados Pessoais

Obtain the data holder's unequivocal authorization before processing their personal data, or rely on one of the Law's specific grounds: performing a contract with them, a legal obligation you face, protecting their vital interests, a public-interest mission, or your own legitimate interest weighed against their rights.

Saudi Arabia Personal Data Protection Law, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Saudi Arabia must establish a lawful basis under the Personal Data Protection Law, most commonly the Data Subject's consent, following the consent mechanics set out in the Implementing Regulations.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel (Personal Data Protection Act)

Have a lawful basis, ordinarily the person's consent, before collecting, processing, transmitting, storing, or using their personal data.

Serbia Law on Personal Data Protection

Have one of the lawful grounds Article 12 lists, such as consent, contract necessity, legal obligation, vital interest, public interest, or legitimate interest, before processing personal data of a person in Serbia.

Take consent only where you can demonstrate it was given, present a bundled consent request separately from other matters in plain, simple language, and let the person withdraw consent at any time as easily as they gave it.

Seychelles Data Protection Act, 2023, application and processing principles

Have a lawful basis for processing personal data, such as informed and explicit consent, contractual necessity, a legal requirement, or a legitimate interest.

Allow a data subject to withdraw consent at any time, without this affecting the lawfulness of earlier processing.

Singapore Personal Data Protection Act, comprehensive consent-based regime

An app that collects, uses, or discloses the personal data of an individual in Singapore must obtain the individual's consent, or rely on a Part 3 or Schedule exception, and must state its purpose for the collection, use, or disclosure.

Slovakia Act on the Protection of Personal Data

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Slovakia; the Act's own text is not confirmed, and any Slovak-specific addition to that basis is unverified.

Slovenia Zakon o varstvu osebnih podatkov (ZVOP-2), Personal Data Protection Act

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Slovenia, and expect ZVOP-2's own institutional and procedural rules to govern rather than a GDPR restatement alone.

Solomon Islands Telecommunications Act 2009, Confidentiality and Consent Duties

If operating as a licensed telecommunications service provider in Solomon Islands, do not collect, use, maintain, or disclose a consumer's information without the consumer's consent, other than publishing the consumer's name, address, and listed telephone number in a directory.

Take all reasonable steps to keep a consumer's communications confidential, and do not intercept, monitor, alter, or modify the content of a message without authorisation.

Somalia Data Protection Act No. 005 of 2023

Establish a lawful basis before processing personal data, such as the data subject's consent, the performance of a contract, a legal obligation, or the data subject having intentionally made the data public, and process it fairly and transparently.

Where you rely on consent, be able to prove the data subject gave it.

South Africa Protection of Personal Information Act 4 of 2013 (POPIA)

Obtain a lawful basis, such as the data subject's consent, before processing personal information, and limit processing to the purpose for which it was collected.

South Korea Personal Information Protection Act, comprehensive regime and lawful bases

An app that collects, uses, or discloses the personal data of individuals in South Korea must establish one of PIPA's lawful processing grounds, most commonly consent or a documented legitimate interest justification, before processing, and must confine use to the stated purpose of collection.

South Korea PIPC Guideline on Processing Publicly Available Data for AI Development and Services

An app training AI models on personal data scraped from publicly accessible Korean web sources must rely on and document PIPA Art. 15(1)(6)'s legitimate interest basis, since publicly available data is not exempt from PIPA.

Spain Ley Orgánica 3/2018 (LOPDGDD), GDPR-Aligned Comprehensive Regime

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Spain, and rely on a statute-rank Spanish or EU norm rather than mere regulation if the basis is public interest or legal obligation, per LOPDGDD Article 8.

Sri Lanka Personal Data Protection Act, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Sri Lanka, including a voiceprint or faceprint, must have a lawful basis under Schedule I, ordinarily consent, contract necessity, or a legitimate interest satisfying a balancing test, and must give a data subject a way to seek review of a decision based solely on automated processing that has created or is likely to create an irreversible and continuous impact on their rights.

Suriname Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed

Have a lawful basis, such as a contract, a legal obligation, vital interests, a public interest task, official authority, a legitimate interest that does not override the data subject's rights, or the data subject's consent, before processing personal data.

Where processing rests on consent, present the request separately from other matters, in clear and simple language, and let the data subject withdraw consent as easily as it was given.

Sweden Dataskyddslagen (Data Protection Act), GDPR-Complementing Provisions

Establish a GDPR Article 6 lawful basis before processing personal data of a person in Sweden; Dataskyddslagen adds domestic legal bases mainly for public-sector processing, not a modification of the private-sector Article 6 list.

Switzerland Federal Act on Data Protection (nFADP), General Processing Principles

Have a justification, consent, an overriding private or public interest, or a legal basis, before processing personal data of a person in Switzerland in a way that would otherwise violate their personality rights.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data

Determine a lawful basis under one of the grounds article 7 lists before processing personal data, such as the data subject's consent to a specific purpose, a contractual or legal obligation, or a court order.

Taiwan Personal Data Protection Act (個人資料保護法)

Collect, process, or use the personal data of an individual in Taiwan only for a specific purpose and on one of the Act's stated lawful bases, and confine use to the purpose stated at collection unless a further basis under Article 16 or 20 applies.

Tajikistan Law on the Protection of Personal Data, comprehensive regime

An app that collects or processes the personal data of individuals in Tajikistan must obtain the subject's consent, limit processing to a specific, predetermined, lawful purpose, and notify the subject of the data collected about them with a right to correction.

Thailand Personal Data Protection Act, comprehensive regime

An app that collects, uses, or discloses the personal data of an individual in Thailand must obtain consent by default before processing, unless a Section 24 statutory exception applies.

Timor-Leste Constitution of the Democratic Republic of Timor-Leste, Section 38(2) (Personal data deferred to statute)

Rely on Section 38's own two operative rules, the access right and the sensitive-category consent bar, rather than on a statutory definition of personal data, because none exists to scope a Timor-Leste deployment against.

Togo Loi n° 2019-014, protection des données à caractère personnel

Have a lawful basis for processing personal data, generally the data subject's consent, or rely on a legal obligation, a public interest task, contract performance, or the data subject's vital interests.

Tonga Privacy Act 2025, comprehensive personal information protection regime from a date not yet set

Do not process personal information unless the data subject has given specific, informed consent that has not been withdrawn, or another lawful basis in section 27 applies, such as contractual necessity, a legal obligation, vital interests or the public interest.

Trinidad and Tobago Data Protection Act, 2011

Whether or not Part III or Part IV binds you yet, be responsible for the personal information under your control, identify the purpose of collection before or at the time of collection, and get the individual's knowledge and consent for its collection, use or disclosure.

Tunisia Organic Act on the Protection of Personal Data

Do not make providing a service or granting a benefit conditional on a person accepting that their data be processed or reused for a purpose other than the one it was collected for.

Do not communicate personal data to a third party without the person's express consent given in a form leaving a written trace, unless a listed public security, defense or criminal prosecution exception applies.

Turkey Personal Data Protection Law (KVKK), comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Turkey must establish one of KVKK Art. 5's lawful bases, most commonly explicit consent, before processing, and must confine use to the stated purpose of collection.

Turkmenistan Law on Information About Private Life, comprehensive regime

An app that collects or processes the personal information of individuals in Turkmenistan must obtain the subject's written consent, may not expand its use beyond the original purpose without further consent, and may not subcontract its collection or processing duties to another party by contract.

Uganda Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Obtain the data subject's prior consent before collecting or processing their personal data, unless a specific ground in section 7(2) applies, such as a legal requirement, a public duty, national security, a contract with the data subject, or a legal obligation.

Ukraine Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed

Once enacted, process personal data of a person in Ukraine only under a lawful basis, applying the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.

Once enacted, rely on legitimate interests as a legal basis for processing personal data of a person in Ukraine, alongside consent and contract, under the draft's expansion of legal bases toward GDPR Article 6.

Ukraine Law of Ukraine On the Protection of Personal Data

Establish a lawful basis before processing personal data of a person in Ukraine under Law No. 2297-VI.

United Arab Emirates ADGM Data Protection Regulations, comprehensive regime

An app that is a controller or processor established in or targeting the ADGM free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier, including one derived from a photo, video, or audio recording.

United Arab Emirates DIFC Data Protection Law, comprehensive regime

An app that is a controller or processor established in or targeting the DIFC free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier used to uniquely identify a natural person, including one derived from a photo, video, or audio recording.

United Arab Emirates Federal Decree-Law on the Protection of Personal Data, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in the onshore UAE must establish a lawful basis under PDPL Art. 4, ordinarily consent, and must obtain the Data Subject's explicit consent before processing a faceprint, voiceprint, or other identity-linked biometric identifier, including one derived from a photo, video, or audio recording, since biometric data is a category of Sensitive Personal Data.

United Kingdom UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025

Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.

Do not rely on the recognised legitimate interests basis if you are a public authority exercising your own core functions; a necessity test still applies even though no balancing test is required.

Uruguay Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Obtain the data subject's free, prior, express, and informed consent, documented in writing, before processing their personal data, unless a listed exception applies (data from public sources, a legal mandate, a state function, or a contractual, scientific, or professional relationship).

Communicate personal data to a third party only for a purpose directly tied to the sender's and recipient's legitimate interest, only with the data subject's prior consent, and only after telling them the purpose of the communication and identifying the recipient.

Uzbekistan Law on Personal Data, comprehensive regime and lawful bases

An app that collects, uses, or discloses the personal data of individuals in Uzbekistan must establish one of the Law's lawful bases, most commonly the subject's consent, before processing.

Vanuatu Data Protection and Privacy Act 2024, comprehensive personal data protection regime

Do not process personal data unless it is processed fairly and transparently for an explicit, specified and legitimate purpose under one of the lawful purposes in section 5, such as the data subject's consent, contract necessity, a legal obligation, the public interest, or a legitimate interest that does not override the data subject's rights.

Be able to demonstrate evidence of a data subject's consent, present any request for consent clearly and separately from other matters, obtain it for each specific purpose, and let the data subject withdraw it at any time, free of charge.

Virginia Virginia Consumer Data Protection Act (VCDPA), general applicability and controller/processor duties

Obtain a Virginia consumer's opt-in consent before processing sensitive data, and treat information a consumer restricted to a specific audience as covered personal data, not as exempt publicly available information.

Do not sell precise geolocation data collected from Virginia residents. A 2026 amendment added an outright ban on that sale.

Zambia Data Protection Act, 2021, personal data processing framework

Before processing personal data, establish a lawful basis such as consent, a contract, a legal obligation, or a legitimate interest, and process it fairly, transparently, and only for the purpose collected.

Tell a data subject of the right to withdraw consent before they give it, present the request separately from other matters in clear and plain language, be able to prove the consent was given, and destroy immediately every piece of personal data collected after a withdrawal.

+1 more

Sensitive categories

163 laws, 158 places
PlaceLawWhat it asks, as read here
Alabama Alabama Personal Data Protection Act (HB 351), sensitive data and biometric consent from , in 7 months

Once effective, obtain an Alabama consumer's consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual, racial or ethnic origin, religious belief, a health diagnosis, sexual orientation, citizenship or immigration status, or precise geolocation.

Albania Law No. 124/2024, special categories of personal data, criminal records and children's data

Do not process sensitive data, meaning racial or ethnic origin, political opinions, religious or philosophical belief, trade union membership, genetic data, biometric data, health records, or sexual orientation, unless a listed exception applies, such as the data subject's explicit consent to a specified purpose.

Treat a facial image or other biometric identifier as sensitive data requiring one of Article 9's listed exceptions before you may process it; the definition names a facial image as an example, so a derived faceprint is covered and the definition is not confined to a raw recording.

+3 more
Algeria Loi n° 18-07 relative à la protection des personnes physiques, catégories de données sensibles et biométriques

Do not process data revealing racial or ethnic origin, political opinions, religious or philosophical convictions or trade-union membership, nor health data including genetic data, unless the data subject gave express consent, a public interest or legal provision authorises it, or the ANPDP authorised it.

Where you process genetic data as a doctor or biologist for preventive medicine, diagnosis or care, or process data a person has manifestly made public, or process sensitive data to establish or defend a legal claim, rely on the specific article 18 ground rather than express consent.

Andorra LQPD, special categories, children and criminal-offence data

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union affiliation, or process genetic data, biometric data used to uniquely identify a person, health data, or data about sex life or sexual orientation, unless a listed Article 9(2) exception applies, most commonly the data subject's explicit consent.

Confine any processing of personal data about a person's criminal convictions or offences, or related security measures, to what is strictly necessary and authorised by law or supervised by a public authority with adequate safeguards.

+1 more
Angola Law on the Protection of Personal Data, sensitive data categories

Do not process sensitive data (philosophical or political convictions, party or union membership, religious faith, private life, racial or ethnic origin, or health and sex life including genetic data) unless a legal provision permits it or the Agência de Protecção de Dados authorises it on one of its listed grounds, such as the data subject's unequivocal, express and written consent.

Process health and sex-life data, including genetic data, only with the data subject's or their legal representative's unequivocal, express and written consent or the APD's authorisation, unless it is for preventive medicine, medical diagnosis, consented medical care, health-service management, a medical emergency, or the public interest, and only through a health professional bound by professional secrecy.

+1 more
Antigua and Barbuda Data Protection Act, 2013, sensitive personal data

Do not process sensitive personal data, meaning information about a data subject's physical or mental health, sexual orientation, political opinions, religious or similar beliefs, or the commission or alleged commission of an offence, unless the data subject has given explicit consent to the processing.

Where consent is not obtained, process sensitive personal data only on a listed ground such as an employment law obligation, protecting the vital interests of the data subject or another person, medical treatment by a healthcare professional, legal proceedings or advice, the administration of justice, or exercising a function conferred by law.

Argentina Ley 25.326, sensitive data categories and health data

Do not require a person to provide sensitive data (racial or ethnic origin, political opinions, religious, philosophical, or moral convictions, union membership, or health or sexual-life information).

Collect and process sensitive data only for a reason of general interest authorized by law, or for statistical or scientific purposes where the data subject cannot be identified.

+2 more
Armenia Law on Protection of Personal Data, special category data

An app that processes a category of special data covered by Art. 12 from a person in Armenia must obtain the data subject's consent or rely on a specific legal provision authorizing the processing, and must stop processing immediately once that basis or purpose no longer applies.

Australia Privacy Act 1988 (Cth), Schedule 1, Sensitive and Biometric Information

Do not collect sensitive information about an individual, including biometric information used for automated biometric verification or identification, or a biometric template, unless the individual consents and the collection is reasonably necessary for the entity's functions, or a listed exception in Australian Privacy Principle 3.4 applies.

Austria GDPR Article 9, Special Categories of Personal Data Including Biometric Data, as Applied in Austria

Obtain explicit consent, or establish another GDPR Article 9(2) basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available.

Show the other 153 laws
Azerbaijan Law on Personal Data, special categories of personal data

An app that processes race, nationality, family-life, religious-belief, health, or conviction data from a person in Azerbaijan must have a specific statutory ground for that processing under Art. 9.7; biometric data is not one of these special categories under Azerbaijan's law and is governed instead by the Act's ordinary processing conditions.

Bahrain Personal Data Protection Law, sensitive personal data

An app processing an individual's race, ethnic origin, political or philosophical opinions, religious beliefs, union affiliation, criminal record, or health or sexual status in Bahrain must obtain the Data Subject's consent unless the Art. 5 public-availability exception applies; biometric data is not part of this Sensitive Personal Data category, so it is governed instead by the Art. 15 prior-authorisation rule.

Bangladesh Personal Data Protection Act, 2026, sensitive personal data and biometric data

An app that derives a facial image, voiceprint, or other biometric identifier from a person in Bangladesh must treat it as Sensitive Personal Data and satisfy one of section 7's narrower lawful-basis conditions, ordinarily the data principal's specific consent, before processing it.

Belarus Law of the Republic of Belarus On Personal Data Protection, special personal data

Do not process special personal data, meaning data on race or nationality, political opinions, trade union membership, religious or other beliefs, sex life or health, administrative or criminal records, or biometric or genetic data, without the personal data subject's consent, unless a listed exception applies, such as the data having been publicly disclosed by the subject, a labor relations purpose, or medical care by a bound professional, under Article 8.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, données sensibles et mineurs

Do not process sensitive personal data, including racial or ethnic origin, political opinions, religion or beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, or data about a person's sex life or sexual orientation, unless a listed exception applies, such as the data subject's explicit consent or data the person has manifestly made public.

Verify that a minor is at least sixteen years old before processing their personal data in connection with an information society service offered directly to them, and otherwise obtain the consent of the holder of parental responsibility, making reasonable efforts to verify that consent given the technology available.

+2 more
Bhutan Information, Communications and Media Act of Bhutan 2018, sensitive personal data and biometric information

An app that derives a voiceprint, faceprint, or other biometric identifier from a person in Bhutan must treat it as Sensitive Personal Data or Information and obtain the subject's express written permission before collecting it, unless the information is itself freely available or accessible in the public domain.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, special categories, criminal-conviction data and children's consent

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union affiliation, genetic data, biometric data for unique identification, health data, or data about a person's sex life or sexual orientation, unless a listed exception in Article 11 applies, such as the person's explicit consent.

Process personal data about a criminal conviction or offence only under the supervision of a public authority or where a special law authorizes it with safeguards for the person's rights, and keep any register of criminal convictions exclusively under a public authority's control, under Article 12.

+1 more
Botswana Data Protection Act, 2024, sensitive personal data and children's data

Obtain consent given or authorised by a parent or a person with parental duties over a child under sixteen before processing that child's personal data for an information-society service offered directly to them; a child who is sixteen may consent themselves.

Do not process racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, or data concerning sex life or sexual orientation, unless a listed exception applies, such as the data subject's explicit consent or data the person has manifestly made public.

+1 more
Brazil LGPD, sensitive personal data and children's data

Obtain specific, highlighted consent, or another article 11 legal basis, before processing sensitive personal data such as health, genetic, or biometric data.

Process a child's or adolescent's personal data only with specific, highlighted consent from at least one parent or legal guardian, except to contact the parent once without storing the data or to protect the child, and never condition participation in a game, application, or other activity on more personal data than the activity strictly needs.

Bulgaria GDPR Article 9 and PDPA Employment and National-ID-Number Rules from a date not yet set

Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, health, or other special-category personal data of a person in Bulgaria.

Do not use the Bulgarian national identification number (ЕГН) as a sole service identifier, and grant public access to it only where required by law, per commentary describing the PDPA; verify against the Act's own text before relying on it.

Burkina Faso Personal Data Protection Law, sensitive personal data categories

Obtain the data subject's express consent before collecting or processing sensitive personal data, including data about health, biometric or genetic characteristics, sex life, racial or ethnic origin, political, philosophical, religious or trade union opinions or activity, morals, or criminal investigations, prosecutions, convictions and administrative or safety measures, unless a specific statutory exception applies.

Restrict any processing of personal data about offenses, convictions or safety measures to a court or public authority acting within its legal powers, a public body managing a public service after the CIL's concurring opinion, or a legal auxiliary acting strictly within duties assigned to it.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data, sensitive data categories

Do not process personal data revealing philosophical, ideological or political beliefs or penalty, religion, political party or trade union affiliation, racial or ethnic origin, privacy, or health and sex life including genetic data, unless the data subject has expressly consented with a guarantee of non-discrimination, a legal authorisation applies with the same guarantee, or another of the law's listed grounds is met.

Process health and sex life data, including genetic data, only through a health professional bound by professional secrecy, only for preventive medicine, medical diagnosis, care or health service management, and only once notified to the CNPD under article 23, with adequate information security measures.

+1 more
Cambodia Cambodia's Draft Law on Personal Data Protection, sensitive personal data proposed

If enacted as drafted, a data controller would be prohibited from processing sensitive personal data, which would include a facial image, fingerprints, or another biometric identifier, genetic data, health data, and data revealing racial origin, political opinions, religious or philosophical beliefs, or trade union membership, unless it also met one of nine listed conditions, such as the data subject's explicit consent.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel, données sensibles et mineurs

Get a data subject's explicit consent, and apply extra security and organisational safeguards, before processing a sensitive category of data such as racial origin, biometric or genetic data, health data, or political, religious, or trade union information.

Get authorisation from a holder of parental responsibility before processing a minor's personal data, including for a direct offer of information society services to a child.

+2 more
Chad Loi n°007/PR/2015, traitement des catégories particulières de données (données sensibles et biométriques)

Do not process biometric data, or data revealing racial or ethnic origin, filiation, political opinion, religious or philosophical belief, trade-union membership, sex, health, or sexual life, unless the data subject gives explicit written consent or a listed statutory exception applies.

Process a minor's personal data only in keeping with the representation rules the law sets for the exercise of the minor's own rights.

China Personal Information Protection Law, Sensitive Personal Information

Obtain the individual's separate, explicit consent before processing any sensitive personal information, including a biometric identifier such as a faceprint or voiceprint, in addition to any general consent already collected.

Process biometric identifiers only for a specific, necessary purpose and under strict protective measures, and obtain guardian consent before processing a minor's data.

Colombia Ley 1581 de 2012, Sensitive Categories and Children's Data

Before processing sensitive personal data, including data revealing racial or ethnic origin, political opinion, religious or philosophical belief, union or human rights organization membership, health, sexual life, or biometric data, obtain the data subject's explicit authorization; processing sensitive personal data is otherwise prohibited.

Process sensitive personal data without the data subject's explicit authorization only where it protects the data subject's vital interest and they cannot consent, where a not for profit political, philosophical, religious or union body processes it about its own members without disclosing it to third parties, where it is needed to establish, exercise or defend a right in a judicial proceeding, or where it serves a historical, statistical or scientific purpose and the data subject's identity is suppressed.

+1 more
Colorado HB 24-1058, Protect Privacy of Biological Data

Treat data generated by measuring an individual's biological, genetic, biochemical, physiological, or neural properties, or central or peripheral nervous system activity, as sensitive data requiring the consumer's affirmative opt-in consent before you process it.

Colorado SB 24-041, Protecting Minors' Online Data

Get opt-in consent, parental consent for a minor under 13, before processing a minor's personal data for targeted advertising, sale, or profiling with legal or similarly significant effects.

Comoros Law on the Protection of Personal Data, sensitive personal data

Do not collect or process data revealing political, philosophical or religious opinions, trade union membership, or health or sexual life data, without the data subject's express consent, unless a listed exception applies, such as safeguarding a life the data subject cannot consent to protect.

Process data on offenses, convictions or security measures only as a court, a public authority, a body managing a public service, a legal auxiliary acting within your legal duties, or another legal person managing a dispute over an offense of which you were the victim.

Connecticut Connecticut Data Privacy Act, sensitive data and biometric data definitions

Obtain a Connecticut consumer's opt-in consent before processing sensitive data, including biometric data generated to uniquely identify the individual.

Czech Republic GDPR Article 9, Special Categories Including Biometric Data

Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, health, or other special-category personal data of a person in the Czech Republic; Act 110/2019 supplies no separate Czech basis.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data, sensitive categories of personal data

Do not process personal data revealing a person's racial, ethnic or regional origin, political opinion, religious or philosophical belief, trade-union membership, sex life, or genetic data concerning health, unless a listed exception applies.

Confine processing under the non-profit exception to the body's own members or to people with regular contact related to its purposes, and do not disclose the data to a third party without their consent.

Democratic Republic of the Congo Digital Code, Title III, sensitive personal data and minors

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, refugee or stateless status, trade union membership, sex life, or health, unless a statutory exception applies.

Rely on the data subject's explicit consent, a manifestly public disclosure by the data subject, a vital interest, an important public interest, a public authority's public-interest mission, public-statistics legislation, or supervised preventive or occupational medicine as the only grounds for processing a prohibited special category of data.

+1 more
Denmark GDPR Article 9, Special Categories of Personal Data as Applied in Denmark

Ground the processing of any biometric identifier of a person in Denmark, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent.

Djibouti Digital Code, Book I: sensitive categories of personal data and the minor's consent

Do not process sensitive personal data (racial or ethnic origin, political or philosophical opinions, religious opinions or beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, or health data) without the data subject's express consent or another statutory ground.

Let a minor consent alone to an information-society service's processing of their personal data only from age 16, obtain the consent of the person holding parental authority below that age, and make reasonable efforts to verify it given the technology available.

Dominican Republic Ley No. 172-13 sobre Protección Integral de los Datos Personales, special and sensitive categories of data

Obtain the data subject's free, conscious, and voluntary consent before forming a file, bank, or register that reveals their sensitive data (political opinions, religious or philosophical convictions, union affiliation, or health or sex-life information).

Do not create a data file, bank, or register that stores sensitive data except as this law provides, even though a church, religious association, clinic, hospital, or political or union organization may still keep a register of its own members.

+3 more
Ecuador LOPDP, categorías especiales de datos personales

Do not process personal data without a lawful basis under the Act, and obtain explicit consent before processing a sensitive category of data unless another enumerated ground applies.

Do not process sensitive data at all unless the data subject has given explicit consent or one of the other grounds article 26 lists applies.

+1 more
Egypt Egypt Personal Data Protection Law, Sensitive Personal Data and a child's data

Obtain a parent or legal guardian's consent before processing a child's personal data, and do not condition a child's participation in a game, competition, or activity on personal data beyond what participation requires.

Obtain the Data Subject's explicit written consent before any dealing with their Sensitive Personal Data, outside the cases a law authorises, on top of the Center's licence.

El Salvador Ley para la Protección de Datos Personales, sensitive personal data and children

Do not compel a person to provide sensitive personal data (data touching physical or moral characteristics, or facts of private life whose misuse could cause discrimination or gravely harm honor or privacy, including religious belief, ethnic origin, political or union affiliation, sexual preference, health, or biometric or genetic information); take it only with the data subject's express and unequivocal consent after telling them of their right to withhold it.

Obtain a sensitive data subject's consent in writing, by an autograph signature or its equivalent, and apply the Progressive Exercise of Faculties principle to a child's consent to provide their personal data.

+3 more
Estonia GDPR Article 9, Special Categories of Personal Data as Applied in Estonia

Ground the processing of any biometric identifier of a person in Estonia, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent.

Eswatini Data Protection Act, 2022, sensitive personal information

Do not process sensitive personal information, including genetic data, data related to children, data related to offences or criminal sentences, biometric data, or information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, gender, or health or sex life, unless a listed exemption applies.

Obtain prior parental consent before processing personal information under the parental control exemption, and rely on consent, legal necessity, or Commission authorisation for another listed exemption to the prohibition.

+1 more
Ethiopia Personal Data Protection Proclamation, sensitive personal data and minors

Do not process sensitive personal data, including genetic or biometric data, unless a listed exception applies, such as the data subject's specific written consent.

Process a minor's personal data only with the consent or authorization of a parent, guardian, or tutor, or where necessary to the minor's vitally important interest, and never for marketing, profiling, or merging of profiles.

+2 more
European Union GDPR Article 9, Special Categories of Personal Data Including Biometric Data

Obtain explicit consent, or establish another Article 9(2) basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available.

Treat any biometric identifier your system derives through its own technical processing as special category data, even where the underlying image or audio was lawfully public.

Finland GDPR Article 9 and Data Protection Act Section 6, Special Categories in Finland

Ground the processing of any biometric identifier of a person in Finland, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent, unless it falls within one of the eight contexts Data Protection Act Section 6 lists, none of which is biometric-specific.

Florida Florida Digital Bill of Rights, sensitive data and biometric data definitions

Obtain a qualifying Florida consumer's consent before processing sensitive data, including genetic or biometric data collected to uniquely identify the individual, if you meet FDBR's $1 billion-plus controller threshold.

Display the notice "NOTICE: This website may sell your sensitive personal data" and obtain consent before selling a qualifying consumer's sensitive personal data.

France GDPR Article 9 Special Categories, as Implemented by Loi 78-17 Article 6

Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, health, or other special-category personal data of a person in France; Loi 78-17 Article 6 supplies no separate French basis beyond the Regulation's own list.

Gabon Law No. 025/2023, sensitive categories of personal data and children's data

Process a minor's personal data only on their own consent once they turn eighteen, or otherwise only with the express authorization of the holder of parental authority, and confirm by some means that the consent you rely on is theirs.

Do not collect or process data revealing racial or ethnic origin, political, philosophical or religious opinions, trade-union membership, biometric or genetic data, or data on health or sex life, unless a listed exception applies, such as the data subject's own express consent, a non-profit body's processing of its own members, data the person made public, or preventive medicine and care administered by a bound health professional.

+3 more
Gambia Personal Data Protection and Privacy Act, 2025, sensitive personal data and children's data from a date not yet set

Do not process genetic or biometric data, or data revealing racial origin, political opinions or health status, unless you have both a lawful basis and one of the Act's listed conditions, such as the data subject's explicit consent.

Obtain parental or guardian consent before processing the personal data of a person under the age of 18, and put that child's best interests and privacy first.

Georgia Law on Personal Data Protection, special categories of data

An app that processes special-category data, including biometric or genetic data, from a person in Georgia must rely on one of Art. 6's 20 lawful grounds, most commonly the data subject's explicit consent.

Germany GDPR Article 9 and BDSG Section 26(3), Special Categories and Employment Biometric Data in Germany

Where you deploy a biometric time clock, access control system, or voice-authentication system for employees in Germany, satisfy BDSG Section 26(3)'s conditions rather than relying on employee consent as the sole basis.

Ghana Data Protection Act, special personal data

Do not process special personal data, including a person's ethnicity, race, political opinion, religious belief, health, sexual life, or criminal behaviour, or the personal data of a child under parental control, unless a listed exception applies.

Process special personal data only where it is necessary or the data subject consents, treating processing as necessary where it exercises or performs a right or obligation the law imposes on an employer.

+2 more
Grenada Data Protection Act, No. 1 of 2023, sensitive personal data from a date not yet set

Do not process sensitive personal data, including health, genetic, biometric, sex life, political or religious information, except on one of the Act's listed grounds, ordinarily the data subject's written consent.

Where you rely on a ground other than consent, confirm it is one the Act lists: an employment right or obligation, protecting the data subject's or another person's interests where consent cannot reasonably be obtained, medical purposes handled under a duty of confidentiality, legal proceedings or advice, the administration of justice, a government function, or information the data subject has already made public.

Guam Guam Uniform Civil Remedies for Unauthorized Disclosure of Intimate Images Act of 2019

Do not intentionally disclose, or threaten to disclose, a private intimate image of an identifiable person without that person's consent, when you know or recklessly disregard that the image is private, the person did not consent, or the person is identifiable.

Honduras Ley de Transparencia y Acceso a la Información Pública, protección de datos personales y hábeas data

Do not force a person to provide personal data that could cause them discrimination, or patrimonial or moral harm or risk.

Hungary Infotörvény Definitions, Biometric and Special-Category Data

Obtain an explicit GDPR Article 9(2) legal basis before processing biometric data of a person in Hungary; the Infotorveny's own definition tracks GDPR Article 4(14) without narrowing or expanding it.

Iceland Act No. 90/2018 Articles 3(14) and 9, Special Categories in Iceland

Ground the processing of any biometric identifier of a person in Iceland, including a faceprint captured for unique identification, on an Article 9(2)-style exception such as explicit consent, under Act No. 90/2018 Article 9.

Idaho Genetic Testing Privacy Act, restrictions on employers from a date not yet set

Do not access, request, or require an individual's private genetic information, or require a genetic test, as a condition of a hiring, promotion, retention, or other related employment decision in Idaho if you employ five or more persons.

Indiana Indiana Consumer Data Protection Act, sensitive data and biometric data definitions

Obtain an Indiana consumer's consent before processing sensitive data, including genetic or biometric data collected to uniquely identify the individual, or process a known child's sensitive data only under COPPA's consent framework.

Iran Electronic Commerce Law (2003), Personal Data Chapter

An app that stores, processes, or distributes data revealing a Iranian resident's tribal or ethnic origin, religious or moral belief, ethical characteristics, or physical, psychological, or sexual condition needs their explicit consent first. Any other collection or processing of personal data needs consent for a specified, described purpose, must be limited to that purpose, must stay accurate, and must let the person access their own data with a right to have it corrected or completely removed. The law names no biometric category, so a voiceprint or faceprint is not subject to a heightened consent, retention, or destruction standard beyond the general consent-based rule, and nothing in this chapter conditions moving personal data out of Iran or requires notifying anyone after a security incident. Violating Article 58's sensitive-data consent rule is a criminal offense (one to three years' imprisonment), state-prosecuted rather than privately actionable.

Ireland GDPR Article 9 and Data Protection Act 2018 Section 46, Special Categories and Employment Biometric Data in Ireland

Where you process special category data, including biometric data, about an employee in Ireland, ground it in a legitimate argument tied to vital interests or another Article 9(2) condition with a public-interest character, and put suitable and specific safeguarding measures in place, under Data Protection Act 2018 Section 46.

Treat any biometric identifier your system derives through its own technical processing as GDPR Article 9 special category data, whether or not the source photo or audio was publicly available.

Italy GDPR Article 9 Special Categories and Codice Privacy Article 167(2)

Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, genetic, or health data of a person in Italy, and treat unlawful special-category processing as a Codice Privacy Article 167(2) criminal exposure, not only an administrative one.

Jamaica Data Protection Act, 2020, conditions for processing sensitive personal data

Do not process genetic data, biometric data, health data or any other sensitive personal data unless at least one condition in section 24 is met in addition to a condition in section 23.

Obtain the data subject's consent in writing before processing their sensitive personal data on the consent condition, and stop processing on that condition once the consent is withdrawn.

+1 more
Jordan Personal Data Protection Law, sensitive personal data and biometric data

An app that processes biometric data about an individual in Jordan, including a faceprint or voiceprint, must treat it as Sensitive Personal Data and obtain consent or rely on one of the Law's enumerated exceptions, and must not retain it beyond the processing purpose unless legislation specifies otherwise. Whether Jordan requires a heightened, explicit-consent standard specifically for biometric processing, beyond ordinary consent, is not confirmed.

Kansas Genetic testing nondiscrimination in health-benefit insurance underwriting from a date not yet set

Do not require, request, or use a Kansas health-benefit-plan applicant's or enrollee's genetic test results to condition coverage, set rates, or adjust premiums.

Kansas Student Data Privacy Act, biometric data collection consent from a date not yet set

Obtain the written consent of an adult student, or the parent or legal guardian of a minor student, before a Kansas school district collects the student's biometric data, including a fingerprint, retina or iris pattern, voiceprint, DNA sequence, facial characteristic, or handwriting sample.

Obtain that same written consent before using a device or mechanism to assess a Kansas student's physiological or emotional state.

Kentucky Kentucky Consumer Data Protection Act, sensitive data and biometric data definitions

Obtain a Kentucky consumer's opt-in consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual.

Kenya Data Protection Act, 2019, sensitive personal data

Do not process biometric, genetic, health or other sensitive personal data unless a specific ground under section 45 applies, in addition to the Act's general lawful-basis requirement.

Do not process health data unless you are a health-care provider or a person bound by professional secrecy.

Kosovo Law No. 06/L-082 on Protection of Personal Data, special categories, children and criminal-offence data

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, or data about sex life or sexual orientation, unless a listed Article 8(2) exception applies, most commonly the data subject's explicit consent.

Confine any processing of personal data about a person's criminal convictions or offences, or related security measures, to what an official authority controls under the relevant law.

+1 more
Kyrgyzstan Digital Code, special categories of personal data

An app that processes biometric data for the digital identification of a Kyrgyzstani data subject, including a voiceprint or faceprint, must satisfy one of Art. 80(2)'s narrow lawful grounds before processing; such processing is prohibited by default otherwise. The Code itself supplies no illustrative list of biometric modalities for this general provision.

Latvia Personal Data Processing Law Article 25(2), Special Categories in Latvia

Ground the processing of any biometric identifier of a person in Latvia, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent, under Personal Data Processing Law Article 25(2).

Lebanon Law No. 81/2018, Part V, health, genetic identity and sexual-life data

Do not collect or process data that reveals, directly or indirectly, the health status, genetic identity or sexual life of a person in Lebanon.

Rely on one of the four exceptions only: the person made the data public or explicitly agreed to the processing and no legal impediment applies, the processing is necessary to establish a medical diagnosis or provide medical treatment by a healthcare professional, a right is being proved or defended before a court, or you hold a licence under Article 97.

Lesotho Data Protection Act, 2011, sensitive personal information

Do not process personal information concerning a child who is subject to parental control, or a data subject's spiritual, religious or philosophical beliefs, race or ethnic origin, trade union membership, political affiliation, health, sexual life, or criminal behaviour, unless a listed exemption applies.

Obtain prior parental consent before processing personal information under the parental control exemption, and rely on consent, legal necessity, or Commission authorisation for another listed exemption to the prohibition.

+1 more
Liechtenstein DSG Special-Category Data and Datenschutzstelle Biometric-Data Concept in Liechtenstein

Ground the processing of any biometric identifier of a person in Liechtenstein, including a faceprint or voiceprint captured for unique identification, on a DSG condition equivalent to GDPR Article 9(2), such as explicit consent.

Lithuania GDPR Article 9, Special Categories of Personal Data as Applied in Lithuania

Ground the processing of any biometric identifier of a person in Lithuania, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent.

Louisiana Louisiana Data Privacy Act (Act No. 502), sensitive and biometric data from , in 3 months

Obtain a Louisiana consumer's consent before selling sensitive data, if you meet the LDPA's revenue-from-sale applicability threshold.

Luxembourg GDPR Article 9, Special Categories of Personal Data as Applied in Luxembourg

Ground the processing of any biometric identifier of a person in Luxembourg, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent; no Luxembourg-specific addition to this baseline was found.

Madagascar Law No. 2014-038, sensitive personal data

Do not process sensitive data, including racial origin, biometric, genetic, political opinion, religious or other belief, trade union, health, or sex-life data, unless one of the law's listed exceptions applies, such as the data subject's express consent.

Restrict processing personal data about offenses, convictions, or safety measures to a court, a public authority managing a public service acting within its legal powers, or a legal auxiliary acting within the strict needs of a legally assigned mission.

Maldives Maldives Personal Data Protection Bill, special categories of personal data proposed

If enacted as drafted, a Controller would not be able to process special categories of personal data, which would include biometric data used to identify a person uniquely, genetic data and health data, unless one of the instances section 17 lists applied, such as the data subject's explicit consent to one or more specified purposes.

If enacted as drafted, a Controller relying on legitimate interest would have to weigh the position of a child, whose interests and fundamental rights the Bill treats as a particular reason that interest is overridden.

Mali Loi n° 2013-015, sensitive data and offence records

Do not process sensitive data (data relating to religious, philosophical, political, or union opinions or activities; sexual life or racial origin; health; social measures; prosecutions; or penal or administrative sanctions) unless the Autorité de Protection des Données à Caractère Personnel has defined appropriate safeguards for it and one of the listed conditions applies, such as necessity to safeguard the life of the data subject or a third party who cannot consent.

Limit any processing of personal data relating to offences and convictions to a court or public authority acting within its legal powers, a judicial auxiliary acting for the strict needs of duties the law assigns it, or another legal person handling, for the strict needs of managing contentious matters, offences of which it was itself the victim.

Maryland Maryland Online Data Privacy Act (MODPA), sensitive data and biometric consent

Do not collect, process, or share sensitive data, including genetic or biometric data, unless strictly necessary to provide a product or service the consumer requested. MODPA supplies no separate consent-only path around this necessity requirement.

Never sell sensitive data. MODPA bans the sale of sensitive data outright.

+1 more
Mauritania Loi n° 2017-020, catégories sensibles de données

Before collecting or processing data revealing racial, ethnic, linguistic, or regional origin, political opinion, religious or philosophical belief, trade union membership, sexual life, genetic data, or health, confirm one of the Act's ten listed exceptions applies.

Process data on criminal offences, convictions, or security measures only if you are a court, a public authority, a public-service body, or a legal auxiliary acting within your legal mission.

+1 more
Mauritius Data Protection Act 2017, special categories of personal data

Do not process a special category of personal data (including biometric data uniquely identifying a person) unless one of the specific grounds in section 29(1) applies, in addition to the Act's general lawful-processing requirement.

Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares, sensitive personal data

Obtain the data subject's express, written consent, by autograph signature, electronic signature, or another authentication mechanism, before processing their sensitive personal data, unless a statutory exception applies.

Do not create a database of sensitive personal data unless its creation serves a legitimate, specific purpose consistent with your explicit activities or aims.

Michigan Genetic test; informed consent from a date not yet set

Obtain a test subject's written, informed consent before a physician orders a presymptomatic or predictive genetic test in Michigan.

Minnesota Minnesota Consumer Data Privacy Act, sensitive data and biometric consent

Obtain a Minnesota consumer's opt-in consent before processing biometric data, or any other sensitive data, when that biometric data is processed for the purpose of uniquely identifying the individual.

Missouri Genetic information, insurer and employer restrictions, confidentiality duty

Do not require or request an individual's or their blood relative's genetic information or a genetic test, or consider genetic information or a genetic test result without the individual's approval, when making a health-plan eligibility, premium, coverage, or renewal decision.

Do not use an employee's or job applicant's genetic information or genetic test results to discriminate against them or restrict a right or benefit otherwise due them, unless a statutory exception applies.

+1 more
Moldova Moldova Law No. 195/2024, special categories, a child's consent and conviction data

Obtain explicit consent or another enumerated exception before processing biometric data, including facial images, of a person in Moldova for unique identification.

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data or data concerning health, sex life or sexual orientation, unless one of the article 9(2) cases applies.

+2 more
Monaco Loi sur la Protection des Données Personnelles, données sensibles et mineurs

Do not process sensitive data, meaning data revealing political, religious, philosophical, or trade union opinions, racial or ethnic origin, genetic data, biometric data used to identify a person uniquely, or data about health, sex life, or sexual orientation, unless one of the listed exceptions applies.

Where you rely on a person's explicit consent to process their sensitive data, keep evidence that the consent was specific, informed, and given by a clear positive act, since a law can also bar that prohibition from ever being lifted by consent alone.

+2 more
Mongolia Law on Protection of Personal Data, sensitive personal information

An app processing a Mongolian data subject's ethnicity, religion, belief, health, correspondence, genetic or biometric information, criminal-sentence status, sexual orientation, gender identity, or sexual-relations information must satisfy one of the Law's lawful-basis or health or legal-claim grounds before processing; this category expressly includes biometric and genetic information, so an app declaring only a biometric activity is still bound by this instrument, not only by the biometric_privacy instrument.

Montana Montana Consumer Data Privacy Act, sensitive data and biometric data definitions

Obtain opt-in consent before processing a Montana consumer's genetic or biometric data collected to uniquely identify them.

Montenegro Law on Personal Data Protection, special categories of data from a date not yet set

Do not process special categories of data, meaning data on racial or ethnic origin, political, religious or other beliefs, social origin, trade union membership, health, sex life or sexual orientation, biometric data, or criminal and misdemeanour records, unless one of the exceptions in Article 13 applies, starting with the data subject's consent.

Do not process personal data relating to criminal offences, criminal or misdemeanour penalties or security measures except by, or under the supervision of, the competent state authority, and only with the safeguards the law requires, under Article 14.

Morocco Law No. 09-08, sensitive personal data and offense records

Do not process sensitive data, meaning data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or health data including genetic data, without a specific legal authorization, the CNDP's prior authorization, or the data subject's express consent.

Do not process personal data about offenses, criminal convictions, or security measures unless you are a court, a public authority, a public service body, or an auxiliary of justice acting within your legal duties.

Nepal Privacy Act, 2075, sensitive information and biometric data

An app that holds a voiceprint, faceprint, or other biometric identifier of a person in Nepal must have the person's consent before disclosing or publishing it to a third party, and must have consent or lawful authorization before recording a private conversation to derive it in the first place, though Nepal's Privacy Act does not treat biometric data as a heightened "sensitive information" category the way it treats caste, political affiliation, religion, health, or sexual orientation.

Netherlands UAVG Articles 30-33 and 46, Health, Criminal-Conviction, and National-ID-Number Data

Obtain a GDPR Article 9(2) basis before processing health, genetic, racial or ethnic origin, political opinion, or religious-belief data of a person in the Netherlands, following UAVG's Chapter 3 exceptions where one applies to your processing purpose.

Do not treat the citizen service number (BSN) as a general-purpose identifier; UAVG Article 46 restricts its processing.

New Hampshire New Hampshire Data Privacy Act, sensitive data and biometric data definitions

Obtain a New Hampshire consumer's opt-in consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual, racial or ethnic origin, religious belief, a health condition, sexual orientation, citizenship or immigration status, a known child's data, or precise geolocation.

New Jersey New Jersey Data Privacy Act, sensitive data and biometric definition

Obtain a New Jersey consumer's opt-in consent before processing sensitive data, including biometric data, financial account information, or pregnancy-related health data.

New Mexico Genetic Information Privacy Act from a date not yet set

Obtain a person's informed, written consent before obtaining their genetic information or samples for genetic analysis, or before performing genetic analysis or collecting, retaining, transmitting, or using their genetic information, unless a statutory exception applies.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales, sensitive categories of data

Process sensitive personal data (racial or ethnic origin, political affiliation, religious or philosophical belief, union membership, health or sex life, criminal record, or financial and credit information) only on a general-interest ground recognized by law, the data subject's consent, or a judicial order.

Do not create a data file that stores sensitive personal data except as this Act provides, even though a commercial company or nonprofit association may still keep a file of its own members' data.

+4 more
Niger Loi n° 2022-59, données sensibles, de santé et biométriques

Do not process data revealing racial, ethnic or regional origin, political opinions, religious or philosophical beliefs, trade-union membership, sex life, health, genetic or biometric data, social measures, or criminal or administrative sanctions, unless the data subject made it manifestly public themselves, gave written consent, or another listed exception applies.

Process health data only for the listed purposes, such as preventive medicine, diagnosis, care administration, public health, safeguarding vital interests, administering social-protection benefits, a legal claim, or ethics-committee-approved research, and restrict that processing to medical professionals or persons bound by professional secrecy.

+2 more
Nigeria Nigeria Data Protection Act, 2023, sensitive personal data and a child's data

Obtain a data subject's consent before processing sensitive personal data, and before processing the personal data of a child.

Do not seek, give or accept consent in any circumstance that may propagate atrocities, hate, child rights violations or criminal acts.

North Macedonia Law on Personal Data Protection (LPDP), special categories, a child's consent and biometric, health and genetic data

The processing of a child's personal data for an information society service offered directly to the child is lawful where the child is at least 14 years old, or, if younger, only where a parent or another holder of parental responsibility has given or authorised the consent; make reasonable efforts to verify that consent, taking available technology into account.

Once Chapter II takes effect, do not process a special category of personal data unless one of Article 13's exceptions applies, such as the data subject's explicit consent, a necessity ground tied to employment or social security law, vital interests, or an important public interest carried out with suitable safeguards.

+1 more
Norway Personal Data Act Chapter 3 and GDPR Article 9, Special Categories in Norway

Ground the processing of any biometric identifier of a person in Norway, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent.

Oklahoma Oklahoma Consumer Data Privacy Act, sensitive data and biometric data definitions from , in 3 months

Obtain an Oklahoma consumer's opt-in consent before processing sensitive data, including genetic or biometric data collected to uniquely identify the individual.

Oregon Oregon Consumer Privacy Act, sensitive data and biometric data definitions

Obtain a lawful basis and, for sensitive data, opt-in consent before processing an Oregon consumer's genetic or biometric data.

Panama Ley 81 de 2019, sensitive personal data

Do not transfer sensitive personal data (data touching a person's intimate sphere, or whose misuse could enable discrimination or serious risk, including racial or ethnic origin, religious or philosophical belief, union affiliation, political opinion, health, sexual orientation, or genetic or biometric data) unless the data subject gave explicit authorization or a narrow statutory exception applies.

Take a data subject's consent to processing sensitive health data only when it is prior, irrefutable and express, a higher bar than ordinary consent.

+1 more
Paraguay Ley N° 7593/2025, tratamiento de datos sensibles y categorías especiales from , in 14 months

Treat racial or ethnic origin, religious or political belief, health, sexual orientation, genetic data and biometric data used to uniquely identify a person as sensitive data, and process it only on one of the law's narrow grounds.

Do not process sensitive data at all unless one of the narrow grounds article 20 lists applies, such as the data subject's own consent or data the person has made public.

+1 more
Pennsylvania House Bill 78, sensitive data and biometric data definitions proposed

If enacted, obtain opt-in consent before processing sensitive data, including biometric or genetic data collected to uniquely identify an individual.

Peru Ley 29733, sensitive personal data and minors

For sensitive data (biometric data that by itself identifies a person, racial or ethnic origin, income, political, religious, philosophical or moral opinions, union affiliation, or health or sex-life information), obtain the titleholder's consent in writing, in addition to the general consent requirements, and do not process it without that written consent unless a law authorizes processing without it on important public-interest grounds.

Process health data without consent only where necessary, in a risk situation, for the titleholder's medical or surgical prevention, diagnosis, or treatment at a health establishment or by a health-sciences professional observing professional secrecy, for a public-interest or public-health reason the Ministry of Health has qualified as such, or for an epidemiological or similar study using an adequate dissociation procedure.

Portugal GDPR Article 9, Special Categories of Personal Data as Applied in Portugal

Ground the processing of any biometric identifier of a person in Portugal, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent.

Puerto Rico Ley para la Protección de la Privacidad Cibernética de los Niños y Jóvenes (children's online privacy)

Do not publish or disclose a known minor user's personal information beyond their name and city of residence without the minor's and a parent's or guardian's consent.

Do not profile a known minor through fully automated processing of their personal information unless the profiling is reasonably necessary to the service or serves a compelling, minor-protective purpose, and safeguards are in place.

Québec Express consent for sensitive personal information

Obtain the person's express consent, not an inferred or bundled one, before using sensitive personal information for a new purpose or communicating it to a third person.

Republic of the Congo Law No. 29-2019, special categories of personal data

Do not collect or process personal data revealing ethnic or regional origin, filiation, political opinions, religious or philosophical beliefs, trade union membership, sex life, genetic data, or a person's state of health, unless one of the article 15 grounds applies.

Process genetic data itself only to verify a genetic link for a person's identification, or for the prevention or repression of a specific criminal offence, in the administration of proof in court.

+2 more
Rhode Island Rhode Island Data Transparency and Privacy Protection Act, sensitive data and biometric data definitions

Obtain a Rhode Island customer's opt-in consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual.

Romania GDPR Article 9 and Law 190/2018 Automated Decision-Making and CNP Rules from a date not yet set

Obtain explicit consent or express legal authorization, with adequate protective measures, before using genetic, biometric, or health data of a person in Romania to drive an automated decision or profile, per commentary describing Law 190/2018.

Russia Federal Law No. 152-FZ, Articles 10-11, Special Categories and the Biometric Data Definition

Obtain written consent before processing biometric personal data of a person in Russia, including an identifier such as a facial image or voice recording that would fall under Article 11's general definition, unless a narrow Article 11(2) statutory exception applies.

Never make provision of biometric data a condition of service to a person in Russia, except where a separate federal law affirmatively mandates identification.

Rwanda Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data

Process sensitive personal data, including genetic or biometric information, race, health status, criminal records, religious or philosophical beliefs, political opinion, sexual life or family details, only on one of the five grounds article 10 lists, such as the data subject's consent, a vital interest, public health, or archiving, scientific or statistical purposes.

Before processing personal data you know belongs to a child under sixteen, obtain the consent of a holder of parental responsibility over the child, unless the processing is necessary to protect the child's vital interest.

+1 more
Saint Kitts and Nevis Data Protection Act, 2018, processing of sensitive personal data from a date not yet set

Do not process sensitive personal data, meaning information about a data subject's physical or mental health, sexual orientation, political opinions, religious or similar beliefs, or an offence they committed or are alleged to have committed, unless a listed exception applies.

Process sensitive personal data only with the data subject's explicit consent, for an employment right or obligation, to protect vital interests where consent cannot be given or has been unreasonably withheld, for medical purposes by a healthcare professional or an equivalent confidant, for legal proceedings, advice, or the administration of justice, or where the data subject has deliberately made the information public.

Saint Lucia Data Protection Act, sensitive personal data

Do not process a special category of sensitive personal data (racial or ethnic origin, political opinion, religious belief, physical or mental health, sexual orientation, or criminal or financial record) unless a listed ground applies, the person has given explicit consent, or the person already published it themselves.

Process sensitive personal data for health or medical purposes only through a health practitioner or someone bound by professional confidentiality, and only for preventive medicine, public health, medical diagnosis, medical research, or managing health and hospital care services.

+1 more
San Marino San Marino Law No. 171, special categories of personal data

Obtain explicit consent or another Article 8(2) exception before capturing or storing a biometric identifier of a person in San Marino; Article 8(1) prohibits biometric processing for unique identification absent one.

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data or data concerning health, sex life or sexual orientation, unless one of the article 8(2) cases applies.

+2 more
Sao Tome and Principe Lei n.º 03/2016, sensitive categories and suspect records

Before processing a sensitive category of data (political, religious, trade-union or philosophical affiliation, racial or ethnic origin, private life, health, sex life, or genetic data), obtain the holder's explicit authorization, rely on a specific legal provision, or obtain NAPPD authorization for an important public interest.

Where you process health or sex-life data, including genetic data, for preventive medicine, diagnosis, care or health-service management, do so only through a health professional or another person bound by professional secrecy, notify NAPPD of the processing, and secure it with appropriate information-security measures.

+1 more
Saudi Arabia Personal Data Protection Law, sensitive data and biometric processing

An app that derives a faceprint, voiceprint, or other identity-linked biometric identifier from an individual in Saudi Arabia, for any purpose the purpose-based Sensitive Data definition would reach, must obtain the Data Subject's explicit consent before processing it, and must destroy it once the processing purpose is fulfilled or consent is withdrawn.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel, catégories sensibles de données

Before collecting or processing data revealing racial, ethnic, or regional origin, political opinion, religious or philosophical belief, trade union membership, sexual life, genetic data, or health, confirm one of the Act's narrow exceptions applies.

Process data on criminal offences, convictions, or security measures only if you are a court, a public authority, a public-service body, or a legal auxiliary acting within your legal mission.

+1 more
Serbia Law on Personal Data Protection, special categories of personal data and minors

Do not process data revealing racial or ethnic origin, political opinion, religious or philosophical belief, or trade union membership, or process genetic data, biometric data for unique identification, health data, or data about a person's sex life or sexual orientation, unless a listed exception applies, such as the person's explicit consent for one or more specified purposes.

Where a minor is 15 years old or older, their own consent is enough to process personal data for an information-society service; below that age, get consent from the parent exercising parental responsibility or another legal representative, and take reasonable steps to verify it.

+2 more
Seychelles Data Protection Act, 2023, sensitive data and data of minors

Do not process race, ethnic origin, biometric, genetic, political, religious or health-related personal data unless a specific exception in section 22 applies.

Obtain consent from a parent or legal guardian before processing the personal data of a person below 18 years, and verify that such consent has been given.

Slovakia GDPR Article 9 and Act Section 78, National Birth Number from a date not yet set

Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, genetic, or health data of a person in Slovakia.

Do not process or disclose a Slovak birth number (rodne cislo) without the data subject's explicit consent or their own prior disclosure, per commentary describing Act Section 78; verify this against the Act's own text before relying on it.

Somalia Data Protection Act, 2023, sensitive personal data and children's consent

Obtain consent from a parent or other appropriate legal representative before processing the personal data of a child or of an individual otherwise lacking legal capacity, unless the child is sixteen or older and is asking for an electronic service themselves.

Apply appropriate processes to verify the identity and age of a data subject and of a representative giving consent for them.

South Africa Protection of Personal Information Act, special personal information and children

Do not process special personal information, including a person's biometric information, health, race, or political persuasion, unless a listed ground under sections 27 to 33 applies.

Do not process a child's personal information unless a competent person has given prior consent, another listed ground in section 35(1) applies, or the Information Regulator has authorised the processing as being in the public interest with appropriate safeguards.

+2 more
South Dakota Genetic Data Privacy Act, definitions, consent, and consumer rights

Obtain a South Dakota consumer's opt-in express consent, separately for collection, third-party transfer, research use, retention beyond the initial test, and marketing use of genetic data or a biological sample, if you operate a direct-to-consumer genetic testing service.

Honor a consumer's revocation of consent and destroy their biological sample within 30 days.

South Korea Personal Information Protection Act, sensitive information and biometric data

An app that derives a faceprint, voiceprint, or other unique biometric identifier from a Korean data subject, including one derived from a photo, video, or audio recording, must treat it as sensitive information under PIPA Art. 23 and obtain separate, specific consent before processing it.

Spain GDPR Article 9 and AEPD Biometric Guidance, Special Categories

Do not deploy a biometric employee time-and-attendance system in Spain on the Estatuto de los Trabajadores alone; the AEPD's own guidance holds that statute does not itself authorize biometric means, and a genuine GDPR Article 9(2) basis is needed.

Do not run a facial-recognition matching system against members of the public without a valid Article 9.2 exception; the AEPD categorically prohibited exactly that in its Mercadona enforcement and fined it EUR 2,520,000.

Sri Lanka Personal Data Protection Act, special categories and biometric data

An app that derives a faceprint, voiceprint, or other biometric identifier used to uniquely identify a person in Sri Lanka must treat it as a special category of personal data and satisfy one of Schedule II's conditions, ordinarily the data subject's consent, before processing it.

Suriname Draft Law on the Protection of Privacy and Personal Data, special categories, children and criminal data proposed

Process a child's personal data based on consent only where the child is at least sixteen, or where a legal representative has consented for a younger child after you take reasonable steps to verify that; never process a child's personal data in a way inconsistent with the child's interest.

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data about a person's sexual behaviour or orientation, unless a listed exception applies, such as the data subject's explicit consent.

+1 more
Switzerland FADP Article 5 lit. c, Sensitive Personal Data Including Biometric Data

Obtain express, affirmative consent, opt-in rather than opt-out, before creating a voiceprint or other biometric identifier from a person in Switzerland, or establish another Article 6 basis for the processing.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, sensitive personal data

Obtain the data subject's written and explicit consent before processing their sensitive personal data, unless a legally authorized case applies.

Obtain the consent of a child's legal guardian before processing a child's personal data, and where a child takes part in a game, competition or other activity that calls for personal data, collect no more than participation requires.

Tanzania Personal Data Protection Act, 2022, sensitive personal data

Obtain the data subject's prior written consent before processing genetic, biometric or other sensitive personal data, including data related to a child, and where the data subject is a minor or otherwise unable to consent, seek that consent from a parent, guardian or other legal representative.

Tennessee Tennessee Information Protection Act, sensitive data and biometric definition

Obtain a Tennessee consumer's consent before processing sensitive data, including biometric or genetic data processed to uniquely identify the individual.

Texas Texas Data Privacy and Security Act, sensitive data and biometric consent

Obtain a Texas consumer's opt-in consent before processing sensitive data, including biometric or genetic data collected to uniquely identify the individual, racial or ethnic origin, religious belief, a health diagnosis, sexuality, immigration status, or precise geolocation.

Follow the Children's Online Privacy Protection Act's consent framework, not TDPSA's general consent rule, when processing a known child's sensitive data.

Thailand Personal Data Protection Act, sensitive and biometric categories

An app that captures or processes a faceprint, iris scan, fingerprint, voiceprint, or other biometric identifier from an individual in Thailand must obtain that individual's explicit consent under Section 26 before processing, unless a statutory exception applies.

Timor-Leste Constitution of Timor-Leste, Section 38(3) (Sensitive categories of personal data)

Obtain the person's consent before processing data on their private life, political or philosophical convictions, religious faith, party or trade union membership, or ethnical origin.

Do not rely on a legitimate-interest, contract or public-task basis for those categories: the Constitution prohibits processing them without consent and states no alternative.

Togo Loi n° 2019-014, données sensibles

Do not collect or process data revealing racial or ethnic origin, filiation, political, religious or philosophical opinions, trade union membership, sex life, or health or genetic data, unless a listed exception applies, such as the data subject's written consent or a vital interest that prevents them from consenting.

Process data on criminal offenses, convictions or security measures only as a court, a public authority, a body managing a public service, or a legal auxiliary acting within your legal duties.

+1 more
Tonga Privacy Act 2025, sensitive personal information and children from a date not yet set

Do not process sensitive personal information, including biometric data such as a voiceprint or facial image, unless a section 27 basis is met and, in addition, the data subject has given and not withdrawn consent to that specific purpose or another section 28 ground applies.

Before processing a child's personal information, or that of an individual lacking capacity to consent, obtain the consent of a parent or other appropriate legal guardian and apply appropriate age and consent verification mechanisms, including government approved identification documents.

Trinidad and Tobago Data Protection Act, 2011, sensitive personal information

Section 6(h)'s general principle already binds everyone who handles, stores or processes personal information: do not process sensitive personal information (racial or ethnic origin, political affiliation or trade union membership, religious belief, physical or mental health, sexual orientation, or criminal or financial record) unless a written law otherwise provides for it.

Once Part III is in force, a public body may process sensitive personal information only with the person's consent, or where a listed exception applies, such as health care treatment by a health care professional, information the person already made public, research under section 43, law enforcement or national security, or determining access to social services.

+1 more
Tunisia Organic Act on the Protection of Personal Data, sensitive categories and minors

Do not process personal data about a person's criminal offences, their detection, prosecution, penalties, preventive measures or judicial record.

Do not process data revealing racial or genetic origin, religious, political, philosophical or trade union opinions, or health, unless the person gives express written consent, the data is already manifestly public, or the processing serves a historical, scientific or vital-interest purpose.

+2 more
Turkey Personal Data Protection Law (KVKK), special categories and biometric data

An app that captures or processes biometric data, including a voiceprint or faceprint, from a person in Turkey must treat it as special-category data under KVKK Art. 6 and obtain explicit consent or rely on one of Art. 6(3)'s other statutory grounds before processing, even though the Act does not itself define what counts as biometric data.

Turkmenistan Law on Information About Private Life, special categories of personal information

An app processing a Turkmen data subject's nationality, skin color, religious attitude, political conviction, health, or intimate-life data must have the subject's written consent, rely on publicly available data, or fall within a narrow list of justice, health, or membership-organization exceptions; such processing is prohibited by default otherwise.

Uganda Data Protection and Privacy Act, 2019, children and special personal data

Do not collect or process a child's personal data unless the child's parent, guardian, or another person with authority to decide for the child has given prior consent, or the collection or processing is necessary to comply with the law or is for research or statistical purposes.

Do not collect or process personal data about an individual's religious or philosophical beliefs, political opinion, sexual life, financial information, or health status or medical records, unless a listed exception applies.

+1 more
United Kingdom R (Bridges) v Chief Constable of South Wales Police, Automated Facial Recognition by Police

If you are a public authority deploying facial recognition or another biometric surveillance system in the United Kingdom, put an adequate legal framework and a proper Data Protection Impact Assessment in place before deployment, not after.

United Kingdom UK GDPR Article 9, Special Categories of Personal Data Including Biometric Data

Obtain explicit consent, or establish another UK GDPR Article 9(2) or Data Protection Act 2018 Schedule 1 basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available.

Treat biometric data as covered from the moment you collect it once you have determined a purpose of unique identification, not only from the point you actually perform identification or verification, per the ICO's Biometric recognition guidance.

United States HIPAA Privacy Rule

Do not use or disclose protected health information except as the Privacy Rule permits or requires, and limit use and disclosure to the minimum necessary.

United States Video Privacy Protection Act

Obtain the consumer's informed, written consent before disclosing personally identifiable information about the consumer's video-viewing history to a third party.

Uruguay Ley N° 18.331, sensitive personal data and health data

Do not require anyone to provide sensitive data (racial or ethnic origin, political opinion, religious or moral conviction, union affiliation, health, or sexual life), and process what you do collect only with the data subject's express written consent.

Collect and process sensitive data absent that consent only where an interest-general law authorizes it, the requesting body has a legal mandate to do so, or the purpose is statistical or scientific and the data is disassociated from its subject.

+2 more
Utah Genetic Information Privacy Act

Obtain a Utah consumer's initial express consent before collecting, using, or disclosing their genetic data through a direct-to-consumer genetic testing product or service, and give them a public privacy notice describing your data practices.

Obtain separate express consent before transferring genetic data outside your vendors, using it beyond the primary testing purpose, or retaining a biological sample after testing.

+1 more
Uzbekistan Law on Personal Data, special personal data

An app processing an Uzbek data subject's racial, social-origin, political, religious, ideological, trade-union, health, private-life, or criminal-record data must have the subject's written consent, rely on a state-security purpose, or rely on data the subject has already published in publicly available sources; such processing is prohibited by default otherwise.

Vanuatu Data Protection and Privacy Act 2024, special categories and children's personal data

Do not process special categories of personal data, including biometric data such as a voiceprint or facial image, genetic data, or data revealing racial or ethnic origin, political opinions, trade-union membership, religious belief, health or sexual life, unless an exception in section 6(2) applies, such as the data subject's explicit consent or a safeguarded public-interest ground.

Before processing a child's personal data, obtain the consent of a parent, carer or legal guardian, communicate with the child in clear and plain language, and put appropriate age-verification mechanisms in place, unless the processing is in the child's legitimate interests or is necessary for preventive or counselling services offered directly to the child.

Vermont Vermont Data Privacy and Online Surveillance Act, sensitive data and biometric data definitions from , in 15 months

Once in force, treat any genetic or biometric data you collect about a Vermont consumer as sensitive data requiring opt-in consent, without needing to show the data was collected to identify that person.

Virginia Virginia Consumer Data Protection Act, sensitive data and biometric data definitions

Obtain a Virginia consumer's opt-in consent before processing sensitive data, including genetic or biometric data collected to uniquely identify the individual.

Washington HB 1155, My Health My Data Act

Obtain separate, affirmative opt-in consent before collecting or sharing a Washington consumer's health data, including any biometric identifier used to infer a health condition, whether captured live or extracted from a stored photo, video, or audio recording.

Obtain a further signed authorization before selling consumer health data.

+1 more
Zambia Data Protection Act, 2021, sensitive personal data, children and vulnerable persons

Obtain explicit consent, or rely on another applicable ground, before processing sensitive personal data, including biometric or genetic data, a child's data, political opinions, or health information.

Process a child's or a vulnerable person's personal data only with the consent of their parent, legal guardian or a person exercising parental responsibility.

+3 more
Zimbabwe Cyber and Data Protection Act, sensitive, genetic, biometric and health data

Obtain the data subject's written consent, withdrawable at any time, before processing sensitive data such as race, political opinion, religion, trade union membership, sex life, health or criminal history.

Do not process genetic data, biometric data or health data at all unless the data subject has given written consent.

+2 more
Zimbabwe Cyber and Data Protection Regulations 2024, children's information and automated decisions

Obtain the consent of a parent or legal guardian before processing a child's personal information, and do not subject a child's data to automated decision-making that affects the child's rights.

Make reasonable efforts to verify that the consent to process a child's personal information was given or authorised by the parent or legal guardian, taking available technology into account.

Telephone contact

38 laws, 21 places
PlaceLawWhat it asks, as read here
Australia Do Not Call Register Act 2006, Unsolicited Marketing Faxes

Treat consent as express, or reasonably inferred from the account-holder's conduct and business or other relationships; never treat a number as consenting merely because it has been published, treat express consent that does not itself state a period as lapsing three months after it is given, and check any ACMA determination on inferring consent for a marketing fax sent to a business number.

Australia Do Not Call Register Act 2006, Unsolicited Telemarketing Calls

Treat consent as express, or reasonably inferred from the account-holder's conduct and business or other relationships; never treat a number as consenting merely because it has been published, and treat express consent that does not itself state a period as lapsing three months after it is given.

Australia Telecommunications (Telemarketing and Research Calls) Industry Standard 2017

Do not make, cause to be made, or attempt to make a telemarketing call that is not a research call on a weekday before 9am or after 8pm, a Saturday before 9am or after 5pm, a Sunday, or a listed national public holiday (or its in-lieu weekday holiday), unless the account-holder or their nominee gave express advance consent to that day or time.

California Automatic Dialing-Announcing Devices Act

Before disseminating the prerecorded message, give the person called an unrecorded, natural-voice announcement stating the nature of the call and the caller's name and either an address or telephone number, ask whether the person consents to hear the prerecorded message, and, if the message uses an artificial voice (one generated or significantly altered using artificial intelligence), disclose that fact; disconnect the device when either party ends the call.

California Consumers Legal Remedies Act, Unsolicited Prerecorded Telephone Messages

Before disseminating an unsolicited prerecorded telephone message, first give the person answering an unrecorded, natural-voice statement of your name or the organization you represent and either your address or telephone number, and get that person's consent to listen to the prerecorded message.

California Unsolicited Advertisements by Facsimile Machine

Do not use a fax machine, computer, or other device to send, or cause to be sent, an unsolicited advertisement to a fax machine, where you, the recipient, or both are located in California, unless the recipient gave prior express invitation or permission.

California Unsolicited and Unwanted Telephone Solicitations Act

Do not use the Do Not Call list for any purpose other than compliance, deny a subscriber's right to be placed on it, add a subscriber to it without their knowledge or consent, sell or lease it to anyone other than a telephone solicitor, or charge a fee to place a number on it.

Connecticut Connecticut Action for Unsolicited Facsimile or Automated Telephone Advertising Messages

Do not use a machine that electronically transmits facsimiles through connection with a telephone network, or a device that automatically transmits a recorded telephone message, to transmit unsolicited advertising material or an unsolicited telephone message offering to sell goods or services.

Connecticut Connecticut Telemarketing Act (Conn. Gen. Stat. 42-284 to 42-289, as substantially rewritten by Public Act 23-98)

Do not make, or cause to be made, a telephonic sales call (a live-voice, automated-dialing, recorded-message, soundboard, over-the-top, text or media message call, but not electronic mail) to a consumer without the consumer's prior express written consent: a written agreement, signed by the consumer, that discloses the means of contact and the number to be contacted and clearly and conspicuously authorizes advertisements or telemarketing messages by those means.

Do not knowingly, or while avoiding knowledge, provide substantial assistance or support that enables a person you know or avoid knowing is engaged in telemarketing fraud or a violation of these sections to initiate, originate, route or transmit a voice communication or telephonic sales call; this does not reach designing, manufacturing or distributing a component, product or technology with a commercially significant use beyond circumventing these rules, a provider offering general Internet access, or a terminating network provider completing a call.

Delaware Delaware Harassment Statute (Telephone Solicitation Clause)

Do not, with intent to harass, annoy or alarm another person, communicate with that person by telephone, telegraph, mail or any other written or electronic means, including an intrastate sales call, in a manner you know is likely to cause annoyance or alarm.

Do not knowingly permit a telephone under your control to be used for a purpose this section prohibits.

+1 more
Show the other 28 laws
Florida Florida Telephone Solicitation Act (section 501.059 as rewritten in 2021)

Obtain the called party's prior express written consent, naming the seller and the number to be called, before placing an unsolicited telephonic sales call, text message, or voicemail transmission that uses an automated system for the selection and dialing of telephone numbers or a recorded message played on connection.

Germany Gesetz gegen den unlauteren Wettbewerb, Documentation of Consent to Telephone Advertising

Document a consumer's prior express consent to telephone advertising in an appropriate form at the time the consent is given.

Germany Gesetz gegen den unlauteren Wettbewerb, Telephone Advertising Consent

Obtain a consumer's prior express consent before advertising to them by telephone call.

Before advertising by telephone call to another business or professional market participant (not a consumer), obtain at least that participant's presumed consent, judged by whether the call fits their known or reasonably inferable interests.

Illinois Illinois Automatic Telephone Dialers Act

Do not play a prerecorded sales message placed by an autodialer without the called party's consent.

Disconnect within 30 seconds after the call ends; if that is not technically feasible, have a live operator state their name, the name, address, and telephone number of the business or organization represented, and the purpose of the call, and ask at the outset whether the called person consents to hear the prerecorded message.

+1 more
Illinois Illinois Telephone Solicitations Act

As a live operator, immediately state your name, the name of the business or organization you represent, and the purpose of the call, ask at the outset whether the called person consents to the solicitation, and do not continue without that consent.

Ireland Irish ePrivacy Regulations

Get the called subscriber's or user's prior consent, or check it is recorded as consenting in the National Directory Database, before making an automated-calling or telephone call for direct marketing to a mobile telephone number.

Maryland Maryland prerecorded-message dialing and caller number blocking rules

Do not use an automated dialing, push-button, or tone-activated system with a prerecorded message to solicit a purchase, lease, or rental, offer a gift or prize, conduct a poll, or request survey information used to solicit purchases, unless you have a preexisting business relationship with, or the consent of, the person called.

Maryland Maryland Stop the Spam Calls Act of 2023

Before making, or causing to be made, a telephone solicitation that uses an automated system for the selection or dialing of telephone numbers, or that plays a recorded message when the call connects, get the called party's prior express written consent: a signed written agreement (an electronic signature can qualify) naming the number to be called, with a clear and conspicuous disclosure that signing authorizes those automated or recorded solicitations and that the called party need not sign it, or agree to it as a condition of any purchase.

Do not make a telephone solicitation, including one made through automated dialing or a recorded message, between 8 p.m. and 8 a.m. in the called party's time zone, more than three times to the same person in a 24-hour period on the same subject matter regardless of the numbers used, or while intentionally altering your voice to disguise your identity in order to defraud, confuse, or injure the called party or obtain their personal information.

Massachusetts Telemarketing Solicitation Act

Do not place an unsolicited telephonic sales call to a consumer whose name and telephone number appear on the office's current no sales solicitation calls listing, call between 8 p.m. and 8 a.m. local time at the consumer's location, send the solicitation by fax, or use a recorded message device.

Michigan Home Solicitation Sales Act, Telephone Solicitation Rules (as amended effective 2003)

Do not make a telephone solicitation that consists in whole or in part of a recorded message.

Michigan Telephone Companies as Common Carriers Act, Recorded Commercial Advertising and Caller Identification (section 25 as amended effective 1999)

Do not use a telephone line to contact a subscriber at a residential, business or toll-free number to deliver a recorded message presenting commercial advertising unless the subscriber has knowingly and voluntarily requested, consented to, permitted or authorized the contact, or has knowingly and voluntarily given you the subscriber's telephone number; do not transfer, assign or sell that authorization without the subscriber's written permission.

Montana Unlawful Automated Telephone Solicitation

Do not use an automated telephone system, device, or facsimile machine to dial a telephone number and play a recorded message to offer or sell goods or services, convey information soliciting a purchase, solicit information, gather data, or promote a political campaign.

Montana Unsolicited Advertisement Facsimile Transmissions

Do not use a telephone facsimile machine, computer, or other device to send an unsolicited advertisement, material advertising the commercial availability or quality of property, goods, or a service, to a telephone facsimile machine without the recipient's prior express invitation or permission; this does not reach public safety information sent by a law enforcement or public safety entity.

Nevada Nevada Deceptive Trade Practice Rules for Telephone and Text Solicitations

Do not solicit a person by telephone at their residence between 8 p.m. and 9 a.m.

Nevada Nevada Device for Automatic Dialing and Announcing Statute

Do not use such a device to place a call received in Nevada between 8 p.m. and 9 a.m., or a call-back or second call to a number whose occupant ended the original call.

Oklahoma Telephone Solicitation Act of 2022

Obtain the called party's prior express written consent before making, or knowingly allowing, a commercial telephonic sales call, text message or voicemail that uses an automated system for the selection or dialing of telephone numbers or plays a recorded message when the call connects; the consent must be a signed written agreement (an electronic signature counts where federal law or state contract law recognizes it) that names the telephone number to be called and discloses clearly and conspicuously that the called party need not sign it to buy anything.

Oregon Oregon Automatic Dialing and Announcing Device Statute (as amended by 2025 Or. Laws ch. 580, effective January 1, 2026)

Use such a device to call a subscriber only between 8 a.m. and 8 p.m., and no more than three times in 24 hours, unless one of the government-list exceptions applies or you are responding directly to the subscriber's own message; you may rely on a mobile number's area code to decide whether the subscriber is in Oregon.

Oregon Oregon Unlawful Telephone Solicitations Act (as amended by 2025 Or. Laws ch. 580, effective January 1, 2026)

Do not initiate a telephone solicitation outside the hours of 8 a.m. to 8 p.m., or more than three separate times to a party within a 24-hour period, unless you have an established business relationship with the party (a transaction with the party within the preceding 18 months).

Pennsylvania Telemarketer Registration Act

Do not initiate a robocall to a residential, business or wireless line without the called party's prior express written consent: a signed agreement (an electronic signature can qualify) naming the number, clearly and conspicuously disclosing consent to solicitations including a robocall or text message, and stating that consent is not a condition of purchase; do not use an unfair or deceptive practice to obtain it.

Texas Automatic Dial Announcing Devices

Do not use the device for random or sequential number dialing when it plays a recorded message on connection, for a solicitation call terminating in Texas before noon or after 9 p.m. on a Sunday or before 9 a.m. or after 9 p.m. on a weekday or Saturday, or for a collection call at an hour the federal Fair Debt Collection Practices Act prohibits.

Make the device disconnect within five seconds after either party ends the call, or, if it cannot, have a live operator introduce the call and receive the called person's oral consent before the message begins.

Texas Prohibited Telephonic and Facsimile Communications for Solicitation

Do not make, or use an automatic dial announcing device to make, a telephone call for the purpose of making a sale to a number you know or should know is a mobile telephone the called person will be charged for that specific call, unless that person has consented to receiving it from you or from the business you are calling for.

Do not make or cause a facsimile transmission for the purpose of a solicitation or sale to a device the recipient will be charged for, unless the recipient consented before the transmission, and do not make or cause a solicitation facsimile transmission between 11 p.m. and 7 a.m.

United Kingdom PECR, Automated Calls, Facsimile and Live Telephone Calls for Direct Marketing

Get the called subscriber's prior consent before transmitting, or instigating the transmission of, recorded matter for direct marketing purposes by an automated calling or communication system (one that can automatically dial a sequence of numbers and play sounds that are not live speech), and either do not prevent presentation of your calling line's identity or present a line on which you can be contacted.

Get the called individual's prior consent before making an unsolicited call marketing claims management services; there is no do-not-call-register or existing-customer exception for this subject.

+1 more
United States Telemarketing Sales Rule

Do not deliver a prerecorded telemarketing message to induce a purchase or a charitable contribution without the recipient's prior signed written agreement to receive prerecorded calls from that seller, obtained separately from any purchase requirement.

United States Telephone Consumer Protection Act, Autodialer and Artificial or Prerecorded Voice Calls

Obtain the called party's prior express consent before initiating any call or text to a wireless number using an automatic telephone dialing system or an artificial or prerecorded voice, and before delivering a prerecorded-voice message to a residential line, unless the call is for an emergency purpose.

For a telemarketing robocall or robotext (one that includes or introduces an advertisement or constitutes telemarketing), obtain the recipient's prior express written consent, in a signed writing naming the seller and the telephone number to be called, before sending it; a non-marketing, informational autodialed call or text needs only prior express consent, not a signed writing.

Virginia Virginia Automatic Dialing-Announcing Devices Act

Before an automatic dialing-announcing device (equipment that selects and dials numbers and plays a prerecorded or synthesized voice message) delivers a commercial telephone solicitation to a subscriber in Virginia, either have the subscriber's knowing or voluntary request, consent, permission or authorization to receive it, or have a live operator disclose the sending entity's name, the message's purpose, the kinds of goods or services promoted and, if applicable, that the message seeks payment or a commitment of funds, and obtain the subscriber's consent before the message is delivered.

Virginia Virginia Telephone Privacy Protection Act

Do not initiate, or cause to be initiated, a telephone or text-message solicitation to a Virginia number or resident outside 8:00 a.m. to 9:00 p.m. local time at the contacted person's location, unless that person has given prior consent.

Washington Automatic Dialing and Announcing Device Act

Do not use an automatic dialing and announcing device, a system that automatically dials numbers and plays a recorded or artificial voice message once a connection is made (including one that goes to voicemail), for commercial solicitation to a Washington telephone customer; commercial solicitation means the unsolicited initiation of a call to encourage a purchase of property, goods or services or to wrongfully obtain anything of value, and the section states no consent-based exception.

Do not substantially assist another person in transmitting a commercial solicitation described above while knowing or consciously avoiding knowledge that the initiator is violating this section, unless you are a telecommunications provider that both complied with federal telemarketing rules and implemented a reasonably effective plan to mitigate such calls.

Washington Unsolicited Telefacsimile Messages Act

Do not initiate an unsolicited fax that promotes goods or services for purchase to a recipient with whom you have no prior contractual or business relationship.

Do not send an unsolicited fax to a recipient you knew or reasonably should have known is a government entity, even one with which you have a prior contractual or business relationship.

Biometric privacy

33 laws, 32 places
PlaceLawWhat it asks, as read here
Armenia Law on Protection of Personal Data, biometric data provisions

An app that captures or stores a voiceprint, faceprint, or other biometric identifier from a person in Armenia must obtain the data subject's consent, unless a law-defined purpose can only be achieved through that processing, and must notify the authorized body before beginning to process biometric data, since Armenia's biometric-data definition does not distinguish by modality or by whether the identifier was derived from a recording.

Azerbaijan Law on Personal Data, biometric data enumeration and general processing conditions

An app that captures or stores a facial image, voiceprint (sound fragment and its acoustic parameters in the Act's own term), or other biometric identifier from a person in Azerbaijan is still bound by this Act's ordinary processing conditions, a lawful basis under Art. 9.6 and destruction under Art. 9.4 once the purpose is achieved, even though Azerbaijan does not treat biometric data as a heightened special category and imposes no biometric-specific consent, retention, or storage-technology duty.

Belgium Act of 30 July 2018 Article 9 and GBA/APD Biometric Recommendation and Enforcement

Do not rely on employee consent as the legal basis for a workplace biometric time-registration or access system in Belgium; the Litigation Chamber fined an employer 45,000 EUR for exactly this in Decision 114/2024.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, biometric data processing

Obtain the person's explicit consent before processing a biometric identifier for the individual secure identification of a service user, and only where the processing is otherwise required by law or necessary to protect a person, property, classified information, or a trade secret, and the person's conflicting interests do not prevail, under Article 57a.

Obtain an employee's explicit consent before processing their biometric data to record working time or to control entry to and exit from official premises, and offer it only where required by law or as an alternative to another recording or access method, under Article 57b.

China Provisions on Security Management of Facial Recognition Technology Application

These duties bind the deployment and use of facial recognition; Article 2 exempts facial-recognition R&D and algorithm-training activities from the Measures. Obtain separate, explicit, informed, voluntary consent before collecting or using facial recognition data, with guardian consent for anyone under 14, and use the method with the least impact on individual rights available.

Do not install facial recognition devices inside hotel rooms, public bathhouses, public changing rooms, or public restrooms.

Colorado HB 24-1130, Privacy of Biometric Identifiers and Data

Before collecting a Colorado resident's biometric identifier such as a fingerprint, voiceprint, or facial geometry template, disclose in a clear and accessible manner what is collected, why, and how long it will be kept, and obtain the consumer's consent, whatever your app's overall personal-data processing volume.

Do not sell, lease, or trade a biometric identifier, or disclose one to a third party, without the consumer's consent or a listed statutory exception.

Croatia Croatian Act Articles 21-23, Biometric Data by Sector

Obtain the data subject's explicit GDPR-compliant consent before processing biometric data of a person in Croatia for the individual, secure identification of a service user, per Act Article 22(2).

Offer a non-biometric alternative and obtain explicit consent, or rely on a legal prescription, before deploying employee biometric time-and-attendance or access-control processing in Croatia, per Act Article 23.

Cyprus GDPR Article 9 and Law 125(I)/2018, Genetic and Biometric Data in Cyprus

Do not process genetic or biometric data of a person in Cyprus for life or health insurance purposes, per Law 125(I)/2018's insurance prohibition.

Obtain separate, specific consent, over and above the ordinary GDPR consent standard, before relying on consent as the lawful basis for processing genetic or biometric data of a person in Cyprus.

France CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001)

Do not rely on employee consent alone as the legal basis for a workplace biometric system; use a legal-obligation or legitimate-interest basis, or pair consent with a genuinely equivalent non-biometric alternative.

Georgia Law on Personal Data Protection, biometric data article

An app that captures or stores a facial image, voiceprint, or other biometric identifier from a person in Georgia must have a necessity-based purpose recognized by Art. 9 or the data subject's consent, and must determine in writing, before processing begins, the purpose, volume, storage period, and destruction procedure for that biometric data.

Show the other 23 laws
Greece GDPR Article 9 and Law 4624/2019, Special Categories in Greece

Ground the processing of any biometric identifier of a person in Greece, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent, unless the processing falls within Law 4624/2019's social-security or employment-fitness derogation for grouped genetic, biometric, and health data.

Illinois Biometric Information Privacy Act (BIPA)

Obtain a written release, including informed consent or an accepted electronic signature, before collecting or capturing any retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, after disclosing in writing the specific purpose and length of time the data will be collected, stored, and used.

Never sell, lease, trade, or otherwise profit from a biometric identifier or biometric information, and disclose it only with consent, for a transaction the subject requested, or as required by law or a valid warrant or subpoena.

Indonesia Law on Personal Data Protection, biometric data definition

An app that derives a faceprint, voiceprint, or other biometric identifier from an individual in Indonesia must treat it as specific personal data under Article 4 and obtain the stricter consent Article 21 requires for that category.

Italy Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions

Do not scrape or process publicly posted facial images to build a biometric identification database without a valid GDPR Article 9 basis; the Garante fined Clearview AI EUR 20 million for exactly that and banned further collection.

Japan Act on the Protection of Personal Information, individual identification code and biometric provisions

An app that derives a faceprint, voiceprint, or other individual identification code from a person in Japan, including one derived from a photo, video, or audio recording, must give purpose-of-use notice and avoid wrongful acquisition under APPI's general rules, and must obtain the data subject's consent before disclosing the identifier to a third party.

Japan Act on the Protection of Personal Information, Specific Biometric Personal Information from a date not yet set

An app that handles a data subject's Specific Biometric Personal Information, an individual identification code converted from a bodily feature obtainable without special technology or great expense and of a kind the data subject cannot easily recognize is being captured, must, except in specified cases, notify the data subject in advance or place the purpose of use where the data subject can readily learn it; may not provide it to a third party under the ordinary opt-out mechanism; and must, on the data subject's request, cease using it or stop providing it to a third party without delay, unless a specified exception applies.

Kazakhstan Law on Personal Data and Their Protection, biometric data provisions

An app is not exempt from Kazakhstan's Law on Personal Data merely because biometric data has no dedicated definition in the Act. Collecting biometric data in a public place for identification purposes is restricted to constitutional-order, public-order, rights, health, or morality grounds unless the subject consents, and biometric data stored on Kazakhstani subjects must sit in a database located inside Kazakhstan like any other personal data. Confidentiality of biometric data specifically is deferred to other Kazakh legislation, which the Act does not name and which is not identified here.

Kosovo Law No. 06/L-082 on Protection of Personal Data, use of biometric characteristics

In the public sector, use biometric characteristics only where strictly necessary for the safety of individuals, the protection of property, or safeguarding confidential data and trade secrets, and only where no easier means would achieve that purpose.

In the private sector, apply the same necessity test, inform employees in writing in advance of the measures and their rights, and submit a detailed description of the proposed measures to the Agency for Information and Privacy before taking them.

Malaysia Personal Data Protection Act, biometric data definition and sensitive category

An app that collects or processes a faceprint, voiceprint, or other biometric identifier from an individual in Malaysia, including one derived from technical processing of a photo, video, or audio recording, must obtain the data subject's explicit consent under Act 709's sensitive personal data standard.

Malta GDPR Article 9 and Cap. 586, Genetic, Biometric and Health Data Research Processing in Malta

Ground the processing of any biometric identifier captured for commercial authentication or identification purposes on a GDPR Article 9(2) condition such as explicit consent; Cap. 586's research-specific duty does not reach this use case.

Montenegro Law on Personal Data Protection, biometric measures from a date not yet set

Perform biometric measures, meaning the establishment and comparison of personal traits to establish or prove an individual's identity, only in accordance with this law, under Article 31.

Confine a biometric measure in the public sector to entry into business or official premises and presence at work of employees, provided for by law, and only where the aim cannot be achieved another way, under Article 32.

Netherlands UAVG Article 29, Biometric-Data Exception for Authentication or Security

Rely only on an authentication-or-security purpose, or another GDPR Article 9(2) basis, before processing biometric data of a person in the Netherlands for unique identification; UAVG Article 29's exception reaches no broader purpose on its face.

New York City Biometric Identifier Information Law

A commercial establishment operating in New York City that collects, retains, converts, stores, or shares a customer's biometric identifier information must post a clear and conspicuous sign at every customer entrance disclosing that practice, and must never sell, lease, trade, or otherwise profit from transacting in biometric identifier information regardless of signage.

Poland GDPR Article 9, Act Article 107(2), and Kodeks Pracy Article 22(1b), Biometric Data

Obtain an explicit GDPR Article 9(2) legal basis before processing biometric data of a person in Poland; unlawful processing of biometric data carries a raised criminal penalty ceiling under Act Article 107(2).

Limit an employer's no-consent biometric processing of a Polish employee to controlling access to particularly sensitive information or specially protected premises, and restrict access to authorized, confidentiality-bound staff, per Kodeks pracy Article 22(1b).

Portland Prohibit the Use of Face Recognition Technologies by Private Entities in Places of Public Accommodation

Inside Portland, a product built for or offered to a place of public accommodation must not use face recognition technology to identify, verify, detect, or characterize an individual's facial features, unless the use falls within the ordinance's exceptions for legal compliance, an individual unlocking their own device, or automatic face detection inside a social media application.

Russia Federal Law No. 572-FZ, Unified Biometric System for Identification and Authentication

Route biometric identification, matching an unknown person against a database, of a person in Russia only through the state Unified Biometric System; a private accredited system may only perform authentication, using derived mathematical vectors rather than the original template, and may not transmit those vectors to a third party.

Obtain written consent before processing a person's biometric data in Russia, never condition service on that consent, and retain any biometric sample your organization holds only up to 10 days before deleting it, since the durable copy of record lives in the state system.

Slovenia ZVOP-2 Chapter 4 (Articles 81-84) and Article 80, Biometric and Genetic Data

Treat biometric-data processing in Slovenia as prohibited by default under ZVOP-2 Article 81 unless another Slovenian law both authorizes it and sets its conditions of use; a bare GDPR Article 9(2) basis alone is not sufficient in this jurisdiction.

Do not deploy automated license-plate recognition or a biometric-recognition system on a public surface in Slovenia; ZVOP-2 Article 80 bans this outright, with fines up to EUR 30,000 under Article 105.

Sweden GDPR Article 9, Dataskyddslagen Chapter 3, and the IMY Skelleftea Facial-Recognition Decision

Do not deploy a facial-recognition or fingerprint attendance-tracking system for a person in Sweden on consent alone; IMY treats employer consent as generally invalid given the employment power imbalance and fined the Skelleftea school board for exactly this processing.

Obtain a GDPR Article 9(2) basis, and expect weighty grounds plus a data protection impact assessment to be required, before deploying a biometric identification system in Sweden.

Tajikistan Law on the Protection of Personal Data, biometric personal data

An app that processes a faceprint, voiceprint, or other biometric identifier of a Tajikistani data subject for identification purposes must obtain the subject's written consent, unless the processing falls within a justice, security, or law-enforcement exception. Confidentiality of biometric data specifically is deferred to other Tajik legislation, which the Act does not name and which is not identified here.

Texas Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149

Inform an individual and obtain consent before capturing their retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry for a commercial purpose in Texas.

Do not sell, lease, or disclose a captured biometric identifier except for the narrow statutory exceptions covering identification of a missing or deceased person, a requested financial transaction, legal compulsion, or a law enforcement warrant.

Uruguay Ley N° 18.331, biometric data

Process biometric data only within a lawful basis under article 9 of Ley N° 18.331 (typically the data subject's free, prior, express, and informed consent), since biometric data is not exempt from that consent framework.

Uzbekistan Law on Personal Data, biometric and genetic data

An app that processes a faceprint, voiceprint, or other biometric or genetic identifier of an Uzbek data subject for identification purposes must obtain the subject's consent, subject to narrow statutory exceptions for treaty implementation, administration of justice, or enforcement proceedings. Electronic biometric or genetic data stored outside an information system must be kept on media that exclude unauthorized access.

Washington HB 1493, Biometric Privacy Law

Provide notice, obtain consent, or provide a mechanism to prevent use, before enrolling a biometric identifier such as a voiceprint or faceprint in a database for a commercial purpose. This duty does not reach an identifier generated from a photo, video, or audio recording.

Data subject rights

27 laws, 27 places
PlaceLawWhat it asks, as read here
Belarus Law of the Republic of Belarus On Personal Data Protection, rights of the personal data subject

Let a personal data subject withdraw consent at any time without giving reasons, and within fifteen days of that withdrawal stop processing, erase the data and notify the subject, or, where erasure is not technically possible, restrict further processing and notify the subject instead, under Article 10.

Burkina Faso Personal Data Protection Law, rights of the data subject

Obtain a person's prior consent before sending them unsolicited direct marketing communications of any kind, tell them before their data is first used for that purpose or disclosed to a third party, and let them withdraw consent at any time.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel, droits liés au traitement

Get a person's prior consent before contacting them with direct marketing by phone, fax, SMS, email, instant message, or social network, and let them unsubscribe or change their preferences at any time.

Cyprus GDPR Article 22 and Law 125(I)/2018 Article 31, Decisions About a Person in Cyprus

Do not use personal data you process for archiving in the public interest, scientific or historical research, or statistics to take a decision that produces legal effects for a person in Cyprus or similarly significantly affects them, under Law 125(I)/2018 Article 31.

El Salvador Ley para la Protección de Datos Personales, rights of data subjects

Tell a data subject, before you collect their data, its purpose, its recipients, the database it will sit in, how to reach you and your delegate, the content of their ARCO-POL rights, and the security measures you keep; get a fresh authorization if you later plan a different purpose.

European Union GDPR Article 22, Automated Individual Decision-Making

Do not base such a decision on special category data under Article 9(1) unless the data subject gave explicit consent or the processing serves a substantial public interest, with suitable safeguards in place.

Gabon Law No. 025/2023, rights of the data subject and transparency obligations

Before accessing or storing information on a subscriber's or user's terminal equipment, such as through a cookie, tell them the purpose and how to object, and proceed only once they have consented, except where the access is strictly necessary to provide an electronic communication service they expressly requested.

Ghana Data Protection Act, rights of data subjects

Do not provide, use, obtain, or procure a data subject's personal data for direct marketing without their prior written consent, and stop on their written request at any time.

Jamaica Data Protection Act, 2020, rights of data subjects

Do not process personal data for direct marketing unless the data subject consents or is your customer, and do not approach the same data subject for that consent more than once.

Lebanon Law No. 81/2018, Part V, notice, objection, access and correction

Mark an online promotional advertisement as a promotional advertisement and name the person it was placed for, send no unsolicited marketing email to a real person's name and address without their consent unless you obtained the address lawfully through a previous engagement with them, and put in every marketing email a reply address through which the recipient can ask to stop receiving them permanently and free of charge.

Show the other 17 laws
Libya Law No. 6 of 2022, notice, access and objection rights over personal data

Do not process personal data where doing so causes harm to, or infringes the rights or freedoms of, the person it was collected from.

Do not use a person's data for a purpose other than the one they agreed to without obtaining their consent.

Mauritius Data Protection Act 2017, automated individual decision making

Do not base a decision producing a legal or similarly significant effect on a data subject solely on automated processing, including profiling, unless a listed exception (contractual necessity, a safeguarded legal authorisation, or the data subject's explicit consent) applies.

Do not base automated processing intended to evaluate personal aspects of an individual on special categories of personal data.

Morocco Law No. 09-08, rights of the data subject

Do not send direct marketing by automated call, fax, or electronic mail to anyone who has not given prior consent, and, for the narrow email exception the law allows to existing customers, always let the recipient opt out, free of charge, of further messages.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales, rights of data subjects

Include personal data in a file built for advertising, promotions, offers, or direct sale only with the data subject's consent or from a publicly accessible source, give the data subject free access to it, and let them request removal from it at any time.

Do not send electronic advertising to a person who has expressly stated they do not want to receive it, offer every recipient of an electronic advertisement the means to refuse further advertising or revoke consent, and keep a contract proving the personal data you use for marketing were obtained with consent or from a public access source.

Niger Loi n° 2022-59, droits des personnes concernées

Do not use a person's data for direct marketing without their prior consent, and stop processing their data for direct marketing, free of charge, as soon as they object, telling them of that right before you first use or disclose their data for that purpose.

Oregon Oregon Consumer Privacy Act, consumer rights

Respond to a consumer rights request without undue delay and within 45 days of receipt, decide an appeal within 45 days, and honor a consent revocation within 15 days.

Republic of the Congo Law No. 29-2019, rights of the data subject

Let a minor consent alone to processing of their personal data for an information-society service from age sixteen; below that age, take consent jointly from the minor and the holder or holders of parental authority, and write the information addressed to the minor in clear, simple terms.

Russia Federal Law No. 152-FZ, Article 16, Decisions Based Solely on Automated Processing

Do not make a decision that produces legal consequences for a Russian data subject, or otherwise affects their rights and legitimate interests, solely on the basis of automated processing of their personal data, unless they consented in writing or a federal law that protects their rights provides for it.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel, droits de la personne concernée

Do not send a person direct-marketing communications using their personal data unless they have first expressed consent to receive them.

Somalia Data Protection Act, 2023, information to the data subject and rights of the data subject

Let a data subject withdraw consent as easily as they gave it, and tell them what withdrawing means.

South Africa Protection of Personal Information Act, rights of data subjects

Do not process personal information for direct marketing by electronic communication unless the data subject has consented, or is an existing customer given a free and simple chance to opt out at collection and on every marketing contact afterward.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, rights of data subjects and electronic marketing

Do not process, disclose or divulge personal data without the data subject's explicit consent, unless a legally authorized case applies.

Obtain a data subject's consent, identify yourself as sender, give a correct return address, and label the message as direct marketing before sending any electronic marketing contact, and give the data subject a clear and easy way to refuse it or withdraw consent.

+1 more
Togo Loi n° 2019-014, droits de la personne concernée

Do not send unsolicited direct marketing to a person using their personal data without their prior consent to receive it.

Tunisia Organic Act on the Protection of Personal Data, rights of the data subject

Obtain the person's express, written consent before processing their personal data, and let them withdraw that consent at any time.

Do not rely on a consent given for one form or purpose of processing to cover a different form or purpose, and do not process personal data for advertising without the person's separate, express consent.

United States Children's Online Privacy Protection Rule (COPPA), including 2025 biometric identifier amendments

Obtain verifiable parental consent before collecting, using, or disclosing a child's personal information, including biometric identifiers such as voiceprints or facial templates.

Uzbekistan Law on Personal Data, data subject rights

An app must let an Uzbek data subject learn whether their data is held and processed, obtain information on access conditions, consent to or withdraw from inclusion in public sources, and suspend processing on request where the data is incomplete, outdated, or unreliable.

Zambia Data Protection Act, 2021, automated decisions

Where an automated decision rests on a contract, a written law or explicit consent, put suitable safeguards in place, including the right to obtain human intervention, to put a point of view and to contest the decision, and do not process sensitive personal data automatically at all unless the data subject expressly consented, the processing is in the public interest, or a written law permits it with safeguards.

Enforcement supervision

22 laws, 22 places
PlaceLawWhat it asks, as read here
Angola Law on the Protection of Personal Data, enforcement and supervision

Do not access personal data whose access is barred to you without authorisation, on pain of six months' to two years' imprisonment or a corresponding fine, aggravated where achieved by defeating security rules or for a benefit.

Do not erase, destroy, damage, suppress or modify personal data without due authorisation, on pain of eighteen months' to three years' imprisonment or a corresponding fine, aggravated for particularly serious damage.

Antigua and Barbuda Data Protection Act, 2013, information commissioner and enforcement

Do not intentionally disclose personal information of another person in contravention of this Act, and do not collect, store or dispose of personal information in a manner that contravenes it, each a criminal offence.

Argentina Ley 25.326, enforcement, sanctions, and the habeas data action

Do not access a personal database without authorization, disclose personal data you are bound to keep secret, or insert data into a personal-data file illegitimately; a heavier penalty applies when the conduct reaches a genetic-data databank or DNA registry.

Bahamas Data Protection Act 2003, Commissioner, enforcement and penalties

Do not disclose personal data processed on behalf of a data controller without that controller's prior authority.

Do not obtain access to, or disclose, personal data without the authority of the data controller or data processor who holds it.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, Autorité de Protection des Données Personnelles, sanctions et infractions pénales

Include an unsubscribe link in every unsolicited electronic message you send based on personal data you collected, and do not use another person's or entity's identity to deceive message recipients or website users into disclosing personal or confidential data.

Bermuda Personal Information Protection Act 2016, Commissioner, enforcement and offences

Do not contravene the sensitive personal information restriction, and do not dispose of, alter, falsify, conceal or destroy evidence during a Commissioner investigation or inquiry.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision

Do not access personal data barred to you without due authorisation, on pain of up to one year's imprisonment or a fine of up to 120 days, doubled where achieved by defeating security rules or for a benefit.

Do not erase, destroy, damage or alter personal data without authorisation, on pain of up to two years' imprisonment or a fine of up to 240 days, doubled for particularly serious damage.

Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, article 74 (atteinte à la vie privée et traitement illicite des données à caractère personnel)

Do not record, fix, or transmit another person's private or confidential electronic data without their consent, and do not intercept personal data while it is in transit between information systems.

Do not collect a person's nominative data by unlawful means in order to harm their privacy or standing.

+2 more
Costa Rica Código Penal, artículo 196 bis, Violación de datos personales

Do not appropriate, copy, transmit, publish, or otherwise give unauthorized treatment to a person's data or images without their authorization, since doing so for one's own or a third party's benefit, to the danger or harm of that person's privacy, is a criminal offense.

El Salvador Ley para la Protección de Datos Personales, enforcement and sanctions

Carry the burden of proving that you obtained consent or delivered the privacy notice, and, for an international transfer, that the transfer was lawful.

Do not process personal data without prior consent, deny an ARCO-POL request, use a child's data without parental consent, reverse a pseudonymization, or use, transfer, share or commercialize personal data in violation of this Law.

Show the other 12 laws
Eritrea Penal Code of the State of Eritrea, Violation of Privacy from a date not yet set

Do not intentionally intercept, open, or otherwise interfere with a telephone call, letter, electronic message, or other private communication addressed to another person, without lawful authority.

If facts from a communication not addressed to you come to your attention by mistake, inadvertence, or negligence, do not divulge those facts or derive a gain from them.

Gambia Personal Data Protection and Privacy Act, 2025, the Information Commission, offences and penalties from a date not yet set

Do not sell personal data, and do not process personal data unlawfully for financial gain or to cause harm: both are criminal offences under the Act.

Ghana Data Protection Act, enforcement, offences and penalties

Do not purchase, knowingly obtain, or knowingly or recklessly disclose another person's personal data, and do not sell or offer to sell personal data.

Honduras Código Penal, acceso no autorizado a datos personales (descubrimiento y revelación de secretos)

Do not access, appropriate, alter or use another person's personal data held in a file, register or database, public or private, without authorization and to their detriment.

Do not access another person's documents, papers or communications, or intercept their telecommunications, to learn their secrets or violate their privacy without their consent.

Jamaica Data Protection Act, 2020, the Information Commissioner, penalties and compensation

Do not knowingly or recklessly obtain, disclose or procure the disclosure of personal data without the consent of the data controller concerned, and do not sell or offer to sell personal data obtained that way.

Marshall Islands Criminal Code 2011, Violation of Privacy (unlawful eavesdropping, surveillance, and breach of privacy of messages)

Do not trespass on property, or install a hidden device, with intent to eavesdrop on, observe, photograph, or record sounds or events in a private place, without the consent of the person entitled to privacy there.

Do not install or use, outside a private place, a device that hears, records, amplifies, or broadcasts sounds originating in that place that would not ordinarily be audible or comprehensible outside, without the consent of the person entitled to privacy there.

+2 more
Puerto Rico Código Penal de Puerto Rico, delitos contra el derecho a la intimidad (unauthorized use and disclosure of personal data records)

Do not access, use, modify, or disclose another person's or another company's reserved personal or family data without authorization; doing so is a felony under Puerto Rico's Penal Code, independent of any separate civil privacy duty.

Saint Kitts and Nevis Data Protection Act, 2018, Information Commissioner, enforcement and offences from a date not yet set

Do not wilfully disclose personal information in contravention of the Act, or collect, store, or dispose of personal information in a manner that contravenes the Act.

San Marino San Marino Law No. 171, the Data Protection Authority, remedies and fines

Do not publish or disseminate news or images identifying a child involved in legal proceedings.

Uganda Data Protection and Privacy Act, 2019, enforcement and offences

Do not unlawfully obtain, disclose, destroy, delete, mislead, conceal, alter, sell or offer to sell personal data, on pain of a fine of two hundred and forty to two hundred and forty five currency points or imprisonment of up to ten years, or both.

United States FTC Act Section 5, Unfair or Deceptive Acts or Practices (privacy and data-security enforcement)

Do not engage in unfair or deceptive practices when collecting, using, or sharing personal data.

Venezuela Ley Especial contra los Delitos Informáticos, privacy of personal data and communications (Arts. 20-22)

Do not appropriate, use, modify, or delete a person's personal data or information held in a computer system without their consent.

Do not access, intercept, or reproduce a person's private data message, transmission, or communication signal without authorization.

+1 more

Commercial messages

15 laws, 13 places
PlaceLawWhat it asks, as read here
Australia Spam Act 2003, Address-Harvesting Software and Harvested-Address Lists

Do not supply, or offer to supply, address-harvesting software (software specifically designed or marketed for searching the internet for electronic addresses and collecting, compiling, capturing or otherwise harvesting them) or a harvested-address list, or a right to use either, to another person, where you or the customer is physically present in Australia or an entity carrying on business or activities in Australia at the time, if you have reason to suspect it will be used to send a commercial electronic message in contravention of section 16.

Do not acquire address-harvesting software or a harvested-address list, or a right to use either, while you are physically present in Australia or an entity carrying on business or activities in Australia, if you intend to use it in connection with sending a commercial electronic message in contravention of section 16.

+1 more
Australia Spam Act 2003, Unsolicited Commercial Electronic Messages

Obtain the relevant electronic account-holder's express consent, or consent reasonably inferred from their conduct and business or other relationships, before sending, or causing to be sent, a commercial electronic message (an email, SMS, instant message or similar account message, but not a voice call) that has an Australian link, unless it is a designated commercial electronic message exempt under Schedule 1.

Treat a business or work electronic address as impliedly consenting only if it was conspicuously published, the publication appears to have the agreement of the person or organisation it belongs to, it carries no statement that unsolicited commercial messages are unwanted, and the message you send is relevant to the work, office, function or role the address was published for.

+1 more
California Unsolicited Text Message Advertisements

If you are a person, business, candidate, or political committee in California, do not transmit a text message advertisement, one whose principal purpose is to promote the sale of goods or services or a political purpose, to a mobile telephone, pager, or two-way messaging device, unless an exception applies.

Canada Canada's Anti-Spam Legislation

Get the recipient's prior consent, express or implied, before sending a commercial electronic message (a term broad enough to reach email, SMS and other electronic messages) to an electronic address, unless an exemption applies.

Treat consent as implied, without asking for it, only where you have an existing business relationship (a purchase, lease, barter, written contract, or gaming or investment opportunity within the last two years, or an inquiry or application within the last six months) or an existing non-business relationship (a donation, volunteer work, or membership with a registered charity, political party or candidate within the last two years), or where the recipient conspicuously published or gave you their address without saying they did not want unsolicited messages and the message is relevant to their business, role or duties.

+1 more
Delaware Delaware Unrequested or Unauthorized Electronic Mail Statute

Do not, without authorization, intentionally or recklessly distribute unsolicited bulk commercial electronic mail to a receiving address or account under the control of an authorized user of a computer system, unless the mail is sent between individuals, the recipient requested it, an organization sends it to its own members, or a preexisting business relationship exists.

European Union ePrivacy Directive

Obtain the recipient's prior consent before using an automated calling machine, a fax machine, or electronic mail (including a text message, which the Directive's own definition of electronic mail reaches) to send direct marketing to an individual.

Where you collected a customer's electronic contact details in the course of selling them a product or service, you may market your own similar products or services to that customer without fresh consent, provided you offered a free, easy opt-out at the time of collection and offer it again, free of charge, in every message, unless the customer already refused.

Germany Gesetz gegen den unlauteren Wettbewerb, Commercial Electronic Messages

Obtain the addressee's prior express consent before advertising using an automatic calling machine, a fax machine, or electronic mail, unless the existing-customer exception below applies.

You may market your own similar goods or services to an existing customer by electronic mail without fresh consent only if you obtained their electronic address in connection with a sale, they have not objected to that use, and you clearly told them, both when collecting the address and at every use, that they may object at any time at no cost beyond the basic transmission tariff.

Ireland Irish ePrivacy Regulations

Obtain the recipient's prior consent before sending direct marketing to an individual by automated calling machine, fax, or electronic mail, a term that reaches SMS as well as email.

If an SMS is sent for a purpose other than marketing but includes direct-marketing content, treat it the same as a marketing message and obtain the recipient's prior consent.

+1 more
Nevada Nevada Unsolicited Commercial Electronic Mail Liability Act

Before sending, or causing to be sent, email that includes an advertisement, either have a preexisting business or personal relationship with the recipient, obtain the recipient's express consent, or make the advertisement identifiable as promotional and clearly give your legal name, complete street address and email address, a notice of how to decline further advertising mail, and ADV or advertisement as the first word of the subject line.

Do not disguise the source of an advertisement, use false or misleading subject-line information, give a false return address or a false address for declining mail, ignore a recipient's request to stop, or obtain a recipient's address by a method they did not authorize.

Oklahoma Fraudulent electronic mail messages

Do not initiate an electronic mail message that you know or have reason to know misrepresents or omits information identifying its point of origin or transmission path, falsely claims to be sent by a legitimate online business, or links the recipient to a web page falsely represented as associated with a legitimate online business, to obtain identifying information the recipient believes is being given for a legitimate purpose.

Show the other 5 laws
Pennsylvania Unsolicited Telecommunication Advertisement Act

Do not use a covered mobile telephone messaging system to transmit an unsolicited commercial email message.

United Kingdom PECR, Electronic Mail for Direct Marketing Purposes

Get the individual recipient's prior consent before sending, or instigating the sending of, unsolicited electronic mail, which reaches SMS and other messaging as well as email, for direct marketing purposes, unless the soft opt-in below applies.

You do not need consent if you obtained the recipient's contact details in the course of a sale or sale negotiation with them, you market only your own similar products or services, and you gave the recipient a simple, free means of opting out at the time the details were collected and with every later message.

+1 more
United States CAN-SPAM Act

Do not harvest email addresses from a website or generate them by an automated dictionary attack, and do not falsify the domain name registration information used to send the mail.

United States Restrictions on Mobile Service Commercial Messages

Do not send a commercial message to an address that resolves to a wireless carrier's messaging domain on the FCC's wireless domain names list, unless you have the addressee's express prior authorization naming your business and the address to be messaged.

Washington Commercial Electronic Mail Act, Text Messages

Do not initiate or assist in transmitting a commercial electronic text message to a telephone number assigned to a Washington resident for cellular telephone or pager service with text-messaging capability, unless an exception applies.

You may send one only where the subscriber has clearly and affirmatively consented in advance to receive it, or, if you are the subscriber's own cellular or pager carrier, at no cost to the subscriber, unless the subscriber has said it does not want further commercial text messages from you.

Cross border transfer

4 laws, 4 places
PlaceLawWhat it asks, as read here
China Personal Information Protection Law, Cross-Border Transfer

Give advance notice disclosing the overseas recipient's identity and contact details, and obtain the individual's separate consent, before transferring their personal information abroad.

Jordan Personal Data Protection Law, cross-border transfer

An app transferring or exchanging the personal data of an individual in Jordan with another recipient must obtain the Data Subject's consent, confirm a legitimate interest on both sides, ensure the Data Subject has sufficient knowledge of the purpose, and must not use the data for marketing without a separate consent; Jordan's base Law does not impose an adequacy or localization gate on the transfer.

Somalia Data Protection Act, 2023, cross-border transfers of personal data

Where you transfer without adequate protection on the data subject's consent, inform them of the risks of the transfer first, and stop if they withdraw consent.

Tonga Privacy Act 2025, transfers of personal information outside the Kingdom from a date not yet set

Where you rely on the data subject's consent to transfer without adequate protection, inform them of the risks first and stop if they withdraw it.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.